Playbook

Why Your Insurance Website's Pixel Could Get You Sued

The FTC has already fined two companies a combined $9.3 million for exactly this. Neither one was an insurance agency, but the tag they used is probably the one on your site right now.

An insurance agency founder with closely buzzed short hair and light stubble sits at a bright office desk, looking closely at a laptop screen displaying a browser developer tools network panel with several tracking requests highlighted in indigo and amber, a second monitor in the soft background shows a simple webpage with a Medicare quote form, representing an agency owner auditing his own website's tracking tags for health data exposure
The short version

The FTC fined GoodRx $1.5 million in February 2023 and BetterHelp $7.8 million in July 2023, both for sharing health data with Meta and other ad platforms through ordinary tracking tags23. That same July, the FTC and HHS sent a joint warning letter naming the Meta Pixel and Google Analytics specifically to about 130 hospital systems and telehealth providers1. A federal court later struck down part of HHS's guidance in June 20245, which some vendor blogs now use to claim the whole issue went away. It didn't. The Business Associate Agreement requirement is untouched, the FTC's own penalty for a Health Breach Notification Rule violation is now up to $53,0884, California's wiretapping statute pays plaintiffs $5,000 a violation regardless of HIPAA's status at all6, and CMS added a Medicare-specific consent rule of its own in 20247. This guide covers what actually still applies to an insurance agency's website, and how to check your own site in about ten minutes.

The tag on your quote page

Somewhere on your website, probably in the header, sits a small piece of JavaScript. Someone, maybe you, maybe a marketing vendor, maybe whoever set up the site three years ago, added a Meta Pixel to track ad conversions and a Google Analytics tag to see where visitors come from. It's standard. Nearly every business website runs something like it.

On a general marketing page, that's exactly as unremarkable as it sounds. On the page where a visitor gets a Medicare Advantage plan comparison, requests an ACA subsidy quote, or checks whether a diabetic supplies benefit is covered, that same tag is doing something regulators have spent three years and two settlements worth $9.3 million warning companies about: sending the visitor's identity, tied to that specific health-adjacent page, to an advertising platform that will use it to build a profile and sell more ads.

You didn't build the tag to do that. Nobody who installs a Meta Pixel is trying to disclose protected health information to Menlo Park. But the tag doesn't know the difference between your homepage and your Medicare quote result page, and neither does whatever consent banner you may or may not have wired it to respect.

This guide is not legal advice

What follows is sourced directly from FTC, HHS, CMS, and California's own legislative text, verified live. It is written to help you understand what actually applies and check your own site. For a specific compliance decision, talk to counsel who knows your state and your book of business.

How a pixel actually works

A tracking pixel isn't a physical thing sitting on the page. It's a line of JavaScript that runs in the visitor's own browser the moment the page loads, before they've clicked anything. When it fires, it sends a small request to Meta's or Google's servers carrying the page's URL, the referring page, a persistent identifier tied to that browser or that person's ad account, and, if the site has "advanced matching" or "enhanced conversions" turned on in the ad platform's settings, a hashed version of whatever the visitor typed into a form on that page, an email address, a phone number.

That last part is easy to miss because it's usually a default, not a decision. Meta and Google both promote advanced matching as a way to improve ad targeting accuracy, and a lot of agencies turn it on, or inherit it turned on from a marketing vendor, without realizing what it captures on a quote form that asks about current medications or a specific health condition.

The tag executes with whatever content and URL context exist at that moment. It does not distinguish a general "About Us" page from a page whose URL is literally /diabetic-supplies-coverage-quote. It fires the same way on both, sending the visitor's identity to the ad platform alongside the page they were on, which is precisely the combination that turns an ordinary marketing tag into a health data disclosure.

Walk through it concretely. A visitor searches "Medicare Advantage plans that cover insulin pumps," clicks your ad, and lands on a page you built for exactly that query. The Meta Pixel on that page fires the instant it loads, before the visitor has scrolled, before they've clicked anything. It sends Meta a signal tied to that visitor's Facebook account: this person visited a page about Medicare Advantage plans covering insulin pumps. If the visitor then fills out a quote form with their email address, and advanced matching is turned on, that email travels along too, hashed but still matchable back to a real identity on Meta's side. None of that required a data breach, a hack, or anything malicious. It's the pixel doing precisely what it was built to do.

What it sends

The page URL, the referrer, a persistent browser or account identifier, and sometimes hashed form data.

When it fires

On page load, by default, before a visitor has clicked accept on any consent banner.

What it can't tell

The difference between a homepage and a page naming a specific condition or plan type.

What regulators already did about it

This isn't a hypothetical risk someone is warning you about early. It has already produced two of the larger FTC health-privacy settlements on record, both centered on the exact mechanism described above.

In February 2023, the FTC announced its first ever enforcement action under the Health Breach Notification Rule, against GoodRx. The agency's complaint stated that GoodRx "repeatedly violated" its own promise never to share personal health information with advertisers, disclosing users' prescription medications and health conditions to Facebook, Google, and Criteo, then using the data shared with Facebook to serve those same users personalized, medication-specific ads2. GoodRx paid a $1.5 million civil penalty2.

Five months later, in July 2023, the FTC finalized a $7.8 million settlement with BetterHelp, the online counseling platform, over sharing users' email addresses, IP addresses, and mental health questionnaire answers with Facebook, Snapchat, Criteo, and Pinterest for advertising purposes, despite telling those same users their information would stay private3. About 800,000 people ended up eligible for a refund from that settlement.

That same month, the FTC and HHS's Office for Civil Rights sent a joint warning letter to roughly 130 hospital systems and telehealth providers, naming the technologies directly: "the Meta/Facebook pixel and Google Analytics," describing them as capable of revealing "a user's IP address... appointments scheduled, and physicians' pages visited"1. The letter didn't accuse anyone of a specific violation. It told 130 organizations, in writing, that regulators were watching this exact pattern.

The letter also told those 130 organizations what to actually do about it, and the advice reads the same whether you run a hospital system or a two-person agency: know what tracking technologies are installed on the site, understand exactly what data they collect and where it goes, and confirm whether a Business Associate Agreement is in place with each vendor that could touch protected health information1. Almost no independent agent has ever gone through that exercise for their own website, because nobody ever told them they'd need to.

The federal timeline, event by event
Date Event What it means
Dec 1, 2022 HHS OCR issues its first tracking technology bulletin5 First formal notice that pixels can trigger HIPAA obligations
Feb 1, 2023 FTC fines GoodRx $1.5 million2 First ever Health Breach Notification Rule enforcement action
Jul 14, 2023 FTC fines BetterHelp $7.8 million3 Confirms the pattern extends beyond one company
Jul 20, 2023 FTC and HHS send a joint letter to about 130 hospitals and telehealth providers1 Meta Pixel and Google Analytics named directly, in writing
Mar 18, 2024 HHS OCR revises its bulletin5 Guidance expands, then gets challenged in court
Jun 20, 2024 A federal court vacates part of the bulletin5 One specific rule struck down; the rest stands
CY2025 CMS's CMS-4205-F final rule takes effect7 Medicare agents get their own, separate consent rule
Jan 2025 FTC raises the Health Breach Notification Rule penalty4 Maximum civil penalty rises to $53,088 per violation

What a Texas court changed, and what it didn't

Here's where a lot of the vendor content on this topic gets sloppy, and it's worth being precise, because the actual court order is narrower than the headlines about it.

On June 20, 2024, the U.S. District Court for the Northern District of Texas ruled in a lawsuit brought by the American Hospital Association and sided with the hospitals. The court vacated the specific part of HHS's guidance stating that HIPAA obligations are triggered whenever an online technology connects "(1) an individual's IP address with (2) a visit to a[n] [unauthenticated public webpage] addressing specific health conditions or healthcare providers"5. HHS withdrew its appeal of that ruling two months later.

That is a real, meaningful narrowing. It means visiting a public, no-login page about a health topic, on its own, with nothing else happening, is not automatically a HIPAA event just because an IP address touched it. If your site's tracking exposure started and ended there, the court order would be the whole story.

It isn't. HHS's own guidance page, current as of this writing, states plainly what survived the ruling: "Tracking technology vendors are business associates if they create, receive, maintain, or transmit PHI on behalf of a regulated entity," which still requires an executed Business Associate Agreement5. It also states that on pages where a visitor provides information directly, scheduling an appointment, entering symptoms, requesting a quote tied to a health condition, "the regulated entity is disclosing PHI to the tracking technology vendor, and thus the HIPAA Rules apply"5. Any page behind a login, a client portal, an account dashboard, is untouched by the ruling entirely.

Vacated

What the court struck down

  • The rule that an IP address plus an unauthenticated page visit alone equals PHI
  • Applies narrowly, to public pages with no login and no form submitted

StatusNo longer enforceable as written5

Still in force

What the ruling didn't touch

  • The BAA requirement for any vendor handling PHI on your behalf
  • HIPAA obligations on any page where a visitor submits health-related information
  • Every authenticated page, client portal, or login-protected dashboard
  • The FTC Act, the Health Breach Notification Rule, CIPA, and CMS's TPMO rule

StatusFully enforceable, unaffected by this ruling

The mistake we see most

An agency reads a headline about the bulletin being "struck down" and concludes the pixel issue is settled and safe. The part that got struck down was the narrowest, most contested theory in the whole bulletin. Everything that actually built the GoodRx and BetterHelp cases, real form data going to a real ad platform, was never based on that theory in the first place.

The lawsuit risk HIPAA never covered

Even if every federal HIPAA question got resolved tomorrow in the most favorable way possible for every website in America, a separate and unrelated lawsuit risk would still exist, because it was never a HIPAA claim to begin with.

California's Invasion of Privacy Act, commonly called CIPA, includes a wiretapping provision originally written for phone taps. Plaintiffs' firms have spent the last few years applying it to website tracking tags, arguing that a pixel silently routing a visitor's activity to a third party is functionally the same as intercepting a private communication. Under California Penal Code section 637.2, a plaintiff who proves a violation can recover $5,000 per violation, or three times actual damages if that's greater, and doesn't have to prove any actual harm to collect the flat $5,0006.

Courts are actively split on how far this theory extends. A California federal court's November 2025 ruling in a tracking-pixel case explicitly rejected earlier rulings that had allowed these claims to proceed, calling the current state of CIPA case law on this question a "total mess" and pointing to a pending state legislative fix, Senate Bill 690, that would carve commercial tracking technology out of the statute's reach. Until that gets resolved one way or the other, the litigation exposure is real and unsettled at the same time, which is an uncomfortable but honest way to describe it.

What matters for your website is this: CIPA doesn't ask whether the data was protected health information under HIPAA's definition. It asks whether a tracking technology intercepted a visitor's activity without their consent. That is a lower, broader bar than HIPAA's, and it applies to a pixel firing on any page, not only ones about health topics, which is why this risk sits alongside the HIPAA and FTC exposure rather than replacing it.

In practice, these claims tend to start as a demand letter rather than a filed lawsuit, a plaintiffs' firm identifying a site running a specific tag, sending a letter citing section 637.2, and offering to settle for less than litigation would cost to defend. Whether or not a given claim would survive a motion to dismiss, defending one still means paying a lawyer to find out, which is its own real cost regardless of who would ultimately win.

The rule that's specific to Medicare agents

Every part of this guide so far applies to any business handling health-adjacent data. Medicare agents carry one more layer that a hospital or a therapy app never has to think about: CMS treats you as a Third Party Marketing Organization, or TPMO, and TPMOs have their own consent rules that have nothing to do with HIPAA.

CMS's Contract Year 2025 final rule, CMS-4205-F, states plainly that personal beneficiary data collected by a TPMO for marketing or enrollment "may only be shared with another TPMO when prior express written consent is given by the individual," obtained through "a transparent, and prominently placed, disclosure from the individual to share the information," named separately for each recipient, what CMS calls one-to-one consent7. A blanket consent checkbox covering "our marketing partners" as a group no longer satisfies the rule.

Here's where this connects back to tracking tags directly. If your quote form's lead data flows to a marketing platform, a call center vendor, or an ad retargeting partner that is itself acting as a TPMO, and that flow happens through a tag or an integration your consent language doesn't specifically name, you may be looking at a CMS compliance gap that exists entirely separately from anything HIPAA or the FTC would ever look at. This is not a theoretical overlay. It's the same underlying question, who is this data actually going to, asked by a third regulator with its own enforcement authority over your license.

If you want to know where your own site stands

The free Audit checks a site's technical readiness in under a minute, including whether trackers are firing before consent on health and Medicare-adjacent pages. Run one at strategicaiarchitects.com/audit.

What it actually costs

Put the numbers from this guide next to each other and the shape of the exposure gets clearer. None of these are hypothetical maximums pulled from a statute nobody has ever used. Every one has already been paid, or is the current, live number a regulator would apply today.

$9.3M

Combined FTC penalties against GoodRx and BetterHelp for sharing health data with ad platforms23

$53,088

Current maximum FTC civil penalty per Health Breach Notification Rule violation, as of January 20254

$5,000

Flat statutory damages per CIPA violation in California, no actual harm required6

130

Hospital systems and telehealth providers warned directly by name in the FTC and HHS's July 2023 letter1

Stat card titled What Tracking Pixel Enforcement Has Actually Cost, showing four figures: 1.5 million dollars, GoodRx FTC civil penalty, February 2023; 7.8 million dollars, BetterHelp FTC settlement, July 2023; 53,088 dollars, current maximum FTC Health Breach Notification Rule penalty per violation, updated January 2025; 5,000 dollars, flat California CIPA statutory damages per violation under Penal Code section 637.2, no actual harm required. Source lines for FTC.gov and leginfo.legislature.ca.gov shown on the card
Per-violation exposure, two separate legal frameworks $5,000 CIPA, per violation (Cal. Penal Code 637.2) $53,088 FTC Health Breach Notification Rule max
Sources: California Penal Code section 637.2, current statute6; FTC, "Complying with FTC's Health Breach Notification Rule," updated January 20254.

Neither figure is a ceiling on real-world exposure. CIPA damages stack per violation, and a site with recurring visitors can generate more than one. The FTC's two settlements landed well above its own per-violation maximum because the agency counted each individual disclosure across hundreds of thousands of users. The number that actually matters for your agency isn't either figure in isolation. It's how many pages on your site are firing a tag before consent, on a page tied to a health condition or a Medicare plan, multiplied by however many visitors hit it.

How to check your own site in ten minutes

You don't need to hire anyone to get a first real answer. Most of this is checkable directly, in your own browser, right now.

01

Open developer tools and watch the network tab

Load your homepage with your browser's developer tools open to the Network tab. Filter for facebook.com/tr, google-analytics.com, and googletagmanager.com. Reload the page without clicking anything on a cookie banner. If those requests appear before you've accepted anything, the tag fired without consent.

02

Repeat it on your health and Medicare-specific pages

Do the same check on a plan comparison page, a subsidy calculator result, or any page naming a specific condition or benefit. This is where the exposure concentrates, so a clean homepage doesn't tell you the site is clean.

03

Check advanced matching and enhanced conversions settings

In Meta Ads Manager, under Events Manager, and in Google Ads, under Conversions, look for "Advanced Matching" or "Enhanced Conversions." If either is on, your pixel may be sending hashed emails or phone numbers automatically, pulled straight from your quote forms.

04

Read your own consent language against CMS's one-to-one standard

Pull up the consent checkbox on your quote or contact form. If it says anything like "our marketing partners" as a group, rather than naming each specific recipient of the data, it does not meet CMS's one-to-one consent standard for TPMOs7.

05

Ask whether anyone has a signed BAA with your ad platforms

If the honest answer is no, and it usually is, because Meta and Google don't offer one for these products, then any PHI those tags pick up is moving without one. That's the gap, and it's a structural one, not a settings toggle you can flip to fix it.

Client-side tracking versus server-side tracking

The fix has a name, and it's worth understanding the mechanism rather than treating it as a checkbox to enable, because the underlying idea explains why it actually closes the gap instead of just hiding it.

A standard, client-side pixel runs in the visitor's own browser and sends data straight to Meta or Google the instant the page loads. Nothing you control sits between the visitor and the ad platform. There's no place to check for consent, strip a health-adjacent parameter, or hold the event until it's actually appropriate to send, because the browser already sent it before your server ever saw the request.

Server-side tracking moves that step onto infrastructure you control. The event still gets captured, a page view, a form submission, a conversion, but it routes to your own server first. Your server checks whether consent was actually recorded, strips out anything that shouldn't leave your systems, and only then forwards a cleaned event to the ad platform, if it forwards one at all. The visitor's browser never talks to Meta or Google directly. Your server does, on your terms.

What changes between the two approaches
Question Client-side pixel Server-side, consent-gated
Where does the data route first Directly from the visitor's browser to Meta or Google To your own server first, then forward, if at all
Can it fire before consent Yes, by default, unless separately gated No, consent is checked before anything forwards
Can PHI-adjacent fields be stripped No, the browser sends the raw event as built Yes, your server controls exactly what forwards
Who needs a BAA The ad platform, which won't sign one Your own infrastructure, under your own agreement

None of this requires giving up ad tracking entirely. It requires putting a checkpoint between your visitors' health-adjacent activity and the platforms bidding on your ad spend, so the data that reaches them is what you've actually decided should reach them, on pages where that's appropriate, and nothing on the ones where it isn't.

How we build this in

This section sticks to what's on our own live pages, verified this session. The free Audit checks whether a site's trackers are firing before consent on health and Medicare-adjacent pages as part of its report, so you can see where your own current site actually stands before deciding anything8. When that check flags an exposure, the fix on our own site is named plainly: a Digital Foundation rebuild moves the site to server-side, consent-gated tracking and rewrites the privacy policy to match, which is the mechanism described above, not a raw client-side pixel left to fire on its own8.

Digital Foundation starts at $247 a month, with a 14-day free trial and no long-term contract9. For agencies handling protected health information more directly, running voice AI that touches call recordings, a CRM holding health-related notes, or integrations across a multi-office FMO or IMO, Enterprise builds run on HIPAA-eligible AWS or Azure services under a signed BAA, with server-side data flows and full audit logging, so no third-party vendor ever handles PHI off your own stack, and the agreement is signed before go-live, not after10.

Neither of those claims is a promise about your specific legal exposure disappearing. What we can say plainly is that the specific mechanism regulators have penalized twice, a client-side pixel sending health-adjacent form data straight to an ad platform with no BAA and no consent gate, is not how we build a site in the first place.

The tradeoff, plainly. A consent-gated, server-side setup takes more engineering than pasting a pixel snippet into your header. That's the honest cost. What it buys back is a structural answer to the exact question the FTC, CMS, and California's courts have all been asking in different ways: who actually receives a visitor's health-adjacent data, and did anyone agree to that.

When this doesn't apply to you

This entire guide concentrates on health-adjacent pages, Medicare, ACA, and any benefit tied to a specific condition. If your book is life insurance, final expense, or property and casualty, and your site never asks a visitor about a health condition or returns a result tied to one, a standard client-side pixel on your marketing pages carries meaningfully less of this specific exposure. HIPAA's PHI framework, the FTC's Health Breach Notification Rule, and CMS's TPMO rule are all keyed to health information and Medicare marketing specifically, not to insurance broadly.

It's worth saying plainly: you can run this ten-minute check yourself, decide your site is clean, and be done with it. A lot of agents will. If your quote flow never touches a health condition and your consent language already names each recipient by name, you may not need anything more than the check itself. The point of this guide is knowing which situation you're actually in, not talking every agent into a rebuild they don't need.

Where it does apply almost without exception is any agency selling Medicare Advantage, Medicare Supplement, ACA, or supplemental health products, because the quote flow itself is the exposure. A subsidy calculator that returns a plan based on a household's health status, a Medicare comparison tool that asks about current prescriptions, these are exactly the pages the FTC's own GoodRx and BetterHelp complaints describe, just built by a different kind of business.

Questions agents ask

Is Google Analytics illegal on an insurance agency website?

No. Google Analytics itself is not illegal, and running it on a general marketing site is not a violation on its own. The exposure shows up on specific pages, a Medicare Advantage comparison page, a diabetic supplies quote result, an ACA subsidy calculator that returns a plan tied to a health condition, where the tag can transmit a visitor's identity alongside a health specific interest to Google before that visitor has consented to anything.

Does HIPAA still apply to tracking pixels after the 2024 court ruling?

Partly, and it never stopped applying to the parts that matter most. A federal court vacated the specific rule that an IP address visiting an unauthenticated public health page automatically counts as protected health information. It did not touch the requirement that any vendor creating, receiving, or transmitting PHI on your behalf needs a signed Business Associate Agreement, and Meta and Google will not sign one for their standard advertising pixels.

What is CIPA, and does it apply outside California?

CIPA is the California Invasion of Privacy Act, and its wiretapping provision lets a plaintiff recover $5,000 per violation without proving any actual damages, under California Penal Code section 637.2. It is a California statute, but a plaintiff who accessed your site from California can potentially bring a claim regardless of where your agency is based, which is why agents outside California still ask about it.

Do I need a Business Associate Agreement with Meta or Google?

If a vendor's tool creates, receives, maintains, or transmits protected health information on your behalf, HIPAA requires a signed BAA before that happens. Meta and Google do not offer a BAA for their standard Pixel and Analytics products, which means any PHI those tags pick up on your site is moving without one, by design of the product itself, not by anything in your settings.

What actually counts as a health condition page for this purpose?

Regulators' own examples are specific: a page listing types of medical providers, a symptom checker, an appointment scheduling tool, or a portal where someone logs in to see results. For an insurance site, the closest equivalents are pages naming a specific condition or benefit tied to a health need, a diabetic supplies coverage page, a specific Medicare Advantage plan's provider network, or a quote result tied to a disclosed health status.

What is CMS's one to one consent rule, and does it apply to tracking pixels?

CMS's Contract Year 2025 final rule, CMS-4205-F, requires a Third Party Marketing Organization to get a beneficiary's prior express written consent, named separately for each recipient, before sharing that beneficiary's data with another TPMO for marketing or enrollment. It is a separate rule from HIPAA, aimed at how a beneficiary's information moves between marketing entities, and it applies to independent Medicare agents directly, not only to carriers.

How do I check whether my own site fires trackers before consent?

Open your site, open your browser's developer tools, click the Network tab, filter for facebook.com/tr or google-analytics.com, and reload the page without clicking anything on a cookie banner. If requests to those domains show up before you have accepted anything, the tag fired without consent. Check your general pages first, then any page naming a specific condition or plan type, since that is where the exposure concentrates.

Sources

  1. Federal Trade Commission. "FTC and HHS Warn Hospital Systems and Telehealth Providers About Privacy and Security Risks From Online Tracking Technologies," published 2023-07-20, verified live 2026-08-12. ftc.gov.
  2. Federal Trade Commission. "FTC Enforcement Action to Bar GoodRx From Sharing Consumers' Sensitive Health Info for Advertising," published 2023-02-01, verified live 2026-08-12. ftc.gov.
  3. Federal Trade Commission. "FTC Gives Final Approval to Order Banning BetterHelp From Sharing Sensitive Health Data for Advertising, Requiring It to Pay $7.8 Million," published 2023-07-14, verified live 2026-08-12. ftc.gov.
  4. Federal Trade Commission. "Complying with FTC's Health Breach Notification Rule," civil penalty of up to $53,088 per violation, edited January 2025 for inflation-adjusted maximums, verified live 2026-08-12. ftc.gov.
  5. U.S. Department of Health and Human Services, Office for Civil Rights. "Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates," original guidance 2022-12-01, revised 2024-03-18, noting the 2024-06-20 court vacatur, verified live 2026-08-12. hhs.gov.
  6. California Legislative Information. California Penal Code section 637.2, statutory damages of $5,000 per violation or three times actual damages, current text, verified live 2026-08-12. leginfo.legislature.ca.gov.
  7. Centers for Medicare and Medicaid Services. "Contract Year 2025 Medicare Advantage and Part D Final Rule (CMS-4205-F)," TPMO one-to-one prior express written consent requirement, verified live 2026-08-12. cms.gov.
  8. Strategic AI Architects. "Free Audit," HIPAA and consent tracking scan feature, verified live 2026-08-12. strategicaiarchitects.com.
  9. Strategic AI Architects. "Digital Foundation," pricing and server-side tracking, verified live 2026-08-12. strategicaiarchitects.com.
  10. Strategic AI Architects. "Enterprise," HIPAA-eligible AWS and Azure infrastructure and Business Associate Agreement terms, verified live 2026-08-12. strategicaiarchitects.com.

See whether your own site fires trackers before consent

Run the free Audit, a live AEO Audit plus a HIPAA tracking scan of your site, in under a minute.

Related reading: why your subsidy calculator is wrong · can your AI follow-up get your agency sued

← All guides