Is Google Analytics HIPAA-compliant?

Written by Karolina Lubowicka, Małgorzata Poddębniak

Published February 20, 2026

Quick summary

Google Analytics is not HIPAA-compliant. Google explicitly states it doesn’t satisfy HIPAA requirements and won’t sign a business associate agreement (BAA) with covered entities. Healthcare organizations that collect protected health information (PHI) cannot use Google Analytics without risking HIPAA violations.To collect analytics data on PHI lawfully, you need a vendor that will sign a BAA.

What this covers: why Google won’t sign a BAA, where PHI leaks into analytics, what the 2024 court ruling did and didn’t change and how to choose an analytics platform that supports HIPAA compliance.

Who it’s for: marketing, analytics, IT and compliance teams at healthcare providers, health plans and their business associates.

Using analytics tools in a highly regulated sector, such as healthcare, requires caution, especially if you operate in the US or work with US patients. In this case, you must process and store protected health information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA). HIPAA sets federal standards for processing, storing, and disclosing protected health information in any form: electronic, written, or spoken.

You can’t share PHI with an analytics vendor unless HIPAA permits it. That has always been true. What changed is how much sensitive data tools like Google Analytics now collect by default, and how closely regulators and plaintiffs’ lawyers are looking.

Disclaimer: This blog post is not legal advice. Piwik PRO provides privacy-friendly analytics software, but does not provide legal consultancy. If you’d like to make sure you’re in compliance with HIPAA guidelines, we encourage you to consult an attorney.

Can healthcare organizations use Google Analytics? 

In short, if you’re a HIPAA-covered entity, using GA4 puts you at serious risk of a HIPAA breach.

If you use Google Analytics or similar software, you’re likely already optimizing your website to serve your customers better. But what about Google Analytics and HIPAA compliance?

Does Google Analytics collect PHI? 

Google explicitly prohibits using Google Analytics for any purpose involving PHI if you’re a covered entity or business associate and they won’t sign the required business associate agreement (BAA).

Protected health information (PHI) encompasses any data related to a patient’s health condition, treatment, or payment when combined with personal identifiers.

Google’s HIPAA disclaimer 

Google’s own Analytics documentation states that covered entities and business associates “may not use Google Analytics for any purpose involving Protected Health Information.” Google adds that it makes no representation that Google Analytics satisfies HIPAA requirements.

Why Google won’t sign a BAA with you

Google won’t sign a BAA because:

  • Google’s data usage practices conflict with HIPAA: Google’s terms and conditions allow them to use collected data for advertising, service development, and content personalization, practices that violate HIPAA when applied to PHI.
  • No data residency guarantee: Data is stored in randomly assigned data centers, potentially outside the US, making it impossible to maintain the accountability HIPAA requires. You don’t know the exact location of your patients’ data.

As a result, if you pass any trace of PHI/ePHI into Google Analytics, you’re breaking HIPAA regulations and Google’s terms of service. This may result in the termination of your GA account, on top of your HIPAA exposure.

Does Google Analytics follow users across websites? 

Google Analytics creates individual user profiles that persist across websites, following users long after they leave your site. For healthcare organizations, this means:

  • Patient behavior data may inform the ads they see elsewhere online
  • Unique identifiers link health-related browsing to individual users
  • These data collection practices occur without clear visibility to site visitors

This not only violates HIPAA but also erodes patients’ trust in your organization.

read also

How to make your analytics HIPAA-compliant: A practical checklist for healthcare marketers

Follow this step-by-step HIPAA compliance checklist to ensure your analytics meet healthcare privacy standards and protect patient data.

Can you use Google Analytics if you avoid collecting PHI?

Using Google Analytics without collecting PHI is theoretically possible, but it is also risky. PHI can appear in unexpected places:

  • URLs containing patient identifiers or appointment details
  • Form fields capturing health-related information
  • Page visits to symptom checkers or treatment pages, when combined with IP addresses

What did the 2024 court ruling change?

In June 2024, a federal court in the Northern District of Texas struck down part of the HHS guidance on online tracking technologies. The court held that HIPAA is not triggered simply because a tool connects a visitor’s IP address with a visit to a public, unauthenticated page about a health condition or provider. OCR filed an appeal that August, then withdrew it ten days later. Unless HHS issues new rules, that ruling stands.

That was a real win for hospital marketing teams, but it is narrower than it sounds. Everything else in the guidance still applies:

  • Authenticated pages, like patient portals, are unaffected. PHI flowing to a vendor from behind a login still needs a BAA.
  • Unauthenticated pages that let people book appointments or use a symptom checker can still involve PHI, depending on what is collected.
  • Using PHI for marketing or advertising still needs patient authorization.
  • OCR has said it prioritizes HIPAA Security Rule compliance when it investigates tracking technology, so the question of whether you can show you assessed the risk still matters.

What other privacy laws apply to healthcare analytics? 

Since 2024, the pressure has shifted away from federal HIPAA enforcement and toward three other places:

  • Private lawsuits
    Website pixels have become a common basis for class actions against healthcare providers, and the exposure isn’t limited to large health systems. 
  • State health-privacy laws
    Washington’s My Health My Data Act and similar state laws reach organizations HIPAA does not cover, and some give individuals a private right of action.
  • The FTC
    The FTC has acted against health apps and services for sharing health data with advertising platforms, using the FTC Act and the Health Breach Notification Rule. Being outside HIPAA doesn’t put you outside federal reach.

So the practical position is unchanged. If you are a covered entity, you still need an analytics vendor that will sign a BAA and can show you where your data goes.

Whether or not a piece of data is considered PHI is subject to interpretation. HHS has also previously stated that whether PHI is being disclosed depends on the visitor’s underlying intentions, which are difficult to determine with complete certainty.

PHI turns up in more places than most teams expect, so it pays to be careful about what you collect and who you send it to.

Considering all these aspects, using Google Analytics by HIPAA-covered entities is risky. If you want to take that risk, you must ensure no PHI finds its way into the platform.

Here’s what PHI in URLs looks like:

  • https://healthclinics.com/your_account_john_hill/stomatologist_nelson_green 
  • https://healthclinics.com/url8554

The first URL contains PHI: your patient’s name, and their doctor’s name and specialization. Meanwhile, the second URL has PHI scrubbed and shows only a universally unique identifier. Ensure your settings and site architecture are properly configured so the first URL switches to the second one before it reaches your analytics.

De-identifying data to remove PHI is technically possible since it would no longer fall under HIPAA, but it presents significant challenges:

  • It’s time-consuming and requires strict organizational processes
  • It’s especially difficult for custom dimensions and event attributes
  • De-identified data loses value for personalization, patient journey analysis (returning visitors will appear as new visitors) and detailed conversion attribution
  • Even minor errors can result in HIPAA violations

Does server-side Google Tag Manager make GA4 HIPAA-compliant?

Server-side GTM gives you more control over data sharing, but it doesn’t solve the HIPAA problem:

  • GTM’s use policy requires compliance with GA4’s terms of service, which prohibit sending PII (and PHI is a subset of PII)
  • You must de-identify all PHI before sending data to Google, a complex, error-prone process
  • The risk of accidental PHI disclosure remains high

What GA4 actually costs you in a regulated setup

Suppose you do the work. You scrub PHI from URLs, lock down your forms, and keep Google Analytics running. You are still paying a price, and it usually shows up in three places.

  1. Your reporting has holes in it
    Stripping identifiers breaks the link between visits. Returning patients look like new visitors, multi-session journeys fall apart, and conversion attribution gets unreliable. You end up reporting on campaigns with numbers you privately don’t trust.
  2. You can’t prove anything to your own auditors
    When legal or security asks where patient data went, ‘we configured it carefully’ is not an answer. Without a BAA and an audit trail, you are relying on your own configuration being right, and staying right, every time someone adds a tag.
  3. Every site change is a new risk
    A new landing page, a new form field, a new third-party script. Each one is another chance for PHI to leak into a platform that was never built to hold it.

If any of that sounds familiar, the problem isn’t your configuration. It’s that you’re asking a tool built for advertising to behave like a tool built for regulated data.

How to make your analytics HIPAA-compliant

To achieve HIPAA compliance in analytics, use a platform that signs a business associate agreement (BAA). This allows you to collect PHI without de-identification or data restrictions.

When selecting the right tool, review each platform’s strengths individually and examine your specific needs in terms of functionality, ease of use, resources, and cost.

HIPAA compliance with Piwik PRO

Piwik PRO enables you to securely collect and analyze PHI and ePHI, helping you deliver an even better, more personalized patient experience.

It provides a strong analytics foundation supportive of HIPAA compliance through:

  • Business associate agreements (BAA) tailored to your needs
  • Microsoft Azure hosting in the US
  • ISO 27001 certification, plus a SOC 2 Type II report that includes HIPAA in scope
  • 100% data control: we don’t share or reuse your data
  • Granular access controls restricting data to authorized personnel
  • Detailed audit logs recording data access and configuration changes

HIPAA support, including the BAA, is part of our Enterprise plan on the Trusted Insights and Secure Intelligence tiers. 

Piwik PRO’s integrated platform includes:

  • Analytics, Tag Manager, and Data Activation in one solution
  • User-friendly interface with customizable dashboards and reports, enabling both basic and advanced analytics
  • Integrations with marketing tools and data storage platforms

Setup is guided, with migration support. Most teams are seeing data within days, and a full implementation usually takes a few weeks depending on complexity. 

See how this works for hospitals and health systems on our HIPAA-compliant analytics page.

Piwik PRO vs. Freshpaint

Both Piwik PRO and Freshpaint sign a BAA , but they do different jobs. Piwik PRO is the analytics platform. Freshpaint is a layer that controls what patient data reaches the tools you already use. 

Piwik PRO is an all-in-one platform with analytics and data activation capabilities that can be further extended through integrations with other tools and platforms. It also employs high-level privacy and security features. Overall, you get  comprehensive analytics capabilities within a single platform that’s built for HIPAA compliance.

Freshpaint, on the other hand, sits between data sources (such as data warehouses) and third-party data destinations, acting as a buffer to prevent PHI from being sent to non-compliant tools. It isn’t an analytics platform in its own right, so it needs to be connected to other tools to give you reporting. That means the two products solve different problems: Freshpaint governs what reaches your existing stack, while Piwik PRO replaces the stack.

Best practices for HIPAA compliance in analytics

Start by reviewing your website architecture, analytics implementation, and tag management setup. Work with your legal team or hire an analytics auditor to assess your digital infrastructure.

Key areas to audit include:

Data collection

  • Are you collecting user IDs? How are they used?
  • What PHI appears in URLs, page titles, or query strings?
  • What information do forms collect, and how is it used?

Privacy measures

  • Are IP addresses anonymized or hashed?
  • Do you collect GPS or precise location data?
  • What third-party scripts run on your site?

Vendor management

  • Which tools have access to PHI?
  • Do you have BAAs in place for all vendors handling PHI?

Your legal and security teams should monitor regulatory changes from HHS/OCR and FTC, and regularly evaluate your analytics setup for compliance.

Learn more: Learn how to ensure your campaigns are HIPAA-compliant: HIPAA-compliant marketing and advertising: What you can and can’t do.

What to do instead of Google Analytics

Google Analytics isn’t HIPAA-compliant and poses significant risks for covered entities. While de-identifying PHI is technically possible, the margin for error is thin and the consequences are severe.

For healthcare organizations serious about compliance, the solution is simple: use an analytics platform that signs a BAA and provides HIPAA-specific safeguards. This approach lets you gain valuable patient insights while protecting privacy and maintaining compliance.

Your next steps should be to:

  • Consult your legal team about BAA requirements
  • Audit your current analytics setup for PHI exposure
  • Evaluate analytics alternatives that can support your HIPAA compliance strategy

Frequently asked questions

Is Google Analytics HIPAA-compliant?

No. Google explicitly states that Google Analytics doesn’t satisfy HIPAA requirements and won’t sign a business associate agreement (BAA) with covered entities or business associates.

What is a business associate agreement (BAA)?

A business associate agreement (BAA) is a contract between a HIPAA-covered entity and a business associate. It ensures that the business associate understands its responsibilities regarding PHI and will protect it according to HIPAA guidelines. If you want to use a tracking technology that collects and processes PHI, you must sign a BAA with the vendor.

Why doesn’t Google offer a BAA for Google Analytics?

There are two main reasons:

  • Data hosting and residency: Google doesn’t offer on-premises hosting or guaranteed data residency. Data is stored in randomly assigned data centers, potentially outside the US, which conflicts with HIPAA’s accountability rule regarding knowing the location of patient data.
  • Data usage: Google’s terms allow them to use collected data to develop new services, measure advertising effectiveness, and personalize content. Using PHI for advertising purposes would be a HIPAA violation.
What happens if I pass PHI/ePHI into Google Analytics?

You would be violating HIPAA regulations and Google’s terms of service. This could result in the termination of your Google Analytics account, breaches of HIPAA, fines and damage to your organization’s reputation.

Can I use Google Analytics if I don’t collect PHI/ePHI?

Yes, but it requires significant caution and effort. You must ensure that no PHI/ePHI is transmitted to Google Analytics. Mistakes can be costly. PHI can be found in various locations, including post-login areas, unauthenticated pages, or mobile apps (for example, in URLs, form fields, or event data).

What is considered PHI?

PHI includes any health information (diagnoses, treatments, lab results, payment details) combined with personal identifiers. When IP addresses or other identifiers are linked to health-related page visits or form submissions, this combination can constitute PHI.

Did the 2024 court ruling make Google Analytics safe for healthcare?

No. The June 2024 ruling in AHA v. Becerra narrowed one part of the HHS guidance: an IP address combined with a visit to a public page about a health condition is no longer automatically PHI. It did not change anything about authenticated pages, the requirement for a BAA, or the rules on using PHI for marketing. Google still won’t sign a BAA, so covered entities collecting PHI still can’t use Google Analytics.

How can I make my analytics support HIPAA compliance?

Use an analytics platform that signs a BAA (like Piwik PRO, Mixpanel, or Heap), de-identify all PHI before collection, or choose a hosting arrangement that gives you full control over where data sits.

Which analytics platforms offer a BAA?

Analytics vendors that offer a BAA include:

  • Piwik PRO (Enterprise plan) 
  • Mixpanel (Enterprise plan) 
  • Heap
  • Amplitude
  • Freshpaint (paid plans) 
  • Adobe, for Customer Journey Analytics with the Healthcare Shield add-on, but not Adobe Analytics 

Most vendors restrict the BAA to paid or enterprise plans, so check which tier you need before you start an evaluation. Keep in mind that a BAA is a contract, not a setting. You still control what data you send. 

The comparison of 9 platforms supporting HIPAA-compliant analytics

Compare Piwik PRO, Matomo, Piano Analytics, Adobe CJA, Mixpanel, Amplitude, Heap, Freshpaint and Tealium across three categories: web and digital analytics, product analytics, and data governance and routing. See which sign a BAA, on which plan, and what each one can actually report on.