Three out of four hospital websites are quietly sending patient behavior to advertising networks — even when visitors explicitly opt out. That’s the takeaway from a new joint study by Piwik PRO and Verified Data, and it should terrify anyone running a healthcare digital property in 2026. This isn’t a theoretical privacy debate. It’s a $100 million legal problem that’s already changing how HIPAA-regulated organizations approach their marketing stack.
The Numbers Behind Healthcare’s Tracking Problem
The Piwik PRO/Verified Data report, Are healthcare companies one audit away from a compliance crisis?, scanned 59 major U.S. hospital and clinic websites and found 75 unique tracking tools operating across them — including Google Analytics, Meta Pixel, Microsoft Advertising, and session replay technologies. According to the study, 73% of those sites had active advertising or marketing trackers running even when the Global Privacy Control (GPC) opt-out signal was enabled, and 69% used marketing or advertising cookies.
The narrow gap between those two figures tells a technical story. Some trackers are firing without cookies at all, which means a security team relying on cookie-blocking as a compliance backstop is protecting nothing. If you’re a hospital CIO who told the board “we honor GPC signals,” this data suggests you should verify that claim before your next audit.
Imagine a patient searching your oncology department’s site for chemotherapy side effects, then booking an appointment. If Meta Pixel is on that page, Facebook may know they did both — regardless of whether they clicked “reject cookies.” Our prediction: within 18 months, plaintiffs’ firms will start filing suits based specifically on GPC-signal violations, not just pixel presence.
Why $100 Million in Settlements Is Just the Opening Act
Piwik PRO reports that more than $100 million was paid out between 2023 and 2025 to resolve healthcare privacy violations tied to tracking tools like Meta Pixel, Google Analytics, and Microsoft Advertising code. Major HIPAA breaches connected to these tools have already been reported to the HHS’ Office for Civil Rights by Advocate Aurora Health, Kaiser Permanente, Novant Health, and Atrium Health.
In practice, this shifts how in-house counsel evaluates the marketing stack. What used to be a growth-team decision (“add the Meta Pixel to boost retargeting”) is now a legal-review checkpoint. That cross-functional tension is where purpose-built healthcare software engineered for compliance beats bolting privacy controls onto a general-purpose analytics stack after the fact.
Consider a mid-sized regional hospital system running Google Analytics on its patient portal login page. If a class action alleges PHI leakage, the discovery phase alone can cost millions before anyone even discusses settlement. Our take: the $100 million figure will look quaint by 2027, because attorneys have now built repeatable playbooks against tracker-based disclosure claims.
The Inherited-Stack Problem Nobody Wants to Talk About
Magdalena Pawlitko, Head of Global Sales at Piwik PRO, framed the issue bluntly: healthcare organizations “often inherit their analytics setup rather than actively choose it.” Google Analytics became the default because it was free, established, and widely understood — but what started as page-view counting has, in her words, evolved into “broader behavioral ad targeting platforms.” That scope creep is the actual root cause.
For engineering teams, the tag manager on your marketing site was probably configured by an agency three vendors ago. Nobody currently on staff knows what every script does. That’s a governance failure that shows up on the P&L only when the subpoena arrives. The same pattern shows up in fintech and identity — any regulated vertical where compliance-heavy KYC and digital identity workflows sit downstream of marketing-driven tracking that nobody audited.
If you run a hospital marketing site, the practical move is to inventory every script loaded on PHI-adjacent pages — appointment booking, symptom checkers, portal logins — and confirm each one has a legitimate, documented purpose. Our prediction: within two years, cyber insurers will start requiring quarterly tag-inventory reports as a condition of coverage for healthcare policyholders.
What a Compliant Healthcare Analytics Stack Actually Looks Like
The study’s authors lay out a remediation path: audit the current tracking setup, remove advertising pixels from PHI-adjacent pages, enforce opt-out signals at the tag management layer (not just in individual scripts), replace non-compliant analytics with a purpose-built platform, and make compliance a standing requirement rather than a one-off review. Brian Clifton, founder of Verified Data, argues that organizations that get this right “aren’t just reducing their legal risk. They’re building something more valuable: a digital presence their patients can actually trust.”
Enforcing opt-out at the tag management layer is the technical detail most teams miss. If GPC is honored only by individual scripts, a single misconfigured tag breaks the whole chain. Enforcing at the tag manager creates a single control point that survives vendor changes. The same architectural principle applies when embedding AI into regulated software — governance has to live at the platform layer, not in each feature.
For a practical scenario: a health system replacing Google Analytics with a HIPAA-aligned analytics platform should also route all tags through a single manager that reads GPC and honors it globally, then document the configuration decisions in a compliance log. Our take: the healthcare organizations that treat this as an infrastructure project — not a marketing project — will be the ones that stay out of the next wave of settlements.
FAQ
Q: What is the Global Privacy Control (GPC) signal? A: GPC is a browser-based signal that communicates a user’s preference to opt out of the sale or sharing of their personal data. When a website receives a GPC signal, it should disable tracking behaviors accordingly. The Piwik PRO/Verified Data study found that 73% of scanned healthcare sites kept advertising trackers active even when GPC was enabled.
Q: Does HIPAA cover website tracking tools? A: HIPAA covers protected health information (PHI) — personally identifiable health information that regulated entities must protect. When tracking tools on healthcare websites collect and transmit data that includes PHI to third parties, that transmission can constitute a HIPAA violation. Major breaches involving Advocate Aurora Health, Kaiser Permanente, Novant Health, and Atrium Health have already been reported to HHS’ Office for Civil Rights over exactly this issue.
Q: Can healthcare providers still run digital marketing campaigns? A: Yes. The researchers make clear that healthcare providers do not have to halt digital marketing — they need to audit their setup and build the right infrastructure. That means removing pixels from PHI-adjacent pages, enforcing opt-out at the tag management layer, and documenting compliance decisions as a standing practice.
Key Takeaways
- Healthcare organizations still using Google Analytics or Meta Pixel on PHI-adjacent pages should assume they are on a plaintiff firm’s target list, not that they are safely under the radar.
- Cookie-blocking is not a compliance strategy — the study’s data suggests some trackers fire without cookies, so controls must operate at the tag management layer.
- The next enforcement wave will likely focus on GPC-signal violations specifically, giving compliant vendors a competitive edge in RFPs.
- Cyber insurance underwriters are the next stakeholder to watch; expect tag-inventory documentation to become a policy requirement.
- Treating website analytics governance as an infrastructure decision — not a marketing preference — is what separates the health systems that get sued from the ones that don’t.