Office of Civil Rights Guidance on Online Tracking Technologies under HIPPA

The Office of Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) recently issued a Bulletin on the disclosure of Protected Health Information (PHI) by HIPAA-regulated entities in an online environment increasingly proliferated by tracking technologies.

The Bulletin clarifies that regulated entities are not permitted to use tracking technologies/vendors in a manner that would result in impermissible disclosures of PHI or any other violations of HIPAA rules. It defines tracking technologies and clarifies how HIPAA rules apply to tracking on various webpages, mobile apps, and other platforms.

This Bulletin comes as HHS OCR aims to combat increased health information breaches and other HIPAA violations more effectively. The office has received a substantial increase in complaints over the past few years, with 51,000 complaints in 2022 – a 69% increase since 2017 – and 66% of those cases being alleged violations of health information privacy and security law.