Hippo is HIPAA-compliant ad tracking for community hospitals and health systems. It counts the appointment requests, calls and bookings your service-line campaigns produce, in an account you own, and keeps patient identities, departments and conditions out of what Google and Meta receive.
No annual contracts.
Transparent pricing.
We set it up for you.
In 2021 over 98% of US hospitals and health systems used tracking pixels. By 2025, a marketing firm's analysis of provider websites found 30% did(opens in a new tab). The campaigns kept running. What stopped was the ability to see which orthopedics, maternity or cardiac campaign filled the schedule.
A hospital campaign ends in an appointment request, a find-a-doctor search, a call to the access center or a booking in the scheduler, and the portal sits beside all of them. The page address alone can name the department or the condition. What the account counts as a conversion, and what that conversion carries, decides whether the numbers mean anything.
What is worth counting:
What isn't:
A campaign can fill a service-line page with visitors who never call.
Here is the sum, with example numbers.
The sum, with example numbers
Example figures. Put in your own. Each line needs a count you trust, and the last one needs the campaign it came from.
Try the sum with your own numbers. If the appointments are not tied to campaigns, that is the gap Hippo closes. It records the request, the call and the booking, ties each to the campaign and the service line that produced it, and sends the conversion to Google and Meta without the name, email, phone number, IP address, page path or department.

Campaigns that kept running after the tags came off, with nothing to show for them.
Without robust analytics, we’re flying blind and not driving the consumer’s voice and needs into strategic discussions.
It’s literally going back to the situation of the early 2000s, where you spend money on marketing and have no idea if it’s working or not, you’re just operating off your assumptions.
With budgets tighter and touchpoints broader, gone are the days when top-funnel metrics such as total impressions and click-through rates were enough.

Tags added by vendors and agencies over years, unknown to legal and IT.
It's just a fundamental breakdown in healthcare of who's managing the website? Does IT really have control over what's being installed in that web code? Are they outsourcing stuff and other organizations maybe managing some of that?
All of a sudden, we have a bunch of publicly facing websites that have pixels and tracking beacons on them that legal and privacy teams may not even know were there.
Some of these websites have hundreds of these tracking materials on them.
Google's health category for personalized ads names surgical procedures(opens in a new tab) and treatments for pregnancy and infertility(opens in a new tab), which covers orthopedics, cardiac, bariatric and maternity campaigns. For those campaigns you cannot use your own audience lists(opens in a new tab), and health conversions cannot be measured with enhanced conversions(opens in a new tab) or uploads. Google does not offer a BAA for Google Analytics(opens in a new tab) and says authenticated pages are likely to be HIPAA-covered(opens in a new tab).
Hippo changes none of that. It does not change ad approval or audience rules, adds no words, keywords or claims to your site, and changes no ad copy. It measures what happens after the click.
Meta's health and wellness data category describes a hospital site word for word: provider/patient relationships(opens in a new tab) and a patient portal. That category can block lower-funnel events(opens in a new tab), blocks custom events until they are reviewed(opens in a new tab), and you cannot change the category Meta assigns(opens in a new tab).
Meta's prohibited information includes physical locations that identify a health condition, or places of treatment(opens in a new tab), which is what a cancer center or birthing center page is. The rule covers the names of your events(opens in a new tab), and its core setup(opens in a new tab) strips anything in a URL after the domain. Meta states that its own filters are no substitute for yours(opens in a new tab).
An event name, before and after
Sent without the patient's
With audiences closed off for most service lines and lower-funnel events restricted, the events that still flow are what steer bidding. Hippo sends the appointment request, the call and the booking under neutral names with nothing that names a department or identifies the patient, and keeps a log of appointments by campaign that is yours whatever Meta blocks.
Sources: Google, Health in personalized advertising(opens in a new tab) · Google, Personalized advertising(opens in a new tab) · Google, Customer data policies(opens in a new tab) · Google, HIPAA and Google Analytics(opens in a new tab) · Meta, Data source categories(opens in a new tab) · Meta, Data sharing restrictions(opens in a new tab) · Meta, About prohibited information(opens in a new tab). As of 10/7/26.
Federal
HHS says tracking on logged-in pages generally has access to PHI(opens in a new tab), that data collected on a patient portal login page or registration page(opens in a new tab) is a disclosure of PHI, and that tracking on a page that permits individuals to schedule appointments(opens in a new tab) can reach it. A tracking vendor that receives it is a business associate, and a BAA is required(opens in a new tab).
Federal
A federal court in Texas vacated one part(opens in a new tab) of that guidance in June 2024: an IP address combined with a visit to a public page about a condition or a provider. The court wrote that its ruling should not be read as limiting the rest of the guidance, so the portal, login and scheduling passages still stand.
Federal
It allows statutory damages of $10,000(opens in a new tab) per plaintiff and is the federal claim in most hospital pixel suits.
State
The state's privacy law(opens in a new tab) sets $5,000 per violation with no proof of harm, and was one of the claims behind a $21.5 million settlement over a patient portal's login page. Its medical confidentiality law adds nominal damages of $1,000(opens in a new tab).
State
State attorneys general can enforce HIPAA. New York's secured $300,000(opens in a new tab) from a hospital whose find-a-doctor and condition searches put terms such as "spine surgery" in page addresses that third parties received.
$47.5 million
Members alleged that tracking code from analytics and advertising companies ran on the logged-in pages of Kaiser's websites and apps from 2017 to 2024. The court granted final approval(opens in a new tab) in July 2026 and set the settlement at $47.5 million once opt-outs were counted.
$21.5 million
Patients alleged that analytics and advertising tags ran on the login page of Sutter's patient portal, though not inside it, in violation of California's wiretap law. Sutter settled for $21.5 million(opens in a new tab), and the court entered final approval in March 2026.
$12.225 million
Patients alleged that tracking pixels on the health system's websites, app and patient portal sent their information to Meta and Google from 2017 to 2022. The system settled for $12,225,000(opens in a new tab), and the court granted final approval(opens in a new tab) in July 2024.
$3.74 million
Patients alleged that a pixel on Duke's website disclosed information about people who logged into its patient portal and app from 2019 to 2022. The health system settled for $3,743,600(opens in a new tab), and the court granted final approval in August 2026.
$6.66 million
Patients alleged that the Meta pixel on Novant's website and patient portal sent their information to Facebook from 2020 to 2022. After the federal claims were dismissed, Novant settled the remaining state claims, a $6,660,000 fund(opens in a new tab) deposited by its insurer, and the court granted final approval in June 2024.
$300,000
New York's Attorney General said that tracking tools on the hospital's website fired when visitors searched for doctors, researched conditions or booked appointments, sending health information to third parties. The hospital paid $300,000(opens in a new tab) and agreed to audit third-party tools before deploying them.
The pages were where patients logged in or booked.
Portals, portal login pages, doctor searches and appointment booking.
The tools were ordinary.
The Meta pixel, Google's tags and the analytics on a website.
The guidance that matters survived 2024.
Logged-in, login and scheduling pages are still covered.
The laws behind these cases reach hospitals of every size, and the guidance on logged-in and scheduling pages still stands.
See what your service-line and scheduling pages send to Google and Meta →(opens in a new tab)Book your appointment
Book now
Call us
Booking
Call
Records events
Removes identifying information
Sends clean conversion data
Excluded from conversion events
Names
Conditions
IP addresses
Clean conversion events only


Booking
Call
Take the Google and Meta pixels off your site.
Hippo records visits, bookings, and calls, then removes patient names, health details, and IP addresses from the conversion events sent to Google and Meta.
Google and Meta receive conversion signals they can use to optimize your campaigns. Patient names, health details, and IP addresses stay out of those events.
With your EHR, your scheduler and your access center untouched. Hippo runs on your own subdomain and records the appointment request and the click to call. It connects to your call tracking and your scheduling system so a call to the access center or a booking in the scheduler counts too, attributed to the campaign and service line that produced it. If an agency runs your campaigns, they keep running them, and you keep the data and the accounts.
Your patient portal stays out of Google and Meta entirely. Hippo keeps ad tags off logged-in pages and the portal's login page, and sends nothing from them.
Hippo works with the ad platforms and website tools your practice already uses.
Hippo
See which campaigns led to consult requests and bookings, and what each one cost.

An independent record of results in an account you own. If you change agencies, it stays with you.

Calls that start from an ad are counted as conversions alongside forms and bookings.

A log of every event that went to Google and Meta and what was removed from it first.

$99/month
Month to month.
Start now, no demo call1,000 visitors/month(opens in a new tab)$199/month
Month to month.
Start now, no demo call2,000 visitors/month(opens in a new tab)$299/month
Month to month.
Start now, no demo call10,000 visitors/month(opens in a new tab)Server-side conversion tracking under a BAA, at a price a practice can actually pay.
No. Hippo keeps ad tags off logged-in pages, including the portal and its login page. HHS says tracking on logged-in pages generally has access to PHI(opens in a new tab), and Google tells HIPAA-covered organizations not to put Analytics on authenticated pages(opens in a new tab). Appointments booked in the portal's scheduler are counted from the scheduling system, and what reaches Google and Meta carries no identifiers and no service line.
Part of it. In June 2024 a federal court in Texas vacated the part(opens in a new tab) about an IP address plus a visit to a public page about a condition or a provider, and HHS dropped its appeal. The court said its ruling should not be read as limiting the rest of the guidance, so the passages on logged-in pages, login pages and appointment pages still stand. The hospital settlements since then were brought under state privacy and wiretap laws.
Taking the tags off ended what they were sending, and it also ended the measurement: the campaigns kept running with no way to see which ones filled the schedule. Hippo brings the conversion signal back without putting ad tags on your pages. One script on your own subdomain records the appointment request, identifiers and the service line are removed on our server, and a de-identified event goes to Google, Meta and GA4.
Nothing that names them. New York's Attorney General settled with a hospital(opens in a new tab) whose search for "spine surgery" put that phrase in the page address third parties received, and Meta lists places of treatment(opens in a new tab) as prohibited information. Hippo strips the page path, search terms, doctor, department and condition from every event before it leaves.
Yes. Hippo counts the request form and the click to call on your site, and the calls into your access center and the bookings in your scheduler through its call tracking and scheduling connectors, so a service-line report shows requests, calls and booked appointments together. Each is tied to the campaign that produced it, and none of it puts a tag inside the scheduler or the portal.
Very little in their day. We set up the script and the destinations, and your agency sees de-identified conversions arrive in the same Google Ads and Meta accounts they already manage. What changes is the route: the data goes through one server under a BAA with your hospital, not through ad tags that an agency or a past vendor added to the site.
A banner records a visitor's choice about cookies. HHS says a banner is not a HIPAA authorization(opens in a new tab), and it does not change what a tag sends once it fires. A Massachusetts health system paid $18.4 million(opens in a new tab) in 2022 over analytics tools and pixels placed on its public websites without visitors' consent. Hippo waits for consent where it is required and removes identifiers before anything reaches Google or Meta.
A signed BAA in your hospital's name, a written description of what is removed before anything leaves (IP address, names, emails, phone numbers, dates of birth, and the health context of the page), where the data is stored, and a list of every destination with what each one receives.
No. Google treats surgical procedures(opens in a new tab) and pregnancy treatment(opens in a new tab) as sensitive health content, which removes your own audience lists for those campaigns and bars those conversions from enhanced conversions. Hippo does not change what Google allows; it gives those campaigns a de-identified conversion signal, which is most of what they have left to optimize on.
Yes. Hippo is one script and a setup we do for you, with published pricing and no annual contract, so a small marketing team and its agency can run it without a server build. Systems with several hospitals use the same product with one BAA.
Yes, if you want to know how these laws apply to your hospital. This page describes laws, policies and court cases for general information and is not legal advice. Hippo handles the tracking; an attorney can advise you on your obligations.
See which campaigns bring new clients.
Connect campaign spend to intake inquiries.
Measure consultation bookings by campaign.
Understand what drives online bookings.
See which campaigns bring transfers and refills.
Compare acquisition across your campaigns.
See which campaigns drive consultations.
Know your cost per booked patient.
See which promotions get booked.
Connect campaign spend to appointments.
See which campaigns book consultations.
Measure calls and booking inquiries.
See which campaigns bring new patients.
See which campaigns bring walk-ins and online check-ins.
Understand which campaigns drive inquiries.
See which campaigns bring quote requests and calls.
Connect campaigns to appointment inquiries.
See which campaigns bring trials, subscriptions and orders.