loader from loading.io

Episode 625: Google Analytics for Therapy Practice Websites – The HIPAA Risks Explained

Group Practice Tech

Release Date: 08/21/2026

Episode 625: Google Analytics for Therapy Practice Websites – The HIPAA Risks Explained show art Episode 625: Google Analytics for Therapy Practice Websites – The HIPAA Risks Explained

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we unpack the reasoning, step by step, behind PCT’s position on Google Analytics for therapy practices. We discuss: Can website activity constitute Protected Health Information? HIPAA’s definition of healthcare operations vs. HIPAA’s definition of marketing Business Associates, and how there is no BAA available for Google Analytics The disclosures required for HIPAA authorization for marketing activity Cases where collecting PHI without a BAA has gone...

info_outline
Episode 624: The Math Has to Math: Building a Sustainable, Profitable Group Practice in 2026 — with Julie Herres of GreenOak Accounting show art Episode 624: The Math Has to Math: Building a Sustainable, Profitable Group Practice in 2026 — with Julie Herres of GreenOak Accounting

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat with Julie Herres of GreenOak Accounting about how there’s still good money to be made in private practice, and what you need to know to make it. We discuss: Profitability and intentionality, and what it takes to stay on track Rate changes and cost of living changes impacting group practices How Julie would respond to practice owners who are feeling the squeeze right now Setting up the financials for a healthy practice Compensation for pre-licensed...

info_outline
Episode 623: Now You Can Secure Outbound Email in Google Workspace show art Episode 623: Now You Can Secure Outbound Email in Google Workspace

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have an exciting update about how to make your Google Workspace email HIPAA-secure. We discuss: The encryption mechanism, TLS, and how it fits into HIPAA Security Rule standards Ways that behavioral health practices typically manage email security Escrow style email The transmission security standard under HIPAA Google’s transparency report about safer email HIPAA-friendly conventional email vs. HIPAA secure email Two limitations to be aware of and a...

info_outline
Episode 622: Must You Complete the Note Before Submitting the Claim? Fraud, Mistakes, and the Rules That Actually Apply show art Episode 622: Must You Complete the Note Before Submitting the Claim? Fraud, Mistakes, and the Rules That Actually Apply

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we debunk myths around documentation and fraud with Dr. Maelisa McCaffrey. We discuss: A recent article that is causing concern about whether submitting insurance claims before notes are complete constitutes fraud Fraud vs. mistakes, and consequences for mistakes in billing What constitutes fraud under the False Claims Act, with context from Eric Ström, HIPAA and mental health law attorney and practicing clinician Whether there are rules about when notes...

info_outline
Episode 621: Beyond CBT, Documenting the Therapy You Actually Practice with Dr. Maelisa McCaffrey show art Episode 621: Beyond CBT, Documenting the Therapy You Actually Practice with Dr. Maelisa McCaffrey

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we chat with Dr. Maelisa McCaffrey about how to properly document your therapy sessions. We discuss: Normalizing why documentation is such a struggle for clinicians Dispelling the myth that it is necessary to translate what you’re doing into CBT language for insurance reimbursement and why The danger of only considering insurance when documenting Documenting what actually happened in session Acknowledging that progress notes are never going to fully...

info_outline
Episode 620: Choosing the Right Business Entity for Your Practice: LLCs, PLLCs, PCs & S-Corps Explained (with Dan Pepitone) show art Episode 620: Choosing the Right Business Entity for Your Practice: LLCs, PLLCs, PCs & S-Corps Explained (with Dan Pepitone)

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we interview attorney Dan Pepitone about how to choose the right business entity for your group practice.  We discuss: Building a strong business foundation to reduce risk and exposure to liability The distinctions between different business entities, and tax implications for each Why some states like New York and California require behavioral health care providers to practice under a professional entity like a PC or PLLC When you need to register your...

info_outline
Episode 619: Public Wi-Fi: Is It Still a Security Risk? What Therapists Need to Know About Untrusted Networks show art Episode 619: Public Wi-Fi: Is It Still a Security Risk? What Therapists Need to Know About Untrusted Networks

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share what you need to know about public wi-fi networks & the security risks they pose to your devices and information.  We discuss: The difference between privacy and security How the risks posed by public wi-fi networks have changed over time What security risks public wi-fi networks actually pose to your device How to use a risk analysis lens to put simple, accessible safeguards in place  Listen here: For more,   Resources: ...

info_outline
Episode 618: HIPAA Security Rule Update: What We Know, What We Don't, and What You Should Do Right Now show art Episode 618: HIPAA Security Rule Update: What We Know, What We Don't, and What You Should Do Right Now

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we share what we know about the proposed HIPAA Security Rule and steps to take to safeguard your practice in the meantime until we know more.  We discuss: The current status of the proposed HIPAA Security Rule How regulatory uncertainty does not equal security uncertainty Takeaways from OCR Director Paula Stannard’s comments at the National HIPAA Summit that give insight into the rationale behind the proposed rule Risk analysis, encryption, reasonable...

info_outline
Episode 617: CAQH is Now DataSpring: Why Therapists Should Pay Attention show art Episode 617: CAQH is Now DataSpring: Why Therapists Should Pay Attention

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have an important update for practice owners who bill insurance. We discuss: Why the change from CAQH to DataSpring is not just an administrative rebrand, as DataSpring is trying to position it Why this change is a big deal for practice owners who bill insurance  The action steps recommended by The Group Practice Exchange Additional PCT-recommended action steps Who owns the infrastructure that healthcare depends on? Looking at this change from a risk...

info_outline
Episode 616: Licensure Compacts & Portability Update show art Episode 616: Licensure Compacts & Portability Update

Group Practice Tech

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech. In our latest episode, we have exciting updates for cross-jursidictional and multi-jurisdictional practice. We discuss: The Counseling Compact, and the states in which it is live The ETA for the Social Work Licensure Compact going live Access MFT’s licensure portability effort Portability-friendly laws and how they differ from rights for temporary practice PSYPACT updates Physical location restrictions and requirements for providers under compacts Details of our upcoming CE...

info_outline
 
More Episodes

Welcome solo and group practice owners! We are Liath Dalton and Evan Dumas, your co-hosts of Group Practice Tech.

In our latest episode, we unpack the reasoning, step by step, behind PCT’s position on Google Analytics for therapy practices.

We discuss:

  • Can website activity constitute Protected Health Information?
  • HIPAA’s definition of healthcare operations vs. HIPAA’s definition of marketing
  • Business Associates, and how there is no BAA available for Google Analytics
  • The disclosures required for HIPAA authorization for marketing activity
  • Cases where collecting PHI without a BAA has gone awry
  • The risk context in an increasingly AI world
  • The takeaway: is it permissible for therapy practices to use Google Analytics on their practice websites?
  • Uniting as an industry to demand BAAs for Google Analytics

Listen here: https://personcenteredtech.com/group/podcast/

For more, visit our website.

PCT Resources

  • Marketing in Mental Health: The Legal and Ethical Do’s and Don’ts You Need to Know — This 3 legal-ethical CE credit hour on-demand training, presented by therapist and HIPAA attorney Eric Ström, JD PhD LMHC, unpacks the legal and ethical standards that apply to marketing in mental health practice, with particular attention to HIPAA marketing requirements, Business Associate Agreements (BAAs), authorizations/ROIs, advertising, referrals, reviews, and endorsements.
  • Group Practice Care Premium
    • weekly (live & recorded) direct support & consultation service, Group Practice Office Hours — including monthly session with therapist attorney Eric Ström, JD PhD LMHC
    • Device Security Suite: assignable staff HIPAA Security Awareness: Bring Your Own Device training + access to Device Security Center with step-by-step device-specific tutorials & registration forms for securing and documenting all personally owned & practice-provided devices (for *all* team members at no per-person cost)
    • Remote Workspace Security Suite: assignable staff HIPAA Security Awareness: Remote Workspaces training for all team members + access to Remote Workspace Center with step-by-step tutorials & registration forms for securing and documenting Remote Workspaces (for *all* team members at no per-person cost) + more
  • HIPAA Risk Analysis & Risk Mitigation Planning service for mental health practices — care for your practice using our supportive, shame-free risk analysis and mitigation planning service. You’ll have your Risk Analysis done within 2 hours, performed by a PCT consultant, using a tool built specifically for mental health practice, and a mitigation checklist to help you reduce your risks.
  • PCT’s Comprehensive HIPAA Security Compliance Program (discounted) bundles:
    • For Group Practices
    • For Solo Practitioners
      • Comprehensive HIPAA Security Policies & Procedures
      • Forms & Logs for documenting implementation and maintenance of Policies & Procedures in practice
      • Device & Workspace Security Suites
      • Direct Support & Consultation from PCT team + therapist attorney Eric Ström, JD PhD LMHC (live & recorded + searchable library)
      • Includes the Risk Analysis & Risk Mitigation Planning service + tool
    • HIPAA Security & Privacy Ethics training

Resources

  • HHS Office for Civil Rights: Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates — OCR’s current guidance on how the HIPAA Privacy, Security, and Breach Notification Rules apply to website and app tracking technologies. It addresses when website activity may constitute PHI, tracking on authenticated and unauthenticated webpages, Business Associate Agreements, marketing disclosures, HIPAA authorization, and risk analysis.
  • Google: HIPAA and Google Analytics — Google’s own guidance for HIPAA-regulated organizations. Google states that regulated entities must not expose Google Analytics to PHI and that Google does not offer Business Associate Agreements for Google Analytics.
  • American Hospital Association v. Becerra — June 20, 2024 Court Decision — The federal court decision that partially vacated OCR’s tracking-technology guidance regarding an IP address combined with a visit to an unauthenticated health-related webpage. The decision is important for understanding what may—and may not—constitute individually identifiable health information in the context of website tracking.
  • HHS: Business Associates — HHS guidance on when a person or company becomes a HIPAA Business Associate, including when a vendor performs data analysis or other functions involving PHI on behalf of a covered entity.
  • HHS: Marketing and the HIPAA Privacy Rule — Guidance on HIPAA’s specific definition of marketing, the exceptions to that definition, and when written individual authorization is required for uses or disclosures of PHI for marketing.
  • FTC: BetterHelp Health Data and Advertising Enforcement Action — The FTC’s action concerning BetterHelp’s disclosure of sensitive consumer health information to third parties for advertising purposes. Importantly, this was FTC consumer privacy enforcement, not HIPAA enforcement, but it provides a real-world example of the risks associated with health-related information flowing into advertising and tracking ecosystems.