Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Solutions / Healthcare Privacy Software

Healthcare Privacy Software

Identify and control the pixels, cookies, session-replay tools, chat services and SDKs operating across healthcare websites, portals and applications.

Healthcare privacy software

Protect sensitive health data before a tracker exposes it.

Discover the pixels, cookies, session-replay tools, chat technologies, embedded media, SDKs and third-party services operating across your healthcare websites and applications. Captain Compliance helps control when they load, what they receive and whether the required privacy choice has been captured.

Run a Free Healthcare Privacy AuditBook a Healthcare Privacy Review

// Automated scanning, enforceable controls, continuous monitoring and human privacy support.

Healthcare data-flow monitorIllustrative
Patient journey
Provider search
Condition or treatment page
Appointment request
Symptom checker
Patient-portal login
Telehealth registration
Captain Compliance enforcement layer
Third-party destinations
Analytics platformConsent required
Advertising platformBlocked
Chat providerHuman review required
Session-replay vendorBlocked
Video providerAllowed
CRM or marketing platformPotential sensitive data
● Evidence preserved for every decision

The website is part of the data environment

Sensitive health data can leave before a form is submitted.

Healthcare privacy risk is not limited to electronic medical records. Website pages, appointment tools, symptom checkers, patient-portal login screens, telehealth applications, chat services and embedded content may generate or transmit information about a person’s interests, identity, device, location, symptoms, treatment options, appointments or care.

A privacy notice cannot prevent that transmission. A consent banner cannot protect the user if the underlying code ignores the choice. Captain Compliance examines what the technology actually does.

1 · Patient journey

Provider searchTreatment pagesAppointmentsSymptom toolsPortal loginTelehealth intake

2 · Website technologies

PixelsAnalyticsSession replayChatEmbedded mediaSDKsServer-side APIs

// Enforcement applied here

3 · External recipients

Ad platformsAnalytics vendorsChat providersReplay vendorsCRMVideo hosts

Healthcare tracking risks

Find the technologies operating beneath the patient experience.

Advertising pixels

Identify Meta, Google, TikTok, LinkedIn and other advertising technologies across healthcare journeys.

Session replay

Detect tools capable of recording clicks, scrolling, form interactions, navigation or other visitor behavior.

Chat and chatbot tools

Review third-party chat technologies and the information they may receive from sensitive conversations or page context.

Appointment and intake flows

Identify technologies operating on appointment requests, symptom tools, registrations and healthcare intake pages.

Patient portals

Review login, registration and authenticated journeys separately from general public content.

Embedded video and media

Surface third-party video players, maps, scheduling tools and embedded services that may create additional data flows.

Mobile SDKs and APIs

Extend assessments to application events, device identifiers, advertising IDs and server-side transmissions where supported.

Consent failures

Identify designated nonessential technologies loading before a required choice or continuing after rejection.

// Scanning observes what technologies load and what they transmit where that is observable. It does not decrypt every payload or inspect every server-side process.

Beyond HIPAA

HIPAA is only one part of the healthcare privacy landscape.

HIPAA

The HIPAA Privacy, Security and Breach Notification Rules apply to covered entities and business associates when protected health information is involved — not to every health-related company, website or visitor interaction.

FTC Act

The FTC can challenge deceptive or unfair representations and practices involving the collection, use, disclosure and protection of health information.

Health Breach Notification Rule

The FTC’s rule can apply to certain health applications, connected devices, personal health record vendors, related entities and service providers not covered by HIPAA.

State consumer health-data laws

State laws can regulate broadly defined consumer health data, including in contexts that fall outside HIPAA.

Privacy and interception laws

Depending on the facts and jurisdiction, claims may invoke CIPA, ECPA, state wiretapping laws, consumer-protection statutes, comprehensive privacy laws, biometric laws and other requirements.

“Not covered by HIPAA” does not mean “not regulated.”

HIPAA tracking distinctions

Context determines whether website information is PHI.

Authenticated experiences

Patient portals and authenticated healthcare applications may expose tracking technologies to medical-record numbers, appointment information, diagnoses, prescriptions, billing information and other PHI.

Transactional healthcare journeys

Appointment requests, symptom checkers, registration pages, telehealth intake and similar tools may involve identifiable health information even when the visitor has not logged in.

General public pages

Many unauthenticated pages — visiting hours, careers, general organizational information — may not involve PHI. The analysis depends on the information involved and its relationship to the individual’s health, care or payment for care.

// On 20 June 2024 a federal court vacated the portion of HHS guidance asserting that HIPAA obligations could be triggered solely when technology connects an IP address with a visit to an unauthenticated public page addressing health conditions or providers. That interpretation is not repeated here, and not every page on a healthcare website carries the same legal classification.

Health-data enforcement

Regulators have focused directly on health-data advertising practices.

FTC order · civil penalty

GoodRx

The FTC alleged that GoodRx failed to notify consumers and others about unauthorized disclosures of identifiable health information to Facebook, Google and other companies. The resulting order included a $1.5 million civil penalty.

FTC source →

FTC order · consumer refunds

BetterHelp

The FTC finalized an order prohibiting BetterHelp from sharing health data for advertising and requiring $7.8 million for partial consumer refunds.

FTC source →

FTC allegation · settlement

Monument

The FTC alleged that the addiction-treatment service disclosed personal health information to advertising platforms without consent after promising confidentiality.

FTC source →

// These are distinct matters with different outcomes. The GoodRx figure was a civil penalty; the BetterHelp figure was designated for partial consumer refunds, not a fine. Last legally reviewed: August 2026.

How Captain Compliance helps

Move from written policy to technical enforcement.

Continuous scanningContinuously identify cookies, pixels, scripts, vendors and changes across healthcare websites.Consent enforcementPrevent designated technologies from loading until the required choice or authorization condition is satisfied.

Regional controls

Apply different consent and privacy experiences based on jurisdiction and organizational requirements.

Healthcare journey segmentation

Apply stricter controls to appointments, intake, portals, symptom tools, sensitive content and other designated journeys.

Dynamic privacy noticesKeep disclosures connected to the technologies and processing activities actually in use.

Consent and authorization evidence

Maintain timestamped choices, applicable language, configuration versions and withdrawal records.

Data mapping and assessmentsConnect website findings to data inventories, vendors, DPIAs, PIAs, health-data assessments and remediation workflows.

Human support

Give privacy, legal, engineering and marketing teams access to Captain Compliance specialists.

// Captain Compliance does not determine whether specific information is PHI. That classification requires human and legal review.

Automated scanning plus human review

Healthcare privacy cannot be reduced to a cookie count.

Automated technology review

  • ·Cookies
  • ·Advertising pixels
  • ·Analytics
  • ·Session replay
  • ·Chat
  • ·Embedded video
  • ·Third-party domains
  • ·Consent behavior
  • ·GPC behavior
  • ·Tracker changes

Human privacy review

  • ·Sensitive journey identification
  • ·Health-data context
  • ·Disclosure observations
  • ·Consent and authorization gaps
  • ·Vendor-risk observations
  • ·Applicable-law screening
  • ·Remediation priorities
  • ·Documentation recommendations

Request a Healthcare Privacy Audit

Healthcare use cases

Control risk across the digital patient lifecycle.

Patient acquisition

Use marketing technologies without giving them unrestricted access to sensitive healthcare journeys.

Provider and treatment searches

Understand what tools receive page context, identifiers and user behavior.

Appointment scheduling

Apply appropriate controls to appointment, intake and registration flows.

Telehealth onboarding

Review technologies operating during account creation, eligibility, intake and care access.

Patient portals

Protect authenticated and login-related experiences from unapproved tracking.

Health applications

Review SDKs, APIs, device identifiers, application events and connected services.

Patient education

Control analytics, video, personalization and advertising tools on sensitive content.

Connected platform

One healthcare privacy operating system.

Compliance Shield

Healthcare privacy protection backed by real support.

Qualifying Captain Compliance customers may receive additional protection through Compliance Shield when Captain Compliance technology is properly deployed and maintained under the applicable agreement.

Approved configurationsContinuous monitoringConsent evidenceTechnical documentationClaim-response supportHuman assistance

Explore Compliance Shield

// Compliance Shield is subject to eligibility requirements, approved configurations, continued use and the terms, limitations and exclusions of the applicable written agreement. Not every healthcare privacy allegation qualifies.

Questions

Healthcare privacy, answered plainly.

Does HIPAA apply to every healthcare website?

No. HIPAA applies to covered entities and business associates when protected health information is involved. Many health-adjacent companies, wellness apps and health-content sites fall outside HIPAA — though other laws, including the FTC Act, the Health Breach Notification Rule and state consumer health-data laws, may still apply.

When can website tracking information become PHI?

It depends on context and the individual’s relationship to care. Authenticated portal journeys are the clearest case. Transactional journeys such as appointment requests or intake forms may involve identifiable health information even without login. Many general public pages do not. The classification requires legal review.

Are tracking technologies prohibited by HIPAA?

No. HIPAA does not ban tracking technologies. It regulates the use and disclosure of protected health information, which affects whether a given technology may receive that information, on which pages, and under what agreements and safeguards.

What is the FTC Health Breach Notification Rule?

An FTC rule that can require notification following unauthorized disclosure of identifiable health information by certain health apps, connected devices, personal health record vendors, related entities and their service providers — entities generally not covered by HIPAA.

Can state health-data laws apply when HIPAA does not?

Yes. Several states regulate broadly defined consumer health data in contexts outside HIPAA, sometimes with their own consent, disclosure and rights requirements.

What types of healthcare pages carry the greatest tracking risk?

Authenticated portals, appointment and intake flows, symptom checkers, telehealth registration and pages tied to specific conditions or treatments. These are where identifiers and health context are most likely to appear together.

Does a business associate agreement make every tracker acceptable?

No. A BAA addresses the contractual relationship and permitted uses; it does not by itself make a disclosure permissible, satisfy minimum-necessary requirements, or resolve consent, disclosure and other obligations. Many advertising platforms will not sign one at all.

Can a normal cookie banner protect healthcare data?

Not on its own. A banner records a choice; it does not prevent a transmission unless the underlying technologies are actually blocked until the required condition is met. The enforcement behind the banner is what matters.

How does Captain Compliance block tracking technologies?

Designated nonessential technologies can be prevented from loading or transmitting until the required consent or authorization condition is satisfied, configured per journey, region and technology.

Can Captain Compliance review patient-portal and appointment journeys?

Yes. Authenticated and transactional journeys are reviewed separately from general public content, since the risk profile and applicable requirements differ.

Does Captain Compliance sign a BAA?

BAA availability depends on the engagement, deployment and services involved. Please confirm directly with the Captain Compliance team for your specific configuration rather than assuming availability.

What does the free healthcare privacy audit include?

An automated technology review across healthcare journeys — cookies, pixels, analytics, session replay, chat, embedded media, third-party domains and consent behavior — followed by human review covering sensitive journeys, disclosure observations, consent gaps, vendor risk and remediation priorities.

How does Compliance Shield work?

Qualifying customers with properly deployed and maintained technology may receive defined support under the applicable written agreement. Eligibility, obligations, limitations and exclusions are governed by that agreement.

Get started

Find out what your healthcare website is sending.

Identify tracking technologies, sensitive data journeys, consent failures and third-party transmissions before they become regulatory findings, demand letters or patient-trust problems.

Run My Free Healthcare Privacy AuditTalk to a Healthcare Privacy Specialist

Captain Compliance provides privacy technology, implementation and support. It is not a healthcare provider and does not provide legal advice. Whether information constitutes PHI, which laws apply and what disclosures are permitted depend on your organization, journeys and jurisdiction, and warrant review by qualified counsel.