Define an event before counting it

Two dashboards can show different conversion rates while both are technically working. One may count a button click; another may count a submitted form. Fix the definitions first. For each event, record the trigger, source system, timestamp convention, identifier, permitted destination and owner. Use names that describe what happened rather than names that imply a clinical result.

An inquiry is not a completed intake. A payment attempt is not a settled payment. A submitted clinical request is not a prescribing decision. A shipping label is not carrier acceptance. Make these distinctions visible so the founder can ask an actionable question when a number changes.

Map data destinations before adding tracking

HHS says HIPAA obligations apply to tracking information that includes PHI in regulated-entity contexts. Its bulletin also notes a court vacated a specific interpretation concerning IP addresses and visits to unauthenticated public health pages. Do not assume either that all public-page visits are PHI or that every tracker is acceptable. Have the responsible privacy team assess the actual data flow and applicable rules.

Inventory page URLs, form fields, query strings, event payloads and vendor destinations. Keep diagnoses, symptoms, medication details and clinical notes out of routine marketing exports. An opaque ID or hashed email does not automatically make a disclosure permissible. The HIPAA and data-flow map provides the companion planning worksheet.

Source context: HHS: Use of online tracking technologies by HIPAA covered entities and business associates

Connect operational records without oversharing

Use an approved internal reporting process to connect the journey across systems. Keep the reconciliation key and access permissions under a named owner. The reporting team may need a coarse status such as pending action or fulfilled; it rarely needs the full contents of a clinical conversation. Confirm which status fields can be shared and with whom before building integrations.

Write down which system is authoritative for payment, intake, clinical workflow and shipment. Do not let the marketing platform's estimated purchases replace the payment ledger. If a vendor changes a status definition, version the event dictionary and annotate the report. Otherwise a new integration can look like a sudden business improvement.

Reconcile money and time

Report both acquisition cohorts and order activity. A cohort groups people by the period or channel in which they first entered the journey. Order activity shows what happened during the current period. Mixing them can make a long fulfillment cycle appear to be a poor campaign in one week and an excellent campaign the next.

For each cohort, compare media and attributable variable acquisition costs with fulfilled orders, net receipts, variable delivery costs and refunds. Record the observation window and incomplete orders. Use telehealth unit economics for the cost structure. For operating reviews, also track elapsed time between steps, queue age and rework so the team can see a bottleneck before increasing volume.

Test the report with synthetic journeys

Walk an approved test record through successful payment, failed payment, abandoned intake, canceled order and fulfillment. Confirm that retries do not create duplicate orders and that refunds update net receipts. Use synthetic data in test environments rather than copying patient records into spreadsheets for convenience.

Inspect the report from the founder's perspective. Can someone explain why ten inquiries produced a smaller number of fulfilled orders without seeing sensitive details? Can the team trace a discrepancy to its system owner? Review unmatched records, missing events and delayed updates weekly. Assign every discrepancy an owner and resolution date, and annotate any period whose numbers remain incomplete. A measurement plan is useful when it produces decisions, not when it collects every available field.

Event dictionary starter

These are planning examples. Match definitions to the contracted workflow and approve each data destination before implementation.

On small screens, scroll the table sideways to view every column.

Event dictionary starter
EventDefinition to confirmAuthoritative systemReporting boundary
Inquiry receivedA valid inquiry was submittedApproved form or CRMChannel and permitted contact fields
Intake completedRequired administrative steps submittedIntake platformCompletion status, no answer contents
Payment settledProcessor confirms settlementPayment ledgerApproved amount and order reference
Order fulfilledDefined fulfillment milestone metFulfillment partnerStatus and timing, no clinical notes
Refund recordedRefund posted under agreed policyPayment ledgerAmount, date and approved reason category
Download this worksheet as CSV

Before you move forward

  • Give every event a definition and authoritative system.
  • Review payloads, URLs and destinations for sensitive information.
  • Separate acquisition cohorts from current-period order activity.
  • Reconcile settled receipts, refunds and fulfilled orders.
  • Test retries, cancellations and missing events with synthetic records.

Sources and scope

Source check: October 10, 2026. Primary sources support the rules and vendor descriptions cited above. Worksheets are original planning tools, not provider commitments or forecasts. Requirements can change; confirm current terms for your program.

  1. HHS: Use of online tracking technologies by HIPAA covered entities and business associates

    Supports the PHI tracking discussion and the bulletin's notice of partial court vacatur. Checked October 10, 2026. HIPAA applicability and other privacy duties require a fact-specific assessment.