For multi-location healthcare organizations

In this guide

  1. Executive summary
  2. Recommendations by group size
  3. Detailed feature comparison
  4. Privacy law compliance deep dive
  5. Pricing comparison
  6. Healthcare-specific considerations
  7. Platform selection by tech stack

Executive summary

We looked at five consent management and privacy platforms that matter for multi-location healthcare groups running WordPress or custom sites (Node.js, Astro):

  • Two healthcare-specific CDPs: Ours Privacy and Freshpaint
  • One specialized WordPress consent plugin: Complianz Premium
  • Two general-purpose consent tools: CookieYes and Termly

The context has changed fast. Twenty US states now have comprehensive privacy laws, with eight new ones taking effect in 2025 and three more in 2026. If you run healthcare websites, you’re dealing with two overlapping compliance regimes: HIPAA on one side, state consumer privacy laws on the other.

And enforcement is real. Healthline paid $1.55M in late 2025 because their consent manager didn’t actually honor opt-outs. No medical records were involved.

A note on scope: This is a practical overview for healthcare marketing and operations leaders. We’re not privacy attorneys. Talk to qualified healthcare privacy counsel for advice specific to your situation.

Recommendations by group size

The short version. Detailed analysis follows below.

Large healthcare systems (50+ locations)

Go with Ours Privacy or Freshpaint.

$20K-$150K+/year plus setup. Full HIPAA/BAA, integrated consent management + CDP, state law compliance, and data routing that actually enforces consent choices.

Both offer full HIPAA compliance with BAA protection, and both now bundle consent management into their CDP. The price tag is real, but so is the coverage: marketing analytics, state law compliance, and data routing that actually enforces consent choices rather than just recording them.

Mid-size healthcare groups (10-50 locations)

Go with Ours Privacy or Complianz Premium.

Ours Privacy: $20-30K/year (BAA + healthcare platform). Complianz Premium: €59-€199/year (consent management only, WordPress-only).

Ours Privacy gets you BAA protection and a healthcare-specific platform. Complianz Premium works well if you only need the consent management piece and your sites are all WordPress. It won’t help with the broader marketing data privacy question, but it handles consent collection and geo-targeting reliably.

One catch: Complianz is WordPress-only. If you have custom Node.js or Astro sites in the mix, you’ll need Ours Privacy, Freshpaint, or a JS-based tool like CookieYes or Termly.

Small healthcare practices (1-10 locations)

Go with Complianz Premium (WordPress) or CookieYes/Termly (any platform).

€59-€199/year for Complianz, or $0-$20/month for CookieYes/Termly.

These cover the basics at a price that makes sense for smaller groups. If you outgrow them, you can move to a healthcare CDP later.

Detailed feature comparison

Five platforms, compared across the categories that actually matter for multi-location healthcare groups.

Core privacy and compliance

FeatureOurs PrivacyFreshpaintComplianz Prem.CookieYesTermly
Default Data Blocking✅ Prior consent
GDPR Compliance
CCPA/CPRA
Server-side Tracking⚠️ Via GTM
Google Consent Mode V2
HIPAA/BAA Available
Integrated CMP + CDP✅ (New Jan 2026)❌ CMP only❌ CMP only❌ CMP only

US state and international privacy law coverage

Twenty US states have comprehensive privacy laws in effect as of early 2026. This table covers the ones most relevant to healthcare groups.

Law/RegionOurs PrivacyFreshpaintComplianz Prem.CookieYesTermly
GDPR (EU/UK)✅ Full✅ Full✅ Native✅ Full
ePrivacy Directive
CCPA/CPRA (California)✅ Opt-out + sale✅ Full✅ Do Not Sell✅ Opt-out✅ Auto-updates
VCDPA (Virginia)
CPA (Colorado)✅ Opt-in
CTDPA (Connecticut)
MODPA (Maryland)
TDPSA (Texas)
All 20 Current States✅ Auto-config✅ All states✅ Major states✅ 12+ states✅ Auto-adapts
PIPEDA / Law 25 (Canada)

State law implementation features

FeatureOurs PrivacyFreshpaintComplianz Prem.CookieYesTermly
Opt-in vs Opt-out Handling✅ Auto-config✅ State-specific✅ Region-based✅ Auto-switch
Sensitive Data Categories✅ Healthcare✅ PHI focused✅ Configurable
Do Not Sell Links✅ Auto-generated✅ Footer links
Global Privacy Control (GPC)✅ DNT + GPC✅ Premium
Sale/Share Distinction✅ CPRA
Minor Protection (<13)✅ COPPA + state✅ COPPA
Minor Protection (13–16)✅ State-specific
Data Protection Assessments✅ HIPAA-level⚠️ Limited
FeatureOurs PrivacyFreshpaintComplianz Prem.CookieYesTermly
Cookie/Tracker Scanning✅ Continuous✅ Web tracker✅ Weekly auto✅ Auto scan✅ Auto scan
Dynamic Pixel Detection✅ Real-time✅ Tracker detect✅ Auto updates
Cookie Categorization✅ Healthcare✅ Custom
Banner Customization✅ Full✅ Brandable✅ Templates+CSS✅ Advanced
A/B Testing⚠️ Limited
Multi-language✅ 47+ langs✅ 30+ auto
Geo-targeting✅ Geo IP✅ Premium

Healthcare marketing integrations

FeatureOurs PrivacyFreshpaintComplianz Prem.CookieYesTermly
Google Analytics (GA4)✅ PHI-safe✅ De-identified✅ Standard
Google Ads✅ HIPAA✅ PHI blocked
Meta/Facebook Pixel✅ Healthcare-safe✅ PHI blocked✅ Configurable
Call Tracking (Invoca etc.)
YouTube/Video Embedding✅ IP protection✅ iFrame block
Maps Integration✅ Safe embed
Multi-touch Attribution✅ New
Session Replay✅ HIPAA

Technical implementation

FeatureOurs PrivacyFreshpaintComplianz Prem.CookieYesTermly
Platform SupportWeb, GTM, MobileWeb, GTMWordPress onlyWP + JS snippetWP + JS snippet
ImplementationJavaScript SDKJavaScript/GTMWP PluginWP Plugin/JSWP Plugin/JS
WordPress Native⚠️ Via JS⚠️ Via JS✅ Native✅ Native✅ Native
Custom Sites (Node/Astro)✅ JS SDK✅ JS/GTM✅ JS snippet✅ JS snippet
Multisite Support✅ Enterprise✅ Agency plan
Setup ComplexityMediumMedium-HighLow-MediumLowVery Low
Page Load ImpactMinimalMinimalLowLowLow
FeatureOurs PrivacyFreshpaintComplianz Prem.CookieYesTermly
Privacy Policy Generator✅ Healthcare⚠️ Limited✅ Professional
Cookie Policy✅ Dynamic
Consent Records Storage✅ HIPAA✅ HIPAA✅ Unlimited
Audit Logs✅ Detailed✅ Event verify
Compliance Dashboard✅ Real-time✅ Monitoring
Export Capabilities✅ Multiple✅ CSV✅ CSV

Privacy law compliance deep dive

Twenty states have comprehensive privacy laws in effect as of early 2026, and if you have locations in multiple states, you need to know how each one treats health-related data.

The differences are not academic. California lets you use opt-out consent for cookies. Colorado requires opt-in for health data. Use the wrong model in the wrong state and you’re in violation.

The current landscape (20 states)

States with active laws: California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. More states have laws taking effect in 2027 and beyond.

Key state laws for healthcare

California (CCPA/CPRA)

Opt-out model for cookie consent. Requires a “Do Not Sell or Share My Personal Information” link. Recognizes Global Privacy Control (GPC) signals.

New regulations took effect January 2026 covering automated decision-making technology (ADMT) risk assessments, with initial assessments due by April 2028. The California Delete Act (DROP system) is now operational, meaning data brokers must honor opt-out and deletion requests. Fines up to $7,500 per violation, enforced by the California Privacy Protection Agency.

Colorado (CPA)

Opt-in required for sensitive data, including health information. The original 60-day cure period expired in 2025, so there’s no grace period anymore. Universal opt-out mechanism is now required.

Colorado also passed the first state-level AI law (effective June 2026), which could affect healthcare organizations using AI-driven marketing tools. Fines up to $20,000 per violation.

Maryland (MODPA), new in October 2025

One of the strictest. Maryland bans the sale of sensitive personal data outright, including health data and precise geolocation. The definition of “sale” is broad, which makes this one particularly relevant for healthcare organizations. Stricter data minimization rules than other states.

Virginia (VCDPA)

Opt-in required for sensitive data processing. Opt-out for targeted advertising. Amendments in 2026 expand the obligations. Enforced by the Attorney General only.

Texas (TDPSA)

Worth paying attention to because there are no revenue or data volume thresholds. Even smaller practices may be covered if they do business in Texas. The 2025 amendments expanded data broker requirements and transparency obligations.

Connecticut (CTDPA)

Similar to Colorado: opt-in for sensitive data, universal opt-out signals required. New amendments effective July 2026 add age-appropriate design code requirements and stronger minor protections. Fines up to $5,000 per violation.

How each platform handles state law differences

Healthcare CDP platforms (Ours Privacy and Freshpaint)

Both auto-detect visitor location and apply the strictest applicable standard. They treat all health-related data as sensitive (opt-in consent required) and handle the overlap between HIPAA and state privacy law.

The real advantage of their integrated consent managers (Ours Privacy launched theirs in July 2025, Freshpaint in January 2026) is that consent enforcement is wired directly into data routing. When a visitor opts out, the pixels and analytics actually stop firing. That’s the difference between a consent banner and actual consent enforcement.

Complianz uses a setup wizard to figure out which laws apply and configures region-specific banners for EU, UK, US, Brazil, South Africa, and Canada. CookieYes does geo-targeting with different templates for GDPR vs US laws and auto-translates into 30+ languages. Termly updates its backend automatically when laws change, no plugin update needed.

These tools handle consent collection well. But they don’t route or filter data the way a CDP does. The consent banner fires, the visitor makes a choice, and then whether the actual trackers respect that choice depends on how you’ve configured things. That gap is exactly what got Healthline in trouble.

Pricing comparison

At a glance

PlatformPrice rangeBAA includedWorks onBest for
Ours Privacy$20K-$100K+/yrAny platform50+ locations
Freshpaint$50K-$150K+/yrAny platform50+ locations
Complianz Premium€59-€199/yrWordPress only10-50 locations
CookieYesFree-$20/moAny platform1-10 locations
TermlyFree-$15/moAny platform1-10 locations

Healthcare CDP platforms

Ours Privacy

Annual enterprise subscription: $20,000-$100,000+/year depending on org size. Includes the full CDP + CMP, a BAA, unlimited sites, white-glove setup, and their newer analytics tools (multi-touch attribution, web analytics, session replay, funnels). Backed by Rock Health, Switch Ventures, GreyMatter, and TMV.

Freshpaint

Tiered by organization size: $50,000-$150,000+/year. Includes BAA, all integrations, tiered support, and the new integrated Consent Manager. Raised $30.7M Series B in 2024 (led by Threshold). Pricing isn’t published; you’ll need to contact them for a quote.

PlatformFree tierPaid plansNotes
Complianz✅ (1 site, basic)€59/yr (1 site), €99/yr (5 sites), €199/yr (25 sites + Multisite)Google CMP certified. Also on Shopify. Multisite needs Agency plan.
CookieYes✅ (100K pageviews/mo)~$10/mo (Basic), ~$20/mo (Pro), custom (Ultimate)Google CMP certified. 1.5M+ sites. JS snippet works anywhere.
Termly✅ (10K visitors/mo)$10/mo (Starter), $15/mo (Pro+)JS snippet works anywhere. Auto-updates when laws change.

Note on Complianz: some third-party sources report higher USD pricing ($179 Professional, $399 Agency). Check complianz.io/pricing for current rates.

Hidden costs to watch for

  • Implementation time and resources
  • Ongoing management and updates
  • Fines for non-compliance ($50K-$2M+ for HIPAA violations; up to $7,500 per violation for state laws, and they stack)
  • Lost marketing effectiveness from poor implementation
  • Legal review fees

Healthline’s $1.55M CCPA settlement in late 2025 is worth repeating here: their consent manager looked fine on the surface, but the underlying trackers kept firing regardless of what visitors chose. The fine wasn’t about medical records. It was about a cookie banner that didn’t do what it said it would.

Healthcare-specific considerations

The double compliance problem

Healthcare has a specific problem: you have to comply with HIPAA and state privacy laws, and they cover different data. HIPAA covers PHI. State laws cover consumer data that HIPAA doesn’t touch. And the same data point can fall into both categories depending on context.

Where the lines blur

  • Email collected for a newsletter: Not HIPAA-covered. Subject to CCPA and other state laws.
  • Email + health condition interest: Now it’s PHI under HIPAA.
  • Browsing condition-specific pages: Gray area. Could be subject to both HIPAA and state laws, especially under Maryland’s broad definitions.
  • Appointment booking data: PHI under HIPAA.
  • Tracking pixels firing on healthcare pages: This is what started the wave of lawsuits and the Healthline settlement.

Mistakes that will cost you

  1. Assuming HIPAA covers everything. It doesn’t. State laws apply to data HIPAA doesn’t touch, and fines can stack. You can get hit with both HIPAA and state penalties for the same incident.
  2. Treating “sensitive data” as one definition. Every state defines it differently. Health data is always sensitive, but the scope varies. Maryland’s ban on selling sensitive data (including geolocation) is particularly aggressive.
  3. Using one consent mechanism everywhere. California allows opt-out. Colorado and Virginia require opt-in for health data. Running opt-out consent in Colorado for health data is a straight-up violation.
  4. Forgetting employee data. CCPA/CPRA covers it now. Other states may not. Healthcare workers’ data needs its own handling.
  5. Trusting the banner without checking what’s behind it. Healthline had a consent banner. It looked fine. The trackers kept firing anyway. Enforcement cares about what actually happens, not what the banner says.
  6. Ignoring children’s data. If your practice serves pediatric patients, pay attention. Multiple states are tightening protections for minors, and the trend is accelerating.

Platform selection by tech stack

What you can use depends partly on how your sites are built.

PlatformWordPressCustom Node.jsAstro/Static
Ours Privacy✅ Via JS SDK✅ Via JS SDK✅ Via JS SDK
Freshpaint✅ Via JS/GTM✅ Via JS/GTM✅ Via JS/GTM
Complianz Premium✅ Native plugin❌ WordPress only❌ WordPress only
CookieYes✅ Plugin or JS✅ JS snippet✅ JS snippet
Termly✅ Plugin or JS✅ JS snippet✅ JS snippet

If you’re running a mix of WordPress and custom-built sites (common for multi-location groups that have acquired practices over time), Ours Privacy or Freshpaint give you one dashboard across everything. If all your sites are WordPress, Complianz Premium is hard to beat on value for consent management.

This guide is for informational purposes only and is not legal advice. Privacy laws change frequently. Talk to qualified healthcare privacy counsel about your specific situation.

Who wrote this

Carenetic runs the websites for multi-location healthcare groups, from ten locations to more than two hundred. Support, builds, audits and hosting, all under one team. See what we do →