Part two
How the leak actually happens — one patient's visit.
She googles "therapist for anxiety near me" on her phone during a lunch break, and your practice's ad comes up.
She lands on yourclinic.com/services/anxiety-treatment and reads for two minutes. She never fills out a form, never calls. Just reads.
Automatically, in the background, the Meta pixel on that page tells Meta:
visited: /anxiety-treatment IP address iPhone 15 cookie ID
That cookie ID is the same one attached to her Facebook and Instagram logins. The visit doesn't stay anonymous — it lands on her ad profile.
Somewhere in an ad database, a row now connects an identifiable woman to "seeking anxiety treatment." No one hacked anything — the website worked exactly as designed. That design is the problem, and it's what regulators call an impermissible disclosure.
Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors.— U.S. Department of Health & Human Services, Office for Civil Rights, Bulletin on Online Tracking Technologies