Healthcare privacy software
Protect sensitive health data before a tracker exposes it.
Discover the pixels, cookies, session-replay tools, chat technologies, embedded media, SDKs and third-party services operating across your healthcare websites and applications. Captain Compliance helps control when they load, what they receive and whether the required privacy choice has been captured.
Run a Free Healthcare Privacy AuditBook a Healthcare Privacy Review
// Automated scanning, enforceable controls, continuous monitoring and human privacy support.
The website is part of the data environment
Sensitive health data can leave before a form is submitted.
Healthcare privacy risk is not limited to electronic medical records. Website pages, appointment tools, symptom checkers, patient-portal login screens, telehealth applications, chat services and embedded content may generate or transmit information about a person’s interests, identity, device, location, symptoms, treatment options, appointments or care.
A privacy notice cannot prevent that transmission. A consent banner cannot protect the user if the underlying code ignores the choice. Captain Compliance examines what the technology actually does.
1 · Patient journey
Provider searchTreatment pagesAppointmentsSymptom toolsPortal loginTelehealth intake
2 · Website technologies
PixelsAnalyticsSession replayChatEmbedded mediaSDKsServer-side APIs
// Enforcement applied here
3 · External recipients
Ad platformsAnalytics vendorsChat providersReplay vendorsCRMVideo hosts
Healthcare tracking risks
Find the technologies operating beneath the patient experience.
Advertising pixels
Identify Meta, Google, TikTok, LinkedIn and other advertising technologies across healthcare journeys.
Session replay
Detect tools capable of recording clicks, scrolling, form interactions, navigation or other visitor behavior.
Chat and chatbot tools
Review third-party chat technologies and the information they may receive from sensitive conversations or page context.
Appointment and intake flows
Identify technologies operating on appointment requests, symptom tools, registrations and healthcare intake pages.
Patient portals
Review login, registration and authenticated journeys separately from general public content.
Embedded video and media
Surface third-party video players, maps, scheduling tools and embedded services that may create additional data flows.
Mobile SDKs and APIs
Extend assessments to application events, device identifiers, advertising IDs and server-side transmissions where supported.
Consent failures
Identify designated nonessential technologies loading before a required choice or continuing after rejection.
// Scanning observes what technologies load and what they transmit where that is observable. It does not decrypt every payload or inspect every server-side process.
Beyond HIPAA
HIPAA is only one part of the healthcare privacy landscape.
HIPAA
The HIPAA Privacy, Security and Breach Notification Rules apply to covered entities and business associates when protected health information is involved — not to every health-related company, website or visitor interaction.
FTC Act
The FTC can challenge deceptive or unfair representations and practices involving the collection, use, disclosure and protection of health information.
Health Breach Notification Rule
The FTC’s rule can apply to certain health applications, connected devices, personal health record vendors, related entities and service providers not covered by HIPAA.
State consumer health-data laws
State laws can regulate broadly defined consumer health data, including in contexts that fall outside HIPAA.
Privacy and interception laws
Depending on the facts and jurisdiction, claims may invoke CIPA, ECPA, state wiretapping laws, consumer-protection statutes, comprehensive privacy laws, biometric laws and other requirements.
“Not covered by HIPAA” does not mean “not regulated.”
HIPAA tracking distinctions
Context determines whether website information is PHI.
Authenticated experiences
Patient portals and authenticated healthcare applications may expose tracking technologies to medical-record numbers, appointment information, diagnoses, prescriptions, billing information and other PHI.
Transactional healthcare journeys
Appointment requests, symptom checkers, registration pages, telehealth intake and similar tools may involve identifiable health information even when the visitor has not logged in.
General public pages
Many unauthenticated pages — visiting hours, careers, general organizational information — may not involve PHI. The analysis depends on the information involved and its relationship to the individual’s health, care or payment for care.
// On 20 June 2024 a federal court vacated the portion of HHS guidance asserting that HIPAA obligations could be triggered solely when technology connects an IP address with a visit to an unauthenticated public page addressing health conditions or providers. That interpretation is not repeated here, and not every page on a healthcare website carries the same legal classification.
Health-data enforcement
Regulators have focused directly on health-data advertising practices.
FTC order · civil penalty
GoodRx
The FTC alleged that GoodRx failed to notify consumers and others about unauthorized disclosures of identifiable health information to Facebook, Google and other companies. The resulting order included a $1.5 million civil penalty.
FTC order · consumer refunds
BetterHelp
The FTC finalized an order prohibiting BetterHelp from sharing health data for advertising and requiring $7.8 million for partial consumer refunds.
FTC allegation · settlement
Monument
The FTC alleged that the addiction-treatment service disclosed personal health information to advertising platforms without consent after promising confidentiality.
// These are distinct matters with different outcomes. The GoodRx figure was a civil penalty; the BetterHelp figure was designated for partial consumer refunds, not a fine. Last legally reviewed: August 2026.
How Captain Compliance helps
Move from written policy to technical enforcement.
Regional controls
Apply different consent and privacy experiences based on jurisdiction and organizational requirements.
Healthcare journey segmentation
Apply stricter controls to appointments, intake, portals, symptom tools, sensitive content and other designated journeys.
Consent and authorization evidence
Maintain timestamped choices, applicable language, configuration versions and withdrawal records.
Human support
Give privacy, legal, engineering and marketing teams access to Captain Compliance specialists.
// Captain Compliance does not determine whether specific information is PHI. That classification requires human and legal review.
Automated scanning plus human review
Healthcare privacy cannot be reduced to a cookie count.
Automated technology review
- ·Cookies
- ·Advertising pixels
- ·Analytics
- ·Session replay
- ·Chat
- ·Embedded video
- ·Third-party domains
- ·Consent behavior
- ·GPC behavior
- ·Tracker changes
Human privacy review
- ·Sensitive journey identification
- ·Health-data context
- ·Disclosure observations
- ·Consent and authorization gaps
- ·Vendor-risk observations
- ·Applicable-law screening
- ·Remediation priorities
- ·Documentation recommendations
Healthcare use cases
Control risk across the digital patient lifecycle.
Patient acquisition
Use marketing technologies without giving them unrestricted access to sensitive healthcare journeys.
Provider and treatment searches
Understand what tools receive page context, identifiers and user behavior.
Appointment scheduling
Apply appropriate controls to appointment, intake and registration flows.
Telehealth onboarding
Review technologies operating during account creation, eligibility, intake and care access.
Patient portals
Protect authenticated and login-related experiences from unapproved tracking.
Health applications
Review SDKs, APIs, device identifiers, application events and connected services.
Patient education
Control analytics, video, personalization and advertising tools on sensitive content.
Connected platform
One healthcare privacy operating system.
Compliance Shield
Healthcare privacy protection backed by real support.
Qualifying Captain Compliance customers may receive additional protection through Compliance Shield when Captain Compliance technology is properly deployed and maintained under the applicable agreement.
Approved configurationsContinuous monitoringConsent evidenceTechnical documentationClaim-response supportHuman assistance
// Compliance Shield is subject to eligibility requirements, approved configurations, continued use and the terms, limitations and exclusions of the applicable written agreement. Not every healthcare privacy allegation qualifies.
Questions
Healthcare privacy, answered plainly.
Does HIPAA apply to every healthcare website?
No. HIPAA applies to covered entities and business associates when protected health information is involved. Many health-adjacent companies, wellness apps and health-content sites fall outside HIPAA — though other laws, including the FTC Act, the Health Breach Notification Rule and state consumer health-data laws, may still apply.
When can website tracking information become PHI?
It depends on context and the individual’s relationship to care. Authenticated portal journeys are the clearest case. Transactional journeys such as appointment requests or intake forms may involve identifiable health information even without login. Many general public pages do not. The classification requires legal review.
Are tracking technologies prohibited by HIPAA?
No. HIPAA does not ban tracking technologies. It regulates the use and disclosure of protected health information, which affects whether a given technology may receive that information, on which pages, and under what agreements and safeguards.
What is the FTC Health Breach Notification Rule?
An FTC rule that can require notification following unauthorized disclosure of identifiable health information by certain health apps, connected devices, personal health record vendors, related entities and their service providers — entities generally not covered by HIPAA.
Can state health-data laws apply when HIPAA does not?
Yes. Several states regulate broadly defined consumer health data in contexts outside HIPAA, sometimes with their own consent, disclosure and rights requirements.
What types of healthcare pages carry the greatest tracking risk?
Authenticated portals, appointment and intake flows, symptom checkers, telehealth registration and pages tied to specific conditions or treatments. These are where identifiers and health context are most likely to appear together.
Does a business associate agreement make every tracker acceptable?
No. A BAA addresses the contractual relationship and permitted uses; it does not by itself make a disclosure permissible, satisfy minimum-necessary requirements, or resolve consent, disclosure and other obligations. Many advertising platforms will not sign one at all.
Can a normal cookie banner protect healthcare data?
Not on its own. A banner records a choice; it does not prevent a transmission unless the underlying technologies are actually blocked until the required condition is met. The enforcement behind the banner is what matters.
How does Captain Compliance block tracking technologies?
Designated nonessential technologies can be prevented from loading or transmitting until the required consent or authorization condition is satisfied, configured per journey, region and technology.
Can Captain Compliance review patient-portal and appointment journeys?
Yes. Authenticated and transactional journeys are reviewed separately from general public content, since the risk profile and applicable requirements differ.
Does Captain Compliance sign a BAA?
BAA availability depends on the engagement, deployment and services involved. Please confirm directly with the Captain Compliance team for your specific configuration rather than assuming availability.
What does the free healthcare privacy audit include?
An automated technology review across healthcare journeys — cookies, pixels, analytics, session replay, chat, embedded media, third-party domains and consent behavior — followed by human review covering sensitive journeys, disclosure observations, consent gaps, vendor risk and remediation priorities.
How does Compliance Shield work?
Qualifying customers with properly deployed and maintained technology may receive defined support under the applicable written agreement. Eligibility, obligations, limitations and exclusions are governed by that agreement.
Get started
Find out what your healthcare website is sending.
Identify tracking technologies, sensitive data journeys, consent failures and third-party transmissions before they become regulatory findings, demand letters or patient-trust problems.
Run My Free Healthcare Privacy AuditTalk to a Healthcare Privacy Specialist
Captain Compliance provides privacy technology, implementation and support. It is not a healthcare provider and does not provide legal advice. Whether information constitutes PHI, which laws apply and what disclosures are permitted depend on your organization, journeys and jurisdiction, and warrant review by qualified counsel.