Hippo is HIPAA-compliant ad tracking for telehealth brands. It counts the quiz completions, checkouts and paid first visits your ads produce, and keeps patient identities out of what Google and Meta receive.
No annual contracts.
Transparent pricing.
We set it up for you.
Most telehealth founders go looking for help the week Meta restricts their domain, the Purchase and Lead events stop coming back, and nobody they ask can say what a compliant setup costs. The path runs from ad click to intake quiz, results page, checkout and a paid first visit with a clinician.
Much of that finishes off the ad platforms' sight: in your checkout or your clinical platform. What the account counts as a conversion decides whether the numbers mean anything.
What is worth counting:
What isn't:
A funnel can report plenty of leads and no sales.
Here is the sum, with example numbers.
The sum, with example numbers
Example figures. Put in your own. Each line needs a count you trust, and the last one needs the campaign it came from.
Try the sum with your own numbers. If the paid visits are not tied to campaigns, that is the gap Hippo closes. Hippo cannot lift a category Meta has assigned or restore an event Meta blocks. It decides which events leave your site, strips identifiers and condition data before they do, keeps a log you can read, and ties the paid first visit to the campaign that produced it. Google and Meta get the conversion without the name, email, phone number, IP address, quiz answers or medication.

Ads running with no conversion tracking, and platform counts that do not match the founder's own.
I'm running the ads as a traffic campaign as I don't have conversions tracking setup yet.
one of our conversion events is when a user creates an account with us. In our system, I see 10, but meta only shows 1 (many times none).
Please setup tracking correctly from day 1 as Google search is heavily dependent on the kind of data you feed it to.

Events restricted by Meta, enterprise prices for the fix, and workarounds that cost performance.
I run a small telemedicine business and our events have been restricted because of HIPAA... recommendations for a freelance-type martech person that can help us set this up in a compliant way? And what would that cost?
there are HIPAA-compliant marketing and analytics platforms specifically designed for healthcare providers... but most of these cost a decent amount of money... as they often offer enterprise packages
One of our concerns is HIPAA compliance, so we've leaned on using offline event tracking through Rudderstack instead of the standard Google Ads pixel.
A telehealth brand that facilitates prescribing is a telemedicine provider to Google. Google restricts the promotion of online prescribing services(opens in a new tab), and telemedicine providers must be certified(opens in a new tab) before they can run at all. Certification is also what lets you keyword-target prescription drug terms(opens in a new tab).
Hippo changes none of that. It does not get ads approved, does not replace LegitScript or Google's certification, and adds no words, keywords or claims to your site. It measures what happens after the click.
Health content is a sensitive interest category(opens in a new tab), so you cannot use your own audience lists(opens in a new tab): no Customer Match, no remarketing lists, no lookalikes. Conversions tied to sensitive categories cannot be measured with enhanced conversions(opens in a new tab), and Google does not offer a BAA for Google Analytics(opens in a new tab).
Meta requires telehealth providers that promote prescription drugs to be certified with LegitScript(opens in a new tab) and to request its own authorization; promoting telehealth services generally(opens in a new tab) needs none. Separately, Meta sorts data sources into categories, and telemedicine platforms are a named example(opens in a new tab) of the health and wellness one. That category can block lower-funnel events(opens in a new tab) such as Purchase and Lead, strips anything in a URL after the domain(opens in a new tab), blocks custom events until they are reviewed(opens in a new tab), and you cannot change the category Meta assigns(opens in a new tab). Meta's own advice is to optimize on upper-funnel events(opens in a new tab).
Its rules name prescription medication(opens in a new tab) among the information it must not receive, and the rule covers the names of your events(opens in a new tab). An event called "GLP-1 checkout" breaks it. Meta states that its own filters are no substitute for yours(opens in a new tab).
An event name, before and after
Sent without the patient's
With audiences closed off and lower-funnel events restricted, the events that still flow are what steer bidding. Hippo sends them under neutral names that carry no condition, no medication and nothing that identifies the patient, and keeps a log of visits by campaign that is yours whatever Meta blocks.
Sources: Google, Healthcare and medicines(opens in a new tab) · Google, Restricted drug terms(opens in a new tab) · Google, Health in personalized advertising(opens in a new tab) · Google, Personalized advertising(opens in a new tab) · Google, Customer data policies(opens in a new tab) · Google, HIPAA and Google Analytics(opens in a new tab) · Meta, Drugs and pharmaceuticals(opens in a new tab) · Meta, Data source categories(opens in a new tab) · Meta, Data sharing restrictions(opens in a new tab) · Meta, Core setup(opens in a new tab) · Meta, About prohibited information(opens in a new tab). As of 10/7/26.
Federal
A provider is a covered entity only if it transmits standard electronic transactions(opens in a new tab) such as claims; a cash-pay brand with superbills may sit outside it, and a practice that bills insurance is inside. For a covered practice, HHS says a telehealth platform's logged-in pages(opens in a new tab) give tracking tools access to PHI, and that an appointment booked through its website can send the appointment and the visitor's IP address to the vendor, who is then a business associate, and a BAA is required(opens in a new tab).
Federal
The Health Breach Notification Rule(opens in a new tab) covers health websites and apps outside HIPAA, counts an unauthorized disclosure as a breach, and carries civil penalties of up to $53,088 per violation. The FTC Act reaches a privacy promise: the agency's complaint against Hims & Hers quotes the words "100% online, private, and secure".
Federal
It allows statutory damages of $10,000 per plaintiff, and no proof of harm. It is the claim that survived dismissal against Nourish and Teladoc in 2026 and 2025.
State
The state's privacy law(opens in a new tab) sets $5,000 per violation with no proof of harm, and its medical confidentiality law adds nominal damages of $1,000(opens in a new tab) for a negligent release by a provider of health care, whether or not it bills insurance. Call-On-Doc has agreed to a proposed settlement of claims under the first.
State
The My Health My Data Act(opens in a new tab) covers health data HIPAA does not, including website visitors who never become patients, and requires consent for sharing that is separate from the consent to collect.
Proposed
Call-On-Doc, an online urgent care service, agreed to a proposed settlement(opens in a new tab) of claims under California privacy laws over tracking pixels on its web pages(opens in a new tab), with class members who file a claim receiving up to $20 each. The court granted preliminary approval in May 2026 and held the final approval hearing on August 31, 2026; the settlement site still says the court has to decide whether to approve it. Call-On-Doc denies wrongdoing.
Pending
The FTC, California and Utah sued Hims & Hers on July 29, 2026(opens in a new tab), alleging that health information reached Meta and other platforms through customer lists and through tracking tools. The complaint(opens in a new tab) names the Meta Pixel and the Conversions API and quotes the company's promise of a "100% online, private, and secure" process. The case is pending and Hims denies the allegations.
Settled
LifeMD, which runs the RexMD men's health brand, settled Nevada claims(opens in a new tab) that tracking tools on its websites disclosed health information. Final approval was granted on September 30, 2025; claimants receive $10 in cash or a $25 voucher, and the company recorded about $1.1 million for the settlement(opens in a new tab) in its annual report.
$1.5 million
The FTC's first action under the Health Breach Notification Rule: GoodRx, which runs a telehealth service, paid a $1.5 million civil penalty(opens in a new tab) for sharing users' prescriptions and health conditions with Facebook, Google and other advertising companies, and is barred from sharing health information for advertising.
Pending
Nourish, a virtual nutrition company, failed to dismiss wiretap claims(opens in a new tab) in April 2026 over Google tags on its appointment-scheduling site. The court found it plausible that the tracking served a purpose HIPAA forbids. The case is pending and the claims are allegations.
The pages were booking and intake flows.
The quiz, the booking and the checkout, which is where ad traffic lands.
The tools were ordinary.
Pixels and tags, and in two of the cases the Conversions API. Server-side is not a defense.
Three of the five were outside HIPAA.
The FTC Act, the Health Breach Notification Rule and state law reached them anyway.
The laws behind these cases reach any telehealth site that takes a booking or a checkout.
See what your booking page sends to Google and Meta →(opens in a new tab)Book your appointment
Book now
Call us
Booking
Call
Records events
Removes identifying information
Sends clean conversion data
Excluded from conversion events
Names
Conditions
IP addresses
Clean conversion events only


Booking
Call
Take the Google and Meta pixels off your site.
Hippo records visits, bookings, and calls, then removes patient names, health details, and IP addresses from the conversion events sent to Google and Meta.
Google and Meta receive conversion signals they can use to optimize your campaigns. Patient names, health details, and IP addresses stay out of those events.
With your intake quiz, your checkout and your clinical platform untouched. Hippo runs on your own domain and records the quiz completion, the checkout and the paid visit where they happen. Your quiz, your checkout and your clinical platform stay as they are; what changes is what leaves the page. If an agency or a contractor runs your account, they keep their reporting and you keep the data.
Installing Hippo adds no words, keywords or claims to your site and changes no ad copy, so it touches nothing LegitScript or Google reviews.
Hippo works with the ad platforms and website tools your practice already uses.
Hippo
See which campaigns led to consult requests and bookings, and what each one cost.

An independent record of results in an account you own. If you change agencies, it stays with you.

Calls that start from an ad are counted as conversions alongside forms and bookings.

A log of every event that went to Google and Meta and what was removed from it first.

$99/month
Month to month.
Start now, no demo call1,000 visitors/month(opens in a new tab)$199/month
Month to month.
Start now, no demo call2,000 visitors/month(opens in a new tab)$299/month
Month to month.
Start now, no demo call10,000 visitors/month(opens in a new tab)Server-side conversion tracking under a BAA, at a price a practice can actually pay.
The cases in this industry did not need HIPAA. The FTC sued Hims & Hers under the FTC Act over the promise "100% online, private, and secure" and named the Meta Pixel and the Conversions API; Call-On-Doc agreed to a proposed settlement of California privacy claims over pixels on its web pages; the FTC's first Health Breach Notification Rule(opens in a new tab) penalty, $1.5 million, was against GoodRx. Those laws reach any site a California or Washington resident uses, and the FTC's reach is nationwide.
No. Meta assigns the category, you cannot change it(opens in a new tab), and it blocks specific mid- and lower-funnel events(opens in a new tab) when it does. What a compliant feed changes is which events still flow and how clean they are: a quiz completion or a first visit sent with no custom parameters, no URL path and no condition in the event name, and a log of visits by campaign that is yours whatever Meta blocks. Which events Meta allows for your domain is Meta's decision.
What is in the event when it fires. A telehealth quiz URL carries the step and often the medication; the answers carry the condition. Meta's rules list prescription medication(opens in a new tab) among prohibited information and say event names must not imply it(opens in a new tab), and the FTC's complaint against Hims & Hers treats the Conversions API as one of the two ways health information reached Meta. A compliant setup decides which events leave, strips identifiers and condition data before they do, and keeps a log you can show. The transport is the same.
No. Google requires certification for telemedicine providers(opens in a new tab); Meta requires LegitScript certification and its own authorization(opens in a new tab) for telehealth providers promoting prescription drugs. LegitScript certifies your licensing and business practices to the platforms and says nothing about what your website sends them. Hippo touches no ad copy, keyword, landing page or certification. It measures what happens after the click.
No. The FDA's warning letters to telehealth companies(opens in a new tab) concern claims that compounded products are the same as FDA-approved drugs, and the state attorneys general letters concern weight-loss ad content. Those are advertising-claims matters between you, your counsel and the platforms. Hippo covers one thing: what your website sends to Google and Meta after the click.
Once you submit claims electronically you are a covered entity, and HHS's tracking guidance still says that a telehealth platform's logged-in pages(opens in a new tab) give tracking tools access to PHI, and that a tracking vendor receiving an appointment and an IP address is a business associate, and a BAA is required(opens in a new tab). A cookie banner is not a HIPAA authorization. Hippo signs a BAA with every customer and removes identifiers before anything reaches Google or Meta, so the setup does not change the day you start billing.
Yes, if you want to know how these laws apply to your company. This page describes laws, policies and court cases for general information and is not legal advice. Hippo handles the tracking; an attorney can advise you on your obligations.
See which campaigns bring new clients.
Connect campaign spend to intake inquiries.
Measure consultation bookings by campaign.
Understand what drives online bookings.
Compare acquisition across your campaigns.
See which campaigns drive consultations.
Know your cost per booked patient.
See which promotions get booked.
Connect campaign spend to appointments.
Measure calls and booking inquiries.
See which campaigns bring new patients.
Understand which campaigns drive inquiries.
Connect campaigns to appointment inquiries.
See which campaigns drive website inquiries.