For agencies running practice clients

Optimize on the consult that was booked, without sending anything about the patient.

This page is for paid media agencies whose clients are dental, med spa, aesthetic or chiropractic practices. The work is connecting the practice management or booking system back to Google Ads and Meta so campaigns optimize on booked consults, with a payload that carries no health information. It goes out under your agency's brand.

I don't claim HIPAA compliance. Details below.

What travels to the ad platform, and what never does

Travels

  • That a consult was booked, and when
  • Which click it came from
  • A stage name the practice chose, written in neutral language
  • A value, when the practice is willing to state one

Never travels

  • The procedure, treatment or service the patient asked about
  • Any condition, diagnosis or symptom
  • Anything from a patient record, intake form or clinical note
  • Conversion or audience names that imply a health condition

This is also where a lot of practice accounts are already exposed: a conversion action named after a procedure, or an audience built from a treatment page, puts the sensitive part into the ad platform without anyone deciding to. That is one of the first things a teardown looks for.

Why do practice campaigns drift toward the wrong patient?

Because the form is the only outcome the platform sees. A practice has a consult calendar, a show rate and a treatment plan, and none of those reach the ad account. The algorithm optimizes for people who fill in forms, and the front desk absorbs the difference: more calls, fewer of them worth calling back.

Sending back "consult booked" changes what the campaign is trying to produce, without telling the platform anything about the person.

Questions agencies ask

Is this HIPAA compliant?
I don't make that claim and you shouldn't repeat it on my behalf. Fiori holds no HIPAA certification. What I can describe is what the build does: it sends the fact that a consult was booked, tied to a click, with no treatment, condition or patient detail attached. Whether that meets your client's obligations is a question for their counsel.
So what actually goes to Google and Meta?
A conversion at a stage the practice chose, usually 'consult booked' or 'consult attended', with the click it came from and, optionally, a value. Nothing describing why the patient came in.
Can the practice still use value-based bidding?
It can send a value, as long as the value doesn't encode the procedure. A single blended figure per booked consult keeps the signal useful and the payload neutral.
What do the platforms themselves say?
Meta's Business Tools Terms state that you must not share Business Tools Data that includes or is based, directly or indirectly, on health or financial information or other sensitive categories. Google's personalized advertising policy treats health as a sensitive interest category and restricts the audience and personalization features that can be used with it. Both are linked at the bottom of this page. Read them with your client's counsel.
Who signs what?
An NDA with your agency before any access. If your client's legal team requires a DPA, or anything more specific to their sector, that's between them and you. I'll sign whatever the engagement needs.

On compliance. Fiori Analytics does not claim HIPAA compliance and holds no such certification. Nothing on this page is legal advice. Every practice sits under obligations that depend on its jurisdiction, its services and its own agreements. Validate the approach on this page with your client's legal counsel before you implement it.

Platform policies

Read on September 23, 2026. These are the platforms' own rules, not a summary of anyone's legal obligations. Policies change, so check the source before you quote it to a client.

This is not legal advice.

Send me one practice site.

The teardown shows what their tracking is sending today, including anything sensitive that shouldn't be leaving the site at all.

Get a free teardown