<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Sift Health Blog</title>
    <link>https://sift-health.pages.dev/blog</link>
    <atom:link href="https://sift-health.pages.dev/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Writing on healthcare website risk: online tracking, HIPAA, and enforcement.</description>
    <language>en-us</language>
    <lastBuildDate>Wed, 10 Jun 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>Does Google Analytics violate HIPAA? What the OCR guidance actually says</title>
      <link>https://sift-health.pages.dev/blog/does-google-analytics-violate-hipaa</link>
      <guid isPermaLink="true">https://sift-health.pages.dev/blog/does-google-analytics-violate-hipaa</guid>
      <description>Google Analytics is not automatically a HIPAA violation — but on patient-facing pages it can be. Here is what the HHS OCR online-tracking guidance actually says, what changed after the 2024 court ruling, and how to decide what belongs on your site.</description>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <category>google-analytics</category>
      <category>hipaa</category>
      <category>tracking</category>
      <category>guidance</category>
    </item>
    <item>
      <title>The Meta Pixel hospital enforcement actions, explained</title>
      <link>https://sift-health.pages.dev/blog/meta-pixel-hospital-enforcement-explained</link>
      <guid isPermaLink="true">https://sift-health.pages.dev/blog/meta-pixel-hospital-enforcement-explained</guid>
      <description>How a single advertising pixel on appointment pages triggered breach notifications to millions of patients, multi-million-dollar settlements, and a joint FTC/OCR warning — and what the pattern means for any healthcare website.</description>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>meta-pixel</category>
      <category>enforcement</category>
      <category>tracking</category>
      <category>hipaa</category>
    </item>
    <item>
      <title>A practical pre-launch website risk checklist for healthcare practices</title>
      <link>https://sift-health.pages.dev/blog/healthcare-website-risk-checklist</link>
      <guid isPermaLink="true">https://sift-health.pages.dev/blog/healthcare-website-risk-checklist</guid>
      <description>Launching or redesigning a practice website? Here is a concrete, ordered checklist — transport security, trackers, forms, privacy policy, and hygiene — that catches the issues regulators and plaintiffs have actually pursued.</description>
      <pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate>
      <category>checklist</category>
      <category>launch</category>
      <category>forms</category>
      <category>security-headers</category>
    </item>
  </channel>
</rss>