Healthcare marketing may be quietly going dark. On 2026-08-27 we tried to load the homepage of every US health system in the federal AHRQ Compendium, all 639 of them, and recorded what each one that loaded sent and to whom. 494 loaded for us. 143 of those, 28.9%, fired no ad pixel, no analytics and no session replay that we detected. At the same time, 170 systems with no public pixel-litigation record we could find sent requests to an advertising platform, and about half of the settled systems we could scan loaded a healthcare privacy vendor's collector.
This is a single scan, not a trend line: we have no earlier pass over this cohort. But for marketing, the dark 28.9% is the number that matters. If a quiet homepage means measurement stopped, a dark year writes no baseline, and a baseline is what budget defenses are made of.
This expands on the LinkedIn post where I first shared these numbers. The report, with the method, the exclusions and a receipt table for its headline figures, is free further down this page.
Key Takeaways
- We tried to load the homepages of all 639 US health systems in the AHRQ Compendium on one day. 494 loaded, 129 returned an HTTP block or timed out, and 16 failed for other reasons. Every whole-cohort share below is stated over the 494.
- 143 homepages (28.9%) fired no ad pixel, analytics, replay, privacy-vendor collector or first-party collection endpoint that we detected. If measurement is missing behind them too, so is the baseline for defending spend.
- 171 homepages (34.6%) sent at least one request to an advertising platform during our visit, and 170 of those systems have no public pixel-litigation record that we could find. For 18 of the 171, that request could also have come from an embedded YouTube player.
- None of the settled systems we could scan sent an ad-platform request from the homepage, and about half of them loaded a healthcare privacy vendor's collector. So far, what we can see lines up with the lawyer's letter rather than the policy memo.
- Consent mostly did not gate what we saw. Of the 283 homepages that fired analytics or ad tags, 250 did so with no banner present (194) or before our scanner clicked the banner (56).
- This is a record of what public homepages did on a stated date. It is not a compliance assessment of anyone, and it cannot see booking pages, portals, or server-side processing that leaves no trace in the browser.
What We Scanned, and What a Scan Like This Can See
The cohort is the AHRQ Compendium of U.S. Health Systems 2023. AHRQ defines a health system as at least one hospital and at least one group of physicians providing comprehensive care, connected through common ownership or joint management, and its 2023 list contains 639 of them. We did not choose which systems to look at, which is what makes the denominator worth something.
We loaded each homepage in a scripted real browser, took no consent action first, and recorded every network request it made against named tracker categories: ad pixels, analytics, session replay, privacy and server-side vendors, tag managers, call tracking, and first-party collection endpoints. We also recorded whether a consent banner appeared and what had already fired before our scanner clicked it.
| Scan outcome, 2026-08-27 | Systems | What we claim about them |
|---|---|---|
| Loaded (2 served a geo-block page and 1 a default web-server page) | 494 | Every whole-cohort share in this article is stated over these 494 |
| HTTP 403 or 429, or a timeout | 129 | Nothing, in either direction |
| Failed for other reasons (DNS, certificate, connection, HTTP 406 or 503) | 16 | Nothing |
The instrument is narrow, and it is worth saying how before any number lands. We scanned homepages only, and booking or condition pages may carry different tags. The scanner captured a few seconds after the page loaded and did not scroll or interact, so tags that load later can be missed. A system that collects on its own servers and forwards from there can look quiet from outside. A consent banner that loads after our capture window reads to us as absent. And the scan ran from a non-US network, so every figure describes what a non-US visitor saw on that date. A US-vantage rerun is planned and will be published as a comparison, not a replacement.
28.9% of Health System Homepages That Loaded Fired No Ad Pixel, Analytics or Replay We Detected
143 of the 494 homepages fired no ad pixel, no analytics, no session replay, no privacy-vendor collector and no first-party collection endpoint that our scanner looks for. If nothing is being measured behind them, that is not caution as far as marketing is concerned. It is blindness.
In some of those 143, machinery was still loading: 22 loaded a tag manager container, 4 a call-tracking script and 1 a customer-data platform, with no ad, analytics or replay tag firing. That can mean tags were removed, fire only on other pages or after consent, or moved server-side. One outside scan cannot tell which.
Here is why it matters to a marketing leader, whatever the reason. Removing tags may reduce legal exposure. For marketing, it can be a costly answer. Every month without on-site measurement is a month with no record of what a channel produced on the site, so the next time the budget is questioned there is little to compare against. Channel comparison, budget defense and the effect of any change made after the tags came off all get harder to answer, and nothing on the site looks broken while it happens.
We cannot tell from outside which of the 143 removed measurement, which moved collection somewhere we cannot observe, and which never measured on this page. That is exactly the question to ask internally: if our homepage went quiet, where is the baseline living now, and who can show it to me?
170 Systems With No Public Litigation Record We Could Find Sent Requests to an Ad Platform
At the other end of the spectrum, 171 of the 494 homepages (34.6%) sent at least one request to an advertising platform's domain during our visit, in 11 cases only after our scanner accepted a consent banner. 170 of those 171 belong to systems with no public pixel-litigation record that we could find. That record is a floor: we included a case only where we could cite a public source for that system, and sealed or unreported matters cannot be verified.
One caveat on the count. For 18 of the 171, the only advertising request went to DoubleClick hosts that an embedded YouTube player also calls, and our scanner recorded domains rather than full URLs. The number of homepages with a deployed ad pixel could therefore be as low as 153.
| What fired on the homepage | Systems | Share of 494 |
|---|---|---|
| Google Analytics 4 | 224 | 45.3% |
| Any advertising-platform request | 171 | 34.6% |
| Requests to Google Ads or DoubleClick domains | 165 | 33.4% |
| Server-side or privacy-vendor collector | 79 | 16.0% |
| Session replay | 52 | 10.5% |
| Adobe Analytics | 41 | 8.3% |
| Meta Pixel | 39 | 7.9% |
| None of the above, and no first-party collector | 143 | 28.9% |
A system can appear in several rows. In this scan the Meta Pixel was rare next to Google's tags: Google advertising domains appeared on a third of these homepages and GA4 on nearly half. We have no earlier scan of this cohort, so we cannot say how any of these shares moved.
Size tells a consistent story. Ad-platform requests fall as systems get larger: 43.1% of systems under 200 beds (n=123), 34.6% at 200 to 999 beds (n=246), and 25.6% at 1,000 beds and above (n=121). The Meta Pixel falls fastest, from 12.2% to 7.7% to 3.3%. Four scanned systems carry no bed count in the AHRQ record and sit outside the tiers. We can describe that gradient, but we did not test why it exists. Larger systems may be more likely to have in-house legal review, and may be more likely to run their own stack than inherit an agency's. Both explanations fit, and one scan cannot separate them.
What We Saw on the Settled Systems
We cross-referenced every system against the public pixel-litigation record we could source for it: settlements, suits filed, and reported tracking-technology breaches. The settled systems are the interesting group. Four of them returned HTTP 403 to our scanner, so we claim nothing about those.
Among the settled systems we could see, not one sent a request to Meta, Google Ads, LinkedIn, Bing or TikTok from its homepage. I went into that table expecting hypocrisy. The data said something more useful: on the homepage, the settled systems we could scan look different from everyone else.
The second observation is the one worth carrying into a planning meeting. About half of those settled systems were not quiet. They loaded a healthcare privacy vendor's collection endpoint, and none of them loaded an ad platform's pixel. What we saw is that vendor's domain in the browser, not a contract and not proof of where processing happens. For those systems the browser sent the request to the vendor rather than to an ad platform, and where the vendor forwards it is not something a browser scan can see. Either way, that is not the same as having stopped measuring. The rest of the settled systems we could scan either fired nothing we detected or ran analytics only.
Two readings are available here, and only one is supported. The supported one is narrow: on one day, on one page, systems that paid look different from systems that have not. The unsupported one is that a settlement fixes an organization's tracking. A homepage is plausibly among the cheaper surfaces to clean and the easier ones to audit, which may make it an early place to change and one that tells you little about what sits behind it.
None of this says any operator was non-compliant, then or now. A third-party pixel on a healthcare homepage is a fact about a web page, not a finding about a law.
Consent Mostly Did Not Gate What We Saw
283 of the 494 homepages fired analytics or advertising tags. 194 of them did so with no banner present, and 56 more fired before our scanner clicked a banner it could click, so 250 of the 283 fired ungated. Only 168 of all 494 homepages showed a consent banner or loaded a consent platform we could detect.
On two thirds of the homepages we loaded, our scanner detected no banner, which fits a notice approach rather than a consent approach. It matters for a measurement reason. If tags fire before a choice on some pages and after it on others, the analytics record for a single campaign is assembled under different rules across the same site, which downstream modeling can only partly correct.
The same holds for the systems that load a healthcare privacy vendor's collector. On 67 of the 68 systems where we detected the most common of those vendors, its collector fired before our scanner made any consent choice, and only 29 of those 68 showed a banner or loaded a consent platform we could detect (25 with a visible banner). The browser request goes to the vendor rather than an ad platform, but on the homepages we loaded, the gate mostly was not there either. Both figures lean one way: a late banner or gating inside a tag manager can look ungated from outside, so the true banner count may be above 29 and the true pre-consent count below 67.
Three States, and the Question Each One Stops Answering
We found no credible public number for how US healthcare marketing measurement has changed since 2022, and I am not going to invent one. What the scan does support is a map of which questions get harder to answer in each state it found.
| State | What still works | What quietly stops working |
|---|---|---|
| Ad-platform requests firing (171 of 494) | Platform-reported conversions, in-platform optimization, retargeting | Control over timing: any change is likely to be driven by a legal review on someone else's schedule |
| No measurement detected (143 of 494) | No third-party pixel request detected on that page during our visit | If measurement was removed rather than moved: channel comparison, budget defense, and the effect of any change made after the tags came off |
| Measurement sprawl (clinic groups one layer down) | Each location can have its own numbers and its own dashboard | One definition of a conversion, one comparable cost per booked appointment, any statement about the estate as a whole |
The third row is easy to miss, because nothing about it looks broken. The report documents it in the clinic groups underneath the health systems: on 2026-07-26, one urgent-care franchise's single tag container was configured with 749 distinct GA4 measurement IDs, and on that date 409 of its 482 published locations sent the booking click to a domain the operator does not own. We looked at why a dashboard per clinic scales the problem instead of solving it in an earlier piece.
If you want one question to find out which state you are in, do not ask "are we compliant" or "do we have analytics". Ask what a booked appointment costs at your tenth-largest location, and then ask how that number was assembled. If the answer is that it cannot be produced, that is the conversation we have with healthcare marketing teams.
What to Check on Your Own Site This Quarter
None of these steps requires buying anything. Most of them check something we observed from outside, which you can check about yourself in an afternoon.
- Load your own homepage in a clean browser and watch the network panel. Take no consent action. Write down every domain that receives a request before you click anything. It is a manual version of the check our scanner automated, and it takes ten minutes.
- Repeat it on the ten location pages that matter most. The corporate site is often the one that gets reviewed first. Acquired sites can keep their previous owner's stack until somebody looks.
- Count the measurement IDs in your tag container. If the number surprises you, that is the finding. Sprawl is a governance problem that stays invisible until it is counted.
- Follow one booking click all the way to the end. Start at a paid ad, land on a location page, click through to book, and note where the domain changes and what is still attached to the URL. We walked through what can happen to campaign identity at the booking handoff in detail.
- Decide, in writing, what may be sent where. One page naming which platforms may receive what, who signs off, and who checks. Waiting for a letter means having that conversation on someone else's timeline.
- If nothing is being collected, put a floor back under yourself. A healthcare privacy vendor's collector is what about half of the settled systems we could scan loaded on 2026-08-27, and first-party or server-side collection can restore a baseline. Whether it changes your legal position is a question for your counsel, and note from the consent numbers above that moving collection server-side does not gate anything on consent by itself. Our post-pixel measurement playbook covers the server-side build.
- Fix definitions before you buy tooling. Agree what counts as a booked appointment and make every location report it the same way. A new platform inherits old definitions, only faster.
The scan is repeatable by design, and we intend to run it again and publish the movement. Three things will tell the story next time: whether the 170 systems with no public litigation record we could find that send ad-platform requests shrink without a matching wave of settlements, how many of the 143 quiet homepages show server-side collection, and whether consent gating arrives alongside that shift or stays rare.
Frequently Asked Questions
What does "going dark" mean for healthcare marketing?
In our scan it means a health system homepage that fired no advertising pixel, no analytics, no session replay, no privacy-vendor collector and no first-party collection endpoint that our scanner looks for. On 2026-08-27 that described 143 of the 494 US health system homepages that loaded for us, or 28.9%. We scanned once, from outside, so we cannot say those systems stopped measuring. Some of the 143 still loaded a tag manager container or a call-tracking script, and one sent requests to a customer-data platform.
How many US health systems still use tracking pixels on their websites?
Of the 494 health system homepages we could load, 171 (34.6%) sent at least one request to an advertising platform's domain during our visit: Meta, Google Ads or DoubleClick, LinkedIn, Bing or TikTok. In 11 of those cases the request came only after our scanner accepted a consent banner. For 18 of the 171, the only such request went to DoubleClick hosts that an embedded YouTube player also calls, and our scanner recorded domains rather than full URLs, so the number with a deployed ad pixel could be lower. The Meta Pixel fired on 39 homepages (7.9%). These figures come from one day, homepages only, and a non-US network, so they describe what that visit saw, not a full picture of any site.
Did health systems that settled pixel lawsuits stop measuring?
One homepage scan cannot tell whether any of them stopped. What it shows is this: none of the settled systems we could scan sent a request to an advertising platform from the homepage, about half of them loaded a healthcare privacy vendor's collection endpoint, and the rest either fired nothing we detected or ran analytics only. For the ones loading a vendor collector, the browser's request went to the vendor rather than to an ad platform. Where the vendor sends the data next is not something a browser scan can see.
Is a health system homepage with no trackers HIPAA compliant?
Our scan cannot answer that, and neither can any scan of a public page. It records what a page sent on a stated date. It is not a compliance assessment, and a quiet homepage says nothing about booking pages, patient portals, call centers or server-side processing. That question belongs with your own counsel and privacy officer. What the scan can help with is a separate question with its own cost: whether your marketing team still has a measurement baseline.
How was the Healthcare Marketing Measurement 2026 scan done?
We took the full list of 639 health systems in the AHRQ Compendium of U.S. Health Systems 2023, loaded each homepage in a scripted real browser on 2026-08-27 without taking any consent action first, and recorded every network request against a list of named tracker categories, plus whether a consent banner appeared. 494 homepages loaded. 129 returned HTTP 403 or 429 or timed out, which is consistent with bot protection or geo-fencing. 16 failed for other reasons: DNS, certificate or connection errors, or an HTTP 406 or 503. The scan ran from a non-US network, which is its most important limitation. The report on this page carries the method, the exclusions and a receipt for each headline figure.
Can I see what the scan recorded for my own health system?
Yes. If you run marketing at a US health system or a multi-location clinic group, ask us for your row, including what we recorded and what we could not see. We would rather be corrected by an operator than be quoted uncorrected.