Privacy-safe healthcare analytics

Keep Google Analytics and Meta ads — without the patient data.

Tracking scripts like the Meta pixel and Google tag quietly hand an ad network the pages your patients read, their IP and their device — with no BAA covering any of it. See what your site is leaking below, then fix it with a single tag.

No credit card required · Works with any website platform · 5-minute setup

Keeps Meta & Google attribution De-identified before either sees it No engineering team required

Compliance you can point to

Hosted in the USA HIPAA Safe Harbor BAA available Encrypted at rest

The problem

Your website talks to ad networks behind your back.

If your site uses Google Analytics or runs Facebook ads, there's a small piece of code — a pixel — quietly reporting on every visitor. Not just how many people came, but who, and what they read:

the "HIV testing" page they visited their IP address their phone model their cookie ID

On a normal business site, that's just marketing. On a healthcare site, "this person read this health page" is patient information going to an ad network — a company that will never sign a BAA. Regulators, and plaintiffs' lawyers, noticed.

New to this? Read the plain-English explainer →

Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors.
— U.S. Department of Health & Human Services, Office for Civil Rights, Bulletin on Online Tracking Technologies

How it works

One tag on your site. A relay in the middle. Clean data out the other side.

Step 1

Connect what you already use.

Sign in and connect your Google Analytics with one click — and your Meta pixel too, if you run Facebook or Instagram ads. No new dashboards to learn: your reports stay in the tools you already know. Run Microsoft Ads or other platforms through a tag manager? Connect your GTM server container and those keep working from clean data too.

Google Analytics 4 Connected
Meta Pixel · Conversions API Connected
Microsoft Ads · via your GTM Connected
Old browser pixels Removed
Step 2

Paste one line. That's the install.

Add the minusPHI tag before </head> on your site — WordPress, Squarespace, Wix, Webflow, anything — and remove the old pixels. Phone clicks, booking links and contact forms are detected as conversions automatically. There is nothing to configure on a server, and no developer required.

index.htmlstyle.css
<!-- your entire analytics stack, after minusPHI -->
<script src="https://app.minusphi.com/mphi.js"
        data-site-key="mphi_XXXXXXXXXX"
        data-ingest="https://ingest.minusphi.com/">
</script>

Watch it work

From ad click to clean analytics — with the patient removed in the middle.

Arrives at the relay
"event":"book_appointment"kept
"gclid":"Cj0KCQjw8…"kept
"ip":"203.0.113.7"stripped
"email":"jane.doe@gmail.com"stripped
"phone":"+1 (555) 014-2276"stripped
"_fbp":"fb.1.171982…"stripped
"device":"iPhone15,3 iOS 19.2"stripped
"referrer":"portal.clinic.com/results"stripped
Leaves the relay
"event":"book_appointment"
"gclid":"Cj0KCQjw8…"
"source":"google / cpc"
"session":"rnd_7f3a91c2" // random, first-party

The conversion and its ad-click ID survive — that's what campaigns optimize on. The person doesn't.

What we send

Deny by default. Every field that forwards is on an allow-list; everything else is stripped.

Forwarded — de-identified
  • Page views & traffic sources to your GA4 (public marketing pages only)
  • Page views to Meta as domain-only — never which page was visited
  • Conversions: leads, booking clicks, phone clicks — the signal ad delivery needs
  • Ad-click IDs (gclid / fbclid / msclkid) on conversions, so campaigns keep attributing
  • A random first-party ID so sessions count correctly — never tied to a person
Never sent — to anyone
  • IP addresses, device fingerprints, third-party cookies
  • Names, emails, phone numbers — hashed or not
  • Page URLs to Meta, form contents, anything typed by a visitor
  • Anything from patient portals, intake, scheduling or confirmation pages
  • Health-condition terms — pages mentioning them are suppressed entirely
Fail-closed: a page the relay can't classify, a field it doesn't recognize, a URL carrying a condition term — all suppressed automatically, and an independent self-check verifies every event before it leaves. Full compliance & security page →
New

Even the map on your site is an informant

A HIPAA-compliant map that shows your office — without telling Google or Apple who looked.

Same map. Same directions.
No third party watching.

A standard map embed sends each visitor's IP address — plus your practice's location — straight to Google or Apple's servers the moment the page loads, with no BAA behind it. minusPHI now draws that map itself, from our own U.S. servers: patients pan, zoom, find your nearest office and tap for directions, and no map company ever learns who looked.

  • Every office on one map, with phone, hours and accessibility
  • "Nearest office" computed on the visitor's phone — never transmitted
  • One line of HTML — the tag you already installed does the rest

Explore HIPAA-compliant maps →

yourclinic.com/locations — private map
Downtown212 Elm St · (555) 014-2200
Directions ↗
Northside48 Lake Ave · (555) 014-2300
Directions ↗

Built for healthcare

Whatever you practice, the pixel problem is the same — and so is the fix.

See all 12 specialties →

Med spas

A nurse injector performing a treatment in a bright med spa

Instagram and Google ads that fill your consult calendar — while every client's browsing stays off the ad networks.

Learn more

New to all this?

Most practices have no idea their website does this.

You didn't install a "tracking pixel" — your web designer did, years ago, because every website gets one. Nobody told you what it sends. We wrote a plain-English explainer for practice owners and managers: what a pixel is, what it tells Facebook about your patients, and what regulators expect you to do about it. No jargon, ten-minute read.

Read: The pixel problem, explained

A physician in a white coat using a smartphone

Questions

The honest answers.

Will my Meta ads still optimize without the pixel?

Yes — for what matters. Lead and appointment campaigns optimize on conversion events, which minusPHI delivers server-side with the ad-click ID attached, so attribution keeps working. What you give up is visitor retargeting, because that inherently requires handing Meta the browsing data this product exists to protect. Any vendor promising both is fudging one of them.

Do Google or Meta sign a BAA for this?

No — and with minusPHI they don't need to. A BAA is required when a vendor receives protected health information. The relay's job is to make sure they never do: events are de-identified before either company sees anything, and sensitive pages are suppressed entirely.

What happens on sensitive pages, like a patient portal?

Nothing is sent at all. Portals, intake forms, scheduling flows, confirmation pages, and any URL carrying a health-condition term are suppressed before forwarding — not scrubbed, simply never sent. You'll see marketing traffic in your analytics; nobody sees care activity.

Does it work with my website platform?

If you can paste one script tag — WordPress, Squarespace, Wix, Webflow, custom — it works. There's nothing to install server-side and no developer required. Conversions like phone clicks, Calendly/Zocdoc bookings and contact forms are detected automatically.

Is this legal advice or a compliance guarantee?

No. minusPHI is engineering: it controls exactly what data leaves your site, using allow-lists and de-identification aligned with HIPAA Safe Harbor. Your compliance program is still yours — we just make the tracking-pixel part of it defensible instead of dangerous.

Your ads keep learning. Your patients stay private.

Start free — connect in 5 minutes

No credit card required · 5-minute setup