Blog · Medical Marketing

HIPAA-Compliant Google Ads for Clinics: Advertise Without Exposing PHI

Google will not sign a BAA, yet clinics run profitable search campaigns every day. The difference is account architecture: here is how to keep protected health information out of the platform entirely.

Google Ads puts your practice in front of people at the precise moment they search for care. It can also quietly transmit protected health information (PHI) to a company that has no legal obligation to safeguard it. The default account setup — a tag on every page, remarketing switched on, customer lists uploaded for matching — is standard practice in retail and a potential reportable breach in healthcare.

None of that means clinics should avoid paid search. HIPAA-compliant Google Ads is entirely achievable, and practices run profitable, compliant campaigns every day. But compliance has to be engineered into the account before the first dollar is spent, because violations happen in the plumbing — tags, audiences, and data uploads — not in the ad copy.

This guide covers paid advertising only. For email, social media, your website, and the rest of the compliance picture, see our complete guide to HIPAA-compliant marketing. One thing up front: this is practical guidance from practitioners, not legal advice — have a healthcare attorney or your compliance officer review your setup before launch.

Why ad platforms and PHI are a legal minefield

For years, healthcare organizations installed advertising pixels the way every other business did: paste the code, collect the data, optimize the campaigns. That era ended in December 2022, when the HHS Office for Civil Rights published guidance on online tracking technologies. The guidance took the position that when a tracking tool collects an identifier — an IP address, a device ID, a cookie — together with information suggesting a person sought or received care, the combination can constitute PHI. Sending it to an ad platform that has not signed a business associate agreement becomes an impermissible disclosure.

A federal court later narrowed part of that guidance as it applies to unauthenticated public pages, but the enforcement climate has not relaxed. The FTC has penalized digital health companies for sharing user health data with advertising platforms, hospital systems have faced class-action lawsuits over pixels on their sites, and several states have passed their own consumer health data laws that reach beyond HIPAA. The direction of travel is unmistakable: regulators treat ad-platform data flows as disclosures, and the burden of getting it right sits with you.

HIPAA-compliant digital advertising, then, is less about what your ads say and much more about what your website and account send back to the platform.

Google does not sign a BAA — plan around it

Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on your behalf must sign a business associate agreement (BAA). Google signs BAAs for certain Google Workspace and Google Cloud services. It does not sign one for Google Ads, and it does not sign one for standard Google Analytics. There is no enterprise tier, negotiation, or workaround that changes this.

That single fact defines the entire strategy. You cannot make Google Ads compliant by contract, so you make your data flows compliant by design: nothing that leaves your website, your CRM, or your call tracking and reaches Google may contain PHI. Every technique in this article follows from that one rule.

What counts as PHI in an advertising context

PHI is broader than most practice owners assume. It is any individually identifiable information tied to a person's health condition, care, or payment for care, held by a covered entity or its business associates. In an ads context, identifiers you would never think of as medical — an IP address, a click ID, a cookie — become PHI the moment they are paired with health context.

Concrete examples of data flows that can cross the line:

  • A conversion tag firing on a URL such as /fertility-consultation-confirmed, which ties a click ID to a service line
  • A remarketing audience built from visitors to condition or treatment pages
  • A patient email list exported from your EHR and uploaded to Google for Customer Match
  • Form answers — symptoms, insurance, date of birth — passed into URL parameters or the data layer
  • Call recordings or transcripts flowing through a call tracking vendor that has not signed a BAA

Notice the pattern: none of these involve a name or a chart number. Health context plus any identifier is enough, and ad platforms collect identifiers by default.

How to structure campaigns so no PHI reaches Google

Compliant account architecture comes down to four disciplines. Each one closes a specific channel through which PHI leaks into ad platforms.

Turn off patient-based remarketing

Do not build remarketing lists from patient portal pages, booking confirmations, or condition-specific pages. Those audiences are, functionally, lists of people who sought care — PHI by another name. Google's personalized advertising policy prohibits targeting based on health conditions anyway, so health-derived audiences violate platform policy and HIPAA at the same time. In healthcare, the growth lever is search intent, not retargeting: high-intent keywords earn the return that other industries chase with audience lists.

Never upload patient data

Customer Match — uploading email or phone lists so Google can target those people — is off the table whenever the list comes from patient records. Hashing does not fix it: hashed identifiers are a security measure, not de-identification under HIPAA, and the disclosure to a vendor without a BAA happens either way. The same logic applies to enhanced conversions built on patient email addresses.

Keep tags and URLs clean

Fire conversion tags only on generic thank-you pages whose URLs reveal nothing about the service booked. Keep every advertising tag off authenticated experiences — portals, intake forms, telehealth visits. Never pass form values into URLs or the data layer. Deploy a consent banner and configure Google consent mode so your tags respect each visitor's choices; consent tooling does not make a PHI transfer legal, but it is a baseline expectation under state privacy laws and Google's own requirements.

De-identify your conversion data

For measurement beyond basic on-page conversions, route data through infrastructure inside your compliance boundary: a server-side tagging container you control, or a healthcare analytics vendor that signs a BAA, strips identifiers, and forwards only de-identified conversion events to Google. The platform keeps enough signal to optimize bidding; it never receives anything that identifies a patient.

Google's healthcare ad policies are a second rulebook

HIPAA is only half the compliance picture. Google's Healthcare and medicines policy restricts what can be advertised at all: prescription drug terms are limited to certified advertisers, addiction treatment services require LegitScript certification, and speculative or experimental treatments are prohibited outright. Certain categories also require country-specific certification before ads will serve.

Separately, Google classifies health as a sensitive category for personalized advertising. You cannot target audiences by health condition or run ads that imply knowledge of a person's medical situation. In practice, this reinforces the HIPAA-safe playbook: build campaigns on keywords, geography, ad schedules, and landing page quality — signals about the search, not the searcher. A dedicated medical landing page that converts high-intent traffic does more for your cost per booked patient than any audience segment you are not allowed to use.

The pre-launch compliance checklist

Before spending anything, walk through this list with whoever owns compliance at your practice:

  • Inventory every tag and pixel on your site; document what each one sends and to whom
  • Remove all advertising tags from authenticated pages: portals, intake forms, telehealth
  • Confirm conversion pages use generic URLs with no condition, treatment, or appointment details
  • Disable remarketing and audience collection across clinical content
  • Verify no patient-derived lists have been uploaded to the account — and lock down who could upload one
  • Deploy a consent banner and configure Google consent mode
  • Collect signed BAAs from your form, call tracking, and analytics vendors
  • Review ad copy and landing pages against Google's Healthcare and medicines policy
  • Document the entire review — a dated record of your risk analysis is worth a great deal if a regulator ever asks

None of this takes long compared with the cost of getting it wrong. A tracking-technology breach is reportable, public, and entirely preventable.

Measuring cost per booked patient without violating privacy

The most common objection to HIPAA-compliant Google Ads is that it breaks measurement. It does not. It moves measurement inside your walls, where it arguably belongs.

The PHI problem is data flowing out to Google, not data flowing in. Your HIPAA-compliant CRM or practice management system can store the campaign, keyword, and click ID that brought in each inquiry, because those systems sit inside your compliance boundary under a BAA. Attribution lives there, at full fidelity.

The workflow is simple. Capture campaign parameters into the CRM at the point of inquiry. Mark which inquiries become booked patients. Divide spend by bookings, per campaign, every month. You get true cost per booked patient — the only advertising number that ultimately matters — without a single patient record touching the ad platform. Outbound, send Google only de-identified, aggregated conversion counts so its bidding algorithms still have something to learn from.

This is the operating model we use at Medical Marketing when we manage Google Ads for clinics: PHI-free data flows to the platform, full-fidelity attribution inside the practice's own systems. Compliant and measurable are not opposites — they are the same discipline applied at two different layers.

Set the account up this way from day one, and HIPAA stops being the reason you avoid paid search. It becomes the reason you run it better than the practices that never checked their plumbing.

Frequently asked questions

Does Google sign a BAA for Google Ads?

No. Google signs business associate agreements for certain Google Workspace and Google Cloud services, but not for Google Ads or standard Google Analytics. That means nothing you send to the ad platform — tag data, audiences, uploaded lists, conversion details — may contain protected health information. Compliance has to be engineered on your side of the data flow, not obtained by contract.

Can my clinic use remarketing?

Not the way other industries do. Audiences built from patient portals, booking pages, or condition-specific content are effectively lists of people who sought care, which makes them PHI. Google's personalized ads policy also prohibits health-based targeting. Most healthcare compliance teams disable remarketing entirely and put the budget into high-intent search campaigns instead.

Is Google Analytics HIPAA compliant for ad tracking?

Standard Google Analytics is not, because Google will not sign a BAA for it and HHS guidance specifically flagged tracking technologies on healthcare websites. If you need analytics tied to ad campaigns, use a server-side setup or a healthcare analytics vendor that signs a BAA, strips identifiers, and forwards only de-identified events.

Is hashing patient emails enough to upload a Customer Match list?

No. Hashing is a security measure, not de-identification under HIPAA. A hashed patient email is still individually identifiable information, and uploading it to a vendor without a BAA is still an impermissible disclosure. Customer Match should never be fed from your EHR, practice management system, or any list derived from patient records.

Can I still measure which campaigns actually book patients?

Yes. Capture campaign, keyword, and click ID into your HIPAA-compliant CRM at the point of inquiry, mark which inquiries become booked patients, and calculate cost per booked patient internally. Send only de-identified, aggregate conversion signals back to Google so its bidding keeps learning. You lose nothing that matters for decision-making.

Keep reading

HIPAA compliant marketing: what your practice can and cannot doCan doctors advertise on Google? Yes — here are the rulesGoogle Ads for weight loss clinics: capturing GLP-1 demand without getting suspe

Shall we grow your clinic?

Talk to our AI agent, trained on the €10M+ we've invested in medical marketing.

Talk to our AI agent