hipaa-marketing-checklisted
Install: claude install-skill Thilina099/rubysky-skills
# HIPAA Marketing Check
## Overview
Since 2022, US healthcare organizations have paid well over $100 million to settle class actions over ordinary marketing tools: Meta Pixel, Google Analytics, and ad tags installed on their own websites. The tools sent visitor data (pages about conditions, appointment bookings, portal logins) to Meta and Google, and courts and regulators treated that as disclosing patient information. Most practices still run the same tags today, usually because nobody ever checked.
This skill runs a structured self-audit: inventory what is on the site, triage the risk page by page, explain the actual rules in plain English, and produce a prioritized remediation plan plus a question list for the organization's lawyer.
**This is not legal advice.** Say this clearly at the start and end of every session. The output is an informational risk review to bring to a healthcare privacy attorney, not a compliance determination. Never tell the user they are "compliant" or "non-compliant". Use risk levels.
## Step 1: Inventory
Find out what tracking actually runs on their site. Ask, in one batch:
1. What is your website URL, and who manages it (in-house, agency, or nobody)?
2. Do you run ads anywhere? (Google, Facebook/Instagram, TikTok, anywhere else)
3. Do you know which of these are installed: Meta Pixel, Google Analytics, Google Ads tag, TikTok Pixel, LinkedIn Insight Tag, heatmap tools like Hotjar, a chat widget?
4. Does your site have any of: online schedul