Skip to main content

CCPA · By industry

Website tracking & privacy compliance for dental practices

Privacy compliance for a dental website is mostly about one thing: the advertising pixels and session-replay tools on your appointment, symptom, insurance, and patient-portal pages, and what they quietly transmit to ad networks about people seeking care. That data flow is what recent settlements punish. Complidar captures every tracker firing on those pages across up to 120 pages, sends the Global Privacy Control signal, and shows you what a plaintiff's firm or regulator would see first.

The pixel on the dental booking page

The expensive pattern is mundane: a Meta Pixel, Google ads tag, or TikTok pixel on the pages where a patient requests an appointment, reads about a procedure, checks insurance, or logs into a portal. When those tags fire, the data leaving for the ad network can describe someone seeking dental care, which is patient-adjacent information that should not be shared without consent. Donnelly v. Aspen Dental settled for roughly $18.5M in 2025 over exactly this: a Meta Pixel on a dental website transmitting patient-adjacent data without consent. A practice running standard marketing tags on its booking flow is running the same configuration.

This is the privacy angle, separate from accessibility. Where an ADA suit is about whether a screen reader can use the page, this is about what the page leaks while it loads. The two failure modes live on the same site but are sued under entirely different law, and a scan that only checks WCAG never sees this one.

The law that reaches a dental marketing site

Two frames apply, and neither depends on HIPAA. The CCPA treats information about a consumer's health and care-seeking as sensitive personal information, with its own disclosure and 'Do Not Sell or Share' obligations and the Global Privacy Control signal regulators expect sites to honor. Separately, the FTC has built a health-pixel enforcement line under the Health Breach Notification Rule and FTC Act Section 5: FTC v. Premom ($100K) and Cerebral ($7M) put dollar figures on it, and the GoodRx and BetterHelp actions targeted health-adjacent businesses for sharing user data with advertisers. Most dental practices are not HIPAA-covered for their marketing site, but these state-privacy and FTC theories still reach it.

Whether a given statute applies to your specific practice (CCPA thresholds, which FTC theory, your state's consumer-health-data law) is a counsel determination. What your booking and symptom pages actually transmit to which third parties, and when relative to consent, is observable, and that is the part a scan settles.

  • Meta Pixel, Google ads, and TikTok pixels on appointment-request, symptom or service, insurance, and patient-portal pages
  • Session-replay tools recording what a patient types into an intake or booking form
  • Whether any tracker fires before consent, and whether the consent banner actually controls it
  • A working 'Do Not Sell or Share My Personal Information' pathway and Global Privacy Control honoring
  • Privacy-policy disclosure of care-seeking data sharing, checked against what the trackers actually send

What the scan checks here

  • Advertising pixels (Meta, Google, TikTok) on appointment-request, symptom/service, insurance, and patient-portal pages
  • Session-replay and analytics vendors receiving activity from patient-facing forms
  • Trackers firing before consent on care-seeking pages, captured from real network traffic
  • Global Privacy Control honoring and a 'Do Not Sell or Share' pathway where required
  • Whether tracker payloads carry care-seeking context alongside a user identifier
  • Privacy-policy language on sensitive-data sharing, checked against observed tracker behavior

Honest limits: A scan verifies what your pages transmit: which trackers fire on care-seeking pages, when relative to consent, and what your policy says about it. It cannot determine whether your practice meets CCPA thresholds, which FTC or state-privacy theory a regulator would choose, or how a server-side conversions API is configured behind the page. Those are questions for counsel and configuration review, and the report labels which findings are which rather than implying a clean page-level scan equals full compliance.

Common questions

We're a small dental office and not really HIPAA-covered for our website. Are we still exposed?

Yes, and that's the point of these cases. The CCPA's sensitive-data rules and the FTC's health-pixel theory under Section 5 and the Health Breach Notification Rule reach marketing sites that HIPAA doesn't cover. Donnelly v. Aspen Dental (roughly $18.5M, 2025) was about a pixel on a dental site, not a HIPAA program. Whether a specific statute applies to you is a counsel question; what your pages send is a scan question.

Can our appointment page really have a Meta Pixel problem?

If the pixel fires while a patient requests a visit, reads about a procedure, or checks insurance, the data flowing to the ad platform can describe care-seeking, which is the exact fact pattern in Donnelly v. Aspen Dental and the FTC's GoodRx and BetterHelp actions. The scan captures every request your booking and symptom pages make and names the recipients.

Is this the same as the accessibility lawsuits dental sites get?

No, it's a separate risk on the same site. Accessibility suits are about whether someone can use the page; this is about what the page leaks to ad networks while it loads, sued under CCPA sensitive-data rules and FTC health-pixel theory rather than the ADA. A scan that only checks WCAG misses this entirely, which is why Complidar runs both.

Check your site free

All 22 checks · up to 120 pages · no card

Last updated 2026-06-28 · Informational, not legal advice: how to read this