See which ads actually book patients, without handing patient data to Google or Meta.
Hippo is HIPAA-compliant conversion tracking for practices and telehealth companies.
✅ One snippet, live the same day.
✅ BAA signed at checkout.
✅ Pricing is on this page.
The two ways healthcare marketing goes wrong
You can't tell what's working
Practice owners tell the same story in every forum: "$15k with almost no return." Three agencies and zero ROI. Asking patients how they found you doesn't settle it either, because most of them just say "Google."
I've spent near 15k USD with almost no return.
r/therapists …could NEVER show me how many leads were generated through their ads.
r/Chiropractic It's really hard to say right now if it's the marketing or the economy.
r/Dentistry The fix gets you sued
The tools that could answer the question keep showing up in lawsuits. Law firms now scan healthcare websites for tracking tags. Google won't sign a BAA for Analytics. Meta restricts conversion events for anyone in the health category.
Google won't sign a BAA for Analytics.
r/therapists I'm going through a provider's site right now and removing GA from everything except a few generic pages.
r/agency Law firms scanning healthcare websites for the presence of any analytics tags… and then filing lawsuits.
r/PPC
Hippo exists so you don't have to choose between the two. You get real booking numbers, and patient identities never leave your site.
Start now, no demo callHow Hippo works
Remove the pixels that send PHI.
Take the Google and Meta pixels off your site.
Paste one snippet.
Hippo records visits, bookings, and calls, then strips anything that could identify a patient before the data goes anywhere else.
Send clean conversions back to Google and Meta.
The platforms still get the signal their bidding needs, so your campaigns keep optimizing. Names, conditions, and IP addresses stay out of it.
What you get
Booked patients
Google Ads reports "conversions." Hippo shows you who actually scheduled, so you know your cost per new patient for every campaign. As one dentist put it, the best tracking focuses on "booked patients, not just leads."
A check on your agency
An independent copy of the numbers they report, in an account you own. If you ever switch agencies, everything stays with you.
Tracking that survives ad blockers
Server-side events keep flowing when browsers block pixels.
Proof of compliance
A log of every event that went out and what was stripped from it. If a lawyer or auditor ever asks, you have the receipts.
Built for your practice
Therapists and group practices
Run ads without sending client data to Meta, and find out whether those $12 clicks ever turn into clients.
Dental
Cost per new patient for every campaign, in an account that belongs to you.
Med spas
Works alongside LegitScript certification and shows which promotions actually get booked.
Telehealth
The compliant server-side setup you've been trying to hire someone to build. Working today.
Pricing
1,000 visitors/month
$99/month
Month to month.
- BAA signed at checkout
2,000 visitors/month
$199/month
Month to month.
- BAA signed at checkout
10,000 visitors/month
$299/month
Month to month.
- BAA signed at checkout
Every plan includes:
- BAA signed at checkout
- No setup fees
- Cancel anytime. No compliance add-on that locks you in the day you enable it.
The same architecture as the $35,000-a-year enterprise tools, at a price a practice can actually pay.
The lawyers are already scanning for this
Class action firms scan healthcare websites for tracking tags, then file. The defendants aren't all venture-backed startups, either.
Derick Dermatology
Pixels on the booking flow.
South Coast Med Spa
Pixels sending patient info to Google.
Aspen Dental
Meta Pixel and Google Analytics.
SimplePractice
Trackers on the client portal.
Frequently asked questions
Is Google Analytics (GA4) HIPAA compliant?
No. Google won't sign a BAA for Analytics, which means nothing covers that data on a healthcare site. This is why legal teams keep pulling GA off provider websites. Hippo reports the same numbers under a BAA.
Will Google or Meta sign a BAA?
Google offers BAAs for Workspace and Cloud, but never for Analytics or Ads. Meta doesn't offer one at all. Staying compliant means keeping PHI away from both platforms in the first place, which is the job Hippo does.
Can I put the Meta Pixel on my medical website?
On a booking page, a portal, or a condition page, the pixel sends an identifier along with the page context. That combination is where most of the current lawsuits started. The safe route is a tag that strips identifying data before anything is sent.
Is a consent banner enough?
No. A banner records a preference, and the pixel fires anyway. HHS guidance does not treat cookie consent as HIPAA authorization.
My agency runs our ads. Isn't compliance their problem?
HIPAA liability stays with the covered entity, meaning you. As one agency put it in a dental forum: "if they mess up, it's on you." Hippo works whether you or your agency runs the account, and the data belongs to you either way.
Will removing the native pixel hurt my campaign performance?
It can, if you replace it with nothing. Advertisers who go dark this way watch Meta report one conversion while their own system shows ten. Hippo sends cleaned conversion events through the platforms' server-side APIs instead, so bidding keeps learning from real bookings.
Why is Meta restricting my events?
In January 2025, Meta began suppressing lower-funnel events for advertisers in the health and wellness category. Server-side conversions with PHI removed are the supported way to restore that signal.
Can I do retargeting or lookalike audiences?
For the most part, no. Platform policy and HIPAA both restrict it, whatever tool you use, and a vendor promising full remarketing to patient lists should worry you. Hippo sticks to what can be done safely: conversion measurement and clean optimization signal.
Can't I just build this with server-side GTM?
You can, and some agencies try. It often fails legal review anyway; one reported that moving GTM server-side and anonymizing IPs "wasn't enough for the lawyers." A DIY build also leaves you holding the liability, with no PHI-stripping layer and no audit trail.
How is Hippo different from the enterprise tools?
The architecture is the same: no client-side pixels, PHI stripped, server-side conversions under a BAA. The difference is who it's built for. Hippo publishes its pricing, goes live the same day, and sizes its plans for a practice's ad budget rather than a hospital system's.
Is the BAA really included?
Yes, in every plan. You sign it electronically at checkout, before any data flows.
How long does setup take? Do I need a developer?
One snippet. Most sites go live the same day, and our team will handle the implementation with you if you want help. No developer required.