If your healthcare organization embeds Google Maps to help patients find your locations, you may be exposing yourself to HIPAA liability every time a patient loads that map. This isn’t speculation from a compliance blog. It’s documented directly in Google’s own privacy policy, developer documentation, and platform terms of service, combined with clear guidance from the HHS Office for Civil Rights. Here’s what the primary sources actually say.
What Google Collects When You Embed a Map
1. IP Addresses
Google’s privacy policy states explicitly that the information collected includes “unique identifiers, browser type and settings, device type and settings, operating system, mobile network information including carrier name and phone number, and application version number” and that Google also collects “information about the interaction of your apps, browsers, and devices with our services, including IP address, crash reports, system activity, and the date, time, and referrer URL of your request.” This applies when any Google service, including an embedded map, loads on a visitor’s device.
2. The Full URL of the Page the Map Is Embedded On
This one is particularly significant for healthcare sites, and it comes straight from Google’s own Maps Embed API documentation. Google instructs developers to include referrerpolicy="no-referrer-when-downgrade" in the embed code in order to “allow the browser to send the full URL as the Referer header with the request so the API key restrictions could work properly.”
In plain English: Google’s recommended implementation intentionally sends the complete URL of the embedding page to Google’s servers. On a healthcare website, that URL frequently reveals the clinical context — /oncology/find-care, /mental-health/locations, /addiction-treatment/services. That’s not abstract tracking data. That’s a patient telling Google where they are seeking care.
The clinical context embedded in a subdirectory path makes the exposure obvious, but the compliance obligation exists even when the domain name itself doesn’t signal “healthcare.” We explore that question in depth in our companion post: Does Your Domain Name Protect You From HIPAA Liability? →
3. Cookies
The Google Maps Platform Terms of Service state directly: “As noted in the Documentation, certain Maps API(s) store and access cookies and other information on end users’ devices.” The Maps Embed API, the standard iframe embed most healthcare websites use, is explicitly among the cookie-setting implementations. These include the NID cookie, which stores a user identifier that persists across sessions.
4. Google Maps Platform Terms of Service Prohibit HIPAA Use
Perhaps the most damning piece of primary source evidence is buried in the current Google Maps Platform Terms of Service. Under prohibited uses, Google explicitly states that customers may not use the service “to transmit, store, or process health information subject to United States HIPAA regulations.” It seems Google has already determined their product is not appropriate for HIPAA-regulated contexts, but most healthcare websites don’t know this clause exists.
This prohibition is not conditional on the nature of your domain name or whether Google can identify your site as a healthcare organization. It applies to every covered entity that embeds Google Maps.
5. Google’s BAA Does Not Cover Google Maps
Google does offer a Business Associate Agreement for certain Google Cloud and Workspace products. Google Maps Platform is not among them. Without a BAA, any transmission of Protected Health Information (PHI) to Google via a Maps embed has no contractual safeguard, and no legal basis under HIPAA.
Why This Triggers HIPAA Violations
The question that matters under HIPAA is whether the data being transmitted constitutes PHI. The HHS Office for Civil Rights guidance on online tracking technologies clearly answers this.
HHS states that individually identifiable health information (IIHI) collected on a regulated entity’s website or mobile app “generally is PHI, even if the individual does not have an existing relationship with the regulated entity and even if the IIHI, such as in some circumstances IP address or geographic location, does not include specific treatment or billing information.” The guidance further clarifies that when a patient visits a healthcare website to find care, for example, looking at oncology services to seek a second opinion, transmission of that patient’s IP address or geographic location to a third party is a disclosure of PHI.
When that third party has no BAA and has explicitly stated in their own terms of service that their product is not for HIPAA use, the HIPAA violations stack quickly:
- 45 CFR § 164.502 — Impermissible disclosure of PHI to a third party without authorization
- 45 CFR § 164.502(e) / § 164.314 — No Business Associate Agreement in place
- 45 CFR § 164.508 — No valid patient authorization for disclosure to Google
- 45 CFR §§ 164.308, 164.312 — No contractual guarantee of security safeguards for ePHI in transit
- 45 CFR § 164.400 et seq. — Potential breach notification obligation to OCR for each impermissible disclosure
The Compliant Alternative
Sounder Maps was built specifically to address this problem. Unlike Google Maps, Sounder Maps uses self-hosted vector tile infrastructure with no third-party network calls. this means patient IP addresses and page context never leave your environment. There are no cookies, no referrer headers sent to outside parties, and no Google BAA to worry about, because Google isn’t in the picture at all.
If your organization is ready to replace Google Maps with a HIPAA-compliant alternative, contact us to learn more about Sounder Maps.
A note on the legal landscape: In June 2024, a federal court vacated a narrow portion of the HHS tracking technology guidance as it applied to unauthenticated (not logged into the website) public webpages. The full implications of that ruling, and why it ultimately strengthens rather than weakens the case for compliance, are covered in our companion post: Does Your Domain Name Protect You From HIPAA Liability? The core obligations regarding authenticated pages, BAAs, and the prohibition on unauthorized PHI disclosures remain fully in effect. And as noted above, Google’s own Terms of Service prohibit HIPAA use of Google Maps Platform independently of any HHS guidance, a fact no court ruling changes.



