Vanderbilt Health’s Analytics Journey Prioritizes Consumer Privacy

January 21, 2025

Solving for consumer privacy protections with HIPAA-compliant technology solutions may have the added benefit of expanding analytics capabilities. But be prepared for how much time and effort it takes.

// By Jane Weber Brubaker //

jane-brubaker

The healthcare privacy landscape has been in flux since 2022, after several healthcare organizations were sued for HIPAA violations related to the presence of Facebook’s Meta Pixel on their websites. This tracking technology gave the social media platform access to patients’ and consumers’ protected health information (PHI).

In December 2022, the U.S. Department of Health and Human Services (HHS) Office of Civil Rights (OCR) issued a bulletin with guidance about the use of tracking technologies in general and what would constitute a HIPAA violation.

The bulletin upended the healthcare digital marketing world because, without the tracking technologies embedded in platforms like Facebook and Google Analytics, marketers would not be able to analyze customer journeys on their websites from end to end. But these major digital advertising platforms will not sign a business associate agreement (BAA) with healthcare organizations to protect PHI.

Like many health systems, Vanderbilt Health needed to reorient to these new realities and related legal and compliance risks. For almost a year after the HHS/OCR bulletin issued its guidance, the health system continued to use Google Analytics while it was searching for a new analytics solution to replace it.

Waters-Travis-Vanderbilt

Travis Waters, associate director of digital experience analytics at Vanderbilt Health

“At that point, we had selected a vendor to use, but we had not completed our contracting process,” says Travis Waters, associate director of digital experience analytics at Vanderbilt Health. “Around November 2023 is when we decided to remove all tracking, and that’s when we went kind of blind.”

Ten months later, on August 1, 2024, Vanderbilt Health went live with its new HIPAA-compliant analytics solution. Here, we trace the journey from evaluation and selection to implementation, and the new capabilities Waters is excited about.


This content is only available to members.

Please log in.

Not a member yet?

Start a free 7-day trial membership to get instant access.


Log in below to access this content: