For multi-location healthcare organizations
In this guide
- Executive summary
- Recommendations by group size
- Detailed feature comparison
- Privacy law compliance deep dive
- Pricing comparison
- Healthcare-specific considerations
- Platform selection by tech stack
Executive summary
We looked at five consent management and privacy platforms that matter for multi-location healthcare groups running WordPress or custom sites (Node.js, Astro):
- Two healthcare-specific CDPs: Ours Privacy and Freshpaint
- One specialized WordPress consent plugin: Complianz Premium
- Two general-purpose consent tools: CookieYes and Termly
The context has changed fast. Twenty US states now have comprehensive privacy laws, with eight new ones taking effect in 2025 and three more in 2026. If you run healthcare websites, you’re dealing with two overlapping compliance regimes: HIPAA on one side, state consumer privacy laws on the other.
And enforcement is real. Healthline paid $1.55M in late 2025 because their consent manager didn’t actually honor opt-outs. No medical records were involved.
A note on scope: This is a practical overview for healthcare marketing and operations leaders. We’re not privacy attorneys. Talk to qualified healthcare privacy counsel for advice specific to your situation.
Recommendations by group size
The short version. Detailed analysis follows below.
Large healthcare systems (50+ locations)
Go with Ours Privacy or Freshpaint.
$20K-$150K+/year plus setup. Full HIPAA/BAA, integrated consent management + CDP, state law compliance, and data routing that actually enforces consent choices.
Both offer full HIPAA compliance with BAA protection, and both now bundle consent management into their CDP. The price tag is real, but so is the coverage: marketing analytics, state law compliance, and data routing that actually enforces consent choices rather than just recording them.
Mid-size healthcare groups (10-50 locations)
Go with Ours Privacy or Complianz Premium.
Ours Privacy: $20-30K/year (BAA + healthcare platform). Complianz Premium: €59-€199/year (consent management only, WordPress-only).
Ours Privacy gets you BAA protection and a healthcare-specific platform. Complianz Premium works well if you only need the consent management piece and your sites are all WordPress. It won’t help with the broader marketing data privacy question, but it handles consent collection and geo-targeting reliably.
One catch: Complianz is WordPress-only. If you have custom Node.js or Astro sites in the mix, you’ll need Ours Privacy, Freshpaint, or a JS-based tool like CookieYes or Termly.
Small healthcare practices (1-10 locations)
Go with Complianz Premium (WordPress) or CookieYes/Termly (any platform).
€59-€199/year for Complianz, or $0-$20/month for CookieYes/Termly.
These cover the basics at a price that makes sense for smaller groups. If you outgrow them, you can move to a healthcare CDP later.
Detailed feature comparison
Five platforms, compared across the categories that actually matter for multi-location healthcare groups.
Core privacy and compliance
| Feature | Ours Privacy | Freshpaint | Complianz Prem. | CookieYes | Termly |
|---|---|---|---|---|---|
| Default Data Blocking | ✅ | ✅ | ✅ Prior consent | ✅ | ✅ |
| GDPR Compliance | ✅ | ✅ | ✅ | ✅ | ✅ |
| CCPA/CPRA | ✅ | ✅ | ✅ | ✅ | ✅ |
| Server-side Tracking | ✅ | ✅ | ⚠️ Via GTM | ❌ | ❌ |
| Google Consent Mode V2 | ✅ | ✅ | ✅ | ✅ | ✅ |
| HIPAA/BAA Available | ✅ | ✅ | ❌ | ❌ | ❌ |
| Integrated CMP + CDP | ✅ | ✅ (New Jan 2026) | ❌ CMP only | ❌ CMP only | ❌ CMP only |
US state and international privacy law coverage
Twenty US states have comprehensive privacy laws in effect as of early 2026. This table covers the ones most relevant to healthcare groups.
| Law/Region | Ours Privacy | Freshpaint | Complianz Prem. | CookieYes | Termly |
|---|---|---|---|---|---|
| GDPR (EU/UK) | ✅ Full | ✅ Full | ✅ Native | ✅ Full | ✅ |
| ePrivacy Directive | ✅ | ✅ | ✅ | ✅ | ✅ |
| CCPA/CPRA (California) | ✅ Opt-out + sale | ✅ Full | ✅ Do Not Sell | ✅ Opt-out | ✅ Auto-updates |
| VCDPA (Virginia) | ✅ | ✅ | ✅ | ✅ | ✅ |
| CPA (Colorado) | ✅ Opt-in | ✅ | ✅ | ✅ | ✅ |
| CTDPA (Connecticut) | ✅ | ✅ | ✅ | ✅ | ✅ |
| MODPA (Maryland) | ✅ | ✅ | ✅ | ✅ | ✅ |
| TDPSA (Texas) | ✅ | ✅ | ✅ | ✅ | ✅ |
| All 20 Current States | ✅ Auto-config | ✅ All states | ✅ Major states | ✅ 12+ states | ✅ Auto-adapts |
| PIPEDA / Law 25 (Canada) | ✅ | ✅ | ✅ | ✅ | ✅ |
State law implementation features
| Feature | Ours Privacy | Freshpaint | Complianz Prem. | CookieYes | Termly |
|---|---|---|---|---|---|
| Opt-in vs Opt-out Handling | ✅ Auto-config | ✅ State-specific | ✅ Region-based | ✅ Auto-switch | ✅ |
| Sensitive Data Categories | ✅ Healthcare | ✅ PHI focused | ✅ Configurable | ✅ | ✅ |
| Do Not Sell Links | ✅ Auto-generated | ✅ | ✅ | ✅ Footer links | ✅ |
| Global Privacy Control (GPC) | ✅ | ✅ | ✅ DNT + GPC | ✅ Premium | ✅ |
| Sale/Share Distinction | ✅ CPRA | ✅ | ✅ | ✅ | ✅ |
| Minor Protection (<13) | ✅ COPPA + state | ✅ | ✅ COPPA | ✅ | ✅ |
| Minor Protection (13–16) | ✅ State-specific | ✅ | ✅ | ✅ | ✅ |
| Data Protection Assessments | ✅ HIPAA-level | ✅ | ⚠️ Limited | ❌ | ❌ |
Cookie and tracker management
| Feature | Ours Privacy | Freshpaint | Complianz Prem. | CookieYes | Termly |
|---|---|---|---|---|---|
| Cookie/Tracker Scanning | ✅ Continuous | ✅ Web tracker | ✅ Weekly auto | ✅ Auto scan | ✅ Auto scan |
| Dynamic Pixel Detection | ✅ Real-time | ✅ Tracker detect | ✅ Auto updates | ✅ | ✅ |
| Cookie Categorization | ✅ Healthcare | ✅ | ✅ Custom | ✅ | ✅ |
| Banner Customization | ✅ Full | ✅ Brandable | ✅ Templates+CSS | ✅ Advanced | ✅ |
| A/B Testing | ✅ | ⚠️ Limited | ✅ | ❌ | ❌ |
| Multi-language | ✅ | ✅ | ✅ 47+ langs | ✅ 30+ auto | ✅ |
| Geo-targeting | ✅ | ✅ | ✅ Geo IP | ✅ Premium | ✅ |
Healthcare marketing integrations
| Feature | Ours Privacy | Freshpaint | Complianz Prem. | CookieYes | Termly |
|---|---|---|---|---|---|
| Google Analytics (GA4) | ✅ PHI-safe | ✅ De-identified | ✅ Standard | ✅ | ✅ |
| Google Ads | ✅ HIPAA | ✅ PHI blocked | ✅ | ✅ | ✅ |
| Meta/Facebook Pixel | ✅ Healthcare-safe | ✅ PHI blocked | ✅ Configurable | ✅ | ✅ |
| Call Tracking (Invoca etc.) | ✅ | ✅ | ❌ | ❌ | ❌ |
| YouTube/Video Embedding | ✅ | ✅ IP protection | ✅ iFrame block | ✅ | ✅ |
| Maps Integration | ✅ | ✅ Safe embed | ✅ | ✅ | ✅ |
| Multi-touch Attribution | ✅ New | ✅ | ❌ | ❌ | ❌ |
| Session Replay | ✅ HIPAA | ❌ | ❌ | ❌ | ❌ |
Technical implementation
| Feature | Ours Privacy | Freshpaint | Complianz Prem. | CookieYes | Termly |
|---|---|---|---|---|---|
| Platform Support | Web, GTM, Mobile | Web, GTM | WordPress only | WP + JS snippet | WP + JS snippet |
| Implementation | JavaScript SDK | JavaScript/GTM | WP Plugin | WP Plugin/JS | WP Plugin/JS |
| WordPress Native | ⚠️ Via JS | ⚠️ Via JS | ✅ Native | ✅ Native | ✅ Native |
| Custom Sites (Node/Astro) | ✅ JS SDK | ✅ JS/GTM | ❌ | ✅ JS snippet | ✅ JS snippet |
| Multisite Support | ✅ Enterprise | ✅ | ✅ Agency plan | ✅ | ✅ |
| Setup Complexity | Medium | Medium-High | Low-Medium | Low | Very Low |
| Page Load Impact | Minimal | Minimal | Low | Low | Low |
Legal documents and reporting
| Feature | Ours Privacy | Freshpaint | Complianz Prem. | CookieYes | Termly |
|---|---|---|---|---|---|
| Privacy Policy Generator | ✅ Healthcare | ⚠️ Limited | ✅ | ✅ | ✅ Professional |
| Cookie Policy | ✅ | ✅ | ✅ Dynamic | ✅ | ✅ |
| Consent Records Storage | ✅ HIPAA | ✅ HIPAA | ✅ Unlimited | ✅ | ✅ |
| Audit Logs | ✅ Detailed | ✅ Event verify | ✅ | ✅ | ✅ |
| Compliance Dashboard | ✅ Real-time | ✅ Monitoring | ✅ | ✅ | ✅ |
| Export Capabilities | ✅ Multiple | ✅ | ✅ CSV | ✅ CSV | ✅ |
Privacy law compliance deep dive
Twenty states have comprehensive privacy laws in effect as of early 2026, and if you have locations in multiple states, you need to know how each one treats health-related data.
The differences are not academic. California lets you use opt-out consent for cookies. Colorado requires opt-in for health data. Use the wrong model in the wrong state and you’re in violation.
The current landscape (20 states)
States with active laws: California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. More states have laws taking effect in 2027 and beyond.
Key state laws for healthcare
California (CCPA/CPRA)
Opt-out model for cookie consent. Requires a “Do Not Sell or Share My Personal Information” link. Recognizes Global Privacy Control (GPC) signals.
New regulations took effect January 2026 covering automated decision-making technology (ADMT) risk assessments, with initial assessments due by April 2028. The California Delete Act (DROP system) is now operational, meaning data brokers must honor opt-out and deletion requests. Fines up to $7,500 per violation, enforced by the California Privacy Protection Agency.
Colorado (CPA)
Opt-in required for sensitive data, including health information. The original 60-day cure period expired in 2025, so there’s no grace period anymore. Universal opt-out mechanism is now required.
Colorado also passed the first state-level AI law (effective June 2026), which could affect healthcare organizations using AI-driven marketing tools. Fines up to $20,000 per violation.
Maryland (MODPA), new in October 2025
One of the strictest. Maryland bans the sale of sensitive personal data outright, including health data and precise geolocation. The definition of “sale” is broad, which makes this one particularly relevant for healthcare organizations. Stricter data minimization rules than other states.
Virginia (VCDPA)
Opt-in required for sensitive data processing. Opt-out for targeted advertising. Amendments in 2026 expand the obligations. Enforced by the Attorney General only.
Texas (TDPSA)
Worth paying attention to because there are no revenue or data volume thresholds. Even smaller practices may be covered if they do business in Texas. The 2025 amendments expanded data broker requirements and transparency obligations.
Connecticut (CTDPA)
Similar to Colorado: opt-in for sensitive data, universal opt-out signals required. New amendments effective July 2026 add age-appropriate design code requirements and stronger minor protections. Fines up to $5,000 per violation.
How each platform handles state law differences
Healthcare CDP platforms (Ours Privacy and Freshpaint)
Both auto-detect visitor location and apply the strictest applicable standard. They treat all health-related data as sensitive (opt-in consent required) and handle the overlap between HIPAA and state privacy law.
The real advantage of their integrated consent managers (Ours Privacy launched theirs in July 2025, Freshpaint in January 2026) is that consent enforcement is wired directly into data routing. When a visitor opts out, the pixels and analytics actually stop firing. That’s the difference between a consent banner and actual consent enforcement.
WordPress consent plugins (Complianz, CookieYes, Termly)
Complianz uses a setup wizard to figure out which laws apply and configures region-specific banners for EU, UK, US, Brazil, South Africa, and Canada. CookieYes does geo-targeting with different templates for GDPR vs US laws and auto-translates into 30+ languages. Termly updates its backend automatically when laws change, no plugin update needed.
These tools handle consent collection well. But they don’t route or filter data the way a CDP does. The consent banner fires, the visitor makes a choice, and then whether the actual trackers respect that choice depends on how you’ve configured things. That gap is exactly what got Healthline in trouble.
Pricing comparison
At a glance
| Platform | Price range | BAA included | Works on | Best for |
|---|---|---|---|---|
| Ours Privacy | $20K-$100K+/yr | ✅ | Any platform | 50+ locations |
| Freshpaint | $50K-$150K+/yr | ✅ | Any platform | 50+ locations |
| Complianz Premium | €59-€199/yr | ❌ | WordPress only | 10-50 locations |
| CookieYes | Free-$20/mo | ❌ | Any platform | 1-10 locations |
| Termly | Free-$15/mo | ❌ | Any platform | 1-10 locations |
Healthcare CDP platforms
Ours Privacy
Annual enterprise subscription: $20,000-$100,000+/year depending on org size. Includes the full CDP + CMP, a BAA, unlimited sites, white-glove setup, and their newer analytics tools (multi-touch attribution, web analytics, session replay, funnels). Backed by Rock Health, Switch Ventures, GreyMatter, and TMV.
Freshpaint
Tiered by organization size: $50,000-$150,000+/year. Includes BAA, all integrations, tiered support, and the new integrated Consent Manager. Raised $30.7M Series B in 2024 (led by Threshold). Pricing isn’t published; you’ll need to contact them for a quote.
WordPress consent plugins
| Platform | Free tier | Paid plans | Notes |
|---|---|---|---|
| Complianz | ✅ (1 site, basic) | €59/yr (1 site), €99/yr (5 sites), €199/yr (25 sites + Multisite) | Google CMP certified. Also on Shopify. Multisite needs Agency plan. |
| CookieYes | ✅ (100K pageviews/mo) | ~$10/mo (Basic), ~$20/mo (Pro), custom (Ultimate) | Google CMP certified. 1.5M+ sites. JS snippet works anywhere. |
| Termly | ✅ (10K visitors/mo) | $10/mo (Starter), $15/mo (Pro+) | JS snippet works anywhere. Auto-updates when laws change. |
Note on Complianz: some third-party sources report higher USD pricing ($179 Professional, $399 Agency). Check complianz.io/pricing for current rates.
Hidden costs to watch for
- Implementation time and resources
- Ongoing management and updates
- Fines for non-compliance ($50K-$2M+ for HIPAA violations; up to $7,500 per violation for state laws, and they stack)
- Lost marketing effectiveness from poor implementation
- Legal review fees
Healthline’s $1.55M CCPA settlement in late 2025 is worth repeating here: their consent manager looked fine on the surface, but the underlying trackers kept firing regardless of what visitors chose. The fine wasn’t about medical records. It was about a cookie banner that didn’t do what it said it would.
Healthcare-specific considerations
The double compliance problem
Healthcare has a specific problem: you have to comply with HIPAA and state privacy laws, and they cover different data. HIPAA covers PHI. State laws cover consumer data that HIPAA doesn’t touch. And the same data point can fall into both categories depending on context.
Where the lines blur
- Email collected for a newsletter: Not HIPAA-covered. Subject to CCPA and other state laws.
- Email + health condition interest: Now it’s PHI under HIPAA.
- Browsing condition-specific pages: Gray area. Could be subject to both HIPAA and state laws, especially under Maryland’s broad definitions.
- Appointment booking data: PHI under HIPAA.
- Tracking pixels firing on healthcare pages: This is what started the wave of lawsuits and the Healthline settlement.
Mistakes that will cost you
- Assuming HIPAA covers everything. It doesn’t. State laws apply to data HIPAA doesn’t touch, and fines can stack. You can get hit with both HIPAA and state penalties for the same incident.
- Treating “sensitive data” as one definition. Every state defines it differently. Health data is always sensitive, but the scope varies. Maryland’s ban on selling sensitive data (including geolocation) is particularly aggressive.
- Using one consent mechanism everywhere. California allows opt-out. Colorado and Virginia require opt-in for health data. Running opt-out consent in Colorado for health data is a straight-up violation.
- Forgetting employee data. CCPA/CPRA covers it now. Other states may not. Healthcare workers’ data needs its own handling.
- Trusting the banner without checking what’s behind it. Healthline had a consent banner. It looked fine. The trackers kept firing anyway. Enforcement cares about what actually happens, not what the banner says.
- Ignoring children’s data. If your practice serves pediatric patients, pay attention. Multiple states are tightening protections for minors, and the trend is accelerating.
Platform selection by tech stack
What you can use depends partly on how your sites are built.
| Platform | WordPress | Custom Node.js | Astro/Static |
|---|---|---|---|
| Ours Privacy | ✅ Via JS SDK | ✅ Via JS SDK | ✅ Via JS SDK |
| Freshpaint | ✅ Via JS/GTM | ✅ Via JS/GTM | ✅ Via JS/GTM |
| Complianz Premium | ✅ Native plugin | ❌ WordPress only | ❌ WordPress only |
| CookieYes | ✅ Plugin or JS | ✅ JS snippet | ✅ JS snippet |
| Termly | ✅ Plugin or JS | ✅ JS snippet | ✅ JS snippet |
If you’re running a mix of WordPress and custom-built sites (common for multi-location groups that have acquired practices over time), Ours Privacy or Freshpaint give you one dashboard across everything. If all your sites are WordPress, Complianz Premium is hard to beat on value for consent management.
This guide is for informational purposes only and is not legal advice. Privacy laws change frequently. Talk to qualified healthcare privacy counsel about your specific situation.
Who wrote this
Carenetic runs the websites for multi-location healthcare groups, from ten locations to more than two hundred. Support, builds, audits and hosting, all under one team. See what we do →


