Ours Privacy, a HIPAA-compliant marketing and data infrastructure platform, has raised $15 million in an oversubscribed series A funding round.
The software is a full-stack marketing solution designed with healthcare privacy in mind. It integrates with a slew of data sources—from websites to EHRs to Big Tech platforms—cleans PHI, and transmits it to third parties. Its core offering, a customer data platform, can be paired with tools for consent management, A/B testing or web analytics.
The funding round was led by Lightbank and Health Velocity Capital, with participation from Rock Health, Lakehouse, TMV, Switch Ventures, Serena Ventures, GreyMatter and others.
“Ours Privacy was an easy investment decision for us. What sold us was the product and customer feedback,” Eric Ong, partner at Lightbank, said in a press release. “Ours Privacy didn’t build a compliance layer and call it a day—they built an entire growth stack that rivals anything else on the market, all in one place. Ours Privacy is quickly becoming the backbone of the modern healthcare marketer’s tech stack.”
The Office for Civil Rights, which enforces HIPAA rules, has issued guidance cautioning that HIPAA applies to tracking technologies like "pixels," meaning PHI cannot be shared with third parties for marketing purposes. Pixels are embedded analytics tools that help companies track who is clicking on an ad and what they do after they click on it.
“This is how advertising works and we all kind of intuitively know that by the ads that follow us around,” Jessica Holton, co-founder and CEO, told Fierce Healthcare in an exclusive advanced interview. “It makes your ad way more efficient in terms of customer or patient acquisition costs, but it comes at the expense of sharing that data.”
Whereas stakes are low in the consumer world, a number of healthcare organizations have been dinged for violating privacy laws. As a result, many healthcare organizations have pulled back from pixels to avoid penalties, Holton explained. Just last month, the FTC, California and Utah jointly sued Hims & Hers for allegedly sharing consumers’ health information with Meta, Snap and other third parties, among other complaints.
“Hims shared its consumers’ health information with advertising platforms by sharing lists of certain customers with those companies,” the FTC complaint says. “Hims also shared consumers’ health information via third-party tracking technologies that automatically shared certain 'Events'—the actions of visitors on Hims’ website—with those companies.”
The co-founders of Ours Privacy encountered this challenge when running a telehealth company. They struggled to find a secure way to conduct marketing and analytics and realized it’s a universal risk.
Not being able to do digital marketing can be detrimental to a company’s bottom line, per Holton: “I cannot highlight enough how catastrophic not having any kind of pixel-type thing in place would have been for our marketing. It would have astronomically increased the cost of acquiring patients and customers.”
Ours Privacy’s offering appears to be resonating with the market. Today, it works with over 200 providers, payers, digital health companies and more, including multi-billion-dollar healthcare organizations. It doesn’t disclose their names to ensure privacy.
What information customers decide to strip is up to them, though Ours Privacy provides guidance. A company may want to strip parts of a URL that indicate a user booked an appointment, for example, or their email address. What ultimately gets sent to third parties is basic, just enough to optimize ad campaigns: someone clicked on an ad, and it resulted in an undisclosed behavior the company liked. Holton calls these data “signals.”
“It is less data than what a consumer business is able to share back with Facebook, but it’s definitely better than nothing,” Holton said. Plus, if users don’t opt in to data sharing, they won’t be tracked by Ours Privacy, so “you’re honoring patient choices in a way that a pixel might not, necessarily.”
Even though customers are not sharing PHI with third parties, they themselves can retain those insights. Working with a centralized platform like Ours Privacy saves companies from having to stitch together multiple sources of data on their own, and being able to see consumer actions—like where people are spending time on their site—has its own value, Holton noted.
The risks of careless tracking for organizations are multifold, Holton said. HIPAA breaches must be reported, which looks bad for a company. There are also fines or lawsuits associated with non-compliance. Poor security management can leave a company open to hacking threats.
But there’s a deeper problem, Holton argues: violating trust. If a patient is Googling cancer treatment and then gets targeted at work with a cancer drug ad, that’s PHI. “If a shoe ad follows me, I don't feel as personal to that. It’s different with healthcare data,” Holton said.