On March 18, 2024, OCR revised its guidance on “Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates” to remind regulated entities and the public that the use of online tracking technologies is subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules (“HIPAA Rules”). These online tracking technologies, like Google Analytics or Meta Pixel, collect and analyze information about how users are interacting with a regulated entity’s website or mobile application.