HHS Releases Bulletin on Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
Time 1 Minute Read

On December 1, 2022, the Office for Civil Rights at the U.S. Department of Health and Human Services (“HHS”) released a Bulletin on the obligations of HIPAA covered entities and business associates under the HIPAA Privacy, Security, and Breach Notification Rules when using online tracking technologies. 

In the Bulletin, HHS warned, for example, that some HIPAA-regulated entities may be sharing electronic protected health information (“PHI”) with online tracking technology vendors in violation of the HIPAA Privacy Rule. Tracking technologies used by regulated entities may have access to PHI, such as an individual’s IP address, medical record number, home or email address, appointment dates, diagnosis and treatment information, prescription information and billing information. According to HHS, some regulated entities may routinely share PHI with tracking technology vendors through mobile apps and webpages.

The Bulletin notes that compliance with the HIPAA Privacy, Security and Breach Notification Rules when using tracking technologies requires, for example, providing appropriate notification in case of a breach, implementing technological and administrative safeguards, ensuring that vendors can access only the minimum PHI necessary for their services, and establishing a Business Associate Agreement with tracking technology vendors that qualify as “business associates” under HIPAA.

You May Also Be Interested In

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Time 2 Minute Read

The New York Office of the Attorney General recently reached a $500,000 settlement with a New York orthopedics practice for allegedly failing to protect patient and employee information in light of a 2023 data breach.

Time 2 Minute Read

On September 30, 2025, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a settlement with five affiliated health care providers collectively known as Cadia Healthcare Facilities for potential violations of the HIPAA Privacy and Breach Notification Rules.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page