Skip to main content

The highest-stakes tracking question of any sector

A practice website looks like any other business website and is not one. The moment a page relates to a condition, a provider or an appointment, ordinary marketing tools start touching information that is regulated differently from everything else on the internet.

Last reviewed
2026-09-16

Why people arrive here

Usually a compliance officer, an insurer, or a hospital partner asking what tracking runs on the patient-facing pages. Sometimes it is a marketing agency having installed a pixel on a scheduling page without anybody assessing it. Occasionally it is an accessibility demand letter, because clinics are public accommodations like any other business.

What bites hardest

These are the same obligations every business website carries. In this sector they are the ones that produce letters first.

ADA web accessibility

Title III of the Americans with Disabilities Act requires places of public accommodation to be accessible to people with disabilities. The Department of Justice takes the position that this reaches the websites of businesses open to the public, and has published guidance saying so.

Session replay and wiretapping

Session replay tools record a visitor interactions with a page, including mouse movement, scrolling and keystrokes, and send them to a vendor for playback. Chat widgets often route conversations through a third party too. A substantial volume of litigation argues that doing either without consent is interception of a communication under state wiretap law.

Breach notification

A legal duty to tell affected people, and often a regulator, after personal information you hold has been acquired by somebody who should not have it. Every US state has such a law, and so do the EU and UK under the GDPR.

Cookie consent

Rules about storing information on a visitor device, and about the tracking that storage enables. In the EU and UK the relevant rule comes from the ePrivacy Directive as implemented nationally, alongside the GDPR standard for consent. In the US the question is framed through state privacy statutes and their opt-out rights.

Sector rules to watch

These reach this sector specifically and have no page in the library yet. Each one is a question for a lawyer who knows your business.

HIPAA and online tracking technologies

The Department of Health and Human Services has published guidance on tracking technologies used by covered entities, addressing when information collected on a webpage can be protected health information. Parts of that guidance have been litigated, so its current scope is contested. What is not contested is that HIPAA applies to protected health information wherever it is handled, which makes a third-party pixel on a patient-facing page a question to answer before installing it.

Use of Online Tracking Technologies by HIPAA Covered Entities and Business AssociatesUS Department of Health and Human Services

The HIPAA Security Rule

Where a website or a form handles electronic protected health information, the Security Rule sets administrative, physical and technical safeguards. Most practice marketing sites should be built so that they never touch it at all, which is a simpler position to hold than a compliant one.

HIPAA Security RuleUS Department of Health and Human Services

What WebSpark does

  • No session recording, no advertising pixels, and no analytics on a patient-facing page unless you have decided otherwise with advice.
  • Every third party a page can contact is declared once, and the browser refuses any origin nobody declared, so a tag added later cannot quietly start collecting.
  • Every page tested against WCAG 2.2 AA before it publishes, with a dated record of what was found.
  • Consent that matches the region a visitor is in, with nothing third-party loading before a grant.
  • Data requests logged with their arrival date and tracked against the statutory deadline.
  • A monthly operations record you can hand to a customer, an insurer or a funder.

What stays yours

  • Whether your site should handle protected health information at all. We can build it so it does not, which is usually the right answer for a marketing site, but that is a clinical and legal decision.
  • Your patient portal, scheduling system or electronic records, which are separate systems with their own obligations.
  • Business associate agreements with anybody who does touch protected health information.

WebSpark describes obligations and evidences what a site does. It does not provide legal advice, and this page is not a substitute for a lawyer who knows your business and your state.