Is Google Analytics HIPAA Compliant? The 2026 Answer for Healthcare Marketers
Google Analytics is not HIPAA compliant. Google does not offer a Business Associate Agreement (BAA) for Google Analytics 4, which means any protected health information (PHI) transmitted to Google's servers from your healthcare site constitutes an unauthorized disclosure under HIPAA. Two root problems drive this verdict: Google refuses to sign a BAA for GA4, and the platform collects PHI by default on any healthcare website regardless of how it is configured.
The short answer (and why it is not that simple)
So is Google Analytics HIPAA compliant? No. But the clear verdict sits on top of a layered problem most healthcare marketers underestimate.
Most websites run Google Analytics without legal concern. Healthcare sites cannot, because the data GA4 captures on a medical clinic or telehealth platform automatically becomes PHI under federal law. The same IP address that is anonymous on a retail site becomes a health record when it appears alongside a URL like /weight-loss-consultation. No configuration option eliminates that risk entirely, because Google still processes the data and will not sign a BAA.

What PHI does Google Analytics actually collect?
GA4 collects more data than its predecessor ever did, and on healthcare sites, much of that data qualifies as protected health information. The platform's event-driven model means every user interaction generates a data record, not just pageviews.
GA4 PHI signal types on healthcare sites:
- IP addresses are automatically collected and logged against every session, regardless of regional settings
- Full URL paths containing condition or diagnosis keywords, such as
/std-testingor/glp1-weight-loss-program, link device identifiers to implied health status - UTM parameters passed from ad platforms carry condition names, campaign themes, or treatment categories embedded in the click URL
- Form-field event data fires when patients start or submit appointment request and intake forms, attaching interaction timestamps to health-service pages
- Audience segment labels built from health-related page visit patterns feed directly into Google Ads targeting pipelines via the GA4 Audiences API
IP addresses, URL paths, and UTM parameters
HIPAA's definition of PHI requires only that data relate to an individual's health condition and be individually identifiable. A patient's IP address combined with a URL path like /testosterone-therapy-consultation meets that threshold without a name, email, or any explicit identifier anywhere in the session.
UTM parameters extend the exposure further. A campaign tag like utm_content=glp1-weight-loss-program arrives from a paid click pre-loaded with health condition context. GA4 stores it alongside the session record. The ad platform and the analytics tool now both hold data linking a specific device to a health condition category, PHI entering two systems, one of which has no BAA.
Event data that becomes PHI in healthcare context
GA4's enhanced measurement fires events automatically: scroll depth, form interactions, video views. On a general website, these are routine analytics signals. On a page about a specific medical treatment or appointment category, every one of those events links behavioral data to implied health status at scale.
A scroll-depth event on /addiction-treatment-options tells Google that a specific device engaged with that page. GA4 accumulates these signals into audience profiles across sessions and devices. Those profiles feed ad campaigns via server-to-server connections. The PHI exposure is not an edge case, it is built into GA4's core architecture.
Does Google sign a BAA for Google Analytics?
Is Google Analytics HIPAA Compliant Without a BAA?
No. Google does not offer a Business Associate Agreement for Google Analytics or GA4. Google's product terms exclude GA4 from its HIPAA-covered services, and the company has not indicated any plans to change that position.
Determining whether Google Analytics is HIPAA compliant requires answering this question first, because a BAA is not optional under HIPAA. Any vendor that handles PHI on behalf of a covered entity must sign one. Without a BAA, transmitting PHI to Google via GA4 is an impermissible disclosure regardless of any other data processing agreements in place.
A Data Processing Agreement, which Google offers for some products, covers GDPR-style lawful processing requirements under EU law. It does not create HIPAA obligations for the vendor, does not restrict how Google uses the data internally, and has not been accepted by regulators as a BAA substitute in any enforcement context.

What changed with GA4, new risks healthcare marketers miss
Most existing content on this topic was written for Universal Analytics, which Google retired in July 2023. GA4's architecture creates PHI surfaces that UA never had. Healthcare marketers who migrated and assumed the risk profile stayed similar are working from an outdated picture.
Three GA4 changes expand the exposure significantly. The event-driven data model logs every user interaction with attached parameters rather than a simple pageview, generating more potential PHI per session. Cross-device identity linking uses Google signals and user IDs to stitch sessions across devices, increasing the specificity of health-condition associations per individual. The Audiences API shares segment data with Google Ads via server-to-server connections, meaning behavioral segments built from condition-specific pages can flow into ad targeting pipelines without any manual export step. Universal Analytics had none of these integrations at the same depth.
Does Consent Mode v2 make GA HIPAA compliant?
No. Consent Mode v2 is a consent-signaling framework that tells Google whether a user has accepted or declined cookies. It enables behavioral modeling for cookieless traffic and helps recover conversion data under GDPR consent requirements in the EU. It has no functional relationship with HIPAA.
When a user on a healthcare site accepts cookies, Consent Mode v2 does not change what GA4 collects. The IP address, URL path, and behavioral events all transmit to Google's servers. Consent Mode v2 only changes what happens when a user declines. For consenting users, the full PHI exposure remains unchanged.
User consent does not replace a BAA. HIPAA does not permit covered entities to waive compliance obligations by obtaining patient consent to share data with a vendor that has not signed a BAA. Consent mode manages cookie behavior. HIPAA governs vendor agreements. The two operate on different legal planes, and conflating them is a common mistake that creates documented enforcement exposure.
A thorough data-flow review for HIPAA-sensitive websites covers the full tracking path from browser to analytics platform to ad network, going well beyond what a consent banner configuration addresses.

Real enforcement: what fines look like for GA and healthcare sites
OCR investigations into website tracking
The HHS Office for Civil Rights issued a bulletin in December 2022 (HHS OCR, December 2022) stating explicitly that tracking technologies transmitting PHI to third parties without a BAA constitute impermissible disclosures. OCR has since opened formal investigations into covered entities using pixels and analytics tools on patient-facing pages.
OCR has settled cases involving website tracking at six- and seven-figure amounts. The enforcement pattern shows OCR treats analytics-related PHI disclosures with the same weight as data breaches. The unauthorized disclosure is the violation, not whether the data was subsequently misused. Healthcare organizations that asked "Is Google Analytics HIPAA compliant?" and kept GA4 running without a BAA had already committed the impermissible disclosure OCR investigates, the harm does not need to materialize for the violation to be real.
FTC actions against health data sharing
The FTC has pursued enforcement against health data sharing with ad platforms under Section 5 of the FTC Act, running independently of HIPAA. In 2023, the FTC settled with GoodRx for sharing prescription-related data with Google and Meta, resulting in a $1.5 million civil penalty and operational restrictions. BetterHelp settled for $7.8 million over sharing mental health intake data with ad platforms. Both involved data-sharing practices that GA4 enables by default on healthcare sites.
This enforcement track extends beyond covered entities. A telehealth startup that falls outside HIPAA's covered-entity definition is still exposed to FTC Section 5 action for sharing health-related behavioral data with ad platforms. The two agencies run parallel enforcement tracks, and neither one waits for the other.
The data-sharing practices that push health signals into ad platforms also create ad policy enforcement risk from Google itself, the compliance violation and the campaign disruption come from the same underlying behavior.
If your site is running GA4 without a compliance-reviewed tracking stack, the enforcement record above is reason enough to book a tracking audit before the next campaign goes live.
Your options: keep, configure, or replace GA?
When healthcare teams confirm for themselves that the answer to "Is Google Analytics HIPAA compliant?" is a firm no, the decision tree forks into three directions: restrict GA4 to non-PHI pages, replace it with a BAA-covered tool, or build a hybrid architecture that does both.
| Tool | BAA available | Data residency | GA4 feature parity | Ad platform integration | Entry cost |
|---|---|---|---|---|---|
| GA4 | No | Google-controlled (US/EU) | Native | Native | Free |
| Piwik PRO | Yes | EU, US, private cloud, on-premise | High | Via Piwik PRO integrations | Free tier + paid plans |
| Freshpaint | Yes | US, configurable routing | High | Native GA4-compatible pipeline | Mid-market |
| Server-side GTM | No (GA4 still processes data) | Partial (server you control) | Native GA4 backend | Via connectors | Infrastructure + dev cost |
No current top-ranking article on this query includes a direct tool comparison. The table above reflects the four configurations most commonly evaluated by healthcare marketing teams when deciding what to do after confirming that Google Analytics is not HIPAA compliant.
Option 1: server-side GTM (mitigation, not compliance)
Server-side Google Tag Manager moves tag execution from the browser to a server you control. This lets you strip certain identifiers, specifically IP addresses and some cookie fields, before forwarding data to GA4. It reduces what reaches Google. It does not stop Google from processing what does arrive.
Google still will not sign a BAA for GA4 regardless of how the data is routed. Server-side GTM is a risk-reduction engineering control, not a compliance solution. Healthcare organizations that position it as HIPAA compliance are making a claim the tool cannot support, and that gap creates its own liability if OCR investigates the full data flow.
Option 2: HIPAA-compliant analytics alternatives with a BAA
Piwik PRO and Freshpaint both offer Business Associate Agreements for healthcare organizations. Evaluation criteria beyond BAA availability include data residency (where behavioral data is stored and under what jurisdiction), self-hosting options (Piwik PRO supports on-premise deployment; Freshpaint offers cloud-hosted configurable data routing), and conversion tracking parity for Google Ads campaigns.
Neither tool replicates every GA4 feature. Both cover the core use cases for healthcare performance marketing: session analytics, conversion tracking, and ad platform attribution. For organizations running patient acquisition at telehealth scale, rebuilding the event schema in a compliant tool is an upfront investment that eliminates the regulatory exposure from the first session forward.
Option 3: hybrid stack for healthcare marketers
A hybrid architecture keeps a restricted GA4 instance on non-PHI surfaces, blog content, general marketing pages, service pages with no health-condition context, while running a HIPAA-compliant analytics tool on all patient-facing surfaces: booking pages, intake forms, and condition-specific landing pages.
This approach suits organizations that need GA4's audience tools for top-of-funnel paid media while isolating PHI-adjacent conversion data in a compliant system. The governance requirement is strict. Every page needs a documented classification, and that classification must be reviewed regularly because websites change and new pages drift into the wrong bucket. Without ongoing governance, the hybrid model collapses the moment an appointment page ends up under GA4 coverage.
Fix your tracking before the next ad dollar goes in
Healthcare marketers running GA4 without a compliance-reviewed tracking setup are building patient acquisition spend on top of unmitigated legal exposure. Every campaign dollar driving traffic to a GA4-instrumented appointment page adds to the risk surface. The enforcement cases above show what OCR and the FTC do when they examine that data trail.
The starting point is a tracking audit: map every data flow from browser to analytics tool to ad platform, identify which pages create PHI linkage, and design a compliant architecture before resuming scale. A compliant tracking stack is not only a risk control, it is the measurement foundation that makes it possible to identify what drives patient acquisition and scale it with confidence. Webugol builds tracking-first acquisition systems for US healthcare providers, clinics, telehealth platforms, and high-ticket specialty practices, where compliant measurement is the foundation of every campaign decision. Book a Strategy Call to identify where your current stack creates exposure and what a defensible architecture looks like.
FAQ
Does Google Analytics sign a BAA for healthcare?
No. Google does not offer a Business Associate Agreement for Google Analytics or GA4. Without a BAA, transmitting PHI to Google via GA4 constitutes an impermissible disclosure to a business associate under HIPAA.
What PHI does Google Analytics collect from healthcare websites?
GA4 collects IP addresses, full URL paths, UTM parameters, and behavioral event data. On healthcare sites, these signals combine with page context to constitute PHI, no name or email address is required for the data to qualify under HIPAA's definition.
Is GA4 HIPAA compliant if I enable Consent Mode v2?
No. Consent Mode v2 manages cookie consent signals and enables behavioral modeling for cookieless users. It does not stop PHI from reaching Google's servers for consenting users, and it does not substitute for a BAA, which Google does not offer for GA4.
What are the HIPAA fines for using Google Analytics on a healthcare site?
OCR has settled cases involving website tracking at six- and seven-figure amounts, following its December 2022 bulletin on tracking technologies. FTC enforcement under Section 5 adds a separate liability track for health data shared with ad platforms, independent of HIPAA fines from OCR.
What analytics tools are HIPAA compliant and offer a BAA?
Piwik PRO, Freshpaint, and select server-side analytics providers offer Business Associate Agreements for healthcare organizations. Evaluate each for data residency options, GA4 feature parity, and the specific scope of the BAA before switching your tracking stack.

