If you search for guidance on healthcare website tracking you will find confident, contradictory answers, and the reason is almost always chronology rather than disagreement. The OCR tracking bulletin has four dates attached to it, and most published advice was written at one of them and never revisited. An article from early 2023 and an article from late 2024 describe genuinely different legal landscapes, and neither usually says which moment it is describing.
So before the substance, the timeline. It is short, and it resolves most of the confusion on its own.
What the OCR tracking bulletin actually said
In December 2022 the HHS Office for Civil Rights published guidance on the use of online tracking technologies by covered entities and business associates. Its uncontroversial content restated existing law: if a tracking vendor receives protected health information on your behalf, that vendor is a business associate and the arrangement requires a contract under 45 CFR 164.502. Nobody litigated that.
That restatement was more consequential than it sounded, because it named a category most practices had never applied to a marketing tool. A business associate is not only a billing company or a records vendor. It is anyone who receives protected health information to perform a function on your behalf, and an analytics platform processing page views on your instruction fits the description when what it receives is PHI. The guidance simply pointed at tools nobody had classified that way and asked the obvious question.
The contested content concerned unauthenticated pages. The guidance took the position that when a visitor to a public webpage addressing a specific health condition is observed by a tracker, the combination of that visit with an identifier such as an IP address could itself be individually identifiable health information, because the visit implies something about the visitor's health.
The Proscribed Combination
The name the litigation gave to that theory: an individual's IP address, together with a visit to an unauthenticated public webpage addressing specific health conditions or health care providers, treated as individually identifiable health information even though the operator does not know who the visitor is or why they came.
That is the piece that mattered, because it swept in the ordinary marketing pages of every practice in the country. A page named for a treatment, plus any analytics tag, plus the IP address every web request carries, and a practice was suddenly handling protected health information on its homepage funnel.
The revision nobody read
In March 2024, with litigation underway, OCR revised the guidance. The revision softened the framing and added examples distinguishing a visitor browsing out of curiosity from one seeking care for themselves. It did not abandon the underlying theory.
This revision is the single most common source of stale citations, because a great deal of writing published in mid-2024 cites the revised guidance as though it were settled and current. It was current for roughly three months.
It is worth understanding why the revision did not resolve the problem it was responding to. The added examples turned on the visitor's purpose: a student researching a condition was treated differently from a person seeking treatment for themselves. That distinction is coherent as a matter of principle and unusable as a matter of engineering, because the two visitors are indistinguishable at the point where the decision has to be made. A web server sees a request. It does not see a motive. Guidance that hinges on motive cannot be implemented by anyone, which is close to the ground the court eventually took.
What the court vacated
On June 20, 2024 the United States District Court for the Northern District of Texas, in American Hospital Association v. Becerra, held the Proscribed Combination unlawful and vacated it. The court found it fell outside the statutory definition of individually identifiable health information, failing both prongs: the data does not reliably relate to an individual's health, and it does not identify them.
The court's practical objection carries further than the legal one. The position required an operator to know why a visitor arrived. A medical student, a journalist, a competitor, a worried relative and a prospective patient generate an identical request. Compliance would have required reading minds.
HHS filed an appeal and then withdrew it on August 29, 2024. The vacatur therefore stands, and the definitional analysis in what counts as PHI on a website is the framework that survived.
What the OCR tracking bulletin still requires
Here is where most summaries fail in the opposite direction. The vacatur removed one inference-based theory about public pages. It did not remove HIPAA from websites, and the surviving material is the part that describes the clearest exposure.
Authenticated pages. Behind a patient login the operator knows the visitor's identity and already holds their record. Nothing in the ruling touched this, and it was never seriously argued.
Submitted information. When a visitor types a symptom, a condition or a reason for the visit into a form, that is disclosed information rather than inferred information. The court's reasoning about the impossibility of divining intent has no application to a person who told you directly.
Business associate contracts. Where a vendor creates, receives, maintains or transmits PHI on a covered entity's behalf, a contract is required. The practical difficulty is unchanged: several large advertising platforms decline to enter one, which settles whether their tags belong on the pages where PHI is present. That constraint drives the analysis in analytics on patient-facing pages.
Breach notification. The quietest survivor and the one with the sharpest edge. If protected health information was disclosed to a vendor without authorisation, the disclosure is a breach, and breach notification obligations attach to it. That matters because it is retrospective. A tag removed today does not undo what it sent last year, and the several large health systems that filed notifications covering millions of patients in 2022 and 2023 did so over exactly this mechanism rather than over any enforcement action about the guidance itself.
Reading those two facts together explains why the vacatur changed less than the headlines suggested. The theory that was struck down governed inference on public pages. The obligations that create the largest and most concrete liability, notification duties attaching to data that already left, were never in the case.
How to date any advice you read on this
Because the ground moved twice in eighteen months, the most useful reading skill here is placing a document on the timeline. Three tells work reliably.
If a piece asserts that an IP address plus a visit to a treatment page is PHI, full stop, with no mention of litigation, it predates June 2024 and its central claim has been vacated. If it announces that pixels are fine on healthcare sites now, it read the holding and not the scope, and it is wrong about authenticated pages and submitted data. If it cites the March 2024 revision as the current state without mentioning what followed, it stopped reading three months early.
Worth noting that an AI assistant asked about the OCR tracking bulletin today will often produce one of those three answers, because they dominate the training material. The correction is cheap and specific: name the four dates.
There is a fourth tell, subtler than the others. Some writing treats the OCR tracking bulletin as though it were a regulation. It is not. Sub-regulatory guidance describes how an agency reads a rule; the rule itself is the statute and the Privacy Rule text, which is why the court could vacate a piece of the guidance without altering a word of 45 CFR. Anything that says the bulletin required something is using the wrong verb, and that imprecision is usually a signal that the writer is summarising other summaries rather than the underlying authority.
The deeper lesson for a practice is that the legal theory moved twice while the pages did not. A site that holds non-essential tags until a visitor agrees occupied a defensible position under the 2022 guidance, under the 2024 revision, and after the vacatur, without a single change. That stability is the argument for putting the decision in front of the tag rather than in a policy document, and it is what consent gating does. Whether HIPAA reaches you at all is the prior question, covered in does HIPAA apply to your website, and state consumer health data statutes run on an entirely separate track that this litigation did not touch, which state privacy detection covers.
Key takeaways
- Four dates: issued December 2022, revised March 2024, partially vacated June 20 2024, appeal withdrawn August 29 2024. Most disagreement about this topic is a chronology problem.
- The court vacated only the Proscribed Combination, the theory that an IP address plus a visit to a public health-topic page is individually identifiable health information.
- Tracking on authenticated pages, information a visitor submits, and the business associate contract requirement were never challenged and still stand.
- The March 2024 revision softened the framing without abandoning the theory, and was current for about three months. It is the most commonly cited stale source.
- Three tells date any article you read: no mention of litigation, a declaration that pixels are fine again, or the revision cited as current.
- The legal theory moved twice while the pages did not. Holding tags until a visitor agrees was defensible at every point on the timeline.
Common questions
Is the OCR online tracking bulletin still in effect?
Partly. A federal court vacated one component of it on June 20, 2024, and HHS withdrew its appeal on August 29, 2024, so that vacatur stands. The rest of the guidance was not struck down and continues to describe how OCR reads the Privacy Rule, including its treatment of authenticated pages, submitted information and business associate contracts.
What exactly did the court vacate?
The theory the litigation called the Proscribed Combination: that an IP address collected from a visitor to a public, unauthenticated webpage addressing a health condition amounts to individually identifiable health information. The court held it fails both the relates-to and identifies prongs of the statutory definition.
Does the ruling mean tracking pixels are fine on healthcare websites again?
No. The ruling addressed one inference-based theory about public pages. Tracking on pages behind a patient login, tracking that captures information a visitor actually submits, and the business associate contract requirement where a vendor receives protected health information were all left standing, and state consumer health data laws are a separate framework entirely.
Editorial note. This article describes what published guidance, statutes and court filings say as of its publication date. It is general information, not legal advice, and it is not a statement about any particular practice's obligations. Consential.io is not a law firm. Regulations and case law change. Confirm your own position with healthcare counsel licensed in your state before acting on anything here.
Sources
- Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates, HHS Office for Civil Rights, December 1, 2022, revised March 18, 2024 Cited without a link: hhs.gov is not reachable from our verification environment.
- American Hospital Association v. Becerra, No. 4:23-cv-01110 (N.D. Tex. June 20, 2024) Order vacating the Proscribed Combination; HHS withdrew its appeal August 29, 2024. Cited without a link: courtlistener.com is not reachable from our verification environment.
- 45 CFR 160.103, definition of individually identifiable health information Electronic Code of Federal Regulations
- 45 CFR 164.502, uses and disclosures of protected health information, including the business associate contract requirement Electronic Code of Federal Regulations
Check your own pages against what still stands
The free scan reports which trackers load before consent and flags pages that pair an advertising tag with a health-intent form.