Personalized remarketing based on health conditions is disallowed under Google’s advertising policy and risky under HIPAA, even when a platform’s tools technically let you build the audience. The safe path is non-personalized and contextual targeting, predefined audience categories, and an immediate audit of every tag sitting on a page tied to symptoms, conditions, or appointments. Before you touch campaign settings, stop sending any protected health information to ad pixels and separate your health intake forms from pages carrying tracking code.
TL;DR:
- Using remarketing lists based on health conditions violates Google’s policies and risks HIPAA breaches, requiring non-personalized, contextual targeting instead.
- Tracking pixels on appointment or symptom pages can disclose protected health information and must be removed or moved to server-side tracking to ensure compliance.
- Audience segmentation should be based on content context or predefined categories, not individual visit data that links to health conditions, to avoid triggering sensitive category restrictions.
- Ensuring vendor agreements include signed BAAs and proper data de-identification minimizes legal risks and industry penalties related to PHI disclosures.
- Conducting a quick audit of website pages, vendor relationships, audience settings, and implementing cookieless measurement methods can identify and reduce your account’s compliance exposure.
Table of Contents
- How platform policies and HIPAA intersect to restrict healthcare remarketing
- Personalized vs non-personalized advertising: how to classify your audiences
- Technical controls and account architecture that reduce PHI exposure
- Compliant audience strategies and alternatives to traditional remarketing
- HIPAA and legal checklist: documentation and permissions you must have
- Common mistakes that get accounts flagged and the single best fix for each
- Step-by-step compliance audit you can run this week
- Agency perspective: lessons from implementing compliant healthcare ad programs
- How AdJet Marketing can help: compliant audits, cookieless setups, and managed campaigns
- Primary source documents and policy pages
- Sources
- FAQ
How platform policies and HIPAA intersect to restrict healthcare remarketing
Two separate rule sets govern what you can do here, and they don’t always speak the same language. One is legal: HIPAA governs how covered entities and their vendors handle protected health information (PHI). The other is contractual: Google, Meta, and other ad platforms set their own policies about what data can fuel personalized advertising, regardless of whether HIPAA technically applies to your practice.
HHS guidance on online tracking technologies makes the legal exposure explicit: when a tracking pixel captures data tied to an identifiable person and a health context, such as a visit to an appointment page for a specific condition, that transmission can count as a disclosure of PHI. Sending that data to a vendor like Google or Meta without a business associate agreement (BAA) or valid authorization can be an impermissible disclosure, and a cookie banner alone does not satisfy HIPAA’s authorization requirements. A related OCR bulletin walks through concrete examples, including appointment scheduling pages, where tracking technology created exactly this kind of exposure.
Google’s own policy closes the loop from the other direction. Under Google’s personalized advertising rules, advertiser-curated audiences, meaning remarketing lists, customer match uploads, and similar user-level targeting, are barred for content that falls into the Health sensitive interest category. Google allows predefined audiences here because those categories are built without sensitive signals attached to individual users. The two rule sets reinforce each other: even if you had a signed BAA and valid patient authorization, Google’s policy would still block personalized targeting for many health-related campaigns.
Enforcement risk runs on two tracks:
- Platform-side: account suspensions, ad disapprovals, or policy strikes when Google or Meta detects advertiser-curated audiences on sensitive-category content.
- Legal-side: civil monetary penalties from OCR, breach notification obligations, and increasingly, private litigation under state privacy statutes.
Unauthorized disclosure of PHI to a tracking vendor may trigger civil money penalties, according to HHS, and a website’s cookie consent banner does not substitute for HIPAA-compliant authorization. That single fact should reset how most practices think about their existing tag setup.
Meta’s advertising policies for sensitive categories operate on similar logic to Google’s, restricting granular health-based targeting even where the underlying data never technically qualifies as PHI. Programmatic display networks vary more widely in enforcement consistency, which is part of why many practices treat them as higher risk rather than lower.
Personalized vs non-personalized advertising: how to classify your audiences
The difference between what’s allowed and what gets your account flagged usually comes down to one question: where did the targeting signal come from, and does it tie back to an individual’s health status?
Personalized advertising relies on advertiser-curated audiences: remarketing lists built from your site visitors, customer match lists uploaded from your patient database, or lookalike audiences modeled on either. When any of these audiences are built from visits to health-specific pages, condition-related content, or appointment forms, they fall under Google’s Health sensitive interest restrictions.
Non-personalized advertising includes contextual targeting (placing ads based on the content of a page, not the identity of the viewer) and predefined audience categories that Google builds without individual-level health signals.
Use this sequence to classify what you’re currently running:
- Identify the audience source. Was it built from your own tag data (advertiser-curated) or from Google’s own predefined categories?
- Check what pages fed the tag. If the remarketing pixel fired on a symptom page, a condition-specific landing page, or a booking confirmation, the audience is tainted regardless of platform.
- Confirm the targeting method. Contextual keyword targeting and content-based placement carry no personalization risk because they never touch user identity.
- Test for PHI leakage. If form fields, URL parameters, or page titles reveal a health condition and that data reaches the ad platform, you have a compliance problem independent of the targeting method.
- Verify with platform tools. Google’s Ads interface flags sensitive category classifications at the campaign level; if your account has been auto-tagged as Health, treat every existing audience list as suspect until reviewed.
A compliant setup looks like: a contextual campaign served against searches for “physical therapy near me,” with no remarketing list attached. A non-compliant setup looks like: a remarketing list built from visitors to a page titled “Manage Your Diabetes with Our Clinic,” even if that list is anonymized in your own database, because Google’s policy blocks the practice at the category level, not just the identifiability level.
Technical controls and account architecture that reduce PHI exposure
Once you know which audiences and pages are the problem, the fix is mostly architectural. You’re rerouting data flow so that sensitive pages never hand identifiable information to an ad vendor in the first place.
Start with tagging:
- Move pixels off PHI-bearing pages. Appointment confirmation pages, symptom checkers, and intake forms should not carry the same remarketing pixel as your general services pages.
- Use server-side tracking where possible. Routing conversion data through a server, rather than firing client-side pixels directly from the browser, gives you a control point to strip identifiable fields before anything reaches an ad platform.
- De-identify before you send. If you need conversion data for optimization, send an anonymized event (a form submitted) rather than a value tied to a name, email, or condition.
- Separate domains or accounts for sensitive services. A pain management clinic running both general orthopedic content and a chronic pain treatment program might split these onto different subdomains or ad accounts, so a policy flag on one doesn’t disable remarketing capability for the other. Our guide to Meta Pixel and HIPAA walks through what this looks like in practice for Meta specifically.
On the vendor side, any analytics or advertising vendor that touches PHI needs a signed BAA, and you should document exactly what “permitted use” means in that agreement, since minimum-necessary standards apply here just as they do to clinical data sharing. Our breakdown of how to protect PHI in marketing workflows covers the vendor due diligence questions worth asking before you sign anything.
Cookieless tactics fill the gap left by restricted remarketing: contextual targeting, Google’s Consent Mode, offline conversion imports, and de-identified data flows through a customer data platform. Our piece on cookieless remarketing tactics covers implementation patterns for each.

Pro Tip: Before splitting a domain or account, map which conversion actions currently feed your Smart Bidding models. Do this too fast and you can lose weeks of optimization data.
Compliant audience strategies and alternatives to traditional remarketing
Losing remarketing lists doesn’t mean losing performance. It means shifting where the intelligence in your targeting lives, from user identity to page context and aggregate signals.
Start with contextual keyword targeting and site-context retargeting as your default. These place ads based on what a page is about, not who visited it previously, so they sidestep the personalization restriction entirely while still reaching people actively researching your services.
Predefined Google audiences are the next layer. Google builds these categories without attaching individual-level health signals, which is exactly why they remain usable where advertiser-curated lists are not. The constraint is that you can’t customize them the way you’d customize a remarketing list, so targeting precision is broader by design.
First-party data still has a role, just a narrower one:
- Patient email lists built with proper authorization language can support direct communication, though not necessarily ad-platform uploads.
- Non-sensitive signals, like general site engagement unrelated to specific conditions, can sometimes feed broader remarketing without triggering the Health category flag.
- Our guide to patient email marketing covers what consent language needs to say before a list is usable at all.
For measurement without user-level audiences:
- Import offline conversions tied to phone calls or booked appointments, using de-identified conversion values.
- Lean on Smart Bidding with aggregate conversion signals rather than individual remarketing lists to optimize spend.
- Track assisted conversions at the campaign level, not the user level, to understand which contextual placements are working.
This combination, contextual targeting plus predefined audiences plus offline conversion data, tends to recover most of the performance a practice loses when advertiser-curated remarketing goes away. Our Google Ads optimization tips for healthcare go deeper on structuring campaigns around these levers specifically.
HIPAA and legal checklist: documentation and permissions you must have
Most of what gets a practice into trouble isn’t a single bad decision. It’s the absence of a document that should have existed before a campaign launched.
Under HHS marketing guidance, most uses or disclosures of PHI for marketing purposes require the patient’s written authorization under 45 CFR 164.508. The exceptions are narrow: communications about treatment, case management, or the covered entity’s own health-related products or services, made face to face or as a low-value promotional item. Digital advertising to third-party platforms generally does not fall inside those exceptions.
Run through this before your next campaign goes live:
- Authorization language. Does your patient intake or website consent flow include HIPAA-compliant marketing authorization, not just a general cookie notice?
- BAA coverage. Is every vendor that could receive PHI, analytics tools, ad platforms, CDPs, covered under a signed business associate agreement?
- Minimum-necessary check. Are you sending only the data actually required for the marketing function, or is excess patient information riding along in the same payload?
- De-identification review. Where authorization isn’t in place, has the data been stripped of identifiers before it leaves your systems?
- Breach notification readiness. Do you have a documented process for what happens if a vendor disclosure is later found to be impermissible?
A cookie consent banner does not constitute valid HIPAA authorization, according to HHS, which is worth repeating because it’s the single most common misconception we run into with new clients.
Beyond HIPAA, state-level privacy statutes have become their own enforcement track. California’s Invasion of Privacy Act litigation shows that pixel placement can trigger costly private lawsuits even in cases where HIPAA itself might not directly apply.
Common mistakes that get accounts flagged and the single best fix for each
Most of the healthcare accounts we review share a small handful of recurring problems, not dozens of unique ones.
- Running pixels on appointment or checkout pages. This is the single most common cause of both policy flags and PHI exposure. The fix is to remove the client-side pixel from that page entirely, or move the conversion event to a server-side call that strips identifying fields before transmission.
- Uploading patient lists for customer match without authorization. This happens more than you’d expect, usually because a marketing team assumes an email list export is fair game once a patient has opted into general communications. Halt the upload immediately and review whether your authorization language actually covers advertising use, not just email newsletters.
- Mixing sensitive and non-sensitive services in one ad account. A medspa offering both cosmetic treatments and a weight-management program under one domain risks having the whole account classified under Google’s Health sensitive category, disabling remarketing for services that wouldn’t otherwise trigger it. Splitting the sensitive service onto its own domain or subdomain, with its own ad account, contains the restriction instead of letting it spread.
- Relying on fragile custom segments built from inferred health interest. Even without explicit condition data, audiences built around behavior that clearly signals a health interest, repeat visits to a specific treatment page, time spent on a symptom checklist, can still trip Google’s sensitive category detection. Replace these with contextual targeting or predefined audience categories that don’t carry that inference risk.
Search Engine Land’s coverage of the sensitive categories changes points to the same remediation path we recommend most often: split sensitive services onto separate domains or accounts, then lean on offline conversion tracking and Smart Bidding to recover the optimization signal that remarketing used to provide.
Step-by-step compliance audit you can run this week
You don’t need a six-month project to get a clear picture of your exposure. Four steps, run in order, will surface most of what matters.
- Inventory every page and tag. List each page with a marketing pixel and flag any that touch symptoms, conditions, appointments, or intake forms.
- Map vendor relationships. Confirm which vendors have signed BAAs and check whether their permitted-use language actually matches what you’re sending them.
- Review audience settings. Remove any advertiser-curated audience built from visits to a flagged page, and check whether your account is already classified under a sensitive category.
- Implement cookieless measurement and document the change. Switch flagged pages to server-side or de-identified tracking, and keep a written record of what changed and when, since that documentation matters if OCR or a platform ever asks.
Agency perspective: lessons from implementing compliant healthcare ad programs
Most clinics that come to us aren’t looking for a compliance lecture. They’re dealing with poor lead quality, a Google Ads suspension they don’t understand, or a sudden gap in their conversion data after a policy update. The compliance work usually starts as a side effect of solving one of those problems, not the original request.
There’s a real trade-off between targeting precision and safety, and it’s worth naming honestly. Contextual and predefined audiences will rarely match the efficiency of a well-built remarketing list. When a service is genuinely sensitive, chronic condition management, mental health, certain aesthetic procedures tied to medical history, we usually recommend leaning harder into SEO and content-first strategies rather than trying to squeeze performance out of restricted ad formats.
A typical remediation project runs 60 to 90 days: audit and tag cleanup in the first few weeks, campaign restructuring and cookieless setup in the middle stretch, then a monitoring period to confirm the account stabilizes.
— Felix
How AdJet Marketing can help: compliant audits, cookieless setups, and managed campaigns
Fixing tag architecture, splitting accounts, and rebuilding a campaign around contextual and predefined audiences is a lot to manage alongside running a practice. That’s the part where having a team that’s done this specifically for medical clinics and aesthetic practices saves you the trial and error.
Our Google Ads Services start with a tag and account audit, then move into remediation, campaign rebuild, and ongoing monitoring, so you’re not left guessing whether a fix actually worked after it’s live. We also build the landing page side of this equation: pages designed to convert without relying on the PHI-heavy tracking setups that got your account flagged in the first place, whether that’s a Custom Landing Page for a specific service line or a full Custom Branded Website rebuild.
A typical engagement moves through audit, remediation, launch, and monitoring, with clear checkpoints at each stage so you know what changed and why. If your account has already been flagged, or you’d rather have someone else own the technical cleanup, you can start with a Google Ads audit through AdJet Marketing and go from there.
Primary source documents and policy pages
For verification, the core documents behind this guidance are HHS’s online tracking bulletin, HHS marketing guidance under HIPAA, Google’s personalized advertising policy for health interests, and OCR’s December 2022 bulletin on tracking technology requirements.
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
Sources
- Hhs
- Health in personalized advertising – Advertising Policies Help
- Google Ads sensitive categories without remarketing — Search Engine Land
FAQ
What are the 5 P’s of healthcare marketing?
Healthcare marketing frameworks vary by source, and no single HHS or platform document defines a fixed “5 P’s” list for this industry. Practices generally still need to address product or service, price, place, promotion, and people, but treat any specific numbered framework as a general marketing model rather than a regulatory standard.
What are the 5 HIPAA rules?
HIPAA is commonly organized into the Privacy Rule, Security Rule, Breach Notification Rule, Enforcement Rule, and Omnibus Rule, though HHS itself doesn’t publish these as a numbered “5 rules” list. For marketing purposes, the Privacy Rule and its authorization requirements matter most.
Does HIPAA prohibit using PHI for marketing?
HIPAA doesn’t ban marketing outright, but it requires written authorization for most uses or disclosures of protected health information for marketing purposes. Narrow exceptions exist for treatment-related communications and a covered entity’s own services, but sending PHI to ad platforms generally falls outside those exceptions.
What are the 5 basic categories of healthcare regulatory policies?
There’s no single federal document that groups healthcare regulation into five fixed categories, so definitions vary by source. In the marketing context, the categories that matter most in practice are patient privacy (HIPAA), advertising truthfulness (FTC), platform policy compliance (Google and Meta), state privacy statutes, and professional licensing rules specific to your specialty.
Can I use Google Ads remarketing for a medical practice at all?
Yes, but not with advertiser-curated audiences tied to health-specific pages, since Google restricts personalized advertising for content in Health sensitive interest categories. Predefined audiences, contextual targeting, and offline conversion imports remain available alternatives that don’t trigger the same restriction.
Recommended
- How Do We Set Up Remarketing Without PHI Risk? → Cookieless Tactics That Work
- Fix HIPAA Gaps: BAA And EHR Checklist For U.S. Clinics’ Compliant Forms
- How To Comply With HIPAA Regulations In My Med Spa: HIPAA Hiccups? How To Stay Compliant And Confident
- Meta Pixel And HIPAA: What Healthcare Marketers Must Know



