02
HIPAA-Compliant Measurement
HIPAA-aware analytics, PHI/PII controls, BAA-eligible vendors, healthcare tracking audits, and privacy-safe conversion measurement.
HIPAA-compliant measurement is not a cookie banner problem. It is a data-flow problem: what identifiers are collected, what health context is attached, which vendors receive payloads, and whether the stack can prove PHI was filtered before it reached ad platforms.
Related writing
Curated field notes and guides that support this topic hub.

HIPAA-Compliant Marketing Analytics That Actually Works
A practical HIPAA-compliant marketing analytics guide covering PHI leaks, BAAs, server-side filtering, and audit-safe conversion tracking.

Your "HIPAA-Compliant" Tracking Probably Isn't
I've audited tracking setups at healthcare companies that were confident they were compliant. Most had PHI flowing through Google Ads tags. Here's how to check yours.

How PHI Leaks Through Google Ads Tags in Healthcare
Google Ads tags transmit PHI from healthcare sites by default. URL paths, Enhanced Conversions, and remarketing lists are the three main vectors. Here's how each works and how to close them.

How to Audit Your Healthcare Website for Tracking Compliance
A step-by-step healthcare website HIPAA audit you can run yourself in an afternoon, covering PHI in URLs, consent gating, hardcoded scripts, and BAA gaps.

HIPAA and Google Analytics: What You Can and Can't Track
Google won't sign a BAA for GA4 — that's the hard stop. What GA4 collects by default, how it becomes PHI in healthcare contexts, and what a compliant stack looks like.

HIPAA-Safe Alternatives to Google Analytics for Healthcare
GA4 won't sign a BAA, which means it's a HIPAA violation on most healthcare sites. Here's a breakdown of the analytics platforms that will sign one and what switching actually costs you.

How to Run Meta Ads for Healthcare Without Sending PHI
A practical setup for HIPAA compliant Meta ads: what data you can safely send to the Pixel and CAPI, what has to be stripped, and how to verify it in the payload.

What a BAA Actually Covers (And What It Doesn't) for Marketing Tools
A signed business associate agreement doesn't make your marketing stack HIPAA-compliant. Here's exactly what a BAA covers, what it leaves exposed, and why most healthcare marketing teams misread it.

Consent Architecture for Healthcare Websites
A HIPAA consent banner that doesn't gate server-side requests isn't protecting patients. Here's how to architect consent so it actually stops PHI from leaving your stack.