Sponsored Events
Venture Atlanta 2025
October 15 – 16, 2025
The Woodruff Arts Center and Atlanta Symphony Hall
Leading the energy evolution.
Learn more
From compliance to the courtroom, we have you covered.
Learn more
Helping you focus on what matters – improving human health.
Learn more
Trusted advisors to leading insurers for 100+ years.
Learn more
Unlocking value in the middle market and beyond.
Learn more
Full-service legal advice from coast to coast.
Learn more
Applying radical applications of common sense
Explore More
Our standard-setting client experience program.
Explore more
Delivering life-changing help to those most in need.
Explore More
Our firm’s greatest asset is our people.
Explore More
Market-leading eDiscovery and data management services.
Explore more
The Pepper Center for Public Services
Explore more
Strategies helps businesses and individuals solve the complexities of dealing with the government at every level. Our team of specialists concentrate exclusively on government affairs, representing clients nationwide who need assistance with public policy, advocacy, and government relations strategies.
This unique program provides innovative and affordable opportunities to startups and early-stage emerging companies with a solid technology or scientific foundation. We help companies that have a quality management team in place and do not have other significant legal representation.
eMerge’s lawyers and technologists work together to deliver strategic end-to-end eDiscovery and data management solutions for litigation, investigations, due diligence, and compliance matters. We help clients discover the information necessary to resolve disputes, respond to investigations, conduct due diligence, and comply with legal requirements.
Stay ahead of the curve and in touch with our latest thinking on the issues that are top of mind across our practices and industry sectors.
Change happens fast in today’s turbulent world. Stay on top of the latest with our industry-specific channels.
Take a closer look at how we partner with clients to help them realize their goals.
Articles + Publications May 4, 2023
Online Tracking Technologies and HIPAA. In December 2022, the Department of Health and Human Services Office for Civil Rights (OCR) published a bulletin on the use of online tracking technologies (e.g., cookies or web beacons) by entities regulated under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Specifically, the OCR noted:
In the course of gathering data, these online tracking technologies may collect protected health information (PHI); and
The collection or analysis of the data may involve unauthorized disclosures of PHI to third-party tracking technology vendors or other related third-party vendors.
Most importantly, the OCR indicated that individually identifiable health information (IIHI) collected on a regulated entity’s (i.e., a covered entity’s or business associate’s) website or mobile app “generally is PHI, even if the individual does not have an existing relationship with the regulated entity and even if the IIHI, such as IP address or geographic location, does not include specific treatment or billing information like dates and types of health care services.”
The OCR further explains that “tracking technologies on a regulated entity’s unauthenticated webpage that addresses specific symptoms or health conditions, such as pregnancy or miscarriage, or that permits individuals to search for doctors or schedule appointments without entering credentials may have access to PHI in certain circumstances. For example, tracking technologies could collect an individual’s email address and/or IP address when the individual visits a regulated entity’s webpage to search for available appointments with a health care provider.”
Five Steps You Can Take to Avoid HIPAA Tracking Issues. If you (1) use third-party tracking technologies on your website and/or apps; and (2) are a regulated entity (i.e., a covered entity or business associate), then you need a practical approach to mitigate against unauthorized disclosures. Below find five steps you can take to avoid potential noncompliance issues under HIPAA:
Prepare an inventory of cookies and tracking technologies. Establish your baseline using tracking technology detection tools and interviews with IT and marketing.
Determine internal uses. Is the data collected and/or retained in aggregated or de-identified form (e.g., to improve the website)? Is the data used for retargeting or other marketing purposes? What internal functional groups access and/or use the data?
Establish the scope of third-party disclosures. Are there contractual limitations/controls in place with the technology vendor? Are there disclosures of the data to any additional third parties (e.g., secondary uses, such as AI/ML or other analytics)?
Amend existing agreements/templates. Amend existing vendor agreements with business associate agreements, as needed. Include a restriction on any data uses beyond delivering services (applicable to the business associate/vendor and any other sub-business associate service providers).
Add a checkpoint in your vendor contracting and PIA processes. Avoid future surprises by incorporating a tracking technology checkpoint in your procurement or contracting process and/or PIA workflow.
Questions. To learn more about the impact on your company and product pipeline, please contact Jim Koenig, Brent Hoard, Erin Whaley, Marc Loewenthal, Robyn Lin, or any member of our Privacy + Cyber team.
Sponsored Events
Venture Atlanta 2025
October 15 – 16, 2025
The Woodruff Arts Center and Atlanta Symphony Hall
Sponsored Events
Cherrystone Angel Group – Pitch Night 2025
October 14, 2025
CIC Providence
225 Dyer Street, Providence, RI
Sponsored Events
M&A East 2025
October 14 – 15, 2025
Pennsylvania Convention Center
Speaking Engagements
PLI Broker/Dealer Regulation and Enforcement 2025
October 9, 2025 | 4:00 PM – 5:00 PM ET
1177 Avenue of the Americas, Entrance on 45th Street, New York, NY 10036
Leading the energy evolution.
Learn more
From compliance to the courtroom, we have you covered.
Learn more
Helping you focus on what matters – improving human health.
Learn more
Trusted advisors to leading insurers for 100+ years.
Learn more
Unlocking value in the middle market and beyond.
Learn more
Full-service legal advice from coast to coast.
Learn more
Applying radical applications of common sense
Explore More
Our standard-setting client experience program.
Explore more
Delivering life-changing help to those most in need.
Explore More
Our firm’s greatest asset is our people.
Explore More
Market-leading eDiscovery and data management services.
Explore more
The Pepper Center for Public Services
Explore more
Strategies helps businesses and individuals solve the complexities of dealing with the government at every level. Our team of specialists concentrate exclusively on government affairs, representing clients nationwide who need assistance with public policy, advocacy, and government relations strategies.
This unique program provides innovative and affordable opportunities to startups and early-stage emerging companies with a solid technology or scientific foundation. We help companies that have a quality management team in place and do not have other significant legal representation.
eMerge’s lawyers and technologists work together to deliver strategic end-to-end eDiscovery and data management solutions for litigation, investigations, due diligence, and compliance matters. We help clients discover the information necessary to resolve disputes, respond to investigations, conduct due diligence, and comply with legal requirements.
Stay ahead of the curve and in touch with our latest thinking on the issues that are top of mind across our practices and industry sectors.
Change happens fast in today’s turbulent world. Stay on top of the latest with our industry-specific channels.
Take a closer look at how we partner with clients to help them realize their goals.