If your organization runs analytics, ad pixels, or chat tools on its website, this topic affects you. In December 2022, HHS’s Office for Civil Rights issued a bulletin on online tracking technologies. It warned that common tools like Meta Pixel and some analytics scripts could trigger HIPAA violations. A hospital association lawsuit challenged part of that guidance. A federal court agreed with the challenge in 2024. Since then, the rules have shifted again, and they are still not fully settled. Here is what actually changed, and what has not.
How We Got Here: The OCR Bulletin Timeline
This did not start as a single event. It has been a two-year back-and-forth between regulators, hospital groups, and the courts. The two sections below walk through how we got from the original warning to where things stand today.
The Original 2022 Bulletin and the Warning Letters
OCR issued its first bulletin in December 2022. It stated that regulated entities could not disclose protected health information, or PHI, to tracking technology vendors without proper authorization. Roughly six months later, OCR and the Federal Trade Commission acted together. They sent warning letters to about 130 hospitals, telehealth providers, and health app developers. The letters flagged the privacy and security risks tied to tracking tools on their websites and apps.
The 2024 Revision and the Court Challenge
In early 2024, the American Hospital Association and several health systems sued HHS. They argued OCR had overstepped its power. OCR responded by issuing a revised bulletin in March 2024, days before its court filing was due. The hospital groups argued the revision did not fix the core legal problems. On June 20, 2024, a federal judge in the Northern District of Texas agreed. The court vacated part of the guidance.
What the Court Struck Down
The ruling did not throw out the entire bulletin. It struck down one specific interpretation, and the distinction matters for how you read the guidance today.
The Vacated Piece: A Narrow but Real Change
The court vacated one specific part of the guidance. That part said HIPAA rules kick in right away whenever an online tool connects a visitor’s IP address to a visit to a public webpage. This applies only to unauthenticated pages about specific health conditions or providers, ones that do not require a login. In practice, that means something concrete. A hospital’s public webpage about, say, cardiology services no longer counts as a PHI disclosure by default. That is true even if a tracking pixel logged an anonymous visitor’s IP address on that page. HHS considered an appeal, then dropped it in September 2024. The vacatur stands.
What Still Applies
The ruling did not touch the rest of the bulletin. Several categories of tracking still carry real HIPAA duties:
- Tracking technologies on user-authenticated pages, like patient portals or telehealth platforms, still have access to PHI. These pages remain fully covered
- Tracking within mobile apps that regulated entities offer to patients still involves PHI
- Appointment scheduling tools and symptom checkers that collect identifiable information still trigger HIPAA duties, even on public pages
- Any tracking technology vendor that qualifies as a business associate still needs a signed business associate agreement before receiving PHI
Why Enforcement Risk Has Not Gone Away
A single court ruling narrowed one legal theory. It did not end regulatory or legal exposure around website tracking. Two separate pressures are still very much active.
OCR and FTC Have Kept Investigating
OCR has continued pursuing HIPAA enforcement actions tied to website and app data flows. The FTC has pursued its own cases too. Its power comes from the FTC Act. It also comes from the Health Breach Notification Rule, which covers health apps that HIPAA does not reach. Neither agency treated the court ruling as a reason to stop paying attention to tracking tools.
Private Lawsuits Are the Bigger Near-Term Risk
Class action lawsuits over tracking pixels have not slowed down. In 2025, several health systems reached settlements over pixel-related claims. These included MarinHealth, University of Rochester Medical Center, BJC Healthcare, Henry Ford Health, and Eisenhower Health, per the HIPAA Journal. Courts have also let some of these cases move forward on other grounds. Wiretapping and state privacy claims sit entirely outside HIPAA, and judges have allowed them to proceed anyway. In June 2025, a federal court in New York denied Teladoc Health’s motion to dismiss a tracking-related privacy class action. The court let most of the claims against the company move forward.
What This Means for Levo’s Clients
None of this is abstract for the organizations we work with. The type of content on a page, and who can see it, both shape the actual risk level.
Specialty and Behavioral Health Pages Carry Extra Weight
A public page about general services carries less risk under the current guidance. A page tied to a specific, sensitive condition carries more. Behavioral health and addiction treatment pages sit closer to that higher-risk category. This is true even on pages that do not require a login. A visitor reading about outpatient addiction treatment is engaging with content tied to a specific health condition. A general “about us” page is not. The vacated portion of the guidance narrowed HIPAA’s automatic reach here. It did not remove the core privacy risk. State privacy laws or platform policies can still apply.
A Practical Checklist for Right Now
- Inventory every tracking tool running on your website and mobile app. Include analytics, ad pixels, session replay tools, and chat widgets
- Confirm which of those tools sit on authenticated pages, like patient portals, since those still carry the clearest HIPAA duties
- Confirm whether any public pages collect identifiable information, such as appointment forms or symptom checkers. Those remain covered regardless of login status
- Secure signed business associate agreements with any vendor that qualifies as a business associate before PHI reaches them
- Review behavioral health, addiction treatment, and other sensitive-condition pages separately. They carry elevated risk even where general pages may not
The legal question here got narrower. The practical one did not. A court may revisit this rule again. Congress may eventually write something new. Either way, providers still have to decide today what runs on their public pages and who it talks to. This ruling is a reminder of why that groundwork still matters. Waiting for total legal clarity is not really a strategy, since there is no guarantee it arrives. Levo Health reviews tracking setups against where the law and the litigation stand right now. That is different from where they stood back in 2022.

