Allina Health System had to pay $12,500,000 to settle a class action over website tracking pixels that allegedly sent patient data to Meta and Google without consent. The settlement affects about 2,531,323 individuals and divides them into two groups according to whether they visited a public web page or used an authenticated patient portal.

While the case may be about website trackers, the use of tracking pixels embedded in marketing emails has come to the forefront in healthcare marketing. At a recent meeting of Paubox customers, healthcare IT individuals and marketers in rural healthcare settings shared notes on email strategy. Tactics discussed included yes/no feedback buttons as a click-trackable alternative to pixel trackers, click-through links, off-hours send times, and shorter subject lines. The idea is that if the open-tracking pixel is the liability, it should be replaced with something the recipient must click. A feedback button may reduce non-consensual data collection, but still requires HIPAA compliance.

 

Why pixels became a liability in the first place

The regulatory pressure around tracking pixels had a clear origin. In 2023, the HHS Office for Civil Rights (OCR) and the Federal Trade Commission (FTC) jointly sent warning letters to more than 100 healthcare organizations about tracking tools on their sites, instructing the recipients to review the laws referenced in the letter and to take steps to protect the privacy and security of individuals’ health information. The guidance saw tracking pixels as a potential HIPAA and FTC Act issue, whether a webpage was behind a patient login or not.

More specific empirical cases against third-party pixels have since emerged. A peer-reviewed paper, published in PNAS Nexus, examined 12 years of archived website data from 1,201 hospitals across the United States. But the authors said pixel tracking persisted despite privacy rules, such as those already in place under HIPAA.

And hospitals that used third-party pixel tracking had an increased probability of breach by 1.4 percentage points, a 46% relative increase compared to the 3% baseline breach rate of the sample, the authors said. The same study found other breaches related to inadvertent disclosure to third parties, with further increases there. On the other hand, hospitals that relied on first-party pixels, which kept the data collected within the organization’s own systems, showed no meaningful increase in breach risk at all; just 14% of the hospital-years in the study used that approach.

 

The email marketing problem

Website pixels and email open-tracking pixels are small, usually invisible pieces of code that send a request to an external server the moment a page loads or an email is opened. A recipient on a health system's newsletter list opens a promotional email about a screening program. If that email contains an open-tracking pixel routed through a third-party email or marketing platform, the platform's server now has a record tying that person's email address, IP address, and open timestamp to content about a specific health topic.

Whether that is protected health information (PHI) and whether you are allowed to send it depends on whether the organization has a business associate agreement (BAA) with that platform and whether the data is being handled in accordance with the minimum necessary standard.

 

What a yes/no button actually changes, and what it does not

Open-tracking pixels are triggered automatically and invisibly as soon as an email is opened, without any action from the recipient. A yes/no button requires the recipient to click on something. Any core objection the OCR has to tracking pixels is that they collect data without the individual's knowledge. At least a visible engagement prompt is more honest about the fact that an interaction is being recorded.

Still, clicking a ‘Was this helpful?’ button sends back a trackable event, usually to the same email or marketing platform that originally hosted the pixel. If that platform is a third party without a signed BAA, the exposure to compliance issues is no different. The organization has just exchanged one mechanism for collecting data for another that just happens to require a click. Just as a pixel can contain query parameters, redirect links and click-tracking URLs can also contain identifying information.

A yes/no button also generates new data that was not there before. There is now an explicit reply associated with a specific recipient and specific health-related content. The response must be protected as rigorously as any other data element associated with an identifiable person and a health topic. Removing a pixel and adding a feedback loop can be just as easily a redistribution of them.

 

Where this leaves healthcare marketers

The conversation among Paubox customers is that rural and resource-constrained healthcare organizations are investigating how to measure email engagement without making the mistakes that are now unfolding in pixel litigation. A feedback button is a perfectly good design choice. It might cut down on some of the silent, non-consensual data collection that regulators have called out specifically.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

Are tracking pixels in marketing emails automatically a HIPAA violation?

The violation risk comes from transmitting identifiable, health-related data to a third party without a business associate agreement or appropriate safeguards, not from the pixel technology itself.

 

Does switching from a pixel to a yes/no feedback button eliminate the compliance risk?

It changes the interaction from passive to active and improves transparency, but the click still typically routes through the same third-party platform.

 

What is the difference between a pixel and a click-tracking button from a technical standpoint?

A pixel fires automatically when an email is opened, with no recipient action required. A button requires an active click, which means data collection depends on recipient engagement rather than happening invisibly on every open.