Website Tracking Risk
OCR guidance has clarified that standard marketing and analytics tools deployed on healthcare websites may capture PHI through URL parameters, form submissions, and behavioral data linked to health conditions. Organizations should review all tracking deployments on patient-facing web properties.
Watchlist Stats
Who Should Review
Marketing directors, compliance officers, legal counsel, and web technology teams.
Why This Watchlist Matters
Marketing pixels on appointment pages may capture health-related intent as PHI.
Call tracking tools may record patient conversations without proper consent or BAA.
Website analytics tools can collect IP addresses correlated with health conditions.
Session replay and heatmap tools capture form field entries that may include PHI.
Vendor Table — 17 of 17 vendors
| Vendor | Category | BAA Status | Approval Tier | PHI Risk | AI Risk | Last Verified |
|---|---|---|---|---|---|---|
| HubSpot AI | Marketing Automation | Restricted / Review Required | 2026-09-30 | |||
| Dialpad Healthcare | Phones & Call Tracking | Verify Directly | Conditional / Verify BAA | High | High | 2026-09-30 |
| GoTo Connect Healthcare | Phones & Call Tracking | Verify Directly | Conditional / Verify BAA | High | Low | 2026-09-30 |
| RingCentral for Healthcare | Phones & Call Tracking | Verify Directly | Conditional / Verify BAA | High | Medium | 2026-10-01 |
| Mango Voice | Phones & Call Tracking | Verify Directly | Conditional / Verify BAA | High | Low | — |
| Klaviyo | Marketing Automation | BAA Not Found | Not Recommended | High | High | 2026-09-30 |
| HubSpot Healthcare | Marketing Automation | BAA Not Found | Not Recommended | High | High | 2026-09-30 |
| ActiveCampaign Healthcare | Marketing Automation | Verify Directly | Conditional / Verify BAA | High | Medium | 2026-09-15 |
| Act-On | Marketing Automation | Verify Directly | Conditional / Verify BAA | High | Medium | 2026-05-21 |
| 8x8 Healthcare | Phones & Call Tracking | Verify Directly | Conditional / Verify BAA | High | High | 2026-09-30 |
| Ruler Analytics | Analytics & Tracking | Verify Directly | Restricted / Review Required | High | Low | 2026-05-22 |
| Genesys Cloud CX | Phones & Call Tracking | Verify Directly | Approved With Restrictions | High | High | 2026-05-22 |
| Piwik PRO | Analytics & Tracking | Verify Directly | Approved With Restrictions | Medium | Low | 2026-05-22 |
| CallTrackingMetrics | Phones & Call Tracking | Verify Directly | Approved With Restrictions | High | Medium | 2026-05-22 |
| Five9 | Phones & Call Tracking | Verify Directly | Approved With Restrictions | High | High | 2026-05-22 |
| Demandforce | Marketing Automation | Verify Directly | Conditional / Verify BAA | High | Low | 2026-05-21 |
| Birdeye | Marketing Automation | Verify Directly | Approved With Restrictions | High | Medium | 2026-05-22 |
Recommended Actions
Verify BAA before PHI use
Contact the vendor to confirm current BAA terms and scope before processing any PHI.
Restrict PHI entry
Implement technical or administrative controls to prevent PHI from entering unapproved systems.
Require legal review
Engage legal counsel to review data processing agreements and contract terms.
Require security review
Conduct a security assessment before deployment in PHI-adjacent workflows.
Disable tracking where needed
Remove or reconfigure tracking pixels and analytics tools on pages where PHI may be present.
Document consent workflow
Establish and document patient or staff consent processes for relevant data collection.
Review configuration settings
Verify that vendor configuration meets HIPAA requirements for your specific deployment.
Train staff before approval
Provide governance and usage training before allowing staff access to the vendor platform.
Add to internal monitoring
Include this vendor in your organization's recurring vendor risk review cycle.
Governance Checklist
Identify PHI exposure paths for this vendor category
Confirm BAA availability with the vendor directly
Review vendor contract terms and data processing agreements
Review data retention and deletion settings
Review AI training data usage clauses
Review user access controls and audit logging
Document approved use cases and restrictions
Train staff on usage restrictions before deployment
Set a recurring review date based on risk classification
Related Intelligence
Vendor Registry
Browse the full VNDRIQ healthcare vendor registry.
Compare Vendors
Side-by-side comparison of any two vendors.
Benchmark Reports
Executive benchmark reports for healthcare vendor risk.
All Watchlists
View all VNDRIQ vendor risk watchlists.
Analytics & Tracking Category
Compare all Analytics & Tracking vendors.
Website Forms Category
Compare all Website Forms vendors.
Phones & Call Tracking Category
Compare all Phones & Call Tracking vendors.
Marketing Automation Category
Compare all Marketing Automation vendors.
Frequently Asked Questions
Not necessarily — but standard configurations of many analytics tools on healthcare websites may create HIPAA exposure. OCR has issued guidance on tracking technologies. Each deployment should be evaluated against your specific web properties and patient data flows.
VNDRIQ watchlists are based on available public information and internal review. Being on a watchlist does not mean a vendor is unsafe — it means active governance attention is recommended. This is not legal or compliance advice. Verify vendor BAA status and HIPAA program scope directly with each vendor.