Skip to content

What Google Tag Manager’s Update Means for HIPAA Compliance

Is Google Tag Manager HIPAA-Compliant?

No. Google Tag Manager is not HIPAA compliant on its own, and Google will not sign a Business Associate Agreement for it. What determines your compliance is the configuration: a standard client-side GTM setup can send URLs, identifiers, and user-provided data to Google in ways that constitute a disclosure of PHI, while a properly configured server-side implementation lets you filter that data before it ever leaves your environment. GTM is a tool you can use compliantly. It is not a compliant tool by default.

In April 2025, Google changed how Google Tag Manager (GTM) loads its core tracking script. The change looked minor to most marketers. For healthcare organizations and medical device companies operating under HIPAA, it quietly expanded the amount of user data flowing to Google’s platforms, and many containers have been running that way ever since.

This is not just a technical implementation detail. It changes what leaves your website, which means it can expose sensitive information in ways that create real regulatory risk. If you have not audited your GTM containers since the change took effect, this is what to look for and how to fix it.

How the Google Tag Manager Update Changed Data Collection

Google Tag Manager is a tag management system that allows marketers to implement tracking codes and conversion pixels without requiring extensive technical knowledge or developer resources. At the heart of Google’s tracking infrastructure is what they call the “global script tag,” commonly known as the Google Tag, GTAG or gtag.js, which is responsible for running various Google libraries.

This GTAG helps set cookies for Google Analytics and Google Ads, monitoring user sessions and helping with conversion tracking. It essentially manages the lifecycle of cookies across Google’s various marketing and analytics products.

Here is what changed. When a Google Ads tag or Floodlight tag fires, GTM automatically loads the gtag.js script first if your container is not already doing so. That behavior predates the update. What changed in April 2025 is the configuration. The auto-loaded script now runs with all of your Google Tag settings enabled, including automatic event detection and user-provided data collection, rather than the limited implementation it used before.

Google’s stated purpose is accuracy: richer user and session data accompanying the conversion data sent back to its platforms. For most advertisers, that is a straightforward improvement. For covered entities, it is an expansion of disclosure.

What Was The Impact Of The GTM Change On Data Collection And HIPAA Compliance?

From an advertising perspective, this change offers clear benefits. It ensures more accurate conversion tracking by guaranteeing that the proper cookies are set before conversion data is sent back to Google’s platforms. This means better attribution and potentially more precise targeting capabilities.

For most marketers, this automatic implementation simplifies technical setup and improves data accuracy without requiring additional work. Google is essentially ensuring that the correct prerequisites are in place when sending events to their services, even if they weren’t properly configured initially.

However, there’s a critical trade-off happening here that especially affects healthcare organizations: improved data collection often comes at the expense of privacy protections.

What Are The Privacy And HIPAA Compliance Risks Of The GTM Update?

Interestingly, this update runs counter to Google’s previously announced privacy-focused initiatives, such as the deprecation of third-party cookies, which they are no longer phasing out. In certain cases, you may want to track conversion actions without sending all that user data back to Google Ads. Now, this update essentially forces your hand to do just that.

For healthcare marketers operating under HIPAA regulations, this automatic data collection presents serious compliance risks. When the GTAG fires, they can potentially send sensitive data that, when combined with user identifiers, could constitute a violation of HIPAA rules.

The specific risks include:

  • Mixing PHI with PII: If a URL contains condition-specific information (which many healthcare websites do), this information could be sent along with user data to Google, potentially constituting a violation. Any PII associated with a disease state is considered a violation under HIPAA.
  • Google’s Refusal to Sign BAAs: Google won’t sign Business Associate Agreements, meaning they cannot legally receive PHI from covered entities.

Solutions for Healthcare Marketers: Server-Side GTM Implementation

The most comprehensive solution for healthcare marketers is implementing server-side GTM. This approach places a server between your website and Google’s platforms, allowing you to control exactly what data is sent to third parties.

Server-side GTM allows you to:

  • Collect necessary marketing data for campaign optimization
  • Filter out any PHI or sensitive health information before it reaches Google
  • Maintain HIPAA compliance while still leveraging digital marketing tools

However, server-side implementation does come with challenges:

  • Cost considerations: Setting up and maintaining servers on AWS, Azure, or other cloud platforms represents an additional expense.
  • Technical complexity: Implementation requires developer resources and specialized knowledge outside the typical marketing skillset.

For organizations with budget constraints, newer solutions like Stape offer a more accessible path to server-side implementation. Stape provides a simpler setup process with lower costs, though it may not scale as effectively for larger organizations.

Strategic Recommendations and Next Steps for HIPAA Compliant GTM

The change is already live. If you have not reviewed your setup since it rolled out, start here:

Immediate Actions

  • Review your live GTM containers to understand current implementation
  • Set manual GTAG to avoid auto load behavior, making testing and troubleshooting easier. This will also allow you to control which GTAG settings load
  • Assess what data is currently being collected and sent to Google
  • Document your current setup to identify potential compliance vulnerabilities

Determine Your Exposure Level

  • High exposure: If you’re a healthcare organization using client-side GTM for conversion tracking
  • Medium exposure: If you have mixed implementation with some server-side components
  • Lower exposure: If you already have comprehensive server-side implementation

Long-term Strategy

  • Evaluate server-side GTM implementation options and associated costs
  • Prepare stakeholder communications about compliance requirements and necessary changes
  • Consider consulting with marketing technology specialists who understand both HIPAA compliance and digital marketing needs

Safeguarding Patient Privacy While Maintaining Marketing Effectiveness

While Google’s GTM update improves data accuracy and simplifies implementation for most marketers, it presents significant compliance challenges for healthcare organizations. The automatic loading of Google’s tracking libraries means more data being sent to platforms that won’t sign BAAs, creating potential HIPAA violations.

Server-side GTM implementation represents the most comprehensive solution, allowing healthcare marketers to maintain both effective campaigns and regulatory compliance. There is no deadline left to prepare for, which makes an audit of your current implementation the priority. If you’re looking to implement server-side GTM or would like assistance navigating these compliance challenges, we’re here to help you chart a clear path forward while protecting your patients’ privacy. Reach out today to start the conversation.

FAQ About Google Tag Manager and HIPAA Compliance

Can healthcare organizations use Google Analytics?

Healthcare organizations can use Google Analytics, but they must ensure no Protected Health Information (PHI) is sent to Google. This typically requires server-side implementation to filter sensitive data before it reaches Google’s servers.

What is server-side GTM and why is it important for healthcare?

Server-side GTM processes data on your own server before sending it to third parties like Google. This gives you control over what information is shared, allowing you to filter out PHI and maintain HIPAA compliance while still collecting marketing data.

What happens if my healthcare organization violates HIPAA through marketing tools?

HIPAA violations can result in significant financial penalties, ranging from $100 to $50,000 per violation (per record) with a maximum penalty of $1.5 million per year for violations of an identical provision. Beyond financial penalties, organizations may face reputational damage and loss of patient trust.

Want more privacy-first insights like this?

Our newsletter explores the strategies, technologies, and approaches that are actually moving the needle for privacy-first brands. No fluff, just actionable insights and real-world lessons from the front lines of performance marketing.


Wheelhouse DMG Mobile Logo in White and Gold

Contact Us

[wpforms id=”17570″]