Health advertiser tracking checklist: 15 things to check before Meta does
Short answer
The 15 checks cover site links, events, forms, identity, stages and records. Also confirm nothing is sent more than 7 days after it happened, since Meta rejects it.
Run this before you have a problem. It takes about an hour, and it catches most of what gets health advertisers restricted. I've grouped it so you can do it in sittings, and added why each check matters, because a checklist you understand is one you'll actually run.
The site and the links
1. Look at your top 10 landing pages. Do any URLs name a condition, a drug or a treatment? Those addresses travel with every event from that page. 2. Look at your thank-you pages. Same question, and this is the one people forget. 3. Check the page titles. They travel too, and they're often more descriptive than the URL.
The events
4. List every event your pixel and server send. You can't fix what you haven't listed. 5. Read the names as a stranger would. Does any describe a service or a condition? 6. Look at the parameters on each event in Test Events. Is anything there you can't explain?
The forms
7. Does any form ask about symptoms, conditions or medications? If it does, that data belongs in your own system. 8. Does any of that reach an ad platform? Check the events, not the form.
The identity
9. Are you sending a hashed email and phone, and nothing else that identifies a person? Those are what matching runs on. 10. Is the formatting clean before hashing (lowercase email, digits-only phone with country code)? A badly formatted value matches nobody.
The stages
11. Are you sending later stages (booked, showed, paid) and not just the form? They're better signals and can be sent without attaching anything sensitive. 12. Is anything sent more than 7 days after it happened? Meta rejects those, so a slow process quietly loses them.
The record
13. Can you show exactly what was sent for any given conversion? If a reviewer asked tomorrow, could you? 14. Do you have a changelog of tracking changes? It turns mysteries into dates. 15. Does someone own this, by name? A checklist with no owner is a wish.
Score yourself. Zero to three problems, you're in decent shape. More than that, start at number one. Numbers 1, 5 and 13 are usually the most revealing.
One caution: a checklist is a snapshot. The site changes, so the answers change. Put a date in your calendar to run it again, and after any major site update.
If you want to run this in one sitting, here's a schedule for an hour. Ten minutes on the site and links (checks 1 to 3). Fifteen on the events (4 to 6): this needs Test Events and a test booking. Ten on the forms (7 and 8). Ten on the identity and formatting (9 and 10). Ten on the stages and timing (11 and 12). Five on the record and ownership (13 to 15).
Who should be in the room? Whoever manages the ads, whoever manages the website, and whoever handles compliance or the practice's privacy questions, even if they only join for the forms section. The site person answers "where does that come from?", and the compliance person answers "should that be sent?". Two perspectives catch what one misses.
Write down each finding as you go, with a name next to it. A finding without a name doesn't get fixed.
Which item did you fail?
DataCops in short
For this question: Several of these 15 checks are built in: Health mode for links and event names, hashed identity, stage sends inside the window and a delivery log you can read.
DataCops is a tool that keeps condition details out of what your ad platforms see: Health mode cuts page links to the domain, uses neutral event names and leaves out anything that describes a condition, while a bot verdict on every visit and a delivery log show what left and what was real.
How DataCops does it
- Health mode. Page links are cut to the domain, event names are neutral, and anything that describes a condition is left out before an event leaves.
- A log of exactly what left. A delivery log row per conversion, sent, held, skipped or failed, with the reason, which is the record you want when explaining yourself to a reviewer.
- Real people only. Every visit gets a bot verdict against 360+ billion IPs and 350+ monitoring points, with a Real people only switch per ad platform, off by default.
- One script, one DNS record. Collection runs on your own domain, and conversions go server-side to Meta, Google Ads, TikTok and LinkedIn, counted once against the pixel.
- The booking after the form. HighLevel natively, any CRM by webhook, sent as neutral events so a booked consultation still teaches the ads who converts.
Best for: clinics, telehealth and wellness brands, and agencies running health ads, who want conversions to keep counting without condition details in the data.
Ads Warmup: tell the ads who pays
Ads Warmup, DataCops' flagship feature, sends customers you already have to Meta, Google Ads and TikTok before a new campaign spends: upload a CSV (only email is required, up to 20,000 rows), see a 0 to 10 match score per person, pick the event, and send. Rows are dated when you send, and Google Ads credits only people who clicked a Google ad. Preview is free; sending needs a paid plan. Check your own consent basis for the list first. See Ads Warmup.
Ways to do this job
| Option | Best for |
|---|---|
| DataCops | Health mode, neutral events and a delivery log, server-side to four ad platforms |
| Manual event cleanup in your site and tag manager | Teams with an engineer who will maintain it |
| Turning conversion tracking off | Accounts that cannot risk any event |
When not to use DataCops
- You need legal or compliance advice. DataCops is not legal advice and does not make an ad account compliant. Your own advisers decide what you may send.
- You need a regulated setup with a signed agreement. That is the Enterprise plan: talk to the team.
Sources and further reading
More on this: Meta health and wellness restrictions, and the complete guide to offline conversion tracking.
Not legal advice, just a practical list. If you have a compliance person or lawyer, show them this and ask what they'd add.