Linkedin Insights
HIPAA Compliance Risk:
High
Category:
Trackers
Use Case: Advertising analytics, conversion tracking, retargeting, and audience creation for LinkedIn ad campaigns
Why it matters:
The LinkedIn Insights Tag is a tracking pixel used to measure conversions, retarget visitors, and build audience segments for LinkedIn advertising. It collects information about user activity, including pages viewed, actions taken, and referral data. On healthcare websites, these activities may reveal that a user is researching treatment, seeking care, or engaging with condition-specific content.
Because this data is sent to LinkedIn, a third party that does not offer a Business Associate Agreement (BAA) for its advertising products its use on pages where Protected Health Information (PHI) could be inferred may constitute a HIPAA violation.
This risk is especially high when used on landing pages, appointment forms, or blog posts that tie behavior to specific health services.
What HHS says:
According to HHS guidance, online tracking technologies used by third parties may impermissibly disclose PHI when individuals interact with webpages related to their health or care even if the site is public and not behind a login.
While a June 2024 court ruling vacated a narrow portion of that guidance regarding the automatic classification of public-page visits and IP addresses as PHI, HHS still enforces HIPAA compliance when user behavior or other data can reasonably identify someone’s connection to a healthcare provider or condition.
LinkedIn’s tracking tools fall outside HIPAA compliance because they lack a Business Associate Agreement and do not provide HIPAA-aligned data protections.
Recommendation:
If the LinkedIn Insights Tag is installed on your site especially on pages tied to healthcare services, appointment scheduling, or condition-specific resources we recommend removing it immediately unless you have taken documented steps to ensure no PHI is collected or disclosed.
LinkedIn does not offer a Business Associate Agreement for this service, and using it without appropriate safeguards creates significant compliance risk. If advertising analytics are essential, consider using privacy-focused platforms that support HIPAA compliance and are willing to sign a BAA.
Using LinkedIn Insights for ad tracking? Let’s check if it’s safe for your healthcare site.