Hippo is compliant ad tracking for lab testing marketplaces and at-home test brands. It counts the test orders, kit purchases and draw appointments your ads produce, in an account you own, and keeps customer identities and test names out of what Google and Meta receive.
No annual contracts.
Transparent pricing.
We set it up for you.
In this industry the order is the health data. A cart that holds a chlamydia test, a thyroid panel or a fertility kit tells anyone watching the checkout what the customer is worried about, before any result exists. The path runs from ad click to a test page, the cart, the order, and for a lab order a draw appointment, then results in a portal.
The product page, the cart URL and the thank-you page all carry the test name, and that is what a standard pixel sends. What the account counts as a conversion, and what that conversion carries, decides whether the numbers mean anything.
What is worth counting:
What isn't:
A campaign can fill the cart with tests nobody buys.
Here is the sum, with example numbers.
The sum, with example numbers
Example figures. Put in your own. Each line needs a count you trust, and the last one needs the campaign it came from.
Try the sum with your own numbers. If the orders are not tied to campaigns, that is the gap Hippo closes. It records the order, its value and the draw appointment, ties each to the campaign that produced it, and sends the conversion to Google and Meta without the name, email, phone number, IP address or test name.

Founders who are not covered entities and say they are compliant anyway.
Although we are not a HIPAA covered entity, we maintain a HIPAA compliant infrastructure.
no, we are not a covered entity - but we still maintain HIPAA compliant protocols with your data
As far as I know, we are the only company that is HIPAA-, GDPR-, and CCPA- compliant.

Purchase events blocked overnight and accounts locked out of Google.
they were in Google Ads "jail" and had been blacklisted from the advertising platform due to an online pharmacy credential that Google required. On top of that, they have highly aggressive new customer growth targets and were promoting a new HPV testing kit.
Only PageView events were allowed to run. Everything else - AddToCart, InitiateCheckout, Purchase - was blocked.
Meta's core setup restrictions flagged these URLs as PHI violations, blocking all events that transmitted this data.
Google's healthcare policy names fertility testing and STI testing(opens in a new tab) among the products it covers, and its sensitive health category covers physical health conditions, including sexual health(opens in a new tab). For those campaigns you cannot use your own audience lists(opens in a new tab): no Customer Match, no remarketing lists, no lookalikes. Health purchases cannot be measured with enhanced conversions(opens in a new tab) or uploads, and Google does not offer a BAA for Google Analytics(opens in a new tab).
Hippo changes none of that. It does not change ad approval or audience rules, adds no words, keywords or claims to your site, and changes no ad copy. It measures what happens after the click.
Meta sorts data sources into categories, and a site that sells health tests is a candidate for the health and wellness one, whose named examples begin with a patient portal(opens in a new tab). That category can block lower-funnel events(opens in a new tab) such as AddToCart and Purchase, blocks custom events until they are reviewed(opens in a new tab), flags a custom conversion that names a condition(opens in a new tab), and you cannot change the category Meta assigns(opens in a new tab).
Meta's rules name medical procedures, treatments and testing(opens in a new tab) and sexual and reproductive health(opens in a new tab) among the information it must not receive, the rule covers the names of your events(opens in a new tab), and its core setup strips anything in a URL after the domain(opens in a new tab). A purchase event that names an STI panel breaks it. Meta states that its own filters are no substitute for yours(opens in a new tab).
An event name, before and after
Sent without the customer's
With audiences closed off and lower-funnel events restricted, the events that still flow are what steer bidding. Hippo sends the order under a neutral name with its value and nothing that names the test or identifies the customer, and keeps a log of orders by campaign that is yours whatever Meta blocks.
Sources: Google, Healthcare and medicines(opens in a new tab) · Google, Health in personalized advertising(opens in a new tab) · Google, Personalized advertising(opens in a new tab) · Google, Customer data policies(opens in a new tab) · Google, HIPAA and Google Analytics(opens in a new tab) · Meta, Data source categories(opens in a new tab) · Meta, Data sharing restrictions(opens in a new tab) · Meta, Restrictions on custom conversions(opens in a new tab) · Meta, About prohibited information(opens in a new tab) · Meta, Core setup(opens in a new tab). As of 10/7/26.
Federal
The Health Breach Notification Rule(opens in a new tab) covers health websites and apps outside HIPAA, counts an unauthorized disclosure as a breach and carries civil penalties of up to $53,088 per violation. The FTC used it against a company that sells ovulation test kits.
State
The My Health My Data Act(opens in a new tab) covers health data HIPAA does not, which for a test seller is the order itself, and requires consent for sharing that is separate from the consent to collect. Nevada's law follows the same pattern, and Everlywell publishes a notice under both.
State
Illinois's Genetic Information Privacy Act(opens in a new tab) gives a private right of action over disclosed genetic test results. A claim under it against a DNA-testing company over its website trackers survived a motion to dismiss in 2026.
State
The state's privacy law(opens in a new tab) sets $5,000 per violation with no proof of harm, and its medical confidentiality law adds nominal damages of $1,000(opens in a new tab). A national lab's settlement was over claims under California's and Pennsylvania's wiretap laws.
Federal
The lab that performs and bills a test, and the physician group that orders it, are usually covered entities, because they submit claims electronically(opens in a new tab). The storefront that sells a kit for cash usually is not, and the cases below reached it anyway.
$5 million
Everlywell and a sister brand settled claims(opens in a new tab) that Meta and Google tracking pixels on their sites shared what customers bought. The settlement set aside $5 million in two funds, $2.64 million of it for the 660,000 people who bought sensitive tests such as STI kits, and the court has approved the settlement(opens in a new tab).
$100,000
The maker of the Premom ovulation-tracking app, which also sells ovulation test kits, paid a $100,000 civil penalty(opens in a new tab) under the Health Breach Notification Rule after sending users' health data to advertising and analytics companies, and is barred from sharing health data for advertising.
Proposed
Labcorp agreed to a proposed settlement(opens in a new tab) of claims under California and Pennsylvania wiretap law over tracking on searches people ran on its website. It pays no money to the class; it stops using tracking such as the Meta Pixel and Google Analytics on its site for two years. The final approval hearing is December 14, 2026.
Pending
A customer alleges that Nebula Genomics' website trackers could reveal which people had undergone genetic testing. In March 2026 the court let the Illinois genetic-privacy claim proceed(opens in a new tab). The case is pending and the claims are allegations.
$75,000
The genetic testing company behind Vitagene must pay $75,000(opens in a new tab) under a final FTC order over its handling of DNA and health data, and may not share health data with third parties without customers' affirmative consent.
The pages were where people bought.
Product pages, search bars, carts and checkouts, where the test is named.
The tools were ordinary.
The Meta Pixel, Google's tags and the analytics on a store.
HIPAA was not needed.
The FTC, state wiretap laws and genetic privacy law reached sellers outside it.
The laws behind these cases reach any test seller whose checkout a customer in California, Washington or Illinois uses, and the FTC's reach is nationwide.
See what your checkout sends to Google and Meta →(opens in a new tab)Book your appointment
Book now
Call us
Booking
Call
Records events
Removes identifying information
Sends clean conversion data
Excluded from conversion events
Names
Conditions
IP addresses
Clean conversion events only


Booking
Call
Take the Google and Meta pixels off your site.
Hippo records visits, bookings, and calls, then removes customer names, health details, and IP addresses from the conversion events sent to Google and Meta.
Google and Meta receive conversion signals they can use to optimize your campaigns. Customer names, health details, and IP addresses stay out of those events.
With your store, your lab partner and your results portal untouched. Hippo runs on your own domain and records the order, its value and the draw appointment. Your checkout, your lab and physician partners, and your results portal stay as they are; what changes is what leaves the page. If an agency runs your ads, they keep their reporting and you keep the data and the accounts.
Kit registration, the results portal and the follow-up consult stay out of Google and Meta entirely. Hippo keeps ad tags off logged-in pages and sends nothing from them.
Hippo works with the ad platforms and website tools your practice already uses.
Hippo
See which campaigns led to consult requests and bookings, and what each one cost.

An independent record of results in an account you own. If you change agencies, it stays with you.

Calls that start from an ad are counted as conversions alongside forms and bookings.

A log of every event that went to Google and Meta and what was removed from it first.

$99/month
Month to month.
Start now, no demo call1,000 visitors/month(opens in a new tab)$199/month
Month to month.
Start now, no demo call2,000 visitors/month(opens in a new tab)$299/month
Month to month.
Start now, no demo call10,000 visitors/month(opens in a new tab)Server-side conversion tracking under a BAA, at a price a practice can actually pay.
Because the cases in this industry did not need HIPAA. Everlywell settled for $5 million over pixels on its purchase pages, the FTC fined a test-kit seller under the Health Breach Notification Rule(opens in a new tab), and a genetic-privacy claim against a DNA company's trackers survived dismissal. Washington's health-data law covers exactly the data HIPAA does not.
Everything a standard pixel sends. The product page URL, the cart and the thank-you page carry the test name, and Meta's core setup exists to strip anything in a URL after the domain(opens in a new tab) for that reason. Hippo sends the order with its value and nothing that names the test, so the campaign can still optimize on revenue.
A badge describes how you store data, not what your ad tags send. The settlements in this industry were about pixels on product and checkout pages of companies that took privacy seriously elsewhere. The question is what leaves the page when a customer buys, and that is what Hippo controls.
No. The platform runs the cart; the tags on it are the ones you or your agency installed, and what they send is your disclosure. Hippo installs on your own domain, records the order on the confirmation page, and sends Google and Meta an order event with no test name and nothing that identifies the customer.
No. Hippo cannot lift a category Meta has assigned, and you cannot change it(opens in a new tab) either; under the health and wellness category Meta blocks specific mid- and lower-funnel events(opens in a new tab). What a compliant feed changes is what still flows: an order with no test name, no URL path and nothing that identifies the customer, and a log of orders by campaign that is yours whatever Meta blocks.
You are. The lab performs the test and the physician network signs the order, and both may be covered entities for their part. The storefront, its ad tags and what they send to Google and Meta belong to the brand that runs the site.
Not for health purchases. Google says conversions tied to sensitive categories cannot be used for measurement in enhanced conversions(opens in a new tab) or uploads, and sensitive-category advertisers cannot use their own audience lists(opens in a new tab). What remains is the standard conversion sent from your own site, which is the signal Hippo sends.
Yes. Illinois's Genetic Information Privacy Act(opens in a new tab) gives buyers a private right of action, and a claim under it against a DNA company's website trackers survived dismissal in 2026. The FTC's order against a genetic testing company bars sharing health data with third parties without affirmative consent. Hippo keeps the test and the customer out of every event.
They stay out. HHS says tracking on logged-in portal pages(opens in a new tab) generally has access to PHI, and a results account is the most sensitive page you run. Hippo keeps ad tags off logged-in pages and sends nothing from them; the order is the conversion, and nothing after it is.
Not on its own. A banner records consent to cookies; it does not decide what the purchase event contains, and HHS says a cookie banner is not a HIPAA authorization(opens in a new tab) for the sellers that are covered. Hippo waits for consent where it is required and removes the test name and identifiers before anything reaches Google or Meta.
Yes, if you want to know how these laws apply to your company. This page describes laws, policies and court cases for general information and is not legal advice. Hippo handles the tracking; an attorney can advise you on your obligations.
See which campaigns bring new clients.
Connect campaign spend to intake inquiries.
Measure consultation bookings by campaign.
Understand what drives online bookings.
See which campaigns bring transfers and refills.
Compare acquisition across your campaigns.
See which campaigns drive consultations.
Know your cost per booked patient.
See which promotions get booked.
Connect campaign spend to appointments.
See which campaigns book consultations.
Measure calls and booking inquiries.
See which campaigns bring new patients.
See which campaigns bring walk-ins and online check-ins.
Understand which campaigns drive inquiries.
See which campaigns bring quote requests and calls.
Connect campaigns to appointment inquiries.
See which campaigns bring trials, subscriptions and orders.