ClinicOps  /  Briefings  /  Guide

Guide · Published Jun 15, 2026

HIPAA and Your Website Forms: Where PHI Leaks Online

Your website can leak protected health information without anyone noticing, through tracking pixels, unsecured forms, and third-party widgets. Most template and agency sites get this wrong. Here is where PHI actually leaks, what the current rules say, and how to close the gaps.

Websites leak PHI mainly through tracking pixels and analytics on pages with health-collecting forms, through unsecured forms, and through third-party embeds without a business associate agreement. A 2024 court ruling narrowed HIPAA's reach for passive tracking on public info pages, but form-capturing trackers and portal-page trackers remain risky, and FTC and state laws apply regardless. Keep PHI out of third-party trackers.

Key takeaways

  • The biggest leaks: tracking pixels and analytics on pages with forms that collect health information.
  • Also risky: unsecured web forms, third-party chat or scheduling widgets without a business associate agreement, and portal-page trackers.
  • A 2024 court ruling narrowed HIPAA for passive tracking on public info pages, but did not clear form-capturing or portal trackers.
  • FTC enforcement and state privacy laws apply regardless of the HIPAA analysis, so do not rely on the ruling alone.
  • The fix: audit your trackers, keep them off PHI-collecting and portal pages, and get BAAs from vendors that touch PHI.

A practice website feels harmless, but it can quietly send patients' health information to third parties that should never have it, through tools most practices never think about. The leaks are usually invisible, unintentional, and entirely preventable, once you know where they are. This is not legal advice, but it will show you the common gaps and how to close them.

Where PHI actually leaks

Protected health information escapes a website through a handful of predictable channels, and the biggest is the one practices notice least. Tracking pixels and analytics on pages that collect health information: a Meta Pixel or analytics script on your appointment-request or intake page can capture what the patient enters and transmit it to a third party, which is the classic leak. Unsecured web forms: a contact or intake form that collects health details and sends them by plain email or to a backend without proper safeguards. Third-party embeds: chat widgets, scheduling tools, and other embedded services that receive patient information without a business associate agreement in place. And trackers on authenticated pages: analytics or pixels running on patient-portal or logged-in pages, where the data is clearly tied to an individual. The common thread across all four is the same: identifiable health information reaching a company that has no right to it and no agreement to protect it. That is the leak, and it usually happens by default, not by decision.

What the current rules say

The regulatory picture shifted recently, and getting it right matters, so here is the accurate version. In December 2022, HHS guidance warned that online tracking technologies on healthcare sites could result in impermissible PHI disclosures HHS online tracking. Then in June 2024, a federal court vacated part of that guidance, specifically the position that an IP address combined with a visit to an unauthenticated public webpage about a health condition or provider automatically counts as protected health information, and HHS did not appeal. The court's point was that identity plus a page visit does not, by itself, prove a person has a condition. So the broad theory that any tracking on a general health-information page is a HIPAA problem no longer holds. That is genuine relief for passive analytics on public, informational pages. But, and this is the part that matters, the ruling was narrow, and it left the real risks fully intact, which is the next section.

What is still risky

The 2024 ruling narrowed one theory; it did not give a green light. Several things remain clearly risky. Trackers that capture form submissions: if a pixel or analytics tool captures the health information a patient actually enters into a form, that is a disclosure of PHI, untouched by the ruling. Trackers on authenticated pages: analytics on patient-portal or logged-in pages, where data is tied to a known individual, remain a clear exposure. Third-party tools without a BAA: any vendor whose tool receives PHI still needs a business associate agreement. And crucially, other laws apply regardless of the HIPAA analysis: the FTC enforces against sharing identifiable health information through tracking tools without consent, and has taken real action doing so, while state privacy laws add their own requirements. So even where the HIPAA question is now murkier, the FTC and state law can still reach the same conduct. The honest summary: the ruling reduced one specific risk on public info pages, but the core danger, PHI reaching third parties through forms, portals, and embeds, is unchanged, and the safe posture is unchanged too.

Build a front door that does not leak

The free Leak Audit includes a look at where your website and operations expose what they should protect.

Start with a free Leak Audit

How to close the gaps

Closing the leaks is concrete work, not a mystery. Audit what trackers run, and where: inventory every pixel, analytics tag, and third-party script on your site and note which pages they run on, because you cannot fix what you have not found. Keep trackers off the pages that collect health information and off authenticated portal pages, which removes the highest-risk exposures directly. Get a business associate agreement from any vendor whose tool touches PHI, your form provider, scheduling tool, chat widget, hosting where applicable, and do not use tools that will not sign one. Use HIPAA-compliant form and scheduling tools designed to handle PHI properly, rather than generic ones that send data to plain email or non-compliant backends. And keep PHI out of third-party trackers as the governing rule: if a tool that has not signed a BAA could receive identifiable health information, that is the leak to close. This is the same chart-numbers-only, PHI-aware discipline the whole practice should run on, applied to the website, and it is covered for your internal tools in the HIPAA-safe project management guide. Because the law here is evolving and varies by state, confirm your specifics with a qualified healthcare attorney; this guide points you at the gaps, not at legal conclusions.

The 10-minute tracker check

You do not need a consultant to find the most common leaks; a quick self-check surfaces most of them. First, list your key pages, especially any with a form, your appointment request, contact, intake, and patient portal. Then, on each, find out what third-party scripts are running. A free browser-based tracker-detection extension will list the pixels and analytics on a page in seconds, or a developer can check the page source and network activity. Pay special attention to the form and portal pages: any advertising pixel or general analytics tool running there is your highest-priority concern. Next, list your third-party tools, the form provider, scheduling widget, chat tool, and hosting, and for each ask whether it could receive patient information and whether you have a business associate agreement with that vendor. Anywhere a tool that could see PHI has no BAA is a gap to close. This check takes about ten minutes for a small site and tells you most of what you need: which trackers run where, and which vendors touch data they should not. It will not replace a formal review by counsel, but it will catch the obvious leaks, which are the ones most likely to be open right now.

Why this is a trust issue

Beyond compliance, this is about the trust a practice runs on. A patient who fills out your form or uses your portal is handing you sensitive information on the assumption that you will protect it, and a website that leaks that information to advertisers or unvetted third parties breaks that assumption, whether or not it triggers a penalty. Getting this right is therefore part of being the kind of practice patients can trust, not just avoiding a fine. It is also, frankly, where most template and agency-built medical sites fall short, because they bolt on the usual pixels and widgets without thinking about PHI, which is one reason a website built with compliance in mind, a real front door rather than a generic template, is worth the difference. The standard is not complicated: know what runs on your site, keep patient health information out of third-party hands, and get agreements from the vendors that legitimately need access. Do that, and your website stops being a quiet liability and becomes what it should be, a front door that protects the people who walk through it. The broader website work sits in the website audit and the AI search guide.

Where to go next

Find the leak before you fix it

Two ways to start, both free.

Run the free Rescue Kit and its tools yourself, or book a 20-minute Leak Audit where we put a real number on what this is costing, using your own volume. A diagnosis, not a pitch.

Frequently asked questions

Where does PHI leak on a medical website?

Most often through tracking pixels and analytics on pages with forms that collect health information, through unsecured web forms themselves, through third-party embeds like chat or scheduling widgets without a business associate agreement, and on authenticated patient-portal pages. The common thread is protected health information reaching a third party that should not have it.

Are tracking pixels on a medical website a HIPAA violation?

It depends on what they capture. A 2024 federal court narrowed the rules, so an IP address plus a visit to a general health page on a public site is no longer treated as protected health information. But pixels that capture what a patient submits through a form, or that sit on authenticated portal pages, remain a real HIPAA risk.

Did the HIPAA rules on website tracking change?

Yes. In 2024, a federal court vacated the portion of HHS guidance that treated an IP address plus a visit to an unauthenticated health-topic page as protected health information, and HHS did not appeal. The rest of the guidance stands, and tracking that captures form data or sits on portal pages is still risky.

Is Google Analytics or Meta Pixel safe on a practice website?

Only if it does not capture protected health information. On general informational pages the 2024 ruling reduced the risk, but on pages with forms that collect health details, or on patient-portal pages, these tools can transmit PHI to a third party without a business associate agreement, which is a real exposure. Configure carefully or keep them off those pages.

What should a practice do to prevent website PHI leaks?

Audit what trackers run and where, keep pixels and analytics off pages that collect health information and off portal pages, get a business associate agreement from any vendor whose tool touches PHI, and use HIPAA-compliant form and scheduling tools. The goal is simple: keep protected health information out of third-party trackers.

Does the FTC regulate health website privacy too?

Yes, separately from HIPAA. The FTC enforces against unfair or deceptive practices and has taken action against companies that shared identifiable health information through tracking tools without consent, regardless of HIPAA. So even where the HIPAA analysis is uncertain, FTC and state privacy laws can still apply.

Is this legal advice?

No. This is general information to help you spot and reduce common website PHI risks, not legal advice for your specific situation. Website privacy law is evolving and varies by state, so for your own compliance decisions, consult a qualified healthcare attorney or privacy professional.

Sources
  1. HHS online tracking. hhs.gov