HIPAA-Compliant Analytics & Conversion Tracking for Physical Therapy & Chiropractic
Sciatica pages, auto-injury forms, new-patient specials on Facebook — clinics like yours live on local marketing. minusPHI keeps those campaigns converting while what a patient’s body is going through stays off the ad networks.
The exposure
Injury browsing says more than patients realize.
A visit to /work-injury is a fact somebody’s lawyer would love.
Reading about herniated discs, whiplash or workers’-comp treatment implies claims, work status and sometimes litigation — context no patient wants profiled by ad platforms. The pixel forwards all of it, tied to the person, before the first evaluation is ever booked.
Whether you’re insurance-based or cash-pay, state privacy laws treat this as consumer health data — and the same pixel suits filed against big health systems have reached small clinics. Anonymous at the source ends it.
Progress you can see. Data nobody else can.
The fix
De-identified before it ever leaves your website.
The evaluation still counts toward your campaign. The patient behind it stays anonymous.
What keeps working
Everything you advertise with today — untouched.
New-patient specials and community campaigns keep optimizing: bookings arrive server-side with the ad-click ID attached, so Meta knows the offer worked — not whose back hurts.
“Physical therapy near me” attribution keeps working, and GA4 keeps reporting — de-identified before Google ever sees it. Your dashboards don’t change.
Phone taps, evaluation requests and contact forms are detected automatically and counted as conversions. One script tag on the site you already have.
Beyond compliance
Hands-on care. Hands-off data.
The evaluation stays in the room.
Patients tell you where it hurts. Only you.
An auto-accident patient mid-claim, an employee filing workers’ comp, an athlete hiding an injury from a coach — your visitors have real reasons to keep their browsing quiet. Retargeting ads for back-pain treatment are not quiet.
minusPHI makes “we don’t share your browsing with advertisers” part of the care standard — with a plain-language log to prove it.
- A plain-language log of what was sent, hidden, or blocked
- Sensitive pages suppressed automatically — nothing sent at all
- Visitor "do not sell" signals honored, with receipts
Questions
The honest answers.
We’re cash-pay — does HIPAA even apply to us?
Maybe not — and it doesn’t matter. State consumer-health-privacy and wiretap laws cover injury and treatment browsing regardless of billing model, and plaintiffs’ firms don’t check your insurance contracts before filing. Removing the identity ends the question either way.
Will our Facebook promos still optimize?
Yes — for what matters. Offer campaigns optimize on conversion events, delivered server-side with the ad-click ID attached, so attribution keeps working. What you give up is visitor retargeting, because that inherently requires handing Meta the browsing data this product exists to protect.
Does our exercise library or blog change?
Nothing on your website changes — videos, guides, booking widgets and forms all work exactly as they do today. minusPHI only changes what leaves the visitor’s browser: identity out, marketing signal through.
What does setup look like?
About five minutes: paste one script tag into WordPress, Squarespace, Wix, Webflow or a custom site. Conversions are detected automatically, and your first exposure report arrives the same day. No developer required.
Fill the schedule. Protect the story.
Start free — no credit cardFull protection is free for 14 days, then $99/month per website · Cancel anytime