Phelps Dunbar LLP Logo
  • Services
  • Insights
  • Professionals
Phelps Dunbar LLP Logo
  • Services
  • Insights
  • Professionals
  • ABOUT US
  • LOCATIONS
  • SUSTAINABILITY
  • CAREERS
  • Practices
  • Industries

    How Health Care Companies Can Use AI Website Tracking While Protecting Patient Data

    July 22, 2026

    Analytics drive decisions. Website tracking technologies collect user information, giving health care companies data to improve patient engagement and marketing effectiveness, optimize scheduling and communications, and make websites and mobile applications more user-friendly. But these tools can also collect sensitive information about users, including health conditions, treatment interests, provider relationships and care needs.

    The rising emphasis on consumer privacy has increased scrutiny on these tools and the organizations that use them. While the health care industry reassesses the use of pixels, cookies, session replay tools, and other website tracking technologies, AI-powered analytics tools are becoming more common. These AI-powered tools may collect, combine and infer health-related information at large volumes and without human oversight, increasing regulatory enforcement and litigation risk.

    Before using AI-powered tracking technologies, organizations need to understand what the tools collect, what can be inferred from that data, who receives it, and how AI-enabled vendors may use it after collection.

    Tracking Technologies and the Data Collected

    “Tracking technologies” can be code, scripts or images. They’re embedded in the websites, emails and mobile applications patients use to interact with health care organizations. They collect information that organizations can store and analyze. Cookies, pixels, web beacons, session replay tools, third-party analytics and advertising tools are common types of tracking technologies.  

    Tracking technologies are powerful.  They provide information on:

      • User behavior. They track clicks, searches, login status, pages viewed, time spent on each page, and even which sections of pages users viewed.
      • User preferences. When users specify location, language, payment information and account information, tracking technologies can track their preferences even if the tool itself does not store the information.
      • Website traffic. These tools store user’s IP addresses, device identifiers, geolocation, website referral sources, and the websites they viewed after leaving the operator’s website.
      • Conversions. They can track whether a user scheduled an appointment, submitted a form or requested information after engaging with an advertisement.
      • Raw data. These tools capture form entries and responses to chat tools and embedded widgets.

    The use of tracking technologies attracts scrutiny because the information collected may constitute personal information, protected health information (PHI) or consumer health data. And when transferred to a third party, organizations could be responsible for the disclosure of this information.

    The risk is not limited to the raw data collected. Regulators and plaintiffs may also scrutinize what can be inferred from the content of the webpages visited, searches performed, forms completed, or actions taken by the user.

    Current Legal and Regulatory Issues: HIPAA, the FTC and State Privacy Laws

    OCR Guidance on Use of Tracking Technologies

    Since 2022, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) has maintained that when certain information is disclosed through tracking technologies, it constitutes a disclosure of PHI, which then requires compliance with HIPAA.

    A 2024 legal challenge confirmed the guidance did not apply to tracking IP addresses on certain unauthenticated webpages, but the bulk of the guidance remains in place. Health care organizations must still comply with OCR’s guidance for authenticated webpages, some unauthenticated webpages, patient portals, mobile applications, and when tracking technologies collect, store or transfer data that qualifies as PHI to a third party.

    OCR coordinates enforcement of its guidance with the Federal Trade Commission (FTC), including sending joint enforcement letters.

    FTC Health Breach Notification Rule

    Even health care companies not regulated by HIPAA face increased regulatory attention under the FTC Health Breach Notification Rule. The rule expressly covers health apps and connected devices that are not subject to HIPAA.

    According to the FTC, a “breach” doesn’t just include cybersecurity incidents. Even if the disclosure was authorized by the organization, the FTC could view it as a breach if it was not authorized by consumers or is inconsistent with notices supplied to consumers. The FTC has also indicated that the use of tracking technologies may violate the Health Breach Notification Rule.

    State Data Protection Laws

    State privacy laws add another layer of risk. Twenty-three states now have comprehensive data protection laws on the books, and 19 have already taken effect. Many states exempt HIPAA-regulated entities, but non-HIPAA regulated entities may face actions from state attorneys general for failing to provide appropriate notices, obtain required consents, or honor opt-outs of targeted advertising and sales of personal data.

    Wiretapping and Eavesdropping Litigation

    Private litigation has exploded in recent years under state and federal wiretapping laws that allow for private rights of action. Claims for violations of the California Invasion of Privacy Act (CIPA) are the most common, but claims for violations under similar state statutes, such as in Florida and Pennsylvania, and the federal Electronic Communications Privacy Act, along with common law causes of action, have also been brought.

    Plaintiffs have had success alleging that the firing of a tracking technology constitutes unlawful “interception” of a communication between the website operator and the user.  These claims have survived motions to dismiss in some cases and are often brought as potential class actions.

    The volume of these actions led California lawmakers to draft legislation to curb these types of private actions with respect to websites. A vote is expected on the bill by the end of August.

    AI-Powered Analytics Raise the Stakes

    AI-powered tools could magnify these risks. AI-powered tools are built to consume, connect and learn from larger and more varied data sets than traditional tracking technologies.

    They may also draw sensitive inferences from data points that appear less sensitive when viewed in isolation. And as new tools hit the market, they could capture or use PHI in ways not yet anticipated. For health care organizations and digital health companies, this could increase legal risk, which often turns not only on what data is collected, but also on what the data reveals or reasonably implies about an individual.  

    AI-enabled tools may also make data-flow mapping and vendor oversight more difficult. The ability to infer PHI from fewer clicks or website interactions could change the point at which an impermissible disclosure occurs. The use of AI-powered tracking tools for automated decision-making could require additional disclosures, consents and audit trails. Organizations should understand how each AI-enabled tool and vendor uses collected data. They should also assess whether the tool can infer health status, treatment interest, condition-specific browsing behavior, or other sensitive attributes. Health care organizations may need to update vendor contract provisions, business associate agreements, data protection assessments, and governance controls before deploying these tools, since the use of AI-powered tools is likely to increase regulatory oversight in the digital ecosystem.

    Key Takeaways for Health Care Organizations

    The regulatory and litigation environment for tracking technologies in health care continues to evolve. AI-powered analytics will likely intensify the need for disciplined governance. Now is the time to understand the data flows and third-party partners managing those data flows. To manage the risks associated with the use of tracking technologies, health care organizations should:

      • Inventory all tracking technologies, analytics tools, chat tools, pixels, cookies, session replay tools, advertising technologies and AI-enabled digital tools.
      • Map what data is collected, where it is transmitted, who receives it, and whether it may constitute PHI, consumer health data, sensitive personal information, or other regulated data.
      • Confirm that privacy notices, cookie banners, consent mechanisms and opt-out tools accurately describe actual data practices.
      • Avoid firing non-essential tracking technologies before required consent has been obtained and document consent.
      • Review vendor contracts, including Business Associate Agreements, for data use, model training, product improvement, subcontracting, security, breach notification, audit rights, and data retention obligations.
      • Reassess tracking technologies before deploying AI-enabled personalization, chatbots, automated decision-making, or new digital health products.

    Health care companies should also consider conducting an annual review of their digital ecosystems to identify risks before they become regulatory, litigation or incident response issues.

    AI-powered analytics should not be treated as just another website tool. Before deploying or expanding these technologies, organizations should understand the data being collected, the inferences that may be drawn from that data, and the contractual, consent and governance controls needed to manage that risk.

    Contact Lucy Porter, Douglas Wolford or any member of Phelps cybersecurity, privacy and data protection, health care or artificial intelligence teams with questions or for compliance advice and guidance.

    Related Professionals

    -
    Lucy Porter

    Lucy Porter

    Email

    Douglas Wolford

    Douglas Wolford

    Email

    Related Practices

    • Cybersecurity, Privacy and Data Protection
    • Health Care

    Related Industries

    • Artificial Intelligence (AI)
    • Health Care
    Stay connectedReceive our latest thinking on topics you care about.SIGN UP NOW
    • ©2026 Phelps Dunbar LLP. All Rights Reserved
    • Lawyer Advertising
    • Privacy & Disclaimer
    • Contact Us
    © 2026 Phelps Dunbar LLP. All Rights Reserved