← All guides

Tracking · Google Analytics

Google Analytics on a healthcare website: risks, checks, and alternatives

Find out what your practice website sends to tracking tools, what to check under HIPAA, and how to assess cookieless analytics without overclaiming safety.

Your dashboard shows visits. What did the tracking tool receive?

Google Analytics was added when your website launched. Since then, someone added a form, a booking page, or another marketing tool. The reports still load, so tracking feels like a finished job.

But the chart does not show everything the site sends. An event, page address, or script could expose information you did not intend to share without making the report look unusual.

Check the collection before deciding what to keep.

Google says it does not offer a business associate agreement for Analytics. For a practice subject to HIPAA, assess whether the implementation sends protected health information, alongside Google’s product rules.

HHS notes that a court vacated part of its public-page tracking guidance in 2024. An IP address plus a public health-related page visit should not automatically settle the question. Actual form and booking disclosures still need assessment.

Google Analytics and HIPAAHHS tracking guidance and court ruling

Start where people do more than read.

Check what loads on forms and booking pages. Look for addresses containing identifiers, events containing answers, and tools loaded through a tag manager. Use invented activity; involve the responsible advisers if findings suggest exposure.

Document the tool, page, outgoing information, and proposed action. Removing Analytics is incomplete if another script sends the same information.

Cookieless analytics for medical websites: what changes?

Cookieless tools measure activity without setting browser cookies. That does not mean they receive no identifiers or sensitive context. Check requests, logs, retention, and behavior on forms and booking pages too.

Start with useful questions: which service pages get visits, which sources send traffic, and whether visitors use contact links. Choose a reviewed tool that answers those questions with limited collection.

A booking-button click is not a booked patient.

A phone-link tap does not prove a call connected. A booking-link click does not prove an appointment was completed. Use aggregate operational figures to assess outcomes without sending patient records into website analytics.

When tools change, document the date and counting differences. Fewer reported visitors may reflect a new measurement method. Reports should help you decide what to improve, with those limits visible.

Your next steps

  1. 1

    Inventory the scripts

    List the small programs loaded by public pages, booking, forms, and portals. These programs are called scripts; a tag manager can load several of them.

  2. 2

    Review and contain

    Inspect outgoing data using invented test visits. If exposure is suspected, involve the responsible team and contain it promptly.

  3. 3

    Choose useful measures

    Define the needed traffic and action counts. Confirm the replacement’s behavior before enabling it.

  4. 4

    Remove and verify

    Remove unwanted scripts and repeat network checks. Preserve appropriate historical reports and document when measurement changed.

A sample measurement review

A sample measurement review
SignalQuestion to ask
Page addressDoes it contain a patient identifier or sensitive context?
Tracked action, such as a button tapDoes the report receive only the action, or also answers and contact details?
Booking pageWhich other scripts receive activity here?
Historical reportsWhat can we export, and how should it be retained?

These questions identify review work; they do not classify every public page as safe or every event as protected health information.

Before you decide

What changed in the 2024 court decision?

HHS notes that a court vacated the part of its guidance concerning an IP address combined with a visit to an unauthenticated public page about specific health conditions or providers. The distinction matters because that combination alone should not be treated as settling every tracking question.

It does not decide what a particular form, booking flow, or script sends. For your website, we can document those actual data flows so the responsible advisers have something specific to assess against the current guidance.

Will old and new analytics match?

Some difference is expected because tools may define a visit, session, or action differently and filter automated traffic in different ways. A lower number in the new dashboard therefore does not automatically mean fewer people are finding the practice.

We document when the measurement changed and what each report counts. That gives your team context for comparisons and helps distinguish a collection change from a website issue worth investigating.

Sources & further reading

Vendor features and terms can change. Confirm the requirements for your account before making a change.