03
Consent, Privacy & Compliance Architecture
Design consent-aware and compliance-safe measurement systems that preserve useful reporting without exposing sensitive customer data.
Consent is no longer just a banner. It determines which tags fire, what identifiers can be collected, what reaches ad platforms, and whether measurement is safe in regulated environments like healthcare.
Related field notes
All published writing currently classified under this system layer.
HIPAA-Compliant Marketing Analytics That Actually Works
A practical HIPAA-compliant marketing analytics guide covering PHI leaks, BAAs, server-side filtering, and audit-safe conversion tracking.

Server-Side GTM Now Ships Unconsented Floodlight Hits Server-to-Server
Floodlight tags in server-side GTM now transmit unconsented requests server-to-server for modeled conversions. Audit consent gating before your numbers move.

What a BAA Actually Covers (And What It Doesn't) for Marketing Tools
A signed business associate agreement doesn't make your marketing stack HIPAA-compliant. Here's exactly what a BAA covers, what it leaves exposed, and why most healthcare marketing teams misread it.

Consent Architecture for Healthcare Websites
A HIPAA consent banner that doesn't gate server-side requests isn't protecting patients. Here's how to architect consent so it actually stops PHI from leaving your stack.

Disney's $2.75M CCPA Settlement Is an Opt-Out Architecture Problem, Not a Banner Problem
California's record $2.75M CCPA settlement with Disney targets inconsistent opt-out signals across streaming surfaces. Here's what that means for consent and server-side tagging stacks.

How to Run Meta Ads for Healthcare Without Sending PHI
A practical setup for HIPAA compliant Meta ads: what data you can safely send to the Pixel and CAPI, what has to be stripped, and how to verify it in the payload.

Server-Side Tracking for Healthcare: Why It's the Only Compliant Path
Client-side tracking can't be made HIPAA compliant no matter how you configure it. Here's why server-side tracking with a BAA-covered infrastructure is the only architecture that actually works.

Google Ads API v24.2: Multi-Party Approvals and AI-Content Fields Change How You Manage Client Accounts
Google Ads API v24.2 adds multi-party approvals, SyntheticContentInfo fields for AI creative disclosure, and expanded Performance Max reporting. Here's what to fix in your account governance and reporting pipeline.

HIPAA-Safe Alternatives to Google Analytics for Healthcare
GA4 won't sign a BAA, which means it's a HIPAA violation on most healthcare sites. Here's a breakdown of the analytics platforms that will sign one and what switching actually costs you.

How to Audit Your Healthcare Website for Tracking Compliance
A step-by-step healthcare website HIPAA audit you can run yourself in an afternoon, covering PHI in URLs, consent gating, hardcoded scripts, and BAA gaps.

Consent Mode v2 and Server-Side Tracking: How They Work Together
Consent Mode v2 and server-side tracking aren't competing solutions. Here's how they actually connect, and why running server-side GTM doesn't make you exempt from consent gating.

HIPAA and Google Analytics: What You Can and Can't Track
Google won't sign a BAA for GA4 — that's the hard stop. What GA4 collects by default, how it becomes PHI in healthcare contexts, and what a compliant stack looks like.

How PHI Leaks Through Google Ads Tags in Healthcare
Google Ads tags transmit PHI from healthcare sites by default. URL paths, Enhanced Conversions, and remarketing lists are the three main vectors. Here's how each works and how to close them.

Your "HIPAA-Compliant" Tracking Probably Isn't
I've audited tracking setups at healthcare companies that were confident they were compliant. Most had PHI flowing through Google Ads tags. Here's how to check yours.
