Blog

Research & Insights Privacy

Tracking pixels in Australian healthcare: findings from 100 selected websites

In fresh browser sessions, requests on 54 of 100 selected healthcare homepages matched recognised advertising or social collection-endpoint patterns. A separate manual review confirmed a visible consent-choice interface on 10.

Casey Jones Casey Jones Director, Medical Marketing Group 17 min read Updated
Abstract close-up of fine blue diagonal lines and shifting bands of light
Abstract image by Imkara Visual via Unsplash.

Key findings

  • 54/100 selected homepages had a browser request match a recognised advertising or social collection-endpoint pattern during an untouched fresh session.
  • 10/100 showed a visible consent-choice interface in a separate ten-second review. Of the 54 sites with collection-endpoint evidence, 49 had no interface confirmed under those review conditions.
  • Among the ten confirmed interfaces, acceptance persisted on 10/10 and a restrictive choice persisted on 9/10. In 5/9 technically verified restrictive flows, a request met our strict advertising-event rule both before choice and after reload. This did not establish that refusal was ignored or that the same payload or identifier continued.
  • We found 76 privacy-policy links and could read 74. 12/74 used explicit pixel or web-beacon language; among 60 readable policies linked to sites with an observed provider, 7/60 text-matched every provider we observed.

Scope: This is a non-random snapshot of 100 selected homepages. Request-pattern matches are technical observations, not findings of unlawful tracking or non-compliance.

In June 2026, the Australian Privacy Commissioner published two healthcare tracking-pixel determinations and urged organisations using these tools to review their practices. We examined 100 selected homepages serving Australian healthcare consumers to see what a fresh browser session could observe, how often a visible tracking choice appeared, and whether linked privacy policies used language that reflected the technologies detected.

The sample covered ten healthcare sectors and included high-visibility as well as smaller websites. Browser instrumentation captured requests consistently, while researchers reviewed the evidence, all 100 consent screenshots and the resulting classifications. Results are reported only in aggregate and privacy-protected anonymous rows.

Original research

What we observed on 100 selected Australian healthcare homepages

Fixed, purposive sample · fresh-browser request capture · separate consent-interface review.

54%

Ad/social collection endpoint observed

54 of 100 sites

10%

Visible consent choice found

10 of 100 sites

80%

Known measurement or marketing signal

80 of 100 sites

76%

Privacy-policy link found

76 of 100 sites

Collection requests were observed during an untouched six-second browser session. Consent interfaces were reviewed separately after ten seconds on desktop.

Request evidence

54 sites had a request match a recognised collection-endpoint pattern

Detector v2.0.0 · 6-second untouched session

A broader provider match appeared on 58 sites: 54 collection-endpoint matches, two consent-signalling-only matches and two bootstrap or configuration-only matches. The primary metric excludes the latter two tiers.

Mutually exclusive advertising and social-provider request evidence observed across the 100 selected homepages.
Strongest request evidence observed per siteSitesShare of sample
Request matched a recognised collection, conversion or identifier-sync endpoint pattern54 of 10054%
Dedicated consent-signalling endpoint, but no recognised collection endpoint2 of 1002%
Bootstrap or configuration request only2 of 1002%
No matched advertising or social-provider request42 of 10042%

Joint result

Collection evidence and a visible choice interface appeared together on 5 sites

Separate fresh-session passes · descriptive, not a compliance test

Of the 54 sites with collection-endpoint evidence, 5 also showed a visible choice interface and 49 did not. A visible choice appeared on another 5 sites where no collection-endpoint match was observed. The full cross-tab is in the study appendix.

Control behaviour

We tested both choices on all 10 confirmed interfaces

20 separate fresh browser contexts

Each interface was tested twice: once for acceptance and once for rejection or an essential-only choice. A result counted as verified only when the intended click completed and the selected state remained observable after reload.

10/10 Accept choice completed and persisted
9/10 Restrictive choice completed and persisted
5/9 Strict ad-event match before choice and after restrictive reload

How to read these findings. These are technical observations, not findings of legal compliance. Request matching classifies destinations rather than complete payloads, and the request and interface checks used separate fresh sessions. “No interface confirmed” means none appeared in the retained ten-second screenshot. A repeated endpoint after a restrictive choice does not establish that refusal was ignored or that the same event, payload or identifier continued; one restrictive path remained technically unverified, not failed. Full detector rules, definitions and limitations appear in the study appendix.

Explore the full study tables and methodology

Consent detail

The detailed values behind the two concise consent findings shown above.

Recognised advertising or social collection-endpoint request match by manually confirmed visible consent-choice interface.
Endpoint-pattern match in untouched sessionInterface confirmedNo interface confirmedTotal
Observed54954
Not observed54146
Total1090100

Control-flow verification

Technical verification of accept and restrictive-choice flows across the ten confirmed visible consent interfaces.
Choice pathClick and persistence verifiedUnverified
Accept10/10 100%0/10
Reject or essential-only9/10 90%1/10 10%

Sample breadth

The sample was not limited to low-visibility websites

91 .com.au · 7 .com · 2 .health

After the sample was frozen, we checked each root domain in the Australian desktop database of Semrush Domain Overview. It returned an estimate for 98 of 100 sites. 15 were estimated to receive at least 100,000 Australian organic-search visits a month, while 25 were in the 10,000 to 99,999 band.

Observed technical signals by post-selection Semrush organic-search visibility band.
Estimated monthly organic-search visitsSitesMeasurement signalAd/social endpoint match
Below 1,000 or no reliable estimate2263.6% 14/2227.3% 6/22
1,000 to 9,9993878.9% 30/3850% 19/38
10,000 to 99,9992584% 21/2564% 16/25
100,000+15100% 15/1586.7% 13/15

This is a broad search-visibility proxy, not analytics-measured total traffic, revenue, patient volume or business size. Semrush derives this Domain Analytics estimate from search positions, search volume and modelled click-through rates; its separate all-channel traffic product uses a different method. The first band combines 20 sites below 1,000 with two sites for which Semrush showed no reliable estimate. Visibility was never added to the anonymous row data because it would make re-identification easier. The band comparison is descriptive: it does not show that search visibility causes a tracking practice, and sector mix and other differences were not controlled. Read Semrush's methodology distinction.

Sector view

Ten sites in each predefined sector

Counts are shown with a fixed denominator of ten, so no small subgroup is exposed.

Observed technical signals by healthcare sector. Each sector contains ten websites.
Healthcare sectorMeasurement signalAd/social endpoint matchVisible choice interfacePrivacy link
Community and online pharmacy100% 10/1090% 9/1020% 2/10100% 10/10
Cosmetic medicine and dermatology60% 6/1020% 2/100% 0/1050% 5/10
Dental90% 9/1060% 6/1010% 1/1070% 7/10
Diagnostic imaging and pathology80% 8/1060% 6/1010% 1/1090% 9/10
Fertility and reproductive health100% 10/1070% 7/1020% 2/1090% 9/10
General practice70% 7/1020% 2/1010% 1/1060% 6/10
Physiotherapy60% 6/1060% 6/100% 0/1080% 8/10
Psychology and mental health90% 9/1050% 5/1020% 2/1070% 7/10
Specialist medicine60% 6/1030% 3/100% 0/1070% 7/10
Telehealth and digital health90% 9/1080% 8/1010% 1/1080% 8/10

Technology view

Known provider signals observed

Observed platform use, not privacy awareness or control maturity.

Google Tag Manager60%
Google Analytics77%
Google Ads42%
Meta Pixel39%
TikTok Pixel5%
LinkedIn Insight Tag7%
Pinterest Tag3%
Snap Pixel4%
Microsoft Advertising UET19%
Microsoft Clarity17%
Hotjar7%
HubSpot tracking1%

Session replay needs separate scrutiny. Microsoft Clarity signals appeared on 17 sites and Hotjar signals on 7. These tools can reconstruct page journeys and interactions, but we did not access customer dashboards or inspect recording and masking settings. The figures must not be added together because a site may use both.

Absence is not assurance. Meta Pixel appeared on 39 sites. The others may simply not advertise on Meta, may trigger it only on another page or action, or may use measurement our homepage check could not observe. Provider percentages are not measures of privacy awareness, control maturity or compliance.

Privacy-protected row data

100 anonymous website observations

Release-specific random IDs cannot be mapped back through the public dataset.

We publish no organisation name, domain, initial, location, sector or provider fingerprint at row level. Each released four-field pattern is shared by at least three sites. Metrics for 1 row was suppressed because the combination was too distinctive. Do not attempt to infer or publish an organisation's identity from these observations.

View all 100 anonymous rows
Anonymous, release-specific site observations. Suppressed rows disclose no metric values.
Anonymous IDMeasurement signalAd/social endpoint matchVisible choice interfacePrivacy link
H-001NoNoNoYes
H-002YesYesNoNo
H-003NoNoNoYes
H-004YesYesNoYes
H-005NoNoNoYes
H-006YesYesNoYes
H-007YesYesNoYes
H-008YesYesNoYes
H-009YesYesNoNo
H-010YesYesNoYes
H-011YesYesNoYes
H-012YesYesNoYes
H-013NoNoNoNo
H-014YesYesNoYes
H-015YesYesNoYes
H-016SuppressedSuppressedSuppressedSuppressed
H-017YesYesNoYes
H-018YesNoNoYes
H-019YesYesYesYes
H-020YesYesNoNo
H-021YesYesNoYes
H-022YesYesNoYes
H-023YesYesNoYes
H-024YesNoYesYes
H-025YesYesNoYes
H-026NoNoNoYes
H-027YesNoNoNo
H-028YesYesNoYes
H-029YesNoNoYes
H-030YesNoNoYes
H-031NoNoNoNo
H-032YesYesYesYes
H-033YesYesNoYes
H-034YesYesNoYes
H-035YesNoNoYes
H-036YesYesNoNo
H-037YesYesYesYes
H-038YesNoNoYes
H-039YesNoNoYes
H-040NoNoNoYes
H-041YesYesNoYes
H-042YesNoNoYes
H-043YesNoYesYes
H-044YesYesNoYes
H-045NoNoNoNo
H-046NoNoNoYes
H-047YesNoNoYes
H-048YesNoNoNo
H-049YesYesNoYes
H-050YesYesNoYes
H-051YesNoNoYes
H-052NoNoNoYes
H-053YesYesNoYes
H-054YesNoYesYes
H-055YesYesNoYes
H-056NoNoNoYes
H-057NoNoNoYes
H-058YesYesNoYes
H-059YesYesNoNo
H-060YesYesNoYes
H-061NoNoNoYes
H-062YesYesYesYes
H-063YesNoNoYes
H-064YesYesNoNo
H-065NoNoNoNo
H-066NoNoNoNo
H-067YesYesNoYes
H-068YesYesNoYes
H-069YesNoNoNo
H-070NoNoNoYes
H-071YesNoNoNo
H-072YesYesNoNo
H-073NoNoNoYes
H-074YesYesNoYes
H-075YesYesNoYes
H-076YesYesNoYes
H-077YesYesNoYes
H-078YesYesNoYes
H-079YesNoNoNo
H-080YesYesNoNo
H-081YesNoNoYes
H-082YesNoNoNo
H-083YesYesNoYes
H-084NoNoNoYes
H-085YesYesNoYes
H-086YesNoNoNo
H-087YesYesNoYes
H-088YesYesNoYes
H-089YesYesYesYes
H-090YesNoNoNo
H-091NoNoNoYes
H-092YesYesNoYes
H-093YesYesNoYes
H-094YesYesNoYes
H-095YesYesNoNo
H-096YesYesNoYes
H-097YesNoNoYes
H-098NoNoNoNo
H-099YesNoNoYes
H-100YesNoYesYes

Methodology

How the snapshot was collected

Designed for reproducibility and conservative public disclosure.

The observed-page and classification stages are reproducible from the retained study files. The original candidate-discovery list, search sources, within-sector ordering rule and numbers screened or excluded were not retained. We therefore report those selection-stage counts as unknown and restrict every percentage to the selected 100 websites.

Sampling-flow record and material limitations.
Sampling stageWhat the record supportsWhat is not retained
Sector frameworkTen predefined sectors; ten final websites per sectorHow those sectors were prioritised relative to all healthcare categories
Candidate discoveryPurposive selection completed before the reported technical collectionCandidate list, discovery sources, ordering rule and screened total
Eligibility and exclusions100 unique root domains; all nine non-.com.au domains passed current Australian-facing QA; zero exact matches in the recorded current/former client-domain registerCandidate-level exclusion ledger and any unrecorded historical relationships
Final observed set100 public patient-facing root homepages; one per normalised domainCommon ownership across different domains was not tested
  1. Sample fixed before the reported collection. The non-random, fixed-quota design contains ten public patient-facing root domains in each of ten predefined sectors. The recorded design exclusions included clients, government services, public hospitals, directories, duplicate domains and inaccessible websites; the original rejected-candidate ledger does not survive.
  2. Visibility checked after selection. We then recorded Semrush Domain Overview's Australian desktop organic-search estimate for each root domain and grouped the results into four aggregate bands. These estimates did not influence which websites entered the study.
  3. We visited every homepage in a clean session. Browser instrumentation captured requests consistently during the initial six-second observation. We made no consent choice, completed no form and did not enter a booking flow, portal or authenticated area.
  4. We reviewed and tiered the technical evidence. We compared captured requests with published URL-pattern rules for common tag-management, analytics and advertising services. Advertising evidence was separated into collection endpoints, dedicated consent signalling and bootstrap/configuration loads. We also read linked privacy-page text for selected terms and provider names.
  5. We checked every retained consent screenshot by eye. In a separate clean-session pass, each homepage was left untouched for ten seconds in a 1,440 × 1,000 desktop viewport. We retained and manually inspected a screenshot for all 100 sites. The 13 automated candidates were additionally checked at original resolution; ten showed a visible visitor choice and three did not. No decision remained ambiguous.
  6. We tested each confirmed interface in two fresh contexts. One context followed the accept path and the other followed a reject or essential-only path. We retained evidence before the choice, after the click and after reload, and counted a flow only when the click and persisted state could be technically verified.
  7. Identity separation. Raw URLs, request logs, titles and the private ID key are excluded from the repository and public files. Public sector cells contain ten sites; anonymous rows omit sector, visibility and other quasi-identifiers and use a minimum signature group of three.

The sample is purposive, not random or representative of every Australian healthcare website. Results can change by device, location, campaign source, previous consent, tag configuration and time. Browser-assisted review can miss custom or delayed technology, and a matched resource does not establish that personal information was ultimately transmitted. Medical Marketing Group funded, designed and conducted the study, provides paid healthcare marketing and tracking-audit services, and may benefit commercially from interest in this topic.

How to cite

Suggested citation: Medical Marketing Group, Australian healthcare website tracking benchmark 2026, version 2.1.0, observed 19 August 2026. Please link to this article when quoting or reusing the results.

How to read the results

The primary 54/100 result is deliberately narrower than a general detector count. Across 58 sites, the browser contacted a recognised advertising or social provider. We classified the strongest request evidence on each site: 54 matched a collection, conversion, activity or identifier-synchronisation endpoint pattern; two matched only a dedicated consent-signalling endpoint; and two loaded only a provider library, bootstrap or configuration resource. A further 22 sites showed other known measurement or tag-management signals, producing the broader 80/100 headline.

The consent review answered a separate question. We revisited every homepage in a clean session, waited ten seconds, retained a desktop screenshot and reviewed all 100 by eye. Ten showed a genuine visitor choice; 90 did not show one in that fixed window. The endpoint and interface observations came from separate fresh-session passes, so the 49-site cross-tab means only that collection-endpoint evidence appeared in one pass while no interface was confirmed in the other.

The policy figures are text checks, not adequacy scores. A provider may be described generically or addressed in another notice. Equally, not observing Meta Pixel or another platform on a homepage says nothing about the organisation's privacy awareness: it may not use that platform, may trigger it elsewhere, or may measure activity outside our detection rules.

How this study compares with the OAIC's 50-site scan

The OAIC scanned 50 health service provider websites in October and November 2024 and published its findings on 24 June 2026. Our study supplies a later healthcare-specific snapshot, but the samples and definitions differ.

StudyScopeSelected findings
OAIC scan50 health service provider websites; observed October-November 202496% used tracking technologies; 52% used a third-party pixel; 77% of pixel users did not mention that use in their privacy policy.
MMG benchmark100 selected homepages across ten sectors; observed August 202680/100 showed a known measurement or marketing signal; 54/100 matched a recognised ad/social collection-endpoint pattern; 10/100 showed a visible choice interface in the separate review.

These figures cannot show that tracking increased or decreased. The OAIC work explains the regulator's concerns; our benchmark provides current technical observations with exact denominators and privacy-protected anonymous row-level observations.

Why healthcare tracking deserves closer scrutiny

A healthcare website can reveal something sensitive before a patient types a word. A visit to a fertility page, mental-health service, cancer treatment page or booking journey may carry meaning when a URL, device details, advertising identifiers or event names reach another party.

Page context can be data

“Pixel” is shorthand for several browser and server-side measurement techniques. A webpage or tag manager can load code that creates an event containing some combination of the page URL, timestamp, network and device attributes, cookies, campaign parameters and custom fields. A platform may then connect that event with an account, advertising profile or earlier activity.

The OAIC's guidance says technical and inferred information can be personal information when it can be linked or matched with other information. A deterministic hash of an email address or phone number changes its format, but it can still be used for matching. Similarly, seeing a tag-manager script proves only that the container loaded; the live requests, consent state and destination logs show what actually happened.

Session replay needs its own review

We observed Microsoft Clarity signals on 17/100 homepages and Hotjar signals on 7/100. The figures should not be added because a website may use both. These tools can reconstruct navigation, clicks, scrolling and mouse movement. Microsoft says Clarity masks inputs in every masking mode; Hotjar says keyboard input is suppressed by default but can be allowed. We did not access customer dashboards or inspect individual recordings.

Typed text is not the only concern. A condition-specific URL, page sequence or booking action may reveal a healthcare journey even when form fields are masked. A useful review therefore covers route exclusions, URLs and referrers, DOM and image suppression, consent state, custom identifiers, retention and staff access.

What the OAIC's 2026 decisions mean for healthcare websites

The two determinations, [2026] AICmr 40 and [2026] AICmr 41, concerned a fertility service and a telehealth service. On the facts described by the Commissioner, third-party tracking technologies disclosed website interaction information and enabled platforms to distinguish or individualise visitors. The Commissioner found breaches of APPs 3, 5 and 7. The orders required the providers to cease the identified conduct, implement consent, notification and governance measures, and destroy relevant sensitive information in provider dashboards where legally permitted. No financial penalty was imposed in either determination.

The Privacy Act does not impose a blanket pixel ban

The OAIC is explicit that the Privacy Act 1988 does not prohibit tracking pixels. The question is how the actual implementation interacts with the Australian Privacy Principles. The most relevant issues commonly include:

  • APP 3: whether collection is reasonably necessary and whether valid consent is required for sensitive information.
  • APP 5: whether reasonable steps notify people about the collection at the relevant time. A privacy policy is not, by itself, a substitute for that notice.
  • APPs 6 and 7: whether the use or disclosure is permitted, including the consent requirement for using or disclosing sensitive information for direct marketing.
  • APP 8: the position where information is disclosed overseas.

Where sensitive information is likely to be collected or disclosed through a third-party pixel, the OAIC says organisations should generally seek express opt-in consent. A banner alone does not prove that consent is informed, voluntary, current and specific, or that the implementation honours acceptance, refusal and withdrawal.

Platform rules are a separate test

Meta's Business Tools terms restrict customers from sending health and other sensitive information through its tools. Google's personalised advertising policy treats health as a sensitive interest category and restricts advertiser-curated audiences. Visitor consent may not cure a prohibited data category under a platform contract.

The Commissioner's individualisation reasoning may be tested in later review or court proceedings. That uncertainty reinforces the need to assess the organisation's actual data and purposes rather than treating this study, a generic banner or a vendor setting as a legal answer.

What healthcare organisations should do now

Start with the data flow, not the logo on the tag. Four questions quickly separate routine measurement from higher-risk activity:

QuestionLower-risk directionEscalation signal
Where did it happen?Generic corporate contentCondition, treatment, booking, portal or confirmation page
What was included?Coarse, minimised measurementFull URLs, form values, searches, identifiers or health-related parameters
Who received it, and why?Documented measurement purposeAudience building, profile matching, cross-site advertising or vendor use
What control did the visitor have?Relevant tags follow a clear, tested choiceLive behaviour and the notice or control do not align

This is a triage model, not a safe harbour. A practical review should:

  1. Capture the live journey. Test the homepage, sensitive routes and campaign landing pages in untouched, accept, reject and withdraw states.
  2. Inventory every route and recipient. Include tag managers, embedded booking tools, chat, call tracking, analytics, session replay, conversion APIs and server-side containers.
  3. Inspect the fields, not only the event name. Reconcile browser traffic with vendor diagnostics and account settings. Look for URLs, query strings, free text, appointment details, identifiers and automatic matching.
  4. Minimise before adding notices. Remove unused tags and parameters, exclude sensitive routes, separate essential functions from advertising, and consider whether a third-party pixel belongs on the journey at all.
  5. Make the words match the implementation. Align the consent interface, point-of-collection notice and privacy policy with actual data categories, recipients and purposes.
  6. Assign ownership and retest. Give each event an owner and review date, require change control, and bring the evidence to an Australian privacy lawyer.

Useful marketing measurement can continue with less data. Depending on the purpose, alternatives include first-party aggregate analytics, sensitive-route exclusions, contextual advertising, coarse conversion events, local campaign attribution, controlled reconciliation with bookings or calls, and server-side allowlists. Moving an event server-side improves control only if the underlying collection and disclosure have also been assessed.

Who owns the fix when an agency installed the tracking?

The OAIC says responsibility sits with the organisation seeking to deploy the third-party pixel. That does not mean the agency that touched a tag caused a problem, nor does it make every supplier responsible for systems outside its contract or access. Health service providers can be covered by the Privacy Act even when they are small businesses.

ScopeReasonable operational roleStill needs another owner
Channel-specific agency
For example, Meta Ads management
Document and configure the platform assets, events, audiences and parameters within scope; flag observed risks.Website code, tag manager, consent platform, booking tools and notices unless the contract includes them.
Website, tracking or full-service implementerImplement the approved design across systems it controls, maintain an inventory and test the relevant visitor states.The lawful purpose, notice and consent standard unless separately retained and qualified to advise.
Healthcare organisation and privacy lawyerThe organisation owns purpose, vendors and risk decisions; its lawyer advises on the legal position.They need accurate technical evidence from the people who control each system.

This is a practical governance allocation, not a statement of legal liability. Duties depend on the facts, contract, access and conduct. Where nobody has end-to-end visibility, the healthcare organisation should appoint one coordinator to reconcile supplier boundaries and retain the authority to pause a tag.

Bottom line: treat signals as questions, not verdicts

The practical value of the study is the gap between recognised advertising collection-endpoint pattern matches and visible visitor choice across these selected homepages. It gives healthcare organisations a clear reason to compare what their websites actually send with the purposes, controls and notices they have approved.

A cosmetic banner or policy update is not enough. The strongest response is a reproducible technical audit, a purpose-by-purpose decision, current platform-term checks and legal advice based on the real implementation.

Methodology, limitations and disclosure

Medical Marketing Group reviewed a non-random, fixed-quota sample of 100 selected Australian-facing healthcare homepages in fresh browser sessions. The primary result records requests matching published endpoint-pattern rules; it does not establish the complete payload, recipient use, consent validity, personal or sensitive information, or legal compliance. Banner visibility was tested separately in a ten-second desktop capture and can vary by device, location, timing, previous choices or later website changes. Only homepages and linked privacy pages were reviewed; forms, bookings, authenticated areas, server-side pipelines and platform accounts were outside scope. Policy results are text matches, not adequacy assessments. These findings describe the selected sites at the observation time and should not be projected to all Australian healthcare websites. MMG funded and conducted the study, sells healthcare marketing and tracking-audit services, and may benefit commercially from interest in the topic. No sampled organisation is identified or accused. The expanded research appendix records the tables, detector rules, sampling limits, corrections and citation details.

If you need a technical picture of what loads, when it loads and which fields appear to leave your website, talk to Medical Marketing Group about a healthcare tracking audit. Bring your privacy lawyer into the same process so the implementation and advice stay aligned.

General technical and regulatory information only. This is not legal advice, a legal opinion or a finding about any organisation. Laws, facts, contracts and technology configurations differ. Obtain advice from a qualified Australian privacy lawyer before acting on a compliance position. Medical Marketing Group provides technical auditing and implementation support, not legal services.

Frequently asked questions

Are tracking pixels illegal on Australian healthcare websites?

No blanket rule makes tracking pixels illegal. The OAIC says the Privacy Act does not prohibit them. The position depends on the information handled, purpose, necessity, notice, consent, disclosure, direct marketing obligations and actual configuration. Obtain advice on the organisation's facts.

Does a privacy policy make a healthcare tracking pixel compliant?

Not by itself. A policy supports transparency under APP 1, while APP 5 notification is a separate obligation. A policy also cannot cure unnecessary collection, invalid consent, an incompatible disclosure or a platform-contract problem. The words and implementation need to be assessed together.

Did the study include only small .com.au healthcare websites?

No. The sample contained 91 .com.au, seven .com and two .health domains. A post-selection Semrush check placed 15 sites in the 100,000-plus Australian monthly organic-search visibility band and 25 in the 10,000 to 99,999 band. These are modelled organic-search estimates, not total traffic or business-size measures.

What should a healthcare organisation check before deploying advertising tracking?

Map the pages, events, fields, recipients and purposes; inspect browser and server-side evidence; isolate sensitive routes; test untouched, accept, reject and withdrawal states; align notices with live behaviour; check current platform terms; assign owners; and obtain Australian privacy-law advice.

Partnered with the ad platforms. Integrated with the tools your clinic runs on.

Google Meta TikTok Shopify Semrush HotDoc Cliniko Halaxy Best Practice Medical Director Nookal Medirecords Klaviyo MailerLite Evermed GetScripted Sparrowhub ShiftCare Splose Zanda Health Coreplus HealthEngine HICAPS Mailchimp SmartRecruiters HealthShare