On December 1, 2022, OCR released a “guidance” Bulletin re: “Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates.” One of the most troubling positions OCR takes in its Bulletin is that “all IIHI collected on a regulated entity’s website or mobile app generally is PHI, even if the individual does not have an existing relationship with the regulated entity . . .” If your organization maintains a website, portal, FB page, mobile application etc., it must review the tracking technologies associated with these immediately.