The pixel problem

Your website might be telling Facebook who your patients are.

Not because anyone hacked you. Because of a little piece of marketing code that came free with your website — and that nobody ever explained to you.

A plain-English guide for practice owners & managers · ~10 minute read · No jargon

A bright, modern medical practice room

Part one

What is a "tracking pixel," actually?

When your website was built, whoever built it almost certainly added two invisible helpers: Google Analytics (to count your visitors) and, if you've ever run Facebook or Instagram ads, the Meta pixel (to measure whether the ads work). Together, people call these "pixels" or "tags."

A pixel is a tiny piece of code that runs in your visitor's browser. Every time someone opens a page, it wakes up and files a little report — directly to Google or Meta, not to you. The report includes which page was opened, the visitor's internet address (IP), what device they're on, and a cookie ID that ad networks use to recognize the same person across the internet.

For a shoe store, that's harmless bookkeeping. For a medical practice, keep reading.

yourclinic.com/services/anxiety-treatment

What the pixel reports:

page: /anxiety-treatment IP: 203.0.113.7 device: iPhone cookie: fb.1.7182…

Filed with Meta and Google the moment the page opens — before the visitor clicks anything, and without asking you or them.

Part two

How the leak actually happens — one patient's visit.

Maria searches for help.

She googles "therapist for anxiety near me" on her phone during a lunch break, and your practice's ad comes up.

She taps your ad and reads a page.

She lands on yourclinic.com/services/anxiety-treatment and reads for two minutes. She never fills out a form, never calls. Just reads.

The pixel files its report.

Automatically, in the background, the Meta pixel on that page tells Meta:

visited: /anxiety-treatment IP address iPhone 15 cookie ID

Meta recognizes her.

That cookie ID is the same one attached to her Facebook and Instagram logins. The visit doesn't stay anonymous — it lands on her ad profile.

Now it's a record about a person's health.

Somewhere in an ad database, a row now connects an identifiable woman to "seeking anxiety treatment." No one hacked anything — the website worked exactly as designed. That design is the problem, and it's what regulators call an impermissible disclosure.

Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors.
— U.S. Department of Health & Human Services, Office for Civil Rights, Bulletin on Online Tracking Technologies

Part three

Why regulators — and lawyers — care so much.

Since 2022, this exact pattern has moved from "technical detail" to enforcement priority. HHS's Office for Civil Rights published guidance saying that sending "this person visited this health page" to a tracking vendor needs either a signed BAA or patient authorization — and ad networks provide neither. The FTC went after GoodRx and BetterHelp for sharing health data with ad platforms, under rules that apply even to businesses HIPAA doesn't cover, like med spas and wellness brands.

And beyond the regulators, class-action firms discovered the pixel. Hospitals and telehealth companies have paid multi-million-dollar settlements over the browsing data their websites shared. The common thread in every case: nobody at the organization knew the pixel was doing this.

Two clinicians reviewing information at a workstation

Part four

Does this apply to your practice?

Very likely yes, if all three of these are true — and for most practices with a website and any advertising, they are:

  • Your website uses Google Analytics or a Meta pixel. Nearly every professionally built site does — it's the default, not an add-on.
  • People visit pages that say something about health. Services, conditions, treatments, "book an appointment" — on a practice site, that's every page.
  • You're a healthcare organization. Medical, dental, behavioral health, PT, urgent care — and if you're a med spa or wellness brand outside HIPAA, the FTC's rules still reach you.

Not sure what's on your site? That's exactly what the free scan below checks.

Part five

Your three options, honestly.

1 · Do nothing

Keep the pixels; hope nobody looks. Free today, but it leaves the disclosure running on every page view, and enforcement and lawsuits keep growing. This is where most practices are right now — usually without knowing it.

2 · Remove all tracking

Delete the pixels entirely. Compliant, but your ads stop optimizing and your visitor counts go dark — you're buying safety with blindness, and wasted ad spend adds up fast.

3 · Put a filter in the middle

Keep the measurement, remove the leak: a relay that strips identifying details and blocks sensitive pages before anything reaches Google or Meta. That's what minusPHI is — one tag, five minutes, 14 days free, then $99/month flat.

Find out in 60 seconds

See exactly what your website sends, before deciding anything.

Free · No credit card · Results in plain English