Answers · HIPAA & Tracking

What does OCR's tracking-technology guidance actually say about insurance agency websites?

Last reviewed: · Strategic AI Architects Data Desk · reviewed by Mike Moore

OCR's guidance says three things that survived its trip through federal court: tracking-technology vendors that "create, receive, maintain, or transmit PHI on behalf of a regulated entity" are business associates and require a signed Business Associate Agreement; pages where a visitor submits health information — scheduling, symptoms, a quote tied to a health condition — trigger the HIPAA Rules when the site is HIPAA-regulated; and everything behind a login is covered, period. The one rule a federal court vacated on June 20, 2024 — that an IP address plus a visit to a public, unauthenticated health page is automatically PHI — is no longer enforceable as written.

The qualifier: the bulletin binds HIPAA covered entities and business associates, and whether an insurance agency is one is fact-specific — a carrier is; an independent agency usually is only when handling PHI on a carrier's behalf. Read the guidance as the clearest available map of what regulators consider a health-data disclosure via tracking tag, not as a rule that automatically reaches every agency website.

The bulletin's actual timeline

HHS OCR tracking-technology guidance, event by event
DateEventStatus today
Dec 1, 2022Original bulletin publishedSuperseded by the 2024 revision
Mar 18, 2024Bulletin revisedCurrent posted text
Jun 20, 2024U.S. District Court, N.D. Texas (AHA v. Becerra) vacates the IP-plus-public-page ruleThat portion unenforceable; the rest stands
Aug 29, 2024HHS withdraws its appealVacatur final; no further revision as of this review

For an insurance agency website, the practical translation is a page-by-page split. A public blog post about Medicare enrollment windows, visited anonymously, is on the vacated side of the line. A quote form that collects health details, a plan-comparison tool a visitor feeds information into, or any client portal is on the enforceable side — and on those pages, a Meta Pixel or GA4 tag is a vendor without a BAA, because Google will not sign one for Analytics and Meta offers none for the Pixel. The FTC and HHS's July 20, 2023 joint letter to about 130 hospital systems and telehealth providers named both products and told recipients to inventory their tags, map where the data goes, and confirm BAAs — advice that reads the same for a two-person agency.

One honest caveat: vendor marketing on this topic swings between "the bulletin was struck down, relax" and "every pixel is a HIPAA breach." Both are wrong. The vacated portion was the broadest, most contested theory; the pieces that drove real enforcement — form data flowing to ad platforms without consent or a BAA — were never based on it.

Sources

  1. U.S. Department of Health and Human Services, Office for Civil Rights. "Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates," original 2022-12-01, revised 2024-03-18, noting the 2024-06-20 vacatur. Verified live 2026-08-17. hhs.gov.
  2. American Hospital Association. "HHS will not appeal AHA court victory in online tracking case," 2024-08-29. aha.org.
  3. FTC and HHS joint letter to approximately 130 hospital systems and telehealth providers, naming the Meta Pixel and Google Analytics, 2023-07-20. ftc.gov.
  4. Google. "HIPAA and Google Analytics" — no BAA offered for Google Analytics. Verified live 2026-08-17. support.google.com.

Related questions

Did the court ruling kill the OCR bulletin entirely?

No. The June 20, 2024 order in American Hospital Association v. Becerra vacated one specific proposition — that an IP address combined with a visit to an unauthenticated public webpage about health conditions or providers is automatically PHI. The business associate agreement requirement, the treatment of pages where visitors submit health information, and everything about authenticated pages were untouched, and HHS's guidance page still states them.

Does OCR guidance even apply to an insurance agency, as opposed to a hospital?

Only if the agency is a HIPAA covered entity or business associate — which is fact-specific. Carriers are covered entities; an independent agency is typically regulated when it handles PHI on a carrier's behalf. An agency outside HIPAA is not bound by the bulletin at all, but the FTC has applied the FTC Act and Health Breach Notification Rule to non-HIPAA businesses sharing health data with ad platforms, so the practical exposure looks similar.

Has HHS revised the bulletin again since withdrawing its appeal?

As of this page's review date, no. HHS withdrew its appeal on August 29, 2024, and the guidance page remains posted in its March 18, 2024 form with the vacated portion noted. Whether OCR issues new guidance remains open — which is part of why this area stays unsettled.

Want to know where your own site stands? Run the free Audit — a live AEO audit plus a HIPAA tracking scan — or browse all answers.