Healthcare Website Tracking: What We Found on 4,601 Practice Sites
Everyone quotes a 98.6% figure that measured hospital homepages. We scanned 4,601 independent practice websites instead. One in nine came back clean, and trackers were only one of the four ways they failed.
If you have read anything about tracking pixels on healthcare websites in the last two years, you have seen the same number: 98.6% of hospital websites send data to third parties.
It is a real finding from a real study. It is also the wrong number for your practice, and almost every article that quotes it does not say so.
That study was a census of 3,747 non-federal acute care hospitals. To be included, a facility had to have an emergency department, which structurally excludes every dental office, med spa, chiropractic clinic, physical therapy practice, optometry office and dermatology group in the country. It measured homepages, not the pages where a patient types anything. And the fieldwork was done in August 2021, five years ago.
So we measured the thing nobody had measured.
What we did
In July 2026 we scanned 4,601 independent healthcare practice websites across seven specialties: dental, med spa, chiropractic, physical therapy, optometry, dermatology and oral surgery.
For each site we loaded it in a real browser, the way a patient would, and recorded what a patient's information touches: which third-party scripts run, which pages carry forms, whether those two meet, and whether the companies serving the form will sign a Business Associate Agreement.
Then we sorted every site into one verdict.
What we found
492 of 4,601 sites came back with nothing to report. That is 10.7%, or roughly one in nine.
Here is the full ladder.
| What the scan found | Sites | Share |
|---|---|---|
| A tracker running on the page where patients type | 2,067 | 44.9% |
| A patient form served by a platform or host that will not sign a BAA | 519 | 11.3% |
| One exposure signal, most often a tracker or a host that will not sign | 1,464 | 31.8% |
| Nothing to report | 492 | 10.7% |
| Site exists but would not load | 59 | 1.3% |
88.0% of the sites we scanned produced at least one finding.
The reason we are showing you the whole ladder rather than the top rung is that most practices read a tracking statistic, check their own site for a Meta Pixel, find none, and stop. The second largest group in that table is not a tracking problem at all.
Four ways a practice site fails, and only one of them is trackers
These overlap. A site can be in all four.
A tracker on the page where patients type. 44.9%. The clearest of the four, and the one the class action lawyers are interested in. A script belonging to Google or Meta is running while somebody enters their name and their reason for calling.
A tracker anywhere on a healthcare site. 60.7%. Broader and less discussed. The fact that a specific person viewed your page about a specific condition, tied to their IP address, is information about their health. Google Analytics was on 58.2% of the sites we scanned. The Meta Pixel was on 16.6%. Session recording tools, which capture what a visitor does on a page including keystrokes, were on 6.2%.
A form served by a company that will not sign. 39.0%. No tracker required. The practice has an ordinary contact form on ordinary hosting, and the host's published position is that it will not sign a Business Associate Agreement for a practice like yours. Nothing on the page looks wrong. There is simply nobody accountable for what arrives.
A data path that cannot be checked at all. 25.0%. A quarter of the sites we scanned sit behind a proxy that hides the origin server. This is not a failure and we do not count it as one. It means that where the patient data actually goes, once it leaves the page, cannot be determined from the outside by us or by anyone else. It is an open question rather than a clean bill, and a quarter of the market is living inside it.
The specialty you are in barely matters
| Specialty | Sites | Any finding | Tracker on a form page | Clean |
|---|---|---|---|---|
| Med spa | 855 | 89.5% | 43.7% | 8.8% |
| Oral surgery | 111 | 89.2% | 52.3% | 8.1% |
| Dental | 1,631 | 88.3% | 46.0% | 11.2% |
| Chiropractic | 715 | 88.0% | 45.6% | 10.2% |
| Optometry | 537 | 87.9% | 47.9% | 11.2% |
| Physical therapy | 579 | 86.2% | 38.2% | 12.1% |
| Dermatology | 173 | 84.4% | 46.8% | 13.3% |
Five points separate the best specialty from the worst. We went looking for the specialty with a problem and did not find one, which is a more useful result than a league table would have been. Whatever is causing this is not clinical. It is how practice websites get built.
Why we are publishing this number
88% is uncomfortably close to 98.6%, and a reader who has seen the hospital figure quoted at them a dozen times is entitled to assume we have simply repackaged it. So here is the difference, stated plainly.
The hospital study measured one thing: whether a third-party script loaded on a homepage. Ours measures four, on practice sites rather than hospitals, in 2026 rather than 2021, and it reports the 10.7% that came back clean instead of rounding them away. If we had measured only what the hospital study measured, our figure would have been 60.7%.
We also had every commercial reason to publish 98.6% and did not, because it is not a number about you. And we had a commercial reason to drop the 10.7% and did not, because a statistic that cannot come out clean is not a measurement.
Just under nine in ten is the honest figure. If you are in it, the exposure is real regardless of how many others share it. If you are in the other one in nine, we would rather tell you that.
How we counted
The denominator is the part worth scrutinising in any statistic like this, so here is ours in full.
We kept 59 sites that exist but would not load. These are real websites we could not read, through timeouts or errors. They stay in the denominator and count as no finding, which counts against us. Removing them would have nudged the figure up.
These are not a random sample of American healthcare. They are a set assembled by specialty and geography, which carries selection bias we cannot quantify. Treat the figure as a large sample rather than a national estimate.
The scans ran between 21 and 23 July 2026. Sites change. This is a photograph, not a permanent record.
What this does and does not mean
We can see all of this from outside your systems, which means anyone can. It also means there is a great deal we cannot see, and we would rather say so.
What a scan establishes: that a specific script loads on a specific page, that the page carries a form, and what a vendor's published BAA position is. Facts about the HTML your site serves the public, plus a dated vendor reference.
What it cannot: whether a tracker is configured to capture what people type, whether an advertising audience was ever built from that traffic, or where a submission finally comes to rest. Those need access to the accounts.
It also does not mean a fine is coming. There has never been a federal enforcement action against any organisation, of any size, over website tracking technology. Anyone implying otherwise is selling something. What has moved is private litigation, and so far it has been aimed at hospitals and large groups rather than independent practices.
The reason to care is simpler than a penalty. A third party is receiving something a patient handed to you, and nobody has signed anything making them accountable for it.
The part of this that nobody writes about
Here is what the 88% actually tells you, and it is not that practice owners are careless.
Almost none of those sites launched broken. They launched fine, and then a year happened.
An agency added a conversion tag to the appointment page, because measuring appointment requests is their job and nobody told them the page was different. A form vendor shipped an AI summarising feature that is genuinely useful and is not named anywhere in the agreement signed two years earlier. A host changed its subcontractors and disclosed it in a page nobody reads. Somebody built a new location page with a contact form on it, and the form was copied from the old one.
Every one of those is ordinary competent work by someone doing their actual job. None of them is a mistake anyone would catch. And each one silently moves a practice from the 10.7% into the 88%.
This is why a compliance fix has a short shelf life when it is an event rather than a state. You can move a form to a covered vendor on a Tuesday afternoon and be genuinely, verifiably fine on Wednesday. Nothing about that afternoon survives November. And you will not know, because you cannot see your own page the way a scanner sees it, and nobody sends you an email when a tag gets added.
The practices in the 10.7% are not the ones who fixed it once. They are the ones where somebody is still looking.
Checking your own
The same scan runs on request and takes under a minute. It reports what loads on your pages, which of it sits alongside a patient form, whether the companies handling your submissions will sign for what they receive, and what it could not determine from outside, which is the part most tools leave out.
If you already know roughly what it will say and would rather the answer stayed true, that is what the Managed Plan is: the site, the hosting, the form path, the agreements and the monitoring held by one company, and rescanned rather than remembered.