If you’ve spent any time researching Google Analytics and its compliance status in healthcare, you’ve likely come across one of a few common viewpoints.
You may have heard that “Google Analytics isn’t HIPAA compliant,” or perhaps that “Google Analytics presents HIPAA-related risks depending on how it’s implemented, configured and used“ risks that can often be mitigated with the right approach.
You’ve probably also seen the same recommendation time and time again:
“Move to server-side tagging or server-side measurement.”
It’s often presented as the solution for healthcare organizations and practices covered by HIPAA (Health Insurance Portability and Accountability Act) that want to continue using Google Analytics or use a modern compliant approach to data collection, or continue measuring user behaviour while reducing privacy and compliance risks.
While server-side tagging can certainly help improve data governance and give organizations more control over what gets shared with third-party platforms, it’s important to understand what it does and what it doesn’t do.
Simply moving to server-side tagging does not automatically make your Google Analytics or data collection practices in other Martech tools you use HIPAA-compliant.
In fact, once you move to server-side tagging, a new set of considerations appears. You’ll need to think about data transformation, identifier management, infrastructure controls, and perhaps most importantly, where your tagging infrastructure is hosted.
That’s the part many teams overlook, which I cover in this blog post. And this isn’t just about Google Analytics, but about server-side measurement and HIPAA.
Server-Side Tagging Is Not a HIPAA Compliance Shortcut
Let’s clear up one common misconception.
Migrating from client-side tracking to server-side tagging with Server-Side Google Tag Manager (ssGTM) does not automatically create a HIPAA-compliant analytics implementation.
Having server-side tagging with Google Tag Manager (GTM) in place does not automatically permit the collection or sharing of data with non-HIPAA-compliant tools. For example, you should not transmit patients’ first-party PHI data to Meta or collect data from authenticated or PHI-containing pages.

Server-side tagging does not eliminate the need to evaluate the HIPAA compliance of downstream vendors. You must assess each vendor’s compliance status, understand the associated privacy and security risks, and ensure that appropriate safeguards and privacy controls are in place before data collection happens or before sharing any protected health information (PHI).
Server-side tagging is simply a privacy-enabled architecture choice. It gives you greater control over incoming data before it is forwarded to downstream vendors and platforms, but the responsibility for compliance still remains with your organization.
For example, healthcare organizations often implement data transformation processes before data leaves their tagging server. This may include removing or anonymizing identifiers that could create compliance concerns.
IP addresses are a common example. If left untouched, a user’s full IP address may be processed by downstream vendors like Google Analytics, which might be high risk.
The need then arises to implement transformations or anonymization steps within their server-side tagging environment before forwarding data to the vendor endpoint, using a server-GTM custom variable template like “The IP Transformer/Anonymizer” that I developed.
However, these types of controls are only one piece of the puzzle. In this article, I won’t be going into everything that you should ensure is in place.
And even after implementing data minimization and transformation measures, compliance risks can still remain if the underlying infrastructure itself does not meet your organization’s HIPAA requirements.
That’s where hosting becomes critical.
The Hosting Platform Is a Compliance Decision
When organizations evaluate server-side tagging platforms, they often focus on ease of deployment, maintenance, pricing, and/or performance.
Those factors matter, but healthcare organizations covered by HIPAA need to evaluate an additional requirement:
Will the provider sign a Business Associate Agreement (BAA)?
If a vendor will not sign a BAA when one is required, that alone may disqualify the platform from consideration, regardless of how easy or cost-friendly it makes server-side tagging.
In other words, choosing a hosting platform for your server-side GTM container isn’t just an infrastructure decision; it’s also a HIPAA compliance decision.
This becomes especially important because many of the popular server-side tagging hosting providers take very different approaches to HIPAA support.
Comparing Server-Side Tagging Hosting Options for HIPAA Considerations
Below is a high-level overview focused specifically on BAA availability.
Google Cloud Run
Google Cloud Run is one of the most commonly recommended hosting options for server-side tagging with Google Tag Manager.

Because Cloud Run is a service within Google Cloud Platform (GCP), it can support HIPAA compliance requirements when used appropriately. Google also offers Business Associate Agreements (BAAs) for eligible services, including Cloud Run and BigQuery, both of which are frequently used in server-side GTM deployments.
For organizations that already operate within Google Cloud, hosting a server-side GTM container on Cloud Run is often one of the first options considered.
However, there is an important implementation detail that many teams overlook. If your organization already has a Google Cloud organization with a signed BAA, it is generally recommended to deploy the Cloud Run instance manually within an existing project covered by that agreement.
Alternatively, you can use the automated provisioning process from the server-side GTM interface, but you must ensure that the newly created project is provisioned under the same Google Cloud organization.
This distinction matters because Google’s Business Associate Agreement is executed at the organization level. A Cloud project created outside of the covered organization may not automatically fall under the scope of your existing BAA, potentially creating compliance concerns that should be addressed before handling users’ data or protected health information (PHI).
Amazon Web Services (AWS)
Yes, server-side GTM can also be deployed on AWS, and AWS is HIPAA-compliant and will sign a Business Associate Addendum for covered customers.
For teams that already operate or process healthcare data on AWS, deploying server-side tagging infrastructure within their existing environment may simplify governance and compliance reviews.
Microsoft Azure
Like Amazon Web Services (AWS), Microsoft Azure can also be used to host a server-side tagging infrastructure.
Azure supports HIPAA-regulated workloads and offers Business Associate Agreements (BAAs), making it a viable option for healthcare organizations and other entities that handle protected health information (PHI).
For organizations that have already standardized on Azure, deploying a server-side GTM environment within their existing cloud infrastructure can simplify governance, security management, and compliance oversight by integrating the deployment into established operational processes.
Stape
Stape is another popular hosting option for server-side Google Tag Manager deployments, largely due to its affordability, ease of setup, and strong reputation and contribution within the server-side tagging community.

However, organizations operating in HIPAA-regulated environments should pay close attention to how compliance requirements are handled. While Stape does offer HIPAA support and the possibility of a Business Associate Agreement, these arrangements are typically not available through standard self-service plans and often require direct engagement with their customer success/sales team.

As a result, organizations should discuss their compliance requirements, eligibility, contractual obligations, and pricing directly with Stape before making a hosting decision.
This consideration is particularly important for smaller healthcare practices and cost-conscious organizations that require complete clarity regarding compliance costs. If obtaining a BAA through a managed hosting provider significantly increases expenses, hosting a server-side GTM container on Google Cloud Run under an existing Google Cloud organization with a signed BAA may prove to be a more cost-effective alternative.
For larger organizations with broader infrastructure requirements and dedicated compliance budgets, the additional cost of a managed solution may be less significant, making factors such as operational simplicity, support, and internal resource allocation more important considerations than hosting costs alone.
Taggrs
Taggrs also provides an easy and cost-effective way to set up server-side tagging with Google Tag Manager, similar to solutions such as Stape, Google Cloud Run, and the other options discussed in this blog post.

However, if you are a healthcare provider or organization subject to HIPAA, hosting your server-side tagging infrastructure with Taggrs may not be suitable because it does not offer the option to sign a Business Associate Agreement (BAA), a key requirement for HIPAA compliance when working with service providers that handle protected health information (PHI).
At the time this article was written and published, Taggrs does not publicly claim HIPAA support or the availability of a Business Associate Agreement. Organizations with HIPAA compliance requirements should verify the latest information directly with Taggrs before choosing it as their server-side tagging hosting provider.

It’s also worth noting that, like Stape, Taggrs is based in the European Union. Depending on your organization’s compliance, data residency, and privacy requirements, this may be an additional factor to consider when evaluating hosting options.
Tracklution
Tracklution is not a dedicated server-side Google Tag Manager (GTM) hosting provider. However, it deserves a place on this list because of its server-side measurement capabilities, which may be valuable for organizations evaluating privacy-focused server-side tracking and data collection solutions.

At the time of publishing this article, Tracklution, also EU-based, does not support HIPAA compliance and does not advertise BAA support. As always, confirm directly with the provider before making a decision.
Addingwell
Addingwell, which is another player in the sGTM space, is a product of Didomi CMP, but it does not currently position itself as a HIPAA-focused hosting provider and does not publicly advertise BAA availability for covered entities.

Addingwell provides managed server-side Google Tag Manager (GTM) hosting, allowing you to deploy and run your server-side tagging infrastructure on its platform with ease. For organisations subject to HIPAA, however, one important consideration is whether the provider is willing to sign a BAA, which is not an option that exists with Addingwell.

Reaktion
At the time of writing, Reaktion does not advertise BAA support. Organizations should verify current policies directly with the vendor.

It’s important to note that Reaktion is not a server-side Google Tag Manager (ssGTM) hosting provider. Instead, it is a server-side measurement platform, similar to Tracklution, which was discussed earlier in this article.
Although Reaktion does not provide managed hosting for a server-side GTM container, its server-side measurement capabilities make it a relevant solution to include in this comparison.
Reaktion is primarily designed for ecommerce businesses, with features and implementation patterns tailored to online stores and digital commerce use cases.

It’s also worth noting that, like several of the other server-side measurement platforms covered in this article, Reaktion is based in the European Union.
JENTIS
JENTIS is similar to Tracklution in that it is not a dedicated server-side Google Tag Manager hosting provider. Instead, it offers a server-side data collection and measurement platform designed to improve data quality, privacy, and regulatory compliance.

JENTIS also supports client-side tracking, enabling organizations to adopt a hybrid measurement approach that combines both client-side and server-side data collection.
JENTIS has published content discussing HIPAA compliance. However, at the time of writing, there is no clear indication that the company offers to sign a Business Associate Agreement (BAA) with healthcare organizations or that it holds a HIPAA certification.
These are important considerations to keep in mind when evaluating JENTIS for healthcare or other HIPAA-regulated use cases.
Self-Hosting
Self-hosting your server-side Google Tag Manager (sGTM) environment is another topic that often comes up in discussions around ssGTM implementation.
Organizations typically consider self-hosting from the perspectives of cost, privacy, and operational control. However, regardless of the infrastructure you choose to host your server-side GTM environment, the hosting platform itself must be evaluated for HIPAA compliance.
For example, if you are using platforms such as Plesk (a web hosting control panel similar to cPanel) or another self-hosted environment, you should consult your legal counsel to determine your HIPAA obligations.
This includes assessing whether the hosting provider qualifies as a business associate, whether signing a Business Associate Agreement (BAA) with the hosting provider is required, whether they will even sign one, and whether any exceptions apply based on your specific implementation and the data being processed.
Why This Matters Before You Migrate
One of the most common mistakes I see is organizations designing their server-side tagging architecture first and evaluating compliance requirements later.
The process should often happen in reverse.
Before migrating, identify:
- What data will pass through the tagging server and what is sent to the downstream vendors you’ll be using
- Whether HIPAA applies to your organization and use case
- Whether a BAA is required
- Which hosting providers can support those requirements
- What transformations or anonymization controls must be implemented before data is forwarded downstream
- What is the HIPAA status of the vendor receiving the data
Answering these questions early can save significant time and prevent the need for costly migrations later.
Final Thoughts
Server-side tagging can be a valuable component of a privacy-focused measurement strategy, especially for healthcare organizations that want more control over how data is collected and shared.
But it should not be viewed as a compliance shortcut.
The conversation shouldn’t stop at “Should we move to server-side tagging?”
It should also include:
“Where will we host it, and does that hosting provider support our HIPAA compliance requirements?”
For healthcare organizations, that question can be just as important as the tagging implementation itself.




