Is your website handing PHI to your ad platforms?
Agency 39A is your partner for HIPAA-safe digital. HHS OCR has made clear that tracking technologies on health-related pages can disclose PHI to third parties without authorization, a reportable breach. We map where PHI flows, remove or govern the tracking that shouldn't be there, and put the BAAs and Security Rule safeguards in place, with the engineering to keep your marketing measurable.
Talk to a HIPAA strategistCoverage across the rules that put PHI at risk
HIPAA Privacy Rule
Governs how protected health information may be used and disclosed. Tracking tech that sends identifiable health data to Meta, Google, or analytics vendors without authorization is an impermissible disclosure.
HIPAA Security Rule
Requires administrative, physical, and technical safeguards for electronic PHI. We assess access controls, encryption, audit logging, and vendor risk across your digital stack.
HHS OCR online-tracking guidance
OCR's guidance put tracking technologies on regulated health pages squarely in scope. We align your site to it before it becomes an enforcement action or a breach report.
Business Associate Agreements
Analytics, advertising, and hosting vendors that touch PHI need a signed BAA, or they can't be there at all. We map which vendors qualify and put the agreements, or the removals, in place.
Breach Notification Rule
An impermissible PHI disclosure can trigger notification to affected individuals, HHS, and sometimes the media. We help you close the exposure before you're counting the days.
State consumer-health-data laws
Laws like Washington's My Health My Data Act extend consent and disclosure duties to health data beyond HIPAA's reach. We map where they touch your site.
The tracking that can leak PHI, audited and governed
WordPress
Tags and forms on patient-facing WordPress pages audited for PHI leakage
Google Tag Manager
Every tag reviewed for what identifiable health data it sends, and where
Google Analytics 4
Analytics kept useful without shipping PHI to Google
Google Consent Mode
Consent and gating wired so lawful measurement survives PHI removal
Meta Pixel
The tracker most cited in HIPAA pixel breaches, removed or stripped of PHI
LinkedIn Insight Tag
B2B tracking checked for health-condition and patient signals
HubSpot
Forms, chat, and tracking made PHI-safe, with a BAA where one is required
TikTok Pixel
Audited and removed from any page that touches health information
Hotjar
Session replay that can record PHI, masked, gated, or pulled
Google Ads
Conversion tracking that never carries diagnosis or treatment data
Microsoft Clarity
Heatmaps and recordings kept off PHI, or off entirely
OneTrust (migration)
Consent and preference tooling configured for health-data obligations
Five ways we keep your site HIPAA-safe
PHI & tracking audit
A full inventory of every tracker, pixel, form, chat widget, and session-replay tool on your patient-facing pages: what captures identifiable health data, where it goes, and which findings are reportable exposure.
Vendor mapping & BAAs
We identify every vendor that touches PHI, get the Business Associate Agreements signed where they belong, and remove the ones that can't or shouldn't be there.
Tag governance & remediation
We rebuild your tag setup so pixels, analytics, chat, and session replay never receive PHI, and retire the zombie tags nobody remembers installing.
Safeguards & Security Rule controls
Access controls, encryption, audit logging, and server-side patterns that keep ePHI protected while your marketing keeps measuring what it safely can.
Counsel-ready documentation & monitoring
Data-flow maps, vendor and BAA records, and scan reports your compliance officer and attorneys can use, plus scheduled re-scans that catch drift before it becomes a breach.
Not sure what PHI your site is exposing?
Ask for a HIPAA tracking check. We run the same kind of crawl an OCR investigator or plaintiff's expert would and come back fast with what's capturing PHI, where it's going, and what's reportable. No obligation, no scare tactics, just what we found.
Request a HIPAA tracking check