Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Media
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Financial Services
    • Healthcare
    • Higher Education
    • Infrastructure
    • Manufacturing
    • Nonprofit Organizations
    • Real Estate
    • Sports & Stadiums
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • DEI Strategic Services

      Providing our clients with legal, strategic, and practical advice to make transformational changes in their organizations.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Alerts
    4. OCR updates guidance on the risks of using online tracking technologies

      Alerts

    Alert / Healthcare

    OCR updates guidance on the risks of using online tracking technologies

    March 20, 2024

    LinkedInX (Twitter)EmailCopy URL

    By Valerie Montague and Laurie Cohen Grace Connelly, a legal intern in Nixon Peabody’s Healthcare practice and a 2024 J.D. candidate at Loyola University Chicago School of Law and assisted with the preparation of this alert.

    The guidance clarifies compliant use of online tracking technologies by HIPAA-regulated entities, but reiterates OCR’s broad interpretation of what is considered PHI.

    What’s the impact?

    • Faced with widespread industry criticism and AHA legal action, OCR attempted to clarify prior guidance related to the scope of HIPAA-regulated information.
    • The updated guidance does not, however, provide a HIPAA-regulated entity with a workable solution to identify when users’ interactions with the entity’s website or app results in the provision of PHI.
    • The updated guidance reminds health plans, health care providers, and other HIPAA-regulated entities to evaluate how their organizations capture and share data through tracking technologies.

    DOWNLOAD

    PDF: OCR updates Guidance Tracking Technologies

    On March 18, 2024, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) updated its guidance regarding the use of online tracking technologies by Health Insurance Portability and Accountability Act (HIPAA) covered entities and business associates. OCR’s previous guidance, issued in December 2022, advised HIPAA-regulated entities not to share protected health information (PHI) with vendors of online tracking technologies, taking the expansive view that Internet protocol (IP) addresses and other information provided by their website (following user login) or mobile application (mobile app) users “generally is PHI,” even if the individual is not a patient of the organization. In November 2023, the American Hospital Association (AHA), supported by several health systems and state hospital associations, filed a lawsuit against HHS to bar enforcement of its tracking technologies guidance, arguing that the guidance seeks to regulate more than PHI.

    As we previously described, online tracking technologies are of concern for HIPAA-regulated organizations because these technologies could collect and disclose PHI to third-party tracking technology vendors. Often, the tracking technology vendors are not business associates of the HIPAA-regulated entities, and even if they are business associates, the vendors may collect and share data for marketing purposes, which would require written patient authorization. In addition to reemphasizing the risks of these arrangements, the updated guidance continues to take a broad view of what PHI is in relation to users interacting with the websites and apps of HIPAA-regulated entities.

    Clarifications in OCR’s updated guidance

    In the wake of the AHA lawsuit and other industry pushback, OCR’s updated guidance seeks to provide more clarity for HIPAA-regulated organizations regarding the data captured on websites and mobile apps. For entities with user-authenticated websites (those that require a user to log in), OCR states that any associated tracking technology will “generally have access to PHI,” referencing an example of an individual making an appointment for clinical care. If this user-authenticated site is using tracking technologies, the website might automatically transmit information regarding the appointment and the individual’s IP address to the tracking technologies vendor, which requires a business associate agreement (BAA) or HIPAA-compliant authorization.  OCR also views information collected by a HIPAA-regulated entity’s mobile app “generally” as PHI.

    For entities using unauthenticated websites (those that do not require a user to log in), OCR acknowledges that some identifying information captured by tracking technologies may not be PHI. However, OCR continues to caution that PHI captured on an unauthenticated website triggers HIPAA compliance obligations.  OCR describes how the purpose of the user’s visit to the entity’s website is relevant in determining whether HIPAA applies, providing example scenarios where it applies and where it does not. OCR describes a user’s visit to a webpage providing visiting hour information, clarifying that information captured on the user related to that interaction would not be deemed PHI. The guidance also discusses two scenarios involving users interacting with a site’s oncology services information.  In the first example, OCR describes a student using a hospital website to research a term paper, stating that the data captured on the student in this scenario would not be PHI, even if it could be used to identify the student. However, if an individual visits a hospital’s website to research its oncology services when seeking a second opinion on treatment options for a brain tumor, OCR explains that the individual’s IP address, location, or other identifying information would constitute PHI to the extent it is related to the individual’s health or healthcare.  It is unclear how a HIPAA-regulated entity would determine, from available data, whether visits to its site were made by a student for educational purposes or by a patient seeking treatment.

    What is the impact?

    While OCR outlines certain scenarios describing when user website activity falls outside of the transmission of PHI based on the purpose of the user’s interaction with the site, it ignores the fact that the majority, if not all, HIPAA-regulated entities do not have the means to determine a user’s intent in navigating their websites.  Healthcare providers, health plans, and HIPAA business associates remain subject to OCR’s broad interpretation of PHI related to a user navigating their websites absent a concrete way to capture and document the user’s intent. HIPAA-regulated entities must continue to evaluate existing and any new uses of tracking technologies to confirm that PHI disclosures comply with HIPAA.  Disclosures to tracking technology vendors that fall outside HIPAA compliance should be analyzed as potential breaches.

    OCR’s guidance describes its intent to prioritize HIPAA Security Rule compliance when investigating tracking technology issues. In this regard, a HIPAA-regulated entity needs to ensure that its website teams are trained and clearly understand the privacy and security requirements governing the entity’s use of tracking technologies. In addition to executing BAAs with the tracking technology vendors (to the extent they are willing to do so) or seeking patient authorization for the transfer of PHI to a tracking technology vendor (which may not be practical), the guidance suggests that HIPAA-regulated entities engage a vendor/business associate to de-identify data before it is transmitted to a tracking technology vendor. HIPAA-regulated entities should explore all avenues that allow for the compliant use of tracking technologies with their vendors if they continue to use these tools.

    OCR Action

    Practices

    HealthcareDigital Health & TelemedicineHealth Information - Privacy, Security & Data SharingCybersecurity & Privacy

    Industries

    Healthcare

    Insights And Happenings

    • Alert

      CMP and financial settlement are the latest results of OCR's HIPAA Right of Access Initiative enforcement

      April 8, 2024
    • Alert

      CMS clarifies need for informed consent prior to sensitive exams

      April 5, 2024
    • Article

      CIPA trap and trace poses litigation risk for businesses with public-facing websites

      April 3, 2024
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Cookie Preferences
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Purchase Order Terms & Conditions
    • Nixon Peabody International LLC
    • PAL
    © 2025 Nixon Peabody. All rights reserved