The question gets asked regularly in telehealth marketing conversations. The answer has not changed since 2022, but many telehealth practices are still operating as though it has not been settled.
The short answer is no. The standard Meta Pixel, installed on a telehealth website in its default configuration, is not a compliant tracking tool for HIPAA-covered entities under current HHS OCR guidance.
The longer answer involves understanding exactly what the pixel does, what changed in 2022, what HHS OCR's guidance on online tracking technologies actually says, and what the compliant alternatives are for a telehealth practice that wants to run Meta advertising without creating regulatory exposure.
This guide covers all of it.
Key Takeaways
- The standard Meta Pixel is not HIPAA-compliant for telehealth sites in its default configuration: It collects and transmits data that can constitute protected health information when installed on health-related pages without appropriate controls in place.
- Meta removed its Business Associate Agreement option for healthcare advertisers in 2022: Without a BAA, Meta cannot be a business associate of a covered entity for the purposes of the data collected by the pixel. This is the foundational compliance gap that most telehealth practices either do not know about or have not yet addressed.
- HHS OCR's 2022 guidance on online tracking technologies is explicit: Regulated healthcare entities must ensure that tracking technologies on their websites and mobile apps do not result in impermissible disclosures of protected health information to tracking technology vendors.
- The data the pixel collects on health-related pages can constitute PHI: When a user visits a condition-specific telehealth page and the pixel captures that visit along with identifiers like IP address, device ID, or cookie data, that combination can constitute individually identifiable health information under HIPAA.
- The compliant alternative is Meta's Conversions API with server-side event filtering: CAPI allows telehealth practices to pass only the pre-selected, non-PHI conversion events they choose to share, giving Meta's algorithm optimization signal without exposing health-related browsing behavior.
- The risk is not theoretical: The FTC's enforcement actions against GoodRx in 2023 and Cerebral in 2024 both involved pixel-based data sharing with advertising platforms. HHS and FTC have signaled coordinated enforcement attention on digital health tracking practices.
- Consent management does not fully resolve the pixel compliance issue: A consent management platform that captures user permission before the pixel fires reduces risk but does not eliminate the fundamental BAA gap that makes the standard pixel non-compliant for covered entities using Meta advertising.
- Most telehealth practices installed the pixel before this guidance existed and have not revisited it: The 2022 OCR guidance changed the compliance landscape for a tracking technology that many telehealth practices had been using without issue for years. Practices that have not reviewed their tracking setup since 2022 are likely still running in a non-compliant configuration.
What the Meta Pixel actually does
Understanding why the pixel creates compliance issues requires understanding what it actually collects and where that data goes.
The Meta Pixel is a piece of JavaScript code that runs in the visitor's browser when they load a webpage where the pixel is installed. In its standard configuration it automatically collects a set of browser and behavioral data including the page URL the visitor is on, the referral URL they came from, button clicks and form interactions, device and browser information including browser type, operating system, and screen resolution, and identifiers including IP address, cookie data, and any hashed user data available in the browser.
This data flows directly from the visitor's browser to Meta's servers in real time. Meta uses it to build and refine advertising audiences, optimize campaign delivery, and attribute conversions to specific ads.
For a retail or software company, this data flow is entirely standard and raises no particular concerns. The pages being visited are product pages, pricing pages, and checkout flows. The data being collected reflects commercial browsing behavior.
For a telehealth practice, the pages being visited include condition-specific service pages, mental health consultation booking forms, GLP-1 program pages, chronic disease management information, and other content that is directly tied to a visitor's health status or health-related interests. When the pixel captures a visit to a page about anxiety treatment or a GLP-1 weight loss program along with the identifiers that can make that visit individually attributable, the result may constitute individually identifiable health information under HIPAA.
What changed in 2022
Two things happened in 2022 that fundamentally changed the compliance landscape for telehealth practices using the Meta Pixel.
First, HHS OCR published its bulletin on the use of online tracking technologies by HIPAA-covered entities and business associates. The bulletin made clear that regulated healthcare entities must ensure that tracking technologies on their websites do not result in impermissible disclosures of protected health information to tracking technology vendors. It specifically addressed the scenario where a user visits a webpage addressing specific symptoms or health conditions and the tracking technology collects data about that visit alongside identifiers that make the user individually identifiable.
Second, Meta discontinued its Business Associate Agreement for healthcare advertisers. Prior to this change, a telehealth practice using the Meta Pixel could establish a BAA with Meta, creating the legal framework under which Meta could handle health-related data as a business associate of the covered entity. When Meta removed the BAA option, that legal framework ceased to exist. The pixel on a telehealth website no longer has the contractual safeguard that HIPAA would require for a vendor receiving PHI.
The combination of these two developments is the core of the compliance issue. The OCR guidance establishes that health-related tracking data can constitute PHI. The removal of the BAA means Meta is not operating as a business associate with the protections HIPAA requires. Together they create a compliance gap that the standard pixel configuration cannot close.
What HHS OCR's guidance actually says
The December 2022 OCR bulletin on online tracking technologies is worth understanding in precise terms because its scope is broader than many telehealth practices realize.
The guidance applies to covered entities and business associates that use tracking technologies on their websites and mobile apps. It clarifies that individually identifiable health information collected through tracking technologies is PHI when the information relates to the past, present, or future physical or mental health condition of an individual, and when there is a reasonable basis to believe the information could be used to identify the individual.
Importantly the guidance notes that PHI can be created by combining seemingly non-health information with health-related context. A user's IP address is not by itself PHI. But an IP address combined with a visit to a page about a specific health condition, collected together by a tracking pixel, may constitute PHI because the combination is individually identifiable health information.
The guidance also addresses the specific scenario of unauthenticated public webpages, meaning the pages any visitor can access without logging in. Many telehealth practices assumed that their public-facing service pages, as opposed to patient portals, were outside HIPAA's scope. The OCR guidance makes clear that tracking on these public pages can still create PHI when the data collected relates to health conditions and is individually identifiable.
The practical implication is that a telehealth practice with the standard Meta Pixel installed on its condition-specific service pages, its GLP-1 program page, its mental health consultation landing page, or any other page that a visitor might access because of a health condition is collecting and transmitting data that may constitute PHI to a vendor without a BAA in place.
The enforcement context: why this is not theoretical
The compliance concern around pixel-based health data sharing moved from theoretical to enforcement reality between 2023 and 2025.
The FTC's February 2023 enforcement action against GoodRx involved the company's use of pixel-based tracking that shared sensitive health data with advertising platforms including Meta and Google. GoodRx paid a $1.5 million civil penalty and agreed to permanent prohibitions on sharing health data for advertising purposes.
The FTC's April 2024 proposed order against Cerebral involved the telehealth company's use of pixel tracking that shared sensitive mental health and substance use data with advertising platforms. The order required significant operational changes to Cerebral's data practices.
HHS and FTC issued a joint letter in July 2023 to approximately 130 hospital systems and telehealth providers warning of the risks of using online tracking technologies that may impermissibly share patient data with third parties.
The September 2025 FDA and HHS initiative targeting digital health advertising, which produced more than 100 cease-and-desist letters and more than 40 warning letters, demonstrated continued coordinated enforcement attention on digital health marketing practices broadly.
The telehealth practice that continues to run the standard Meta Pixel on condition-specific pages without a compliant alternative in place is not managing an abstract regulatory risk. It is operating in a category that federal enforcement bodies have explicitly identified as a priority.
What the compliant alternatives look like
There are three approaches telehealth practices can take to address the pixel compliance issue. They are not mutually exclusive and are often used in combination.
Server-side tracking via Meta Conversions API
Meta's Conversions API replaces or supplements the client-side pixel with a server-side integration. Instead of the pixel firing in the visitor's browser and collecting all browsing behavior, the CAPI integration sends only the specific, pre-selected conversion events that the practice chooses to share, from its own server rather than the visitor's browser.
The practice controls exactly which events are transmitted and what data is included in each event. A consultation booking confirmation can be sent as a conversion event without including information about what the patient was booking for, which condition page they had visited, or any other health-related context from their browsing session.
This approach gives Meta's advertising algorithm the optimization signal it needs to improve campaign performance while eliminating the impermissible health data disclosure that the standard pixel creates. It is the most widely recommended compliant alternative for telehealth practices that want to continue using Meta advertising.
Consent management platform integration
A consent management platform captures user consent before any tracking fires on the website. Users who decline tracking do not have pixel events fired in their session. This approach reduces the volume of data transmitted to Meta but does not fully resolve the BAA gap for users who do consent, because Meta still does not have a BAA in place even with consented users.
Consent management is a required component of a compliant tracking setup but is not sufficient on its own. It works best in combination with server-side tracking rather than as a standalone solution.
Limiting pixel installation to non-health-related pages
Some telehealth practices choose to install the pixel only on pages that do not carry health-related content, such as the homepage, the contact page, and the about page, while excluding it from condition-specific service pages, booking forms for health services, and any other page where health-related browsing behavior could be captured.
This approach limits the optimization signal available to Meta's algorithm and reduces campaign performance, but it does address the most significant compliance exposure points. It is a pragmatic option for practices that cannot implement full CAPI in the near term and need an interim risk reduction measure.
The 2026 update: what has changed since the original OCR guidance
The original December 2022 OCR guidance established the foundational framework. Several developments since then have sharpened the enforcement landscape.
The GoodRx and Cerebral enforcement actions established that the FTC will pursue digital health data sharing violations with meaningful financial penalties and operational restrictions. The joint HHS and FTC letter to hospital systems and telehealth providers in 2023 demonstrated coordinated enforcement intent across agencies. The September 2025 digital health advertising enforcement initiative showed continued and escalating regulatory attention on the practices of digital health marketers.
Importantly, OCR rescinded its December 2022 bulletin in March 2024 and replaced it with updated guidance in June 2024. The updated guidance modified some aspects of the original bulletin but maintained the core position that tracking technologies on health-related pages can create PHI and that regulated entities must ensure those technologies do not result in impermissible disclosures. Practices that understood the 2022 guidance but have not reviewed the 2024 update should do so.
The net effect of these developments in 2026 is a compliance landscape that is more defined, not less. The uncertainty about whether the OCR guidance applied to public-facing web pages, which existed in 2022, has been substantially resolved through enforcement action and updated guidance. Telehealth practices operating with the standard pixel on condition-specific pages in 2026 are operating with less regulatory uncertainty to hide behind than practices in the same position in 2022.
Practical steps for telehealth practices to take now
If your telehealth practice is currently running the standard Meta Pixel on condition-specific pages, the following steps reduce your compliance exposure in order of urgency.
Conduct a pixel audit. Identify every page on your telehealth website where the Meta Pixel is installed and every event that is being fired to Meta. Specifically identify which pages carry health-related content and which pixel events from those pages are being transmitted.
Engage legal counsel. The specific compliance determination for your practice's pixel configuration requires legal analysis from counsel familiar with HIPAA, the OCR guidance on online tracking, and your specific website architecture. This guide is marketing guidance, not legal advice.
Implement consent management. If you do not have a consent management platform in place, implementing one immediately reduces the volume of data being transmitted without consent and demonstrates a proactive compliance posture.
Plan the CAPI implementation. Server-side tracking via Meta's Conversions API is the compliant long-term solution for telehealth practices that want to continue using Meta advertising effectively. Implementation typically takes two to four weeks with the right technical resources and should be prioritized as a near-term project.
Review the June 2024 OCR updated guidance. Ensure your compliance review is based on the current guidance rather than the original December 2022 bulletin that was rescinded.
Frequently Asked Questions

Rupal Patel
Founder & Fractional CMO, Momentum360
Rupal shares practical insights on marketing strategy, lead generation, digital growth, healthcare marketing, and customer acquisition. Her content is shaped by years of hands-on experience helping businesses improve visibility, attract qualified leads, and achieve sustainable growth.




