HIPAA & Healthcare Data

Short version: Web Tonic acts as a HIPAA business associate when an engagement involves protected health information, and will execute a Business Associate Agreement before any PHI reaches our people or our tooling. We hold no HIPAA certification because none exists for anyone. For healthcare advertising we keep PHI out of ad platforms entirely rather than claiming a pixel can be made compliant.

What a BAA with us covers

We will sign your BAA, or provide one for review. Whichever paper it is on, it will address the obligations HIPAA requires of a business associate: permitted uses and disclosures, safeguards, subcontractor flow-down, individual rights support, breach notification timelines, and return or destruction of PHI at termination. Everything on this page is a contractual commitment you can hold us to, and our team is experienced working inside client environments governed by these rules.

Our PHI-free measurement architecture

The failure mode in healthcare marketing is not strategy, it is telemetry. A single default analytics or advertising tag on the wrong page can transmit a URL, a referrer and an IP address that together disclose a condition. Our pattern for patient-facing properties:

  • Tag inventory and kill list first. Before any campaign work, we enumerate every script on the site and remove or gate the ones that transmit page context to third parties.
  • Consent gating. No marketing or analytics tag fires before an affirmative choice, implemented through a consent platform with Consent Mode signals rather than a cosmetic banner.
  • Server-side collection. Events route through infrastructure the client controls, where identifiers and condition-revealing parameters are stripped before anything is forwarded.
  • Sanitized conversion events. A conversion says “a lead happened,” never which service line, procedure, or diagnosis page it came from.
  • Offline conversion import. Revenue attribution comes from the CRM or practice management system after qualification, using hashed non-clinical identifiers, rather than from patient-journey tracking.
  • Segregated reporting. Performance reporting is built from aggregate, de-identified data. Nobody at Web Tonic needs to see a patient record to optimize a campaign, so nobody does.

Controls that apply to healthcare engagements

  • Role-specific HIPAA training for every team member assigned to the account, refreshed annually.
  • Least-privilege, named-user access with MFA; no shared logins; access revoked within one business day of a staffing change.
  • PHI is never placed in general-purpose AI tools, personal drives, chat, or email.
  • Subcontractors on a healthcare engagement are bound by written flow-down terms before access.
  • Incident notification to the client within 48 hours of confirmation, or faster where the BAA or law requires it.
  • Return or destruction of PHI within 30 days of termination, on request.

How far our assurance extends

  • No HIPAA certification, seal, or third-party attestation — because there is no such thing.
  • We are a business associate, never a covered entity, and we do not advise on clinical or coding compliance.
  • No agency can make a third-party ad platform HIPAA-compliant. Where a platform will not sign a BAA, we solve it by architecture rather than paperwork.
  • This page is not legal advice. Your counsel and privacy officer own the final call.

Frequently asked by healthcare procurement

Can a marketing agency be HIPAA certified?

No. There is no government or accredited HIPAA certification for any organization, product or service. HHS states plainly that business associates cannot self-certify or be certified by a third party as HIPAA compliant. The enforceable instrument is a Business Associate Agreement executed under 45 CFR 164.504(e).

When does Web Tonic become a business associate?

The moment an engagement requires us to create, receive, maintain or transmit protected health information on behalf of a covered entity or another business associate — for example, handling patient intake form data, working inside an EHR-connected CRM, or building audience segments from patient records. Marketing work that never touches PHI does not make us a business associate, and we will tell you which category your engagement falls into before we start.

Is an IP address on a hospital website really PHI?

It can be. OCR’s guidance on online tracking technologies, originally issued in December 2022 and updated on 18 March 2024, takes the position that individually identifiable health information collected on a regulated entity’s website is generally PHI even without an existing patient relationship, where the combination of identifiers and page context reveals something about the person’s health. A federal court in Texas vacated part of that guidance in 2024, which is precisely why we design to the stricter reading rather than the litigated one.

Can you run Meta and Google ads for a healthcare client at all?

Yes — with a different architecture. Neither Meta nor Google will sign a BAA for standard advertising products, so the answer is never “we made the pixel HIPAA compliant.” The answer is that condition-revealing data never enters those platforms: consent-gated tag firing, server-side collection under the client’s control, conversions imported from the CRM after the fact, and no audience built from patient status.

Where do you draw the line?

Install an unmodified client-side pixel on a patient portal, appointment-booking flow, or condition-specific page. Upload patient lists as custom audiences without a lawful basis and a BAA-covered path. Retarget users based on a condition-revealing page view. Put PHI in a spreadsheet, a chat message, or an AI tool that is not covered by an agreement. We will explain the compliant alternative in each case.

Start the review

Send your BAA, security questionnaire, or tracking-technology assessment to [email protected], or book a call and bring your privacy officer. Related: Trust & Compliance · Security program · Subprocessors · Data processing & GDPR.