Skip to content
Mather Media Solutions

Guide · Aesthetic, dental and medical practices

What should a health website never send to Google Ads or Meta?

Updated 27 September 20267 min read

The short answer

Never send an ad platform a procedure or condition in a URL, page title, event name or parameter, any form answer, or any free text. Send a neutral event, a time, a value and a click ID, and report outcomes from a server path you control. Whether HIPAA applies is the practice’s and its counsel’s determination.

Why is a health website different?

On most sites, a pixel that sees the page URL and the form learns which pages sell. On a practice site, the same pixel can learn that a named visitor asked about a specific procedure or condition. The tag does not know the difference; it sends what it can read.

The platforms treat health as a special case too. Google does not allow personalized advertising based on health conditions or treatments. Google’s customer data policies restrict conversions related to health in enhanced conversions. Meta’s Business Tools Terms say advertisers must not share data that includes or is based on health information, and Meta filters data it categorizes as potentially sensitive health information out of its ads systems. Google also says Google Analytics must not be used in any way that gives Google access to protected health information, and that it does not offer a business associate agreement for Analytics.

What has HHS said about tracking technologies?

The HHS Office for Civil Rights published a bulletin on the use of online tracking technologies by HIPAA covered entities and business associates, first issued in December 2022. It names tools such as Google Analytics and the Meta Pixel as tracking technologies and describes when, in HHS’s view, the HIPAA Rules apply to what they collect.

In June 2024 a federal court vacated part of that guidance, concerning visits to unauthenticated public webpages, and HHS’s page on the bulletin says so. The rest of the page, and any later update, is for the practice and its counsel to read in full. We describe it here only so the reader knows it exists and where to find it.

Where does health detail leak into ad platforms?

  • URLs

    A thank-you page at /thank-you-rhinoplasty, a booking link with ?treatment=implants, or a query string that echoes a form answer. Every tag on the page receives the full URL.

  • Page titles

    A confirmation page titled with the procedure booked. Analytics and pixels routinely collect the title.

  • Event names and parameters

    An event called botox_consult, a parameter such as service: dental_implants, or a conversion named after a procedure. The name itself is the health detail.

  • Form contents

    Selected procedure, symptoms, insurance, date of birth. Automatic form capture, advanced matching and tag templates that read the form can pick these up. Even a form’s HTML name can travel as a parameter.

  • Free text

    A “tell us about your concern” box can hold anything, including a diagnosis. No free text field should ever be readable by a marketing tag.

  • Values that map to a procedure

    A conversion value that equals one treatment’s price tells the platform which treatment it was as clearly as the name would.

  • Embedded tools

    Booking widgets, chat tools and patient portals often carry their own pixels, set by the vendor. Check what they send, not only what your own tags send.

What should never be sent?

  • Procedure, treatment, condition or specialty names, in any URL, title, event name, parameter, custom conversion name or audience name.
  • Any form answer other than the contact details used for matching, and those only hashed, only through an approved path, and only where the practice has decided that is acceptable.
  • Any free text a visitor typed.
  • Anything from a logged-in page such as a patient portal. Google says authenticated pages are likely to be HIPAA covered and should not carry Google Analytics tags.
  • Appointment types, provider names or locations that together reveal the treatment.
  • A conversion value that identifies a single procedure.

How should tracking be structured so the ads still learn?

The ads do not need to know what a patient came in for. They need to know that a click led to an outcome the practice values. That can be sent without health detail.

  1. Use neutral names everywhere

    consultation_requested, consultation_booked, consultation_attended. The same names for every procedure, on every platform.

  2. Use one generic confirmation page

    A single /thank-you with no procedure in the path, the title or the query string. If the booking tool redirects, check what it appends.

  3. Capture the click ID, not the answers

    Hidden fields for gclid, gbraid, wbraid and fbclid, saved with the lead. The form answers go to the practice system and nowhere else.

  4. Report the outcome from a path the practice controls

    When the consultation is booked or attended in the practice system, send an offline conversion by click ID to Google Ads and a Conversions API event to Meta, with an allowlist of fields: event name, time, value, click identifier and, where the practice has decided it is acceptable, hashed contact details.

  5. Use a flat or banded value

    A single value per consultation, or a few bands that do not correspond to one treatment, lets bidding favor better leads without naming the procedure.

  6. Turn off automatic collection you have not reviewed

    Automatic advanced matching, automatic events and form interaction tracking read the page for you. Meta documents restrictions on automatic advanced matching for businesses in regulated categories. Check each setting against what it actually sends.

Sending booked consultations to Google Ads and Meta

The step by step import, with the click ID capture and daily upload in full.

Does it differ for aesthetic, dental and medical practices?

  • Aesthetic and elective practices

    The risk is procedure pages and procedure-named conversions: a thank-you URL, a custom conversion or an audience named for a treatment. Neutral names and one confirmation page remove most of it.

  • Dental practices

    Implant, orthodontic and emergency pages each produce their own leads. Keep one consultation event and let the practice system, not the ad platform, record which service it was.

  • Medical practices and clinics

    Condition pages, symptom checkers, insurance fields and patient portals raise the stakes. Many medical practices keep marketing tags off condition and portal pages entirely and report only the booked appointment from the server. That design choice is the practice’s to make with counsel.

Paid media for implant and orthodontic practices

Bidding on the attended consult and the accepted case, with the payload kept neutral.

How do you check what your site is sending now?

  1. List every tag and embedded tool

    The tag manager container, any code pasted into the site, and every third-party widget with its own pixel.

  2. Walk the journey as a test visitor

    Land from a tagged ad URL, read a procedure page, submit the form with test values, and reach the confirmation page.

  3. Read the requests, not the settings

    In the browser’s network panel, open each request to Google and Meta and read the URL, title, event name and every parameter. A setting that says a field is excluded is a claim; the request is the evidence.

  4. Check the platforms’ own views

    Meta Events Manager shows received events and flags; Google Ads and GA4 show conversion names and parameters. Look for anything that names a treatment.

  5. Write it down, field by field

    Destination, event, each field sent, and why. That record is what the practice and its counsel review.

Server-side tracking, when it earns its cost

A server path with a field allowlist, and when a simpler setup does the job.

Common mistakes

  1. 01

    Trusting a checkbox instead of reading the request

    A setting can be on and a template can still send a field. The network request shows what actually left the page.

  2. 02

    Naming custom conversions after treatments

    It puts the health detail in the name, and Meta can restrict custom conversions whose names suggest a health condition.

  3. 03

    Moving everything server side and calling it solved

    A server event can carry the same procedure name as a pixel. The server path is only safer if it sends less.

  4. 04

    Forgetting the vendor pixels

    The booking widget or chat tool can send its own events to the same ad accounts, outside your tag manager.

  5. 05

    Assuming hashed means harmless

    A hashed email is matchable personal data. It belongs in the review like any other field.

Straight answers

What we will not promise

  • That a setup is HIPAA compliant. That determination belongs to the practice and its counsel; we build the field-level record they need to make it.
  • Legal advice of any kind, including on the HHS bulletin or the court ruling. We describe them only so the reader knows to read them.
  • That removing health detail will not change campaign performance. It changes what the platforms can see, and the practice should expect the campaigns to relearn.

Questions

  • Is it safe to use the Meta pixel on a practice website?

    That is the practice’s and its counsel’s determination, not ours. Mechanically, the safer design keeps the pixel to neutral events on pages that name no treatment, sends no form contents, and reports outcomes from a server path with an allowlist of fields.

  • Can I still run conversion-based bidding without sending health data?

    Yes. Bidding needs to know that a click led to a valuable outcome, not what the outcome was clinically. A neutral booked consultation with a flat value, matched by click ID, is enough to bid on.

  • Does server-side tracking make health data safe to send?

    No. It moves where the event is sent from, not what it contains. Its value is control: the practice decides each field that leaves, and can document the choice.

  • Should the patient portal have ad or analytics tags?

    Google says authenticated pages are likely to be HIPAA covered and should not carry Google Analytics tags. Whether any tag belongs there is the practice’s and its counsel’s call; many practices keep portals free of marketing tags entirely.

  • Can we use enhanced conversions for leads?

    Google’s customer data policies restrict conversions related to health in enhanced conversions. Read the current policy with counsel; a neutral GCLID import sends no contact details from the form page.

Start with the diagnostic

Rather have someone check yours?

Map what is breaking, the systems involved, the outcome you need, and whether a pilot is ready. You will see a practical route and first artifact before deciding whether to send the context.

No charge to take the diagnostic · A specific reply within two business days