Measuring healthcare marketing without touching a medical record
Multi-site healthcare groups usually conclude that attribution is off limits because the data is clinical. It is not, because attribution does not need clinical data. What it needs is a phone number, an amount and a date, and there is a way to handle even those properly.
Contents
- The minimum data set
- Where the real risk sits
- Calls dominate, and most measurement ignores them
- Site variation, which is usually the finding
- Episode value, and the trap of first appointment
- Handling the data protection conversation
- Private, insured and mixed funding
- Consent, and why healthcare gets it wrong in both directions
- Reputation and referral, the channels you cannot buy
- Appointment availability as a marketing constraint
- What to do first
Healthcare marketing teams tend to arrive at the same conclusion about measurement, and they arrive at it early: this is clinical data, so we cannot do it. The conclusion is careful, well-intentioned, and wrong in a specific way that costs these organisations a great deal — because attribution does not require clinical data, and the belief that it does prevents an entirely lawful analysis from ever being attempted.
Attribution needs to know that somebody became a patient and what that episode was worth. It never needs to know why they came.
This article is about doing it properly: what the minimum data set is, where the genuine risks are, and what multi-site healthcare groups consistently find when they look.
The minimum data set
Healthcare attribution needs a contact identifier, an episode value, a date and a row reference. Diagnosis, procedure, clinician, department and clinical notes are all unnecessary and should never be exported.
This is worth stating precisely because it is usually the whole objection. When a data protection officer hears marketing attribution they picture patient records leaving the building. When they see a four-column specification with no clinical field in it, the conversation changes character entirely.
Even the department is usually unnecessary and frequently harmful. Knowing that an episode was worth two thousand pounds is sufficient for measuring marketing return; knowing it was an oncology episode adds nothing to the analysis and converts an ordinary personal data set into one implying health information.
Where service-line reporting is genuinely needed — and sometimes it is, because marketing budgets are set by service line — use a coarse category rather than a clinical one, and think about whether that category is small enough to be identifying in a given period.
Where the real risk sits
The significant risk in healthcare marketing is not the attribution export. It is the tracking code on clinical pages and in booking flows, which can transmit information implying a health concern to third parties in real time.
This is the part that has attracted regulatory attention and litigation, and it is worth understanding as distinct from attribution. A tracking pixel on a page about a specific condition can transmit the page address, and therefore the implied concern, alongside an identifier, to an advertising platform. That happens continuously and invisibly.
Attribution based on exported closed episodes has none of that property. It is a batch process, running on data you already hold, containing no clinical field, going to a defined processor under a written agreement. The risk profile is completely different, and conflating the two is what leads organisations to prohibit the safer activity while continuing the riskier one.
If you do one thing after reading this, audit what is loading on your condition pages and in your booking flow. It is a bigger exposure than anything in your reporting.
Calls dominate, and most measurement ignores them
In healthcare a large majority of enquiries arrive by telephone, and many are made by people who will not complete an online form under any circumstances. Measurement built on web conversions will systematically misrepresent the channel mix.
The reasons are structural rather than generational. Healthcare enquiries frequently involve uncertainty, urgency or embarrassment, and people want a person. Appointment availability is often the real question and a form cannot answer it. Older demographics are over-represented in many service lines.
The practical consequence is that a healthcare group measuring only online bookings is measuring a minority of its acquisition, and the channels that generate calls rather than clicks will appear to perform poorly. Matching call records to closed episodes is not a refinement in this sector; it is the main event.
It also means the reception function is part of the marketing funnel whether anybody has said so or not. How quickly calls are answered, what happens at lunchtime, and whether voicemails are returned are marketing variables with large effects.
Site variation, which is usually the finding
Conversion from enquiry to booked episode varies far more between clinic sites than between marketing channels. The group average conceals it, and closing the gap is generally worth more than any campaign change.
| Site | Matched enquiries | Booked episodes | Conversion | Median answer time |
|---|---|---|---|---|
| Site A | 820 | 394 | 48% | 22 seconds |
| Site B | 760 | 281 | 37% | 41 seconds |
| Site C | 690 | 152 | 22% | 2 min 40 s |
| Site D | 540 | 248 | 46% | 26 seconds |
Site C is not receiving worse enquiries. It is answering the telephone in two minutes and forty seconds, and roughly half of the people calling it are hanging up. No marketing intervention available at any budget would produce the improvement that fixing that one number would.
This is the pattern in almost every multi-site healthcare group that runs the analysis, and it is why the first attribution report in this sector usually turns into an operations project rather than a media one.
Episode value, and the trap of first appointment
Attributing only the first appointment value understates marketing considerably in service lines where an episode involves a course of treatment. Use the full episode or pathway value where the finance system can produce it.
A consultation valued at two hundred pounds that leads to a treatment pathway worth six thousand is not a two hundred pound acquisition. Groups that attribute on first appointment value routinely conclude that their marketing is barely breaking even, and the conclusion is an artefact of the field they exported.
Where pathway value is hard to assemble, an interim approach is to attribute first appointment value and separately report the average pathway multiple by service line. It is cruder and it prevents the systematic understatement that otherwise drives budget decisions.
Handling the data protection conversation
Bring the data protection officer in when designing the export, not when presenting the analysis. A four-field specification with no clinical data, a named processor, a written agreement and a retention period is an easy approval; the same work presented afterwards is an incident.
- Specify the fields in writing, and state explicitly which fields you are not requesting.
- Identify the lawful basis with the data protection officer rather than asserting one.
- Put the processing agreement in place before any data moves.
- Agree a retention period based on the reporting need, and confirm deletion is genuine rather than a flag.
- Confirm where the data will be stored and whether it stays in your jurisdiction.
Data protection officers are not obstacles to this work and are usually relieved to be consulted about something proportionate. The friction in healthcare marketing measurement almost always comes from marketing teams assuming the answer will be no and therefore never asking.
CloseRev needs an identifier, an amount and a date, holds data in an isolated per-customer store, encrypts it at rest, deletes on a schedule you set, and records deletions in a ledger you can show. It has no field for and no interest in clinical information.
Private, insured and mixed funding
Where episodes are funded by different payers, attribution should account for the payer mix, because marketing that generates insured referrals and marketing that generates self-pay patients have very different economics.
Self-pay patients typically choose actively, which makes them responsive to marketing and traceable to a source. Insurer-referred and consultant-referred patients arrive through a different mechanism and are largely unattributable to advertising, however much brand activity may have influenced the referrer.
Blending them produces a misleading picture in both directions: marketing looks ineffective because a large share of volume was never marketing-driven, and the self-pay acquisition that marketing genuinely drives is diluted into an average. Split by funding route before drawing any conclusion.
Consent, and why healthcare gets it wrong in both directions
Healthcare organisations tend to be either over-cautious about internal analysis and under-cautious about third-party tracking, or occasionally the reverse. The distinction that matters is whether data leaves your control and who receives it.
Analysing your own records, under your own control, to understand which marketing produced patients is a use of data with a clear purpose and a bounded audience. Loading a third-party advertising tag onto a page about a specific condition transmits information to an organisation outside your control, in real time, for purposes you do not fully determine. These are not comparable activities and treating them as equivalent leads to poor decisions.
The practical implication is that consent design should focus its effort where the transfer happens. Cookie banners and tag governance carry the weight for the website; processing agreements, minimisation and retention carry the weight for the analysis. Applying website-style consent logic to a batch reconciliation of your own records is a category error that stops useful work without protecting anybody.
It is also worth reviewing what your privacy notice actually says. Many healthcare notices describe clinical processing in detail and marketing analysis not at all, which is a gap that is easy to close and awkward to explain if it is discovered by somebody else.
Reputation and referral, the channels you cannot buy
A substantial share of healthcare demand comes from personal recommendation, clinician referral and online reviews. None of it is purchasable and much of it is measurable enough to be managed.
The unattributed bucket in a healthcare group is unusually meaningful for exactly this reason. Where in a retail business a large unknown share often signals a missing export, in healthcare it frequently signals a genuine and valuable reputation effect — people arriving because a friend or a general practitioner suggested you.
It can be sized rather than guessed at. Asking a simple source question at intake, consistently, and comparing the self-reported answer against the matched source gives you an estimate of how much of the unknown bucket is word of mouth rather than measurement failure. That is a strategic number, and very few groups have it.
Where the answer is that reputation drives a large share of demand, the marketing implication is significant: investment in patient experience, review management and clinician relationships is producing revenue that no campaign report will ever credit, and it should be defended on evidence rather than on faith.
Appointment availability as a marketing constraint
In many healthcare groups the binding constraint on growth is not demand but capacity, and marketing measured without reference to availability will produce conclusions that cannot be acted on.
The signature is a site with strong enquiry volume, a poor conversion rate, and a four-week wait for an appointment. The marketing worked; the business could not accept the customer. Reported as a marketing performance figure, this looks like a channel problem and invites a media change that will make matters worse by generating more enquiries nobody can serve.
Attribution reporting in this sector should therefore carry availability alongside conversion, at least at site level. It is usually a straightforward figure to obtain and it changes the interpretation of everything next to it.
It also reframes what marketing is for in a capacity-constrained service line. Where availability is the constraint, the useful marketing objective is not more enquiries but better ones — higher value, better fit, filling the sessions that go unused — and that is a measurable goal with a completely different set of tactics.
What to do first
Start with one service line, one quarter, and the four-field export. A narrow first pass gets through governance faster and produces a finding quickly enough to justify the wider exercise.
Choosing a self-pay service line with a short pathway makes the first analysis considerably easier, because the funding route is clean, the cycle is short enough to see results, and the governance conversation is simpler than one involving a complex pathway.
Expect the first finding to be operational rather than about media. In this sector it is almost always answering times, appointment availability, or enquiries that were never followed up, and all three are cheaper to fix than any campaign is to improve.
Keep the first pass deliberately small in scope as well as in data. One service line, one quarter, one site group, and a single question you want answered. Attribution projects in healthcare fail far more often from scope than from governance: a programme proposing to measure every service line across every site will spend a year in design review, while a narrow first analysis can be approved, run and reported inside a month.
Once the first pass has produced a finding and survived governance, extending it is straightforward, because the hard parts — the field specification, the lawful basis, the processing agreement, the retention period — are already settled and reusable. The second service line takes days rather than weeks, and by the third the process is routine.
The biggest privacy risk in healthcare marketing is on your website, not in your reporting. The biggest performance problem is on your telephones, not in your campaigns.
Questions people actually ask
- Can healthcare organisations do marketing attribution legally?
- Yes, provided the data used is limited to what is needed and handled under the correct legal basis and agreements. Attribution needs a contact identifier, an amount and a date. It does not need a diagnosis, a procedure code or any clinical detail.
- What patient data is needed for attribution?
- A phone number or email, the value of the episode, the date, and a row reference. Names help a human recognise a record during review but are not required for matching, and clinical information is never required.
- Is a phone number in a healthcare context sensitive data?
- The number itself is ordinary personal data, but its context can make it sensitive: a list of people who contacted an oncology service reveals something about health even without a diagnosis attached. Treat healthcare attribution data as higher risk than the equivalent retail data, because it is.
- Should healthcare websites run advertising trackers on clinical pages?
- This deserves specific scrutiny rather than a default. Trackers on pages about particular conditions can transmit information implying a health concern to third parties, and this has been the subject of significant regulatory and legal attention.
- How do you attribute revenue when a patient calls rather than books online?
- By matching call records to closed episodes on the phone number, exactly as in any other business. Calls dominate healthcare enquiry volume, so a measurement approach that only sees online bookings misses most of the picture.
- How much does marketing performance vary between clinic sites?
- Considerably, and usually more than between marketing channels. Answering speed, appointment availability and reception handling differ substantially between sites and have a larger effect on conversion than most campaign changes. It is common to see the best and worst sites in a group convert the same enquiries at rates differing by a factor of two, on identical marketing.