NOVRASCALE
PlatformPricing
Client LoginBook a Free Call
NOVRASCALE
6 min read•Jan 12, 2026•By Matt Delgado

The FTC Warned 130 Hospitals About Google Analytics. Your Practice Website Is Next.

FTC and HHS warned hospitals about Google Analytics on healthcare websites. Here's why your practice's analytics setup may be creating HIPAA exposure right now.

If your practice website uses Google Analytics, you may be creating HIPAA compliance exposure every time a patient visits your site. In July 2023, the Federal Trade Commission and the Department of Health and Human Services sent a joint warning letter to approximately 130 hospital systems and telehealth providers about exactly this risk.

Source: FTC.gov, “FTC and HHS Warn Hospital Systems and Telehealth Providers about Privacy and Security Risks from Online Tracking Technologies,” July 20, 2023

The letter wasn’t a suggestion. It was a warning that tracking technologies — specifically naming Google Analytics and Meta Pixel — pose direct risks to patient privacy when used on healthcare websites.

How Google Analytics Creates PHI Exposure

Google Analytics works by tracking user behavior across your website: which pages they visit, how long they stay, what they click, and where they came from. On a retail website, this is standard marketing data. On a healthcare website, it becomes Protected Health Information.

Here’s the specific chain of events that creates a violation:

  1. A patient visits your “Depression Treatment” or “Anxiety Counseling” page. Google Analytics records this visit.
  2. The same patient fills out your contact form or books an appointment. Google Analytics now has their identity linked to their browsing behavior.
  3. The combination of a person’s identity and their interest in specific health services constitutes PHI under HIPAA’s definition.
  4. That PHI has been transmitted to Google — a third party that has not signed a Business Associate Agreement with your practice.

This is an impermissible disclosure of PHI under HIPAA, regardless of whether Google actually uses the data. The disclosure itself is the violation.

A note on the legal landscape: In June 2024, a federal court in AHA v. Becerra narrowed OCR’s position, ruling that IP addresses combined with page visits on unauthenticated public pages do not automatically constitute PHI. However, the core risk remains: when a patient identifies themselves through a form submission, scheduling request, or authenticated session, and that identity is linked to health-related browsing behavior by analytics, the combination is PHI. The ruling narrowed the scope but did not eliminate the risk for any practice collecting patient information through its website.

Not sure if your analytics setup is creating exposure? Get a free compliance check →

What HHS Says About Tracking Technologies

HHS’s Office for Civil Rights issued a formal bulletin stating that “HIPAA-regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of protected health information to tracking technology vendors or any other violations of the HIPAA Rules.”

Source: HHS.gov, “Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates”

The bulletin specifically defines tracking technologies as “scripts or code on websites or mobile apps that gather information about users and their actions, usually without their knowledge and in ways difficult for users to avoid.” Google Analytics fits this definition precisely.

The Scope of the Problem

This isn’t a theoretical risk. In 2024, 742 healthcare data breaches affecting 500 or more individuals were reported to OCR — resulting in 276.8 million breached records, the worst year on record. That represents a 64.1% jump from 2023.

Source: HIPAA Journal, “Healthcare Data Breach Statistics — Updated for 2026”

While not all of these breaches involve tracking technologies, the FTC’s warning signals that this is an area of active regulatory scrutiny. Enforcement actions are increasing: 20 enforcement actions have been announced since January 2024, with fines ranging from $25,000 to $3 million.

Source: Shook, Hardy & Bacon, “OCR Enforcement Activity: Trends and Insights From a Limited Sample,” March 2025

What to Use Instead

The good news: compliant analytics alternatives exist that give you the traffic data you need without creating PHI exposure.

  • Plausible Analytics — lightweight, privacy-first, no cookies, no personal data collection. Because it collects no personal data, no PHI exposure is created and no BAA is needed.
  • Fathom Analytics — privacy-focused, does not track individual users, does not use cookies. No personal data collection means no PHI involvement.
  • Piwik PRO — enterprise-grade analytics with a Healthcare plan that includes BAA signing, data hosting in compliant environments, and full HIPAA compliance features.
  • Matomo (self-hosted) — open-source analytics installed on your own BAA-covered server. Complete data ownership. No third-party data sharing.

The key difference: these tools either don’t collect PHI at all (Plausible, Fathom) or keep it within your BAA-covered environment (Piwik PRO, self-hosted Matomo). Google Analytics sends data to Google’s servers, where you have no BAA coverage and no control.

The bottom line: If your practice website uses Google Analytics and collects any patient information through forms, scheduling tools, or chat widgets, you likely have an active HIPAA compliance gap. In our experience auditing practice websites, the majority are running standard Google Analytics alongside non-compliant forms — creating a dual exposure most owners don’t know about. The fix is straightforward, but the exposure accumulates with every patient visit until you act.

Is Your Analytics Setup Creating Compliance Exposure?

We'll check your current tracking configuration and tell you exactly what's safe, what's not, and what to switch to. Specific to your practice's setup.

Get Your Free Report Card

If you run a practice in this space, see how we build for Mental Health Practices.

Related Industries

Mental Health Practices →Dental Practices →Med Spas →

Start here

For the full picture, read the pillar guide: 7 HIPAA Violations Hiding on Your Practice Website Right Now.

NOVRASCALE

AI automation for small business. We build the AI system that catches every lead and books more work, so your schedule fills itself.

Get My Free Report Card

Features

  • Lead Generation
  • Website Design
  • Local SEO
  • AI Receptionist
  • AI Follow-Up
  • AI Review Responder
  • AI Quote Builder
  • Review Generation
  • CRM & Pipeline
All features

Industries

  • HVAC
  • Real Estate
  • Roofing
  • Dental
  • Mental Health
  • Law Firms
All 20 industries

Compare

  • vs. Wix
  • vs. Squarespace
  • vs. WordPress
  • vs. GoDaddy
  • vs. Webflow
All comparisons

Tools & resources

  • Free Website Report Card
  • Money-Leak Calculator
  • The platform
  • Request access
  • Demo walkthrough
  • Portfolio
  • Blog
  • Docs
All resources

Company

  • About
  • Reviews
  • Team
  • Contact
  • Talk to Sales
  • FAQ

© 2026 NovraScale LLC. All rights reserved.

Powered by the NovraScale One Platform
PrivacyTermsCancellationBAASecuritySitemap