Description
Since HHS OCR’s 2022 bulletin on tracking technologies, healthcare marketers have been on notice: Meta Pixel, Google Ads tags, and similar third-party scripts firing on appointment forms, intake pages, and patient portals can create real HIPAA exposure, even when nobody meant for it to happen.
Tracking Pixel Exposure Scanner checks your WordPress site the way a browser or Googlebot would. It fetches your published pages and scans the raw HTML for five known tracking signatures: Meta Pixel, Google Ads conversion tags, Google Analytics 4, TikTok Pixel, and Google Tag Manager containers.
Each match gets checked against two things: a configurable list of sensitive-page keywords (appointment, intake, insurance, patient portal, and more, fully editable from the plugin screen) and your site’s active consent-management plugin (Complianz, Cookiebot, CookieYes, Moove GDPR, or similar). A pixel firing on a sensitive page with no consent plugin active gets flagged high severity. The same pixel with a consent plugin active gets flagged medium, because having a CMP installed doesn’t automatically mean that specific pixel is gated at the event level.
This is a facts-only tool. It reports which pixel signatures appear in a page’s raw HTML and which consent plugin, if any, is active sitewide. It does not draw legal conclusions. It can’t see inside a Google Tag Manager container’s tag configuration, and it can’t confirm whether a pixel is properly gated behind consent. Every flag is a starting point for review, not a verdict.
Built for agencies and in-house marketers running WordPress sites in regulated verticals: addiction treatment, behavioral health, medical aesthetics, and general healthcare. Runs entirely on your own site. No data leaves your server.
What you get: a Tools -> Pixel Exposure admin page with a one-click scan button, an editable sensitive-page keyword list, a severity-graded results table (high, medium, low), and per-match dismiss so you’re not re-reviewing the same accepted pixel on every scan.
Install, activate, click Run Scan. Takes about a minute on a typical site.



