HIPAA-Compliant Analytics & Conversion Tracking for Telehealth & Digital Health
Telehealth grows on paid acquisition — and regulators have already made examples of brands that let ad pixels into the funnel. minusPHI keeps your CAC math intact, with the patient removed before anything leaves the page.
The exposure
Your funnel is a medical record in motion.
start-intake?condition=adhd is not a marketing event.
Every step of a telehealth funnel — condition selection, eligibility check, checkout — is health data with an email attached. A standard growth stack pipes it straight to Meta and Google, which is precisely what the FTC fined GoodRx and BetterHelp for.
And it’s no longer just regulators: enterprise partners and payers now ask about pixel hygiene in diligence. Clean tracking stops being a legal patch and starts being a selling point.
The visit is encrypted. The funnel should be de-identified.
The fix
De-identified before it ever leaves your website.
The signup still counts toward CAC. The patient behind it stays anonymous.
What keeps working
Everything you advertise with today — untouched.
Meta and Google campaigns keep optimizing on server-side conversions with click IDs attached — CAC, ROAS and attribution stay measurable while patient identity stays home.
GA4 and the reporting your team lives in keep flowing, de-identified in transit. Growth sees every funnel step; platforms see no one.
One script tag alongside what you run today, including tag managers — with a server-side GTM destination for custom event routing. Your engineers stay on product.
Beyond compliance
Your users signed up precisely because it’s discreet.
Care at home stays at home.
Discreet care that retargets isn’t discreet.
People choose telehealth for ADHD meds, weight loss or mental health because nobody has to know. A retargeting ad on a shared screen undoes the entire value proposition — and churns the user who sees it.
minusPHI turns privacy into a feature you can publish: browsing and funnel events are never shared with advertisers, and there are receipts.
- A plain-language log of what was sent, hidden, or blocked
- Sensitive pages suppressed automatically — nothing sent at all
- Visitor "do not sell" signals honored, with receipts
Questions
The honest answers.
Our engineers could build this — why buy it?
They could. But this is running in five minutes with plain-language receipts, daily exposure scans and consent handling built in — and your engineers stay on the product roadmap instead of rebuilding ad-platform plumbing.
We run a custom stack and a tag manager — does it fit?
Yes: one script tag works alongside what you have, and a server-side GTM destination handles custom event routing. Nothing about your product code has to change.
Do Google or Meta sign a BAA for this?
No — and with minusPHI they don’t need to. A BAA is required when a vendor receives protected health information; the relay’s job is to make sure they never do. Events are de-identified before either platform sees anything.
What do we give up?
Visitor retargeting — it inherently requires handing platforms the browsing data this product exists to protect. Conversion optimization, attribution and analytics all stay. Any vendor promising all of it is fudging something.
Keep the growth curve. Lose the exposure.
Start free — no credit cardFull protection is free for 14 days, then $99/month per website · Cancel anytime