Smarter Audience Targeting for Healthcare—Finally, It’s Compliant
Check it out
Login
Platform
Improve Marketing Performance
Drive growth without increasing budgets through better performance
Audiences
Smart, privacy-first targeting with lookalikes and retargeting lists
Healthcare Integrations
Bring full-funnel marketing to healthcare with 100+ integrations
Measure Marketing Impact
Prove marketing's value to unlock budget with real outcome data
Insights
One dashboard with every channel's performance and real ROI metrics
Ad Performance
Optimize for patient visits, not form fills, with attended appointment data
Protect Privacy & Compliance
Safeguard your marketing strategy from compliance disruption
Web Tracker Manager
See every tracker on your site and identify compliance risks
Consent Management
Consent that actually works by enforcing preferences at the data layer
Event Tracking
Measure what users actually do, not just what they view on your site
Healthcare Solutions
By Healthcare Vertical
By Use Case
Hospitals & Healthcare Systems
Payers
Urgent Care
Pharma & Med Devices
Orthopedics
Specialty Providers
DSO & Dental
Improve Marketing Performance
Measure Marketing Impact
Protect Privacy & Compliance
Customers
Get started / for customers
Login
Docs
Freshpaint Status
Partner Directory
Featured Healthcare Case Studies
Allergy Partners
Dropped Their CPL from $300 to $12
BU Dental
Optimized their digital marketing, reducing CPA by 30%.
Baptist Health
Journey to HIPAA-Compliant Digital Marketing ipsum dolor sit
Explore all Case Studies
Product update
Freshpaint Audiences: Better ROI with Audience Targeting Built for Healthcare
Freshpaint Audiences gives healthcare marketers the power to run targeted ad campaigns that cut wasted spend, reach the right audience faster, stay fully privacy-compliant, and, most importantly, improve ROI.
Resources
Learn & Insights
Blog
Privacy Hub
FAQ
Prove your ROI
Marketing Hub
Events
Case Studies
Product update
Freshpaint Audiences: Better ROI with Audience Targeting Built for Healthcare
Freshpaint Audiences gives healthcare marketers the power to run targeted ad campaigns that cut wasted spend, reach the right audience faster, stay fully privacy-compliant, and, most importantly, improve ROI.
Plans & Pricing
Login
Book a Demo
Posted on 
September 3, 2024

Navigating the Whiplash: How Healthcare Organizations Can Stay Ahead of Data Privacy Regulations

Whiplash. That’s the best word to describe what healthcare organizations are experiencing regarding data privacy regulations. 

It all started with the Markup’s investigation that sparked widespread panic over the use of Meta and Google ad trackers. This led to a wave of class action lawsuits, intensifying concerns about data privacy governance. 

In response, HHS released guidance on the use of online tracking technology, causing many organizations to stop all data-sharing activities. The situation escalated further when the FTC teamed up with HHS to emphasize the importance of data privacy, creating even more uncertainty. 

The American Hospital Association (AHA) then filed a lawsuit against the guidance, prompting healthcare organizations to pause their activities once again as they awaited the outcome. A small victory for the AHA in the courts was exacerbated by clickbait headlines and seemingly gave some organizations the green light to cautiously resume using web trackers.

But most healthcare organizations weren’t fooled by the clickbait headlines. The AHA court ruling was only around the proscribed combination of IP address and health context and did not touch the rest of HHS’s guidance around web tracking technology. 

Most recently, HHS decided not to appeal the AHA lawsuit ruling, but that should not change how organizations approach privacy. Paul Bond, an attorney at Holland & Knight, emphasizes that the decision to forgo an appeal should not diminish the focus on privacy in online tracking technology, stating, "HHS’s decision not to appeal will have zero impact on patient privacy."

All of this leaves healthcare organizations confused about the implications of using data in marketing. This series of twists and turns has left the industry in a state of flux, struggling to keep up with the ever-changing regulatory landscape.

The Challenge of Complying with Expanding Data Privacy Laws

Despite HHS deciding not to appeal the narrow ruling on AHA’s lawsuit, the core of HHS’s guidance about the use of online tracking technologies still applies. Consumer data like ad click ID, device ID, email addresses, and more still fall under HIPAA’s governance for covered entities. 

And even data that isn’t under HIPAA’s governance is starting to be controlled by state-level privacy laws. 

Right now, there are twenty states that have enacted privacy laws that healthcare organizations must comply with.

Most healthcare organizations that operate in any of those states must comply with both HIPAA and the state-level law. Some of those state-level laws are quite strict. 

Take Washington state’s My Health, My Data Act, for example. It explicitly targets health information and goes beyond the protections offered to consumers by HIPAA.

There’s no sign of these laws slowing down. In addition to the twenty states that have already enacted privacy laws, seventeen additional states have introduced data privacy legislation.

If that’s not enough, class action lawsuits are still wreaking havoc on healthcare organizations. These are often not because of HIPAA, or any state-level laws, but of other privacy laws like the Video Privacy Protection Act and Trap and Trace laws.

A durable data privacy solution is essential

These constant healthcare data privacy changes could lead to an unpredictable regulatory environment where what’s compliant today might be non-compliant tomorrow. 

The uncertainty could create a chaotic situation for healthcare organizations, resulting in a data management nightmare. Organizations that choose to wait risk inadvertently violating HIPAA.

Instead of waiting, a better approach is to put a durable solution in place to help you quickly adjust based on changes to HIPAA guidance (and state-level privacy laws, too). 

A durable solution involves taking control of your data by only collecting and activating first-party data through a BAA-protected platform, like Freshpaint. Taking control of your data now is your best defense over constantly evolving data privacy regulations.

Get Freshpaint in your email

If you want to learn how to be even more agile with customer behavioral data, join more than 3k+ others by signing up.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Mark Rogers
Director of Content Marketing
view All Posts
Featured Posts
Hipaa Compliance
Direct Response, Remarketing, and Programmatic Advertising: The HIPAA Pitfalls You Didn't Know
Hipaa Compliance
IP Addresses and HIPAA Compliance: Unpacking the Risks for Healthcare Websites
Use Cases
Don't Remove It! Make Google Analytics HIPAA Compliant Instead
Hipaa Compliance
Staying HIPAA-Compliant: How to Detect Web Tracking Risks on Your Website
Hipaa Compliance
A Privacy-First Framework for HIPAA Compliance: Managing Third-Party Tracking on Healthcare Websites
Hipaa Compliance
Cut the Jargon: A Look at the FTC-HHS Privacy Warning and What It Means For Your Healthcare Org
Use Cases
How To Make Facebook Ads HIPAA Compliant and Still Get Conversion Tracking
Use Cases
What HHS Has to Say About Tracking Technologies in Latest HIPAA Guidance
Growth & Startups
Two Chairs Journey to a HIPAA Compliant Growth Stack
Stay Connected
Platform
Improve Marketing Performance
Audiences
Healthcare Integrations
Measure Marketing Impact
Insights
Ad Performance
Protect Privacy & Compliance
Web Tracker Manager
Consent Management
Event Tracking
Healthcare solutions
Hospitals & Health Systems
Health Tech & Virtual Care
Payers & Health Plans
Urgent Care & Outpatient
Dental & Specialty Practices
Pharma & Medical Devices
DSO (Dental Support Organizations)
Orthopedics
Specialty Providers
Resources
FAQ
Blog
Events & Webinars
Marketing Hub
Privacy Hub
Newsletter Signup
About
About Us & Careers
News & Press
Plans & Pricing
Contact Us
Get a Demo
Case Studies
Customers
Login
System Status
Docs
Follow Us
Privacy Policy
Terms of Service
© 2025 Perfalytics, Inc. Crafted in San Francisco - Site By Takeoff®