Analytics and CRM Vendor Review
Evidence required: current vendor inventory, data-flow diagram, implemented settings, access roles, retention rules, contracts, and any Business Associate Agreement or equivalent documentation relied on by the organization.
Google Analytics 4 should be evaluated from its real configuration and data flow rather than from a blanket assumption about the product. Pass/fail condition: Pass when responsible reviewers can trace what data is collected, where it is sent, who can access it, and which contractual and policy controls apply; fail when the implementation or vendor responsibilities are undocumented or inconsistent with approved use.
Severity: critical. Owner: privacy or legal lead with analytics engineering, security, CRM operations, and marketing. Corrective action: remove unnecessary collection, reconcile vendor terms, document approved data handling, and replace or reconfigure systems whose actual behavior does not match the approved architecture.
Validation step: run controlled test traffic, inspect outbound requests and stored data, compare observed behavior with the approved map, and record reviewer sign-off.
Server-Side Tagging and Event Transformation
Evidence required: server container configuration, transformation rules, event schema, destinations, logs, secrets management, and the approved list of fields permitted to leave the organization's environment.
Pass/fail condition: Pass when each outbound event contains only approved data and the organization can reproduce how the event was transformed; fail when the team assumes that moving tracking server-side automatically removes sensitive information.
Severity: high. Owner: analytics engineering with security, privacy or legal, and paid-media owners. Corrective action: define an allowlist, remove unnecessary fields, harden server access, document transformations, and limit destinations to approved services. Validation step: compare browser input, server processing, and final outbound payloads using controlled test sessions.
Hosting, Encryption, and Access Controls
Evidence required: hosting architecture, transport encryption configuration, storage encryption settings where applicable, access-control lists, privileged-user inventory, logging, backup controls, and vendor documentation.
Pass/fail condition: Pass when the organization can demonstrate that its web infrastructure follows its approved security and privacy requirements; fail when access, storage, transport, or operational ownership is unclear or unsupported.
Severity: critical. Owner: security and infrastructure teams with privacy or legal review. Corrective action: remediate weak access controls, unsupported components, certificate issues, storage risks, and undocumented administrator privileges.
Validation step: perform configuration review, access testing, and documented security acceptance before the environment is treated as approved for production use.
Third-Party Tags on Patient or Account Areas
Evidence required: tag inventory, page-level firing rules, authenticated-area tests, network captures, content security controls, and approved exceptions.
Pass/fail condition: Pass when unapproved marketing tags do not load in patient portals, authenticated areas, or other sensitive experiences; fail when third-party scripts can observe page or interaction data that has not been explicitly approved.
Severity: critical. Owner: web engineering with security, privacy or legal, and marketing operations. Corrective action: disable unnecessary tags, enforce page-level controls, review script sources, and segment authenticated experiences from public marketing instrumentation.
Validation step: test representative authenticated and post-submission pages with network inspection and tag debugging tools.
Lead Form Handling
Evidence required: field inventory, transport path, storage destination, encryption and authentication configuration, vendor relationships, access permissions, retention rules, and deletion process.
Pass/fail condition: Pass when the complete form workflow is documented and approved; fail when submissions enter unmanaged email, databases, spreadsheets, plugins, or CRM routes that the responsible reviewers cannot trace.
Severity: critical. Owner: web product owner with security, privacy or legal, CRM operations, and patient-access leadership. Corrective action: reduce fields to what is necessary, replace unapproved routes, strengthen access controls, and assign ownership for retention and deletion.
Validation step: submit controlled records, trace them end to end, confirm storage and access behavior, and verify deletion or retention handling against the approved workflow.