You cannot improve what you cannot measure, so tracking which ads and keywords produce clients is essential to running Google Ads well. But you also cannot let a prospective client’s information leak to Google, because that is a privacy problem no practice wants. On the surface these two goals seem to conflict: measure everything, but expose nothing. They do not actually conflict. With the right setup, you can track conversions and calls thoroughly without any protected health information reaching Google.
This guide explains what counts as protected information in tracking, why a standard setup is risky, and exactly how to build conversion tracking and call tracking that are safe for a therapy practice.
Quick answer: You can track conversions and calls for a therapy practice without violating HIPAA, but not with a standard, out-of-the-box setup. The safe approach is to track PHI-free conversion events, route data through server-side tracking that strips sensitive information before it reaches Google, and use call tracking that is either covered by a Business Associate Agreement or configured without recording. Done this way, you measure everything you need without exposing protected information.
Key Takeaways
- Standard tracking is risky for therapy. Client-side pixels automatically capture data that can be protected health information, and Google will not sign a BAA for its ad tools.
- Track PHI-free conversion events. Record that a form was submitted or a call happened, as a count, with no names, symptoms, or contact details attached.
- Server-side tracking is the safe backbone. It lets you strip sensitive parameters before any event reaches Google, unlike client-side pixels that send everything.
- Call tracking needs special care. Calls contain protected information, so use a BAA-covered provider or turn off recording and track only metadata.
- You lose nothing essential. PHI-free tracking still tells you which campaigns and keywords produce inquiries, which is all you need to optimize.
- Keep tracking off authenticated pages like client portals, telehealth, and intake forms, and audit your setup periodically.
Not sure whether your tracking is exposing client data? MHIS sets up HIPAA-aware conversion and call tracking for therapy practices, so you can measure your ads without the risk. Book a free consultation with MHIS.
A quick note: This article is educational and reflects current best practices and privacy law. It is not legal advice. HIPAA interpretation and platform rules change, so confirm your specific setup with a healthcare attorney or compliance professional.
Why Standard Tracking Is a Problem for Therapy Practices
The default way most businesses track ads, dropping a client-side pixel on the site and letting it collect data, is risky for a therapy practice. Those pixels automatically capture information that can be protected health information, and they send it to platforms that will not sign a Business Associate Agreement to receive it.
Two facts drive the problem. First, Google will not sign a BAA for Google Ads or Google Analytics. Its BAA covers Google Workspace and Google Cloud, not its advertising and analytics tools, so protected health information may never flow to them. You can confirm the covered services on the Google Cloud HIPAA BAA page. Second, standard client-side tracking captures data automatically: the page URL, the visitor’s IP address, and sometimes form contents, without you controlling exactly what is sent.
When that automatic collection happens on pages that reveal a person is seeking mental health care, or when form data flows through, the tracking can transmit protected information to a platform that is not permitted to hold it. This is not hypothetical. Tracking pixels on healthcare sites have led to large, publicly reported settlements. Current guidance on the topic is on the HHS online tracking technologies page. The good news is that the fix is architectural, not a matter of giving up measurement. For the broader compliance picture, see our related coverage in our guide to Google Ads for therapists.
What Counts as PHI in Your Tracking?
Protected health information is any health-related information tied to an identifiable person, such as a name, email, phone number, IP address, or device ID, combined with the fact that they are seeking therapy. In tracking, it usually leaks through forms, URLs, call content, and the pages a pixel fires on.
Here is where it tends to appear in an ad tracking setup:
- Form field contents: a name, email, phone number, or described symptoms captured on a form and passed into a tracking event.
- URL parameters and page paths: a landing page path like /depression-intake combined with a visitor identifier.
- The pages a pixel fires on: the fact that an identified person visited a specific condition or service page.
- Call recordings and transcripts: the content of a call where someone discusses their mental health.
- IP address plus a condition page: connecting a visitor’s IP with a visit to a page about a specific concern.
The campaign and keyword data itself is not protected information. The risk is in the personal and health-revealing details your tracking might carry alongside it. Keeping those out is the whole job.
The Foundation: Track PHI-Free Conversion Events
The core move is to track conversions as generic, PHI-free events. Record that a form was submitted, a call started, or an appointment was booked, as a simple count, with no personal or health information attached. That gives you everything you need to optimize campaigns without exposing anything sensitive.
In practice, this means a few specific things:
- Define generic conversion events, such as “form submitted,” “call started,” or “booking confirmed,” that carry no names, emails, symptoms, or conditions.
- Do not pass form field contents into your conversions. The event should say a form was completed, not who completed it or what they wrote.
- Keep conditions out of your URLs. Avoid page paths that name a concern if those paths are sent to Google, so the tracking cannot reveal what someone is seeking help for.
- Fire conversion tags on generic confirmation pages, like a neutral thank-you page, rather than on condition pages, portals, or intake forms.
Tracked this way, your reports still tell you which keywords, ads, and campaigns produce inquiries, which is exactly what you need to improve performance. The optimization signal is preserved, and the sensitive detail never leaves your side. For where conversion tracking fits in a full campaign, see our step-by-step guide on how to create a Google Ads campaign for a therapy practice.
The Safe Architecture: Server-Side Tracking
Server-side tracking is the technical backbone of a HIPAA-safe setup. Instead of letting a client-side pixel send whatever it captures directly to Google, you route events through a server you control, where you can strip out sensitive parameters before anything reaches the ad platform.
The difference matters. A standard client-side pixel fires in the visitor’s browser and sends data to Google automatically, including things you may not want to send, like IP addresses, full URLs, and sometimes form data. You have limited control over what leaves. A server-side setup, typically a server-side Google Tag Manager container or a first-party data platform, puts a gate between your website and Google. Every event passes through that gate first.
At the gate, you strip anything sensitive:
- Remove personal identifiers like names, emails, and phone numbers.
- Drop condition-revealing URL parameters and query strings.
- Anonymize or remove the IP address where possible.
- Keep only the PHI-free conversion signal and the campaign attribution needed to optimize.
The result is that Google receives a clean event, a conversion happened, attributed to a campaign, with no protected information attached. This is the approach compliance-focused advertisers in every regulated category have moved toward, precisely because it gives you control over exactly what data leaves your site. It takes proper setup, but it is what makes thorough measurement and privacy compatible.
Getting this architecture right is technical work, and mistakes carry real consequences. MHIS builds HIPAA-aware tracking for therapy practices, from PHI-free conversion events to server-side configuration and compliant call tracking. See how our Google Ads management for therapists works.
Call Tracking Done the Safe Way
Call tracking is the trickiest piece, because the call itself contains protected information: someone discussing their mental health. Recording or transcribing those calls creates stored protected information. The safe approach is to use a call tracking provider that will sign a BAA, or to turn off recording entirely and track only that a call happened.
Call tracking works by assigning a tracking phone number to your ads, often through dynamic number insertion, so you can attribute calls to the campaigns that drove them. That attribution is valuable. The risk is in the call content and the caller’s information.
Here is how to keep it safe:
- Use a call tracking provider that will sign a BAA and offers a configuration built for healthcare, if any protected information will be stored or processed.
- The simplest safe path for most practices is to disable call recording and transcription, and track only call metadata: that a call happened, its source, and its duration. No content means far less exposure.
- Send only a PHI-free conversion signal to Google, meaning “a call from an ad occurred,” never the caller’s number, name, or the call content.
- Keep any recordings or caller data inside a BAA-covered environment, and never route them to Google or Analytics.
What to look for in HIPAA-aware call tracking
- A provider that will sign a Business Associate Agreement.
- The ability to turn recording and transcription on or off, or off by default.
- Protected information stripped from anything sent to ad platforms.
- Secure storage and access controls for any call data.
- Data minimization, collecting only what you actually need.
For most therapy practices, disabling recording and passing only a clean call conversion to Google is the straightforward, low-risk choice, and it still tells you which campaigns generate calls.
Consent and Configuration Hygiene
Beyond the core setup, a few configuration practices keep you on safe footing. The most important thing to understand is that consent does not permit sending protected information. Even with a visitor’s consent, you still cannot send protected health information to a platform that has not signed a BAA.
Keep these in mind:
- Consent tools where required. Use cookie consent and consent-based tracking to meet applicable requirements, but remember consent does not cure sending protected information.
- Keep tracking off authenticated pages. No pixels or analytics on client portals, telehealth pages, appointment schedulers, or intake forms, where visitors are identified clients.
- No conditions in URLs. Structure page paths so they do not reveal what someone is seeking help for.
- Practice data minimization. Collect and send only what you genuinely need, and anonymize IP addresses where you can.
- Audit periodically. Setups drift, and a previously clean configuration can start leaking after a website change, so review it regularly.
What You Can Safely Measure
A common worry is that HIPAA-safe tracking means flying blind. It does not. You can still measure everything you need to run and optimize ads: PHI-free conversions and full campaign attribution. You lose the sensitive details you should never have been collecting anyway, not the performance data.
With a safe setup, you can confidently track:
- Form submissions, as a count, without the form contents.
- Calls, as metadata, without recording the content.
- Bookings, as a confirmation event.
- Campaign, ad group, and keyword attribution, so you know what drives inquiries.
That is the full picture you need to see which keywords convert, which ads perform, and where to put your budget. Optimizing a therapy campaign does not require knowing who called or what they said. It requires knowing which campaign the call came from, and that is entirely PHI-free.
A HIPAA-Safe Tracking Setup, Step by Step
- Map your pages into public marketing pages and authenticated pages (portal, telehealth, scheduler, intake).
- Remove all tracking from authenticated and intake pages.
- Define PHI-free conversion events, such as form submitted, call started, and booking confirmed, with no personal data.
- Fire conversion tags on generic confirmation pages only.
- Implement server-side tracking, and strip personal identifiers, condition-revealing parameters, and IP addresses before sending events to Google.
- For calls, use a BAA-covered provider or disable recording, and pass only a PHI-free call conversion.
- Configure consent where required, remembering it does not permit sending protected information.
- Audit regularly to confirm no protected information appears in any event.
- Have a compliance professional review the setup before relying on it.
Common Tracking Mistakes Therapy Practices Make
- Placing a pixel on the intake form or client portal, the highest-risk pages.
- Passing form contents, like a name, email, or symptoms, into conversion events.
- Leaving a condition in the URL or page path that gets sent to Google.
- Recording calls and storing them with a non-BAA vendor, or routing them to Analytics.
- Assuming Consent Mode makes sending protected information acceptable.
- Uploading client lists for Customer Match, which is both restricted for health and a protected-information risk.
- Never auditing, so a website change quietly starts leaking data.
Data Handling Quick Reference
| Data | Safe to send to Google? | Safe handling |
|---|---|---|
| Generic conversion event, such as form submitted | Yes | Send as a count, with no personal data |
| Client name, email, or phone from a form | No | Keep on your side; never attach to conversions |
| Condition or symptom, from a URL or form | No | Strip from URLs and events |
| That a call happened, its source and duration | Yes, metadata only | Track without recording content |
| Call recording or transcript | No | Use a BAA-covered vendor, or disable recording |
| IP address on a condition page | No, risky | Anonymize, and keep tracking off condition pages |
| Campaign, ad group, and keyword attribution | Yes | Standard and PHI-free |
Frequently Asked Questions
Can therapists track conversions without violating HIPAA?
Yes, but not with a standard, out-of-the-box setup. The safe way is to track PHI-free conversion events, meaning you record that a form was submitted or a call happened, as a count, with no names, symptoms, or contact details attached. You route those events through server-side tracking that strips sensitive information before it reaches Google, and you handle call tracking carefully. Because Google will not sign a Business Associate Agreement for its ad tools, protected health information must never flow to them, so the goal is to send only clean conversion signals and campaign attribution. Set up this way, you can measure which keywords and ads produce inquiries, which is all you need to optimize, without exposing any protected information. Confirm your specific configuration with a compliance professional.
Is Google Analytics HIPAA compliant for a therapy practice?
No. Google will not sign a Business Associate Agreement for Google Analytics, and its own terms state that covered entities and business associates may not use Analytics for any purpose involving protected health information. Its BAA covers Google Workspace and Google Cloud, not Analytics or Google Ads. For a therapy practice, this means you cannot let Analytics receive protected information, which standard client-side tracking can inadvertently capture through IP addresses, URLs, and form data on pages that reveal someone is seeking care. You can still measure your marketing, but it requires a careful setup: keeping tracking off authenticated and intake pages, using PHI-free events, and routing data through server-side tracking that strips sensitive parameters. The key point is that Analytics is not a compliant place for protected information, so your configuration must ensure none reaches it.
What counts as PHI in ad tracking?
Protected health information is any health-related information tied to an identifiable person. In ad tracking, that means data like a name, email, phone number, IP address, or device ID, combined with the fact that someone is seeking therapy. It appears in several places: form field contents such as a name or described symptoms passed into a tracking event; URL parameters or page paths that name a condition alongside an identifier; the fact that an identified visitor viewed a specific condition page; call recordings or transcripts; and an IP address connected to a visit to a condition page. The campaign and keyword data itself is not protected information. The risk lies in the personal and health-revealing details your tracking might carry along with it, and keeping those out of anything sent to Google is the goal.
How do I track form submissions without exposing client data?
Track the submission as a generic event, not as a record of who submitted it. Your conversion should register that a form was completed, as a count, with no name, email, or message contents attached. Fire the conversion tag on a neutral thank-you or confirmation page rather than on the form page itself, and make sure no form field data flows into the event. Then route that event through server-side tracking, where you strip any remaining identifiers before it reaches Google. This gives you exactly what you need for optimization, which is knowing that a campaign produced a form submission and which keyword drove it, without sending any of the personal details the visitor entered. The contents of the form stay entirely on your side, handled through your own secure systems.
Is call tracking HIPAA compliant for therapists?
Call tracking can be done compliantly, but it requires care, because the call itself contains protected information and recording or transcribing it creates stored protected information. There are two safe paths. The first is to use a call tracking provider that will sign a Business Associate Agreement and offers a healthcare-ready configuration, so any protected information is handled under proper terms. The second, and simplest for most practices, is to disable call recording and transcription entirely and track only call metadata, meaning that a call happened, its source, and its duration. Either way, you send only a PHI-free conversion signal to Google, never the caller’s number or the call content, and you keep any recordings inside a BAA-covered environment. For most therapy practices, turning off recording and passing a clean call conversion is the straightforward, low-risk choice.
Should I record calls from my Google Ads?
For most therapy practices, no. Call recordings capture people discussing their mental health, which is clearly protected information, and storing them creates ongoing compliance obligations. Unless you have a specific need and a call tracking provider that will sign a Business Associate Agreement and store recordings securely, the simpler and safer choice is to turn recording and transcription off. You can still track that a call came from a specific campaign, along with its duration and source, which is all you need to measure ad performance. Recording adds risk without adding much value for campaign optimization, since the attribution data, not the call content, is what tells you which ads work. If you do have a genuine need to record, make sure it is under a BAA and handled with proper security, never routed to Google or Analytics.
What is server-side tracking, and do therapists need it?
Server-side tracking routes your conversion events through a server you control, typically a server-side Google Tag Manager container or a first-party data platform, before any data is sent to Google. This differs from standard client-side tracking, where a pixel in the visitor’s browser sends data to Google automatically, often including things you would not want to send, like IP addresses and full URLs. The server-side approach puts a gate between your website and Google, so you can strip out sensitive parameters, personal identifiers, condition-revealing details, and IP addresses, and send only a clean conversion signal. For a therapy practice, this control is what makes thorough measurement and privacy compatible, so it is strongly recommended. It takes proper setup, but it is the technical backbone of a genuinely HIPAA-safe tracking configuration.
Does Consent Mode make my tracking HIPAA compliant?
No. This is an important misconception. Consent tools and Consent Mode help you meet cookie and privacy consent requirements, and they are worth using where required, but consent does not permit you to send protected health information to a platform that has not signed a Business Associate Agreement. Even if a visitor consents to tracking, you still cannot lawfully send their protected information to Google, because there is no BAA covering Google Ads or Analytics to receive it. Consent addresses a different issue, permission to use cookies and tracking, not the separate HIPAA requirement around protected information. So while you should configure consent properly, do not treat it as a substitute for a PHI-free, server-side setup. The two work together: consent for tracking permissions, and a clean architecture to ensure no protected information is ever sent.
Can I put a Google or Meta pixel on my therapy website?
You can place tracking on your public, unauthenticated marketing pages with care, but you must keep it off authenticated pages, meaning client portals, telehealth pages, appointment schedulers, and intake forms, where visitors are identified clients. Those pages carry the highest risk and have been the focus of tracking-related lawsuits. Even on public pages, a standard pixel can capture data you should not send, so the safe approach is to route events through server-side tracking that strips sensitive parameters, use PHI-free conversion events, and fire tags on neutral confirmation pages. Some practices remove pixels from condition-specific service pages entirely when the URL reveals what is being treated. The pixel is not automatically off-limits, but it must be configured carefully so that no protected information ever reaches the ad platform.
What can I safely measure about my ad performance?
Everything you actually need to run and optimize ads. With a safe setup, you can track form submissions as counts, calls as metadata, and bookings as confirmation events, along with full campaign, ad group, and keyword attribution. That tells you which keywords convert, which ads perform, and where your budget produces results. What you give up is the sensitive detail you should never have collected in the first place, such as who called, what they wrote, or what condition they searched. Optimizing a therapy campaign does not require any of that. It requires knowing which campaign an inquiry came from, which is entirely PHI-free. So HIPAA-safe tracking does not mean flying blind; it means measuring performance without measuring people, which is both compliant and completely sufficient for improving your ads.
Will HIPAA-safe tracking hurt my ad optimization?
No, not in any meaningful way. HIPAA-safe tracking still captures the signals that matter for optimization: which campaigns, ad groups, and keywords produce form submissions, calls, and bookings. Google’s automated bidding and your own decisions rely on conversion counts and their attribution, not on who the person was or what they said, so a PHI-free setup provides the data optimization needs. The one thing to get right is making sure your conversion tracking actually fires reliably, because incomplete conversion data does hurt performance. That is another reason server-side tracking helps, since it gives you a controlled, reliable event flow while stripping sensitive information. Done properly, HIPAA-safe tracking and strong optimization go together. The practices that struggle are usually the ones with broken or missing tracking, not the ones with compliant tracking.
Should I hire someone to set up HIPAA-safe tracking?
For most therapy practices, yes, because a genuinely safe setup involves technical work that is easy to get wrong, and the consequences of getting it wrong are serious. Configuring PHI-free conversion events, implementing server-side tracking that strips sensitive parameters, setting up compliant call tracking, and keeping pixels off the right pages all require specific expertise. A misconfiguration can quietly send protected information to Google for months before anyone notices. A specialist who understands both ad tracking and the compliance realities of a mental health practice can build the setup correctly and audit it over time. If you have strong technical skills you may be able to do it yourself, but given the stakes, most practices benefit from expert help. Whichever route you choose, having a compliance professional review the final setup is a sensible safeguard.
Final Key Takeaways
- You can measure ads thoroughly without exposing protected information, but not with a standard setup.
- Track PHI-free conversion events, recording that something happened without who or what.
- Server-side tracking is the safe backbone, letting you strip sensitive data before it reaches Google.
- For calls, use a BAA-covered provider or turn off recording and track only metadata.
- You keep all the performance data you need to optimize, and lose only the sensitive detail you should not collect.
Action Checklist
- Separate public marketing pages from authenticated pages, and remove tracking from the latter.
- Define PHI-free conversion events with no personal data.
- Fire conversion tags on neutral confirmation pages only.
- Implement server-side tracking and strip identifiers, conditions, and IP before sending to Google.
- Use BAA-covered call tracking or disable recording, and pass only a clean call conversion.
- Configure consent, and remember it does not permit sending protected information.
- Audit your setup regularly and after any website change.
- Have a compliance professional review it.
Conclusion
Measuring your ads and protecting client privacy are not opposing goals. They only seem that way because the default tracking setup, a client-side pixel collecting everything, is the wrong tool for a therapy practice. Replace it with the right architecture, PHI-free conversion events, server-side tracking that strips sensitive data before it reaches Google, and call tracking that is either BAA-covered or recording-free, and you get the best of both. You will know exactly which campaigns and keywords produce clients, and no protected information will ever leave your control. It takes deliberate setup, but once it is in place, you can run and optimize your ads with confidence, knowing your measurement is thorough and your clients’ privacy is intact.
If building this the right way is not how you want to spend your time, a therapy-focused marketing partner can set it up and keep it compliant.
Want tracking that measures your ads without risking client data? MHIS will review your current setup, build HIPAA-aware conversion and call tracking, and give you a clear plan across Google Ads, landing pages, and local SEO. Book your free consultation with MHIS today.