Session Replay on Patient Portals: The Highest-Risk Setup in Healthcare
Of all the ways to get website tracking wrong, running session replay in healthcare on a patient portal is the single most dangerous. Behind a login, the visitor isn't anonymous — they're a known patient, and everything they do is protected health information. A replay tool recording that session sends a video-like reconstruction of a patient's private medical activity to a third-party vendor. And the 2024 court ruling that healthcare marketers keep citing as relief? It doesn't reach the portal at all.
Key takeaways
- The patient portal is the worst place for session replay. It's authenticated, so the patient is known and their every click, keystroke and message is protected health information.
- The 2024 court win doesn't save you. AHA v. Becerra vacated OCR's tracking guidance only for unauthenticated public pages. Authenticated portals were never in dispute — they remain fully covered.
- Replay is far worse than a pixel. A pixel logs that a page was visited; replay records the actual content — messages, medications, symptoms typed into forms.
- Most replay vendors won't sign a BAA. Hotjar and Microsoft Clarity don't; sending PHI to a vendor without one is an impermissible disclosure.
- The real risk is the stack. HIPAA-derivative class actions, CIPA wiretapping, and state health-data laws — not just OCR fines — and the 2026 wave targets smaller providers too.
What this guide covers
Why the patient portal is the worst place for session replay
Session replay tools — Hotjar, Microsoft Clarity, FullStory and the rest — record a visitor's session as a playable, video-like reconstruction: mouse movements, scrolls, clicks, keystrokes, and everything typed into forms. On a marketing site that's a useful way to see where visitors get stuck. On a patient portal, it's something else entirely.
The reason is authentication. A patient portal sits behind a login, which means the person on the other side isn't an anonymous web visitor — they're an identified patient. When a replay tool records their session, it captures a known individual reading their lab results, messaging their doctor about symptoms, refilling a prescription, or booking an appointment for a specific condition. Under HIPAA, individually identifiable information tied to someone's health is protected health information (PHI) — and on a portal, essentially everything the patient does qualifies. The recording is then stored on the replay vendor's servers, outside your HIPAA boundary. That transfer, to a vendor without a Business Associate Agreement, is the disclosure that becomes a violation.
This is why healthcare privacy specialists are close to unanimous on one point: don't run session replay in authenticated areas — patient portals, logged-in dashboards, anything behind a sign-in — unless you're using a HIPAA-eligible product under a signed BAA with verified safeguards. The convenience of seeing how patients navigate the portal is not worth turning their private medical activity into a third-party recording.
"But didn't a court strike down the tracking guidance?"
If you work in healthcare marketing, you've probably heard some version of good news in 2024: a federal court struck down OCR's website-tracking guidance, and the government dropped its appeal — so tracking is fine again. That's partly true, and it's the most dangerous half-truth in healthcare privacy right now, because the part that got struck down has nothing to do with your patient portal.
Here's what actually happened. In American Hospital Association v. Becerra (2024), a court vacated the most aggressive part of OCR's tracking bulletin — the theory that an IP address on an unauthenticated, public page (a general health blog, say) could automatically be PHI. OCR later withdrew its appeal, giving covered entities real clarity that ordinary trackers on public pages don't automatically trigger HIPAA. Genuine relief — for public pages.
There's a second reason not to lean on the ruling: even for public pages, OCR's guidance remains the baseline courts reference when deciding whether a covered entity "knew or should have known" its trackers were transmitting PHI. And regulatory enforcement was never the main financial threat anyway — as we'll see, that's shifted decisively to private lawsuits.
Why session replay is worse than a pixel
Most of the healthcare tracking coverage you'll find focuses on advertising pixels — the Meta Pixel, Google tags. Those are a real problem, but session replay on a portal is a categorically bigger one, and it's worth being precise about why.
A tracking pixel typically reports metadata: that a particular page was visited, by a device with a certain IP, at a certain time. That's damaging enough when the page reveals a health context. Session replay reports the content itself. It doesn't just record that a patient opened the secure-messaging page — it can capture what they typed: the symptom they described, the medication they asked about, the diagnosis in the message thread. It's the difference between a log saying "someone entered the building" and a camera recording everything they said inside.
And the safeguard everyone reaches for — input masking — is far less reliable than vendors imply. Masking depends on correctly identifying every sensitive field, and portals are full of fields that masking rules miss: a free-text message box, a custom date-of-birth picker, a third-party intake plugin, a dynamically loaded form. Investigators have repeatedly caught replay tools capturing supposedly "masked" data across industries. One unmasked field is all it takes to ship typed PHI to a vendor's servers — which is why masking is a necessary control but not a sufficient one, and why "we turned on masking" is not a defense you want to rely on for a patient portal.
The tools, and the BAA reality
Under HIPAA, any vendor that receives PHI on your behalf is a business associate and must sign a Business Associate Agreement (BAA) and implement the Security Rule's safeguards. For the common replay tools, that requirement is where things fall apart — because most of them won't sign one for these products.
| Tool | Signs a BAA? | Verdict for patient portals |
|---|---|---|
| Microsoft Clarity | ✗ No | Keep off portals. It's free because it feeds behavioral signal into an advertising ecosystem — which makes "free" an aggravating factor, not a mitigating one. |
| Hotjar (Contentsquare) | ✗ No (standard products) | Keep off portals. No BAA means no lawful way to disclose PHI to it. |
| FullStory | ✅ HIPAA-eligible, will sign | The one that can be used — but a BAA alone isn't enough. You still must verify masking, scoping and retention, and keep replay narrowly limited. |
| Google Analytics / Meta Pixel | ✗ No (these products) | Not for patient-facing pages that can capture PHI. |
The pattern is clear: a BAA is the floor, not the ceiling. Hotjar and Clarity don't clear the floor at all for portal use, so they simply shouldn't run in authenticated areas. FullStory can clear it — but a signed BAA doesn't excuse you from verifying, on the live portal, that sensitive fields are actually masked, that replay is scoped to the narrowest UX question, and that retention is limited. We go deeper on the tool-by-tool GDPR and CIPA picture in session replay under CIPA and session replay under GDPR.
Is a replay tool running on your portal right now?
Most portal trackers are added once and forgotten. See which third-party trackers and replay tools fire on your site — before consent — in about 10 seconds, no account.
Scan your site free →The real risk isn't just OCR — it's a stack of laws
Here's a shift that changes how you should think about this. If you were mentally filing "portal tracking" under "OCR might fine us," you're looking at the smaller threat. OCR's pixel enforcement has actually slowed, and 2026 HIPAA settlements have mostly centered on breaches and failed risk analyses rather than trackers. The financial danger has moved somewhere with far less friction: private lawsuits, stacked across several legal theories at once.
Two things make this stack especially dangerous for portals. First, the theories combine — a single deployment can draw a HIPAA-derivative claim, a CIPA claim, and a state-law claim from the same facts. Second, the 2026 wave is targeting smaller operators: the earliest cases hit the largest health systems, but plaintiff firms have expanded to mid-sized clinics, practices and digital-health companies. "We're too small to be noticed" is no longer true. You can watch the wiretapping side of this develop on our CIPA Lawsuit Tracker, and we cover the "can I actually be sued?" question directly in can you be sued for a HIPAA tracking violation?
What to do instead
The good news is that the fix is clear and mostly about restraint. You don't need to solve an impossible problem — you need to keep replay out of the one place it's radioactive, and verify the rest.
What it means for your website
If you run any healthcare property with a patient portal, the action item from this guide is refreshingly concrete: get session replay off every authenticated page, and don't be reassured by the 2024 court ruling. That ruling helped with public pages; it did nothing for the portal, which is exactly where replay turns a patient's private medical activity into a third-party recording.
The broader lesson of session replay in healthcare is that the sensitivity of the data raises the stakes on everything. A misconfigured tracker that would be a minor issue on an e-commerce site becomes a multi-million-dollar class action when the visitor is an identified patient. The organizations that stay out of trouble aren't the ones with the best legal disclaimers — they're the ones that keep the recording off the sensitive pages in the first place, and can prove what runs where. This is general information, not legal advice; confirm your specific obligations, BAAs and configurations with qualified counsel.
Frequently asked questions
Can I use session replay on a patient portal?
You should not use standard session replay tools like Hotjar or Microsoft Clarity on a patient portal or any authenticated page. Behind a login the patient is identified, so their session activity — messages, medications, symptoms typed into forms — is protected health information, and these tools won't sign a HIPAA Business Associate Agreement. Sending PHI to a vendor without a BAA is an impermissible disclosure. If you genuinely need to study portal UX, use anonymized, aggregate metrics or a HIPAA-eligible product under a signed BAA with masking, scoping and retention verified in practice. This is general information, not legal advice.
Didn't a court strike down the HIPAA tracking rules in 2024?
Only for unauthenticated pages. In American Hospital Association v. Becerra (2024), a court vacated the most aggressive part of OCR's tracking guidance — the theory that an IP address on a public, unauthenticated page is automatically PHI — and OCR withdrew its appeal. That gives real clarity for public pages. But the lawsuit was only ever about unauthenticated pages; authenticated patient portals were never in dispute, because a logged-in patient's activity is PHI by definition. So the ruling provides no protection for session replay on a portal, which is where the risk is highest.
Is Hotjar or Microsoft Clarity HIPAA compliant?
No. Neither Hotjar (now part of Contentsquare) nor Microsoft Clarity signs a HIPAA Business Associate Agreement for these products, so there's no lawful way to disclose PHI to them — which means they shouldn't run on patient portals or other pages that can capture protected health information. Clarity's free model is an aggravating factor rather than a mitigating one, since it feeds behavioral signal into an advertising ecosystem. Of the common replay tools, FullStory is HIPAA-eligible and will sign a BAA, but a BAA alone isn't sufficient — you still must verify masking, scoping and retention.
Why is session replay riskier than an advertising pixel?
Because it captures content, not just metadata. A tracking pixel typically reports that a page was visited, by a device with a certain IP, at a certain time. Session replay records the actual session — what the patient typed, the symptom they described, the medication they asked about, the message they sent their doctor. On a portal, that's a video-like reconstruction of a known patient's private medical activity. Input masking helps but is unreliable: one unmasked field — a free-text box, a custom date picker, a third-party plugin — ships typed PHI to the vendor's servers.
What are the real penalties for tracking on healthcare sites?
The biggest financial risk in 2026 is no longer mainly OCR fines — it's private lawsuits stacked across theories. Patients bring HIPAA-derivative class actions over disclosures to third parties, with reported settlements including $47.5 million and $1.8 million and analysts estimating over $5 million all-in for a serious incident at an average hospital. On top of that, California's CIPA carries statutory damages of $5,000 per violation under Cal. Penal Code §637.2, and state health-data laws like Washington's My Health My Data Act add their own private rights of action. The 2026 wave targets smaller providers, not just large systems.
How do I check what's running on my patient-facing pages?
Start with a full inventory, because trackers are usually added through a tag manager and then forgotten. A free scan loads your pages the way a visitor's browser does and lists the third-party trackers and replay tools that fire — including before consent — which is the exact behavior that drives the litigation. For authenticated portal pages, also review your tag manager and any scripts added outside it, and confirm no replay or non-BAA analytics runs behind the login. This is general information, not legal advice.
The bottom line
Session replay is a useful tool in the wrong place at the worst possible time when it runs on a patient portal. Behind a login, every action is a known patient's protected health information, and standard replay tools ship that content to vendors who won't sign a BAA — an impermissible disclosure with a stack of private-litigation theories waiting behind it.
The 2024 court ruling that healthcare marketers cite as relief applies to public pages and stops cold at the portal login. So the rule that actually protects you is simple and non-negotiable: no session replay in authenticated areas. Keep it off the portal, gate and verify trackers on your public pages, document your risk analysis, and you've removed the single highest-risk setup in healthcare tracking.
The organizations that avoid the settlement check aren't the ones with the best disclaimer — they're the ones that never recorded the session in the first place.
See what's running on your patient-facing pages
ConsentPixel — Privacy · Verified blocks session-replay tools before consent and shows exactly what fires on your live site — the prevention-and-proof layer around a compliant healthcare setup. Start with a free scan, then a 14-day trial.
Scan your site free →Information, not legal advice. This guide explains the risks of session replay on patient portals for general educational purposes and does not constitute legal advice or create an attorney–client relationship. Session-replay tools are lawful products; the risk described here arises from deploying them on authenticated, patient-facing pages that capture protected health information without appropriate agreements and safeguards. HIPAA obligations, Business Associate Agreements, and configurations depend on your specific circumstances — confirm them with qualified counsel. Facts, case references and settlement figures reflect publicly reported information as of September 2026 and may change. The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2. ConsentPixel — Privacy · Verified is not a law firm, and no single tool by itself makes a website compliant with any law, including HIPAA.