Tracking pixels on dental websites can illegally collect patient data and violate HIPAA if they capture identifiable health information without proper business associate agreements. Aspen Dental paid $18.7 million to settle a lawsuit over this issue, and the same risk exists on independent practice websites where Meta Pixel and Google Analytics track appointment bookings and form submissions.
- Aspen Dental settlement: $18.7 million paid in late 2025 for collecting visitor data via tracking pixels without consent from over 2 million patients between February 2022 and January 2025.
- The HIPAA violation: Tracking pixels on appointment pages, contact forms, and patient portals capture identifiable health information that becomes a HIPAA compliance issue when shared with Meta or Google.
- No BAA solution: Meta and Google will not sign business associate agreements for standard pixel and analytics products, making these tools incompatible with HIPAA-protected pages.
- Applies to all practices: The risk affects independent dental practices and DSOs equally when marketing agencies install tracking pixels without addressing HIPAA compliance.
If your practice's website has a "Book an Appointment" button, a contact form, or a patient portal login -- and you're running Meta or Google ad campaigns -- this is worth 10 minutes of your time.
In late 2025, Aspen Dental Management agreed to pay $18.7 million to settle a class action lawsuit alleging that it used tracking pixels on its website to collect visitor data and share it with Meta (Facebook) and Google without patients' knowledge or consent.
The case, Donnelly v. Aspen Dental Management, covered more than 2 million people who booked appointments on Aspen Dental's website between February 2022 and January 2025. The settlement administrator began issuing payments this past February, meaning this isn't old news still working through the courts. It's a resolved case with real money already going out the door.
This is a different Aspen Dental matter than the corporate practice of dentistry settlement I wrote about here last month. That case was about who controls a practice after a DSO (dental service organization) deal. This one is about what happens on a practice's website before a patient ever walks in the door, and it applies just as easily to an independent practice as to a 900-location DSO.
What a tracking pixel actually does
Marshall Strisik.
A tracking pixel is a small piece of code -- most commonly the Meta Pixel or Google Analytics/Google Ads tag -- that marketing platforms provide so practices can measure how well their ads are working. Someone clicks a Facebook ad, lands on your website, books an appointment, and the pixel reports that conversion back to Meta so you know the ad worked.
The problem isn't the concept. It's what the pixel can capture along the way. Depending on how it's installed, a tracking pixel can pick up which pages someone visited, what they typed into a form, and details tied to a specific, identifiable person, like someone booking an appointment for a specific type of dental treatment.
Once that information reaches Meta or Google, current U.S. Department of Health and Human Services Office of Civil Rights guidance treats it as a HIPAA problem, not just a marketing question: The transmission is only lawful if there's a HIPAA-compliant business associate agreement (BAA) covering that data, or a valid patient authorization.
Neither Meta nor Google will sign a BAA for their standard pixel and analytics products, which means there is currently no way to make those tools fully compliant on any page that touches protected health information.
Why this isn't just a DSO problem
Aspen Dental made headlines because of the size of the settlement and the DSO's scale, but the underlying tool is the same one running on thousands of independent practice websites -- often installed by a marketing agency or website vendor, not the dentist personally.
If you've ever told your marketing company, "Just get me more leads from Facebook," there's a good chance a pixel went on your site as part of that setup, without a specific conversation about where the data go afterward.
This is also directly relevant if you run or advise a dental marketing agency. Agencies routinely install tracking pixels as a standard part of campaign setup, because that's how ad platforms measure performance.
If your agency is installing these tools on client websites -- including booking pages, contact forms, or anything connected to a patient portal -- without addressing HIPAA compliance, both the agency and the dental practice client are carrying risk. This is worth a direct conversation with your marketing vendor, not an assumption that they've already handled it.
What to actually check
- Identify every tracking tool on your website. This includes the Meta Pixel, Google Analytics, Google Ads conversion tracking, TikTok Pixel, and similar tools from any other ad platform you use. Your web developer or marketing agency can pull this list, or you can check your site's source code or tag manager account directly.
- Determine which pages those tools are running on. A pixel on your homepage or a general blog post is a different risk profile than one on your appointment booking page, contact form, or any authenticated patient portal.
- Ask directly whether the vendor will sign a BAA covering that specific tool. If the answer is no -- and for standard Meta Pixel and Google Analytics products, it currently is -- that tool needs to come off any page where it could capture identifiable patient information.
- Talk to your marketing agency about alternatives. Server-side tracking configurations and HIPAA-compliant analytics platforms exist and can still give you meaningful campaign data without the same exposure. This is a solvable problem, not a reason to stop advertising.
- Get it in writing. If a marketing agency manages your website, ask them to confirm -- in writing -- what tracking tools are installed and on which pages. This protects both of you and creates a paper trail if the question ever comes up later.
The bigger picture
Tracking pixels are effectively invisible to a practice owner unless someone goes looking for them, which is exactly why this kind of exposure tends to sit unnoticed for years. The Aspen Dental settlement is a reminder that regulators and plaintiffs' attorneys are now looking and that "our marketing company handled the website" is not a defense to a HIPAA-adjacent claim.
This isn't a reason to abandon digital marketing -- it's a reason to make sure the tools running on your website were chosen with patient data in mind, not just ad performance.
Marshall Strisik is the founder of DentalContractsPro.com. He is a healthcare attorney and consultant with two decades of experience advising dentists through DSO acquisitions and practice transitions. Strisik routinely works with new graduates on their first employment agreements.
The comments and observations expressed herein do not necessarily reflect the opinions of DrBicuspid.com, nor should they be construed as an endorsement or admonishment of any particular idea, vendor, or organization.




















