apointoo.
HIPAA

Outside HIPAA Does Not Make Health Conversion Tracking Low Risk

cmsapointoo··9 min read

A finding that HIPAA does not apply to a particular actor or activity answers only the HIPAA question. It does not establish that health conversion tracking is low risk. The same flow may still require a separate assessment under the FTC Health Breach Notification Rule, a state consumer health law such as Washington’s My Health My Data Act, and the policy for the specific Google Ads feature receiving the data.

Each test has its own definitions, exemptions, and duties. Do not turn “not a HIPAA covered entity” into a release gate. Map actor, data, action, recipient, jurisdiction, and advertising product, then record evidence and an owner for each branch.

Build four gates, not one compliance label

A conversion flow can begin with a booking form, pass through a CRM or server, and end in an advertising product. Each step can change the relevant actor, purpose, and disclosure. A clinic, wellness app, software vendor, agency, and ad platform should not be grouped under one label. Nor should every value called a “conversion” be treated alike.

Create one record per flow: source, fields, identifiers, transformations, recipients, purpose, retention, population, jurisdiction, and exact destination feature. A generic destination like “Google” is too broad for a policy decision. A branch may be applicable, exempt, prohibited, conditional, or unresolved, but evidence from one branch does not prove another.

Gate 1: HIPAA asks who is acting and in what role

45 CFR 160.103 defines covered entities through categories including health plans, clearinghouses, and providers that transmit health information electronically in covered transactions. It defines business associate through specified functions and services involving protected health information on behalf of a covered entity or another business associate, with stated exceptions.

A company outside the covered-entity definition for one product may be a business associate elsewhere. A provider can also have activities outside a HIPAA-regulated flow. Assess the specific actor, service, activity, and information. Medical vocabulary or a health-related audience does not decide status.

If HIPAA does not govern the examined flow, record that narrow scope. Do not write “HIPAA does not apply to the company” when the analysis covered one app or marketing pathway, and do not infer that the data is safe to disclose.

When a cloud product is involved, remember that contract coverage is also product specific. The article on why a Google Cloud BAA does not cover Google Ads illustrates why a contract for one service cannot authorize a separate advertising use.

Gate 2: FTC HBNR has its own coverage and breach analysis

The FTC Health Breach Notification Rule appears in 16 CFR Part 318. It applies to covered vendors of personal health records, PHR related entities, and third-party service providers rather than using the HIPAA covered-entity test. The current rule and the 2024 final rule define key terms, including PHR identifiable health information, personal health record, covered health care provider, and breach of security.

The 2024 rulemaking clarified the FTC’s view of health apps and similar technologies, including certain unauthorized disclosures. That does not make every tracking event a reportable breach. Coverage, authorization, recipient, event, and exceptions still require fact-specific review.

Ask whether the product offers a personal health record under the rule, whether it has the technical capacity to draw information from multiple sources, what role each vendor plays, and whether an acquisition or disclosure was unauthorized. Assess notice duties only if the preceding elements hold. Use the Federal Register preamble for agency interpretation and the eCFR for current regulatory text.

Do not close this branch with “outside HIPAA.” The HBNR was designed for a different coverage boundary. Conversely, do not assume that using a health app proves HBNR applicability. Document the definition analysis.

Gate 3: Washington consumer health data law is a separate test

Washington RCW 19.373, commonly associated with the My Health My Data Act, defines consumer health data, regulated entities, processors, consumers, collection, sharing, and sale for its own purposes. It contains jurisdictional provisions and exemptions that must be reviewed before applying an obligation to a particular organization or dataset.

Where the law applies, its requirements include a consumer health data privacy policy and specific rules for collection, sharing, sale, access, deletion, processors, and security. Consent for collection or sharing and a separate signed authorization for sale are distinct concepts in the statute. An ordinary cookie banner should not be assumed to satisfy either without comparing its wording and interaction to the applicable requirement.

Start with person and geography, then classify entity and data. Check statutory exemptions. Determine whether the flow is collection, sharing, or sale under the statute, then test the matching notice, consent or authorization, processor, rights, and security provisions.

Neither “the user lives in Washington” nor “the company is a clinic” completes the statutory analysis. Preserve the facts and section supporting the conclusion.

Gate 4: Google policies depend on the exact advertising feature

Google’s Customer Data policies apply to enhanced conversions for web, enhanced conversions for leads, store sales uploads, and Google-engaged audiences. The policy prohibits uploading conversion information related to sensitive categories, including health or medical information, for the covered Customer Data products. This is a product-policy test, not a HIPAA definition or a determination that every health advertiser is prohibited from measuring any result.

Google’s personalized advertising policy separately treats health as a sensitive interest category and limits advertiser-curated audiences for that content. Customer Match belongs in this separate personalized-advertising and Customer Match policy branch, not in the four-product scope stated above. This policy does not ban all health advertising, but consent, hashing, or a lawful source cannot be assumed to make an audience or upload eligible.

Test the current product and configuration. Review every field and derived value, including URL parameters, event labels, list names, variables, and free text. A neutral event name can carry sensitive meaning when combined with its page or source. Hashing changes representation, not the underlying category or product rule.

For a narrower data design, see the clinic booking outcome taxonomy. If the proposed route uses a server or data manager, the Google Ads Data Manager clinic-form architecture helps identify boundaries, but architecture alone cannot make a prohibited payload eligible.

Consent is not a universal override. The FTC branch may ask whether an acquisition or disclosure was authorized. Washington law specifies consent and sale authorization for covered activities. Google policy can prohibit a use even when the advertiser believes it has valid consent.

Keep booking consent separate from advertising choices. A person may request care without agreeing to a health-related conversion upload. Preserve notice, choice, version, time, and purpose instead of only a boolean called consent.

This is an editorial implementation recommendation. Determine the relevant consent standard under each law; this does not replace legal review or current platform terms.

A safer implementation review for health conversions

After the four gates, review the data path. Many reports can measure booking requested, confirmed, attended, or canceled without diagnosis, treatment, clinician notes, page titles, or free text. The internal treatment-value model explains why internal value and an advertising payload should remain separate.

  • Allowlist fields: reject unexpected values instead of forwarding the full form.
  • Separate destinations: do not reuse a clinical event object as an advertising event object.
  • Remove free text: keep symptoms, procedures, notes, and detailed URLs out of marketing connectors.
  • Log decisions: store gate results, policy version, owner, and evidence without logging health content.
  • Fail closed: pause transmission when classification, consent evidence, or product eligibility is unresolved.
  • Recheck changes: review new fields, destinations, jurisdictions, and policy revisions before release.

A clean technical payload does not cure an inapplicable consent or an unauthorized disclosure. Equally, a valid legal basis does not cure a product-policy prohibition. The implementation review reduces exposure after the independent decisions; it does not merge them.

Document a decision matrix that can be audited

For each flow, create four rows: HIPAA, FTC HBNR, Washington law, and Google policy. Record definitions, facts, conclusion, unresolved questions, source version, approver, and review date. Add other states when needed. “Compliant” alone is not an auditable result.

Require every relevant row to be resolved. HIPAA can be out of scope while HBNR remains open. Law may permit an activity that Google policy prohibits, or policy may allow an approach that lacks required legal authorization. In each case, keep the upload blocked.

Frequently Asked Questions

If a clinic is not a HIPAA covered entity, can it send health conversions to Google Ads?

That conclusion is insufficient. Test FTC HBNR, applicable state consumer health laws, other duties, and the exact Google Ads policy. Any one branch can stop or change the proposed flow.

Does hashing make a health conversion non-sensitive?

No general conclusion follows from hashing. It can transform an identifier, but the event, source, and combination may still relate to health, remain identifiable, or be prohibited by the selected product policy.

Does the FTC HBNR apply to every health app?

No. Apply the rule’s definitions to the product, data sources, actors, and event. The 2024 final rule provides relevant interpretation, but the facts still determine coverage and duties.

Do not assume so. Compare the interaction to the statute’s requirements for the classified collection, sharing, or sale, including the separate authorization provisions where applicable.

Does Google’s sensitive-interest policy ban all healthcare ads?

No. It restricts specified personalized advertising uses and targeting for sensitive interests. The Customer Data policy separately governs covered uploads. Review the exact feature and current policy.

References

Related articles