The US Department of Health and Human Services Office for Civil Rights (OCR) has today issued a bulletin on the use of online tracking technologies by organisations regulated under HIPAA.
Key points
- Tracking pixels, cookies, session replay and similar tools on websites and apps can collect protected health information (PHI).
- Disclosing PHI to tracking vendors for marketing without authorisation may breach the HIPAA Privacy Rule.
- Vendors that receive PHI through tracking tools may be business associates, requiring a business associate agreement.
- Impermissible disclosures may need to be treated as reportable breaches.
The bulletin has fuelled enforcement and class action litigation over website tracking in the US. UK providers of analytics, marketing or web services to US healthcare customers should review what data their tools collect and how it is shared.
Source: Use of Online Tracking Technologies by HIPAA Covered Entities (HHS)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.