Your patient portal likely still has tracking pixels installed. The real question is whether you've documented informed consent before any protected health information reaches a third-party server.
Here's a consent script you can deploy immediately, informed by the legal experiences of healthcare organizations. Atrium Health settled for $1.8 million over claims that its portal shared patient information with Meta and Google without proper consent, affecting nearly 586,000 individuals. Kaiser Permanente's settlement was $47.5 million for similar issues.
Class action lawsuits now pose a greater threat than regulatory enforcement for web tracker misuse. You need a consent mechanism that creates an auditable record before any analytics or advertising pixels activate.
What This Script Does
This consent overlay captures explicit, documented agreement before your portal loads any third-party tracking technology. It's designed to meet both HIPAA Privacy Rule disclosure requirements and state privacy law consent standards.
The script provides three critical elements:
- A timestamped record of who consented to what
- A mechanism to honor "decline" choices without breaking portal functionality
- Language that withstands legal scrutiny by naming actual third parties and data elements
This isn't a cookie banner. Those are for general website visitors. Your portal users are patients accessing protected health information. The legal standard is higher.
Prerequisites
Before deploying this script, ensure you have:
A complete inventory of your tracking pixels. Check your portal's tag manager and list every third-party domain receiving data when a patient logs in. Include analytics platforms, advertising networks, chatbot providers, and appointment scheduling widgets. If you're unsure what's installed, you're not ready to ask for consent.
A decision about what happens when patients decline. Will your portal function without Google Analytics or the Facebook pixel? If declining consent breaks critical features, fix that first or disclose it explicitly.
A database field to store consent status. Log patient ID, timestamp, consent choice (accept/decline), and which version of the disclosure they saw. This becomes your evidence if you're sued.
Legal review of your third-party agreements. Your Business Associate Agreements must cover any vendor receiving identifiable health information. If Meta or Google appears in your pixel inventory but not in your BAA stack, you have a HIPAA Security Rule problem before you even get to consent.
The Consent Script
Deploy this as an interstitial overlay before the patient accesses any portal content:
Before You Continue
[Your Organization Name] uses analytics and communication tools to improve your experience and help us serve you better. Some of these tools are provided by third parties, including Google LLC and Meta Platforms, Inc.
What information is shared:
When you use this portal, these third parties may receive:
- Pages you visit within the portal
- Time spent on each page
- Device and browser information
- IP address
- Appointment types you view or schedule
This information may be linked to your patient account and could include details about your health conditions, treatments, or appointments.
How it's used:
Third parties use this information to deliver analytics services to us and may use it for their own advertising purposes on other websites and platforms you visit.
Your choice:
You can use this portal whether or not you allow these tools. Declining won't affect your access to medical records, appointment scheduling, or communication with your care team.
☐ I consent to the use of third-party analytics and communication tools as described above
☐ I decline, disable third-party tools for my account
Review our complete Privacy Notice | Manage my choices later
[Continue to Portal]
How to Customize It
Replace the placeholder organization name with your legal entity name, the one on your Notice of Privacy Practices.
Edit the "What information is shared" section to match your actual pixel behavior. If unsure what data your pixels capture, use your browser's developer tools to inspect network traffic while logged into a test account. Look for POST requests to domains like facebook.com, google-analytics.com, or doubleclick.net.
Adjust the third-party list. The script names Google and Meta because those were involved in the Atrium Health breach. If you use different platforms, Salesforce Marketing Cloud, Adobe Analytics, TikTok Pixel, name them explicitly. Vague language like "our partners" won't hold up.
Modify the "How it's used" section based on your actual contracts. If your analytics vendor has agreed not to use patient data for their own advertising, say so. If they haven't, the script's current language is accurate.
Set the default state of both checkboxes to unchecked. Pre-checked boxes aren't meaningful consent under most state privacy laws. The patient must take an affirmative action.
Link to your full Privacy Notice using your actual URL. The consent script is a summary, patients need access to the complete disclosure.
Validation Steps
After deployment, verify these four things within 48 hours:
Test the decline path. Create a test patient account, choose "I decline," and navigate the entire portal. Confirm that no third-party requests fire. Use browser developer tools to check the Network tab for requests to external analytics domains. If you see any, your tag manager isn't respecting the consent choice.
Verify consent logging. Check your database to confirm that test consents are being recorded with patient ID, timestamp, and choice. Try to pull a report of all consents from the last 24 hours. If you can't generate this report easily, you won't be able to produce it during discovery.
Review the pixel inventory again. Three months from now, someone will install a new chatbot or scheduling widget without telling you. Set a quarterly calendar reminder to audit your tag manager. Compare the current pixel list to the list in your consent script. If they don't match, you're collecting consent for the wrong things.
Document your validation. Write a one-page memo that says "On [date], we tested the consent script and confirmed [specific results]." Sign it. Keep it with your HIPAA Security Rule documentation. When HHS Office for Civil Rights or plaintiff's counsel asks what you did to validate your consent mechanism, you'll have a timestamped answer.
Federal regulators released guidance materials in 2022 and 2024 warning about HIPAA violations related to online trackers. While enforcement may vary, your exposure to class action litigation remains high. The lawsuits continue because they're profitable for plaintiffs' attorneys and because many healthcare organizations haven't addressed the underlying problem.
This script doesn't eliminate your risk. It documents that you asked first.




