LinkedIn Ads aren't HIPAA-compliant out of the box.

LinkedIn, with its vast community of self-reported professional information, provides marketers a unique opportunity to target business professionals. However, recent lawsuits surrounding healthcare-related digital advertising have raised concerns about using social media platforms to engage audiences.

Like other digital advertising platforms—such as Facebook Ads, Bing Ads, and Google Ads—LinkedIn Ads can present compliance risks for healthcare-focused campaigns. The issue stems from how tracking technologies, like the LinkedIn Tag, may combine visitor identifiers with protected health information (PHI), potentially violating HIPAA regulations.

Challenge

Preventing the LinkedIn Tag from sending protected health information

Solution

Salesforce Data Cloud, a HIPAA-compliant customer data platform (CDP)

Results

HIPAA-compliant marketing on LinkedIn Ads


A recent bulletin from the Department of Health and Human Services (HHS) on tracking technologies underscores the seriousness of this issue, offering healthcare advertisers two high-stakes choices. They can immediately stop all advertising campaigns on LinkedIn, or risk huge financial fines.

Navigating these challenges requires healthcare marketers to prioritize compliance by assessing their tracking technologies, ad strategies, and data practices carefully.

Solving the Use Case

To our knowledge, LinkedIn will not sign a Business Associate Agreement (BAAs) with healthcare advertisers. As a result, healthcare companies must not pair protected health information (PHI) with LinkedIn conversion events. The standard for what passes as "PHI" is a low bar. PHI can include any content on a website that reveals a visitor’s intent related to a healthcare condition or service.

That means that PHI isn't just what users submit on web forms. It's located in URLs, page titles, content, and any visible data on the page. LinkedIn Ads enables visitor tracking through the "LinkedIn Tag," a snippet of javascript code that sends visitor behaviors back to LinkedIn. The tag gathers two key things to measure ad conversions: user identifiers and content identifiers. This information helps marketers measure ad performance – unfortunately, it also pairs user identifiers with PHI.

The LinkedIn Tag identifies users with the following data point:

The LinkedIn Tag also identifies the content driving a conversion with the following parameters:

Each LinkedIn Tag parameter helps marketers identify the who and where of ad conversions, enabling precise performance tracking. Keeping LinkedIn conversion data is crucial for measuring campaign performance. However, pairing sensitive information from the URL and page title with identifiable information is a potential HIPAA violation. To maintain HIPAA compliance when using LinkedIn Ads, it's vital to redact any protected health information (PHI) from parameters such as url or pageTitle.

Here is a diagram to explain:

HIPAA Compliant LinkedIn Ads

To be compliant, healthcare companies need an intermediary to bridge the gap between their websites and platforms like LinkedIn. Recently, the Department of Health and Human Services advised marketers that they could safeguard PHI in a customer data platform (CDP). Salesforce Data Cloud is a leading CDP that will enter into Business Associate Agreement (BAA) with covered entities, establishing a compliant way to manage healthcare data with user identifiers collected from the LinkedIn tag.

The Platform

To ensure HIPAA compliance with LinkedIn Ads, Penrod sets up a secure server-side container for processing data. This data can then be stored in a Customer Data Platform (CDP) like Salesforce Data Cloud for measurement.

The resulting platform architecture for addressing the HIPAA-compliant LinkedIn Ads use case looks like this:

HIPAA compliant LInkedIn Ads with a Customer Data Platform

This ensures that user identifiers are never combined with PHI, helping healthcare companies to launch successful LinkedIn marketing campaigns.

Redacted PHI

Retained Conversion Data

Compliant Ads

Request Free Consultation

Need redacted phi, retained conversion data, compliant ads, and a partner who can help?

We're here for you. Fill out the form on the right for a free consultation!

 
By submitting this form, you confirm that you have read and agree to the Penrod privacy policy.