Analytics Collection Is Approved Without an End-to-End Data Map
Observable evidence: The team cannot produce a current inventory showing what Google Analytics 4 (GA4) collects, which events or parameters are sent, who can access the data, how long it is retained, and which vendor terms apply. A second signal is a configuration record that mentions GA4 but does not reconcile the live payload with the approved marketing use case.
Consequence: Privacy, legal, security, and marketing owners cannot determine whether the production implementation matches the organization's obligations, contracts, and internal controls. A missing or incomplete review can create regulatory, contractual, security, or operational exposure, but the exact legal conclusion depends on the facts.
Correction: Build a system-level map of events, identifiers, page data, form interactions, destinations, retention rules, user roles, and vendor relationships. Remove unnecessary collection, document approved transformations, and route contractual questions to the responsible reviewers.
Owner: Analytics engineering with privacy or legal, security, and the marketing owner.
Verification: Run controlled sessions, inspect browser and server traffic, compare observed payloads with the approved map, and record reviewer sign-off on the deployed configuration.
Severity: critical
Condition-Sensitive Advertising Events Are Enabled Without a Use-Case Review
Observable evidence: Paid-media tags, conversion features, custom audiences, or retargeting rules receive page paths, form events, content labels, or other signals tied to health-related services without a documented review of privacy, platform policy, consent, and business purpose.
Consequence: The organization may transmit or infer sensitive context in ways that conflict with internal policy, vendor terms, platform restrictions, or applicable law. The risk comes from the actual event and audience design, not simply from the presence of a tag.
Correction: Disable unapproved events and audiences, minimize fields, use broader contextual campaign structures where appropriate, and document why each retained event is necessary and permissible for the organization.
Owner: Paid media lead with privacy or legal, security, and analytics engineering.
Verification: Test sensitive pages and forms in a controlled environment, inspect outbound requests, confirm excluded fields are absent, and retain the final approval record.
Severity: high
Clinical Publishing Has No Accountable Medical Review
Observable evidence: Health-related landing pages or educational articles lack a visible author or reviewer, documented approval, source support where needed, credential context, or a maintenance date.
Consequence: Readers cannot easily identify responsibility for consequential information, and the organization loses a clear editorial audit trail. E-E-A-T should not be described as a measurable penalty score, and unsupported claims about automatic ranking suppression should not be used as evidence of failure.
Correction: Assign an appropriate clinician or qualified reviewer, connect the material to accurate professional information, document references and approval, and define when the page must be reviewed again.
Owner: Clinical content owner with editorial operations.
Verification: Audit priority pages against internal approval records and confirm that authorship, reviewer identity, credentials, source support, and revision status are accurate.
Historical source note: The source describes a 60% organic traffic loss after a core update for a dental group, but it provides no exact supporting source URL or causal analysis. Preserve that figure only as an unverified historical observation, not as proof that missing review caused the change.
Severity: high
Lead Forms Reach Systems That Have Not Been Reconciled With the Approved Data Flow
Observable evidence: The team cannot show which fields are collected, how submissions are transmitted, where they are stored, which CRM or messaging tools receive them, who has access, and how retention or deletion works.
Consequence: Sensitive inquiry data can move through systems that were never reviewed together, making access control, incident response, vendor accountability, and patient communication harder to manage.
Correction: Document the complete path from form to destination, reduce collection to what is necessary, replace unapproved integrations, and assign owners for storage, access, retention, and deletion.
Owner: Web product owner with security, privacy or legal, CRM operations, and patient-access leadership.
Verification: Submit controlled test records, inspect transport and storage, confirm access permissions and deletion behavior, and compare the observed workflow with the approved architecture.
Severity: critical
Technical SEO Changes Are Released Without Security Review
Observable evidence: Crawl, indexing, plugin, script, template, or deployment changes are approved without checking public directories, unintended files, security headers, certificate status, third-party scripts, or access to sensitive resources.
Consequence: A marketing change can expose content, introduce an unsafe dependency, or widen public access beyond what the organization intended. Search visibility and security are different controls, but the same web change can affect both.
Correction: Add security and privacy checks to release criteria, restrict unintended resources, review third-party scripts, maintain supported software, and escalate findings to the appropriate technical owner.
Owner: Engineering or security with technical SEO and web operations.
Verification: Recrawl the public site, inspect headers and scripts, test sensitive-path assumptions, and confirm restricted materials are not publicly reachable through the marketing site.
Severity: high
Public Review Responses Confirm More Than the Organization Intends
Observable evidence: Staff or agency replies repeat a diagnosis, treatment, appointment detail, outcome, or patient status, or add keywords that reveal sensitive context in a public forum.
Consequence: The response can create privacy, trust, or legal risk even when the reviewer volunteered details first. Local-search goals should not determine how sensitive information is handled.
Correction: Use neutral, non-confirming response language, route sensitive cases to trained staff, avoid repeating health details, and keep reputation management separate from keyword insertion.
Owner: Patient-experience or reputation lead with privacy or legal review.
Verification: Sample recent responses, compare them with the approved policy, and retrain staff where replies disclose or confirm sensitive information.
Severity: medium
Organic and Paid Reporting Are Combined Without Shared Definitions
Observable evidence: SEO and paid-media teams use incompatible conversion definitions, export data into separate systems, or merge reporting without a documented source-of-truth model, access rules, privacy review, and attribution logic.
Consequence: Leadership may double-count activity, compare unlike metrics, or move sensitive information between systems without a clear need. Cross-channel analysis can be useful, but only when the underlying data model is governed.
Correction: Define common metric names, approved fields, source systems, attribution limitations, access roles, and reporting owners. Share only the information needed for decision-making and label uncertainty where causal attribution cannot be established.
Owner: Marketing analytics with SEO, paid media, privacy, security, and finance stakeholders.
Verification: Trace dashboard metrics back to their source, reconcile conversion definitions, test access controls, and document exclusions, transformations, and attribution limits.
Severity: medium