In a Rutgers University review, researchers examined 12 years of website data covering 1,201 US hospitals and found that facilities with third-party tracking pixels were 46% more likely to report a data breach than those without and that about two-thirds of hospitals in the data set used this kind of pixel at all.
In rural healthcare, that risk compounds an existing resource shortage. In a recent industry survey, 73% of rural healthcare organizations say they are struggling to stay HIPAA compliant due to staffing and funding shortfalls. The same survey found that 88% of rural healthcare leaders were not confident their current email platform was HIPAA compliant as is. They are asking rural clinics to effectively manage the same pixel-driven breach exposure as large systems, with a fraction of the staff to do it.
What tracking actually does, and why it is a HIPAA problem
Third-party tracking pixels are tiny pieces of embedded code that communicate a user’s activity, browsing behavior, IP address, and sometimes visits to condition-specific pages to an outside company, such as an ad network. They fire automatically when the page loads or a message is opened, and do not offer the kind of opt-out choice that a cookie banner does. HHS guidance in 2024 said, “Any disclosure of PHI to the vendor without individuals’ authorizations requires the vendor to have a signed BAA [business associate agreement] in place.” The position has faced legal pushback, but it has not removed the exposure. The courts have had their own view of the risk. The volume of litigation illustrates the risk. BakerHostetler reported that more than 200 lawsuits had been filed against healthcare organizations over tracking technologies, with 75% filed in 2023.
Paubox’s reporting of the 2024 LOKKER analysis of 3,419 US websites across healthcare, technology, financial services, and retail found that 33% of the healthcare organizations studied used the Meta Pixel. Across the full sample, not healthcare websites specifically, 2% used web trackers originating from China, Russia, or Iran. The study also found that 59% of the healthcare websites had consent banners. Across all industries studied, 98.5% of websites set cookies when the page loaded, with an average of 33 cookies before the consent banner appeared.
Patients still want digital engagement
There are practical reasons rural patients would want digital engagement, as research in a rural primary care population notes that “online patient portals have the potential to improve patient engagement and health care outcomes,” linking that benefit directly to the barriers of distance and transportation that many rural patients face in getting to a clinic in person.
A study of a rural family health practice asked patients what they'd actually use digital communication for. Sixty-five percent of patients said they'd use email with their family doctor for prescription refills, 63% for appointment booking, 60% for lab results, and 50% for general education. The same researchers cautioned that electronic communication "raises concerns about patient privacy and data security" that need addressing before scaling it up.
A qualitative study of rural aged care residents and family caregivers found most participants experienced only passive engagement around medication communication, "receiving mainly reactive, one-way information from providers," not because patients wanted less contact, but because proactive outreach from providers was limited.
Operational tracking is not the same as surveillance tracking
Delivery tracking, knowing whether a message was delivered, opened, bounced, or failed, is a different category of activity than surveillance-style tracking. Surveillance-style tracking typically uses third-party cookies, pixels, or analytics scripts to profile users or follow their activity across websites. The FTC explains that third-party trackers can follow users across sites, while HHS warns that tracking technologies may result in impermissible disclosures when they transmit PHI to outside vendors.
An operational question is whether a patient gets or opens an appointment reminder, so staff can follow up. The HHS views appointment reminders as part of treatment, so the reminder itself typically does not require the patient’s authorization. A pixel is used for a different marketing purpose to tell an advertising network that a patient visited a condition-specific page.
However, the operational purpose itself does not automatically make an email pixel HIPAA compliant. If the pixel is sending PHI to a vendor on behalf of the clinic, that disclosure must be allowed under the Privacy Rule and the vendor typically must sign a BAA. Disclosures of PHI for advertising may require the patient’s authorization. HIPAA does not formally categorize tracking as “operational” or “surveillance”; it focuses on what information is disclosed, who receives it, why it is disclosed, and whether the necessary permissions, authorizations, and contractual safeguards are in place.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
Are tracking pixels illegal in healthcare?
Neither HIPAA nor federal privacy law prohibits every use of tracking pixels. The legal risk depends on what information the pixel collects, whether that information identifies a person, who receives it, and why it is disclosed.
When does information collected by a pixel become PHI?
Tracking information may be PHI when it identifies or could reasonably identify an individual and relates to that person’s health, healthcare, or payment for care. An IP address paired with a visit to a public health-information page is not automatically PHI in every case.
Is a cookie banner a valid HIPAA authorization?
The HHS expressly states that cookie banners do not constitute HIPAA-compliant authorizations. Telling visitors about tracking in a privacy policy is also not enough by itself to authorize a PHI disclosure.
