March 27, 2026

Server-Side Tracking 101: A Healthcare Marketer Talking to Another Healthcare Marketer

by

I want to be straight with you — I’m not writing this as an expert looking down at a problem. I’m writing this as someone who had to figure this out the hard way and genuinely wishes someone had explained it more plainly, earlier.

So let me try to be that person for you.

We’ve All Been Running the Same Risky Setup

For years, the standard playbook in healthcare marketing included dropping pixels on your website — small bits of code that track what visitors do and report back to platforms like Google and Meta.

It works. It’s familiar. Every agency recommends it.

The problem is that in healthcare, the data those pixels capture isn’t generic. We’re talking IP addresses, appointment types, condition-specific page visits — information that can qualify as protected health information under HIPAA.

And those platforms? Most of them haven’t signed Business Associate Agreements with us. Which means every time a patient clicks one of our ads, we may be sending PHI to an unauthorized third party without even realizing it.

HHS updated its guidance on this in March 2024. The FTC is enforcing. Class-action lawsuits are piling up. This isn’t theoretical anymore.

What Server-Side Tracking Actually Means in Plain English

When I first heard “server-side tracking” I assumed it was a developer problem, not a marketer problem. I was wrong.

Here’s the simple version: instead of data going straight from a patient’s browser to Google or Meta, it goes through your server first. Your team — or your compliance-aware tech partner — sits in the middle and decides what gets passed forward.

PHI gets filtered out before anything reaches a third party. What continues downstream is clean, aggregated, compliant data that still tells your marketing team what it needs to know.

Think of it as having a trusted colleague review every data packet before it leaves the building.

Here’s What Caught Me Off Guard

I assumed switching to server-side tracking would mean losing visibility. Less data, worse performance, harder conversations with leadership about why numbers looked different.

That’s not what happened.

Traditional pixels are increasingly blocked by browsers, ad blockers, and privacy updates. A lot of our conversion data was already missing and we didn’t know it. Server-side tracking bypasses those blocks, which means we actually recovered data we didn’t know we were losing.

Attribution got sharper. Campaign decisions got better. And we stopped losing sleep over compliance exposure.

What I’d Suggest If You’re Starting From Zero

Start with an audit. Map every pixel, tag, and third-party script running on your site. Ask where that data goes and whether those platforms have signed your BAA.

Then have an honest conversation with your marketing tech team or agency about what a compliant infrastructure actually looks like for your organization.

It’s not as complicated as it sounds once you break it down. And the peace of mind — plus the better data — is absolutely worth it.

If you’re working through this and want to compare notes, reach out. We’re all figuring this out together.

Patrick Soto

Patrick Soto

Chief Operating Officer and Digital / AI Expert

ab+a Advertising is a full-funnel marketing agency specializing in healthcare. Our work goes beyond solving business problems. We inspire progress, elevate brands, and deliver lasting, measurable impact for health organizations worldwide.

Our AI-enabled GiG operating model, Grow. Impact. Good., is designed to drive sustainable growth while advancing meaningful outcomes for the communities our clients serve. Through our Performance Branding approach, we integrate human-centered brand strategy with performance marketing and analytics to create smarter, more efficient growth engines. By blending AI-forward strategy, data-driven insight, and deep healthcare expertise, ab+a delivers purpose-built growth that strengthens organizations and truly matters.

Share and Follow

More from ab+a

Value-Based Care Is Here. Is Your Marketing Strategy Catching Up?

Value-Based Care Is Here. Is Your Marketing Strategy Catching Up?

Let's cut to the point: the transition to value-based care isn't theoretical anymore. It's operational. ACO REACH ends December 31, 2026. The LEAD model launches January 1, 2027. And if your marketing team is still building campaigns around procedure volumes and...

How to Reach the Patient in a High-Demand, Limited-Access World

How to Reach the Patient in a High-Demand, Limited-Access World

Here's the conversation every healthcare CMO is having right now: Marketing drives demand. Patients respond. Then they hit a wall—a six-week wait, a phone tree that goes nowhere, or a scheduler who says "we'll call you back" but never does. Demand isn't your problem....

AI Is Changing How Patients Find You — Are You Optimized for It?

AI Is Changing How Patients Find You — Are You Optimized for It?

The intake call that never came. The referral that went elsewhere. The patient who somehow chose a competitor three blocks away. You're not alone in wondering what happened. The answer isn't your reputation or your clinical quality. It's simpler and harder than that....