Notes
Click-ID-Only Conversion Feeds: How Clinics Send Results to Google Ads Without Patient Data
A click-ID-only conversion feed tells Google Ads which ad clicks turned into real patients by sending three things: the Google click ID, the name of a pipeline stage, and a timestamp. No name, email, phone number, procedure or note leaves your systems. Bidding improves. Patient data stays where it is.
Key takeaways
- The feed sends a click ID, a stage name and a time. Optionally a value. Nothing else.
- Google uses it to see which clicks became booked, shown or paid patients, so it stops buying form fills that go nowhere.
- It is a smaller disclosure than a standard tag or enhanced conversions, which can pass page URLs, form contents or hashed emails.
- It is still a disclosure. The click ID ties back to an ad click Google already knows about, so stage names must be neutral and your privacy officer should sign off.
- Most feeds fail for boring reasons: a booking widget drops the ID, the CRM changes its case, or uploads run after 90 days.
Contents
- What is a click-ID-only offline conversion feed?
- Why the standard setup sends more than you think
- What leaves your systems, method by method
- Where the feed breaks in real clinics
- What this costs, by route
- Tag, enhanced conversions, click-ID feed, or nothing
- How I build it
- The monthly check you can run yourself
- Before you send Google another conversion
Your report says the ads produced 300 conversions last month. Your front desk booked 70 consultations. Somebody on your team asks the obvious question: can we just tell Google which ones were real? Then somebody else asks the harder one: can we do that without handing Google our patient list?
You can. The mechanics are simple and about ten years old. What is new is that owners and chiefs of staff now write it into the brief, in their own words: clean, privacy-compliant tracking, click ID only. This guide explains what that phrase means in practice, what it does and does not protect, and where I see it break.
I am a marketing consultant, not a lawyer. Treat the compliance sections as a map to take to your privacy officer or counsel, with sources, and not as legal advice.
What is a click-ID-only offline conversion feed?
A click-ID-only offline conversion feed is an upload to Google Ads that contains the click identifier from the original ad click, the name of a conversion action, and the time the outcome happened. It carries no personal or health information. Google matches the ID to the click it already recorded and credits the outcome to that keyword, ad and audience.
The identifier is usually the GCLID, the Google Click ID, which auto-tagging adds to your landing page URL. On some iOS traffic Google uses two sibling parameters, gbraid and wbraid, which work the same way for uploads. If you want the background first, I explain the ID itself in what a GCLID is and where it gets lost.
The upload goes through Google's offline conversion import, either as a scheduled file or through the Google Ads API click conversion upload. The minimum payload looks like this:
| Field | Example | Why it is there |
|---|---|---|
| Click ID | a long case-sensitive string | Lets Google find the original click |
| Conversion action | Stage 2 | Tells Google which outcome this is |
| Conversion time | 2026-09-14 15:20:00-04:00 | Places the outcome after the click |
| Value (optional) | 1 | Lets you weight stages without revealing prices |
That is the whole feed.
Why the standard setup sends more than you think
Most clinic accounts I open track a form submission with a tag on the thank-you page. It feels harmless. Look at what actually travels.
The tag fires from the browser, so Google receives the page URL. If your booking flow puts the procedure in the URL, such as a thank-you address ending in a procedure name, that travels too. If the tag is configured to read form fields for enhanced conversions, a hashed email or phone number goes with it. Hashing hides the value from a casual reader, but it is derived from an identifier, and Google can match it to a signed-in user. That matching is the entire purpose of the feature, as Google's own description of enhanced conversions makes clear.
There is a second problem, and it costs more money than the first. The tag counts a form fill. Nobody checks whether that person ever booked. Smart Bidding then buys more people who look like form fillers. I cover that loop in what happens when Smart Bidding learns from an incomplete signal. The short version: the report improves every month and the schedule does not.
A click-ID-only feed fixes both at once. It runs server to server, so no page URL or form content is involved. And it reports stages from your CRM, so Google learns from patients and not from forms.
What leaves your systems, method by method
The table above is the one to show your privacy officer. Then add the honest caveat.
A click ID is not anonymous to Google. Google issued it, and Google knows which ad, which search and often which signed-in user produced it. When you upload "this click reached Stage 2", you are telling Google that the person behind that click did something at your clinic. If the conversion action is named "Gastric sleeve consultation booked", you have told Google far more.
So the feed keeps the disclosure as small as it can be. It does not reduce it to zero. Three practices keep it small:
- Neutral conversion names. Stage 1, Stage 2, Stage 3, or Qualified, Booked, Completed. Never a procedure, a condition or a price tier that maps to one.
- Flat or bucketed values. Use 1, 5 and 20 to rank stages. Do not upload the invoice amount if it identifies the procedure.
- No audiences built from it. Google's personalized advertising policy already bars health-based remarketing. Keep these conversions out of any audience list regardless.
What US rules say
HHS set out its view in its bulletin on the use of online tracking technologies by HIPAA covered entities. In June 2024 a federal court vacated one part of it: the position that an IP address plus a visit to a public, unauthenticated health page is protected health information on its own. HHS dropped its appeal, as the American Hospital Association reported. The rest of the bulletin stands, including the parts about authenticated pages and about disclosing identifiable health information to vendors without a business associate agreement.
A booked consultation is more than a page visit. That is why I treat the feed as something counsel approves in writing, with the payload in front of them. If you are not a HIPAA covered entity, for example a cash-pay practice that never bills insurance electronically, the FTC's Health Breach Notification Rule and state health-privacy laws may still apply to what you share with ad platforms.
What changes in Canada
HIPAA does not govern a Canadian clinic treating Canadian patients. Provincial health-information laws do, such as Ontario's PHIPA and Alberta's Health Information Act, alongside PIPEDA for commercial activity. The vocabulary differs, custodians and consent instead of covered entities and authorizations. The engineering answer is the same: keep identifiable health information inside, and send the minimum. A clinic working in two provinces should have the feed reviewed once against both.
Where the feed breaks in real clinics
| Cause | What actually happens | Hidden cost | What you see in reports | Risk level |
|---|---|---|---|---|
| Booking widget in an iframe | The widget cannot read the click ID from the parent page | Your best leads, the ones who book directly, are invisible to bidding | Bookings exist in the CRM with an empty click ID field | High |
| Redirect or link shortener strips parameters | The visitor lands without the ID | Whole campaigns look like they produce nothing | Paid traffic with no matched outcomes | High |
| Phone calls without call tracking | The caller is never tied to a click | A large share of real demand goes unreported | Calls logged as direct or unknown | High |
| CRM lowercases or trims the ID | The stored ID no longer matches Google's | Uploads fail silently for weeks | "Click not found" errors in the upload log | Medium |
| Uploads run after 90 days | Google rejects clicks older than the conversion window | Long surgical cycles lose their final stage | "Click too old" errors | Medium |
| Procedure names as conversion actions | Health detail is disclosed with every upload | A privacy problem created by the fix itself | Conversion list reads like a service menu | High |
| Duplicate records merged in the CRM | The surviving record loses the original ID | Returning enquirers never count | Match rate falls month over month | Medium |
| Stage uploaded as primary too early | Bidding optimizes to an easy stage | Spend drifts back to cheap leads | Stage 1 volume up, Stage 3 flat | Medium |
The form side of this is covered in HIPAA-compliant forms that still pass the click ID, and the CRM side in what a marketing team can use in a HIPAA-compliant CRM.
The iframe row is the one I meet most. A clinic embeds a scheduling tool, the ID never reaches it, and the people who book without speaking to anyone, the best prospects in the account, train nothing.
What this costs, by route
Market figures below were checked in September 2026 and are for the US and Canada. Treat them as ranges, not quotes.
| Route | Typical cost | Time to first verified upload | What it depends on |
|---|---|---|---|
| Your developer builds it from Google's documentation | Usually a few hours of developer time for capture on a simple site, more with a booking tool and call tracking. Upwork lists tag manager specialists at $20 to $49 an hour (median $30); senior US consultants quote $85 to $175 | Days for capture, then about 30 days of clean uploads before bidding should rely on it | CRM API quality, number of entry points, call tracking |
| Your agency adds it | Published 2026 agency price guides put one-time setup fees between $500 and $5,000, and up to $10,000 for complex accounts. Ask whether tracking is included or billed separately | Depends on their queue | Whether the agency has CRM access at all |
| I build it as part of onboarding | Audit at $500 per ad account, credited toward the first month. The build is a fixed quote after the audit, or included in full management | Scoped in the audit. Bidding switches after about 30 days of clean uploads | Same as above, plus sign-off from your privacy officer |
| Leave it as is | No invoice | Never | Every month of form-fill bidding compounds the waste |
The last row has the largest number in it. You cannot see it on an invoice, which is why it survives. The argument is in cost per patient versus cost per lead.
Tag, enhanced conversions, click-ID feed, or nothing
| Option | What leaves your systems | Signal quality for bidding | Risk | When it makes sense |
|---|---|---|---|---|
| Standard tag on the thank-you page | Page URL, events, sometimes form contents | Low: counts forms, not patients | Depends on URLs and fields | Non-health businesses, or as a temporary secondary signal |
| Enhanced conversions for leads | Click data plus hashed email or phone | High | Hashed identifiers tied to a health enquiry | Where counsel has approved sharing hashed contact data |
| Click-ID-only offline feed | Click ID, neutral stage, time | High | Smallest disclosure that still teaches bidding | Clinics and any regulated, long-cycle service |
| Server-side tagging with field stripping | Whatever you allow through | Medium to high | Configuration drift over time | Larger groups with engineering support |
| No conversion data | Nothing | None: bidding runs blind | None on privacy, high on spend | Rarely. Usually a sign nobody has looked |
An agency is the better choice if you need creative, landing pages and media buying as one package and your cycle is short. For a private-pay clinic with a multi-week cycle and a privacy officer who reads payloads, the feed is the piece that matters most, and it is rarely what an agency is staffed to build.
How I build it
- I map every way a person can enter: forms, booking widget, phone, chat. Each one gets a test click with a fake ID to see whether the ID arrives in the CRM.
- I fix capture. A first-party cookie holds the ID, hidden fields carry it, the booking tool receives it through its own parameter, and call tracking passes it on the call record.
- I add one text field in the CRM, 255 characters, case preserved, never overwritten once set.
- I define three neutral stages with you and create matching conversion actions. Early stages start as secondary so they report without steering bids.
- I build the sender. Depending on your stack this is a scheduled job, a CRM workflow or an n8n flow. It selects records whose stage changed, sends ID, action and time, and writes a log line for each.
- Your privacy officer reviews the literal payload and the log, then approves in writing.
- After about 30 days of clean uploads, the deepest stage with enough volume becomes the primary bidding signal.
What you see after 30 days: uploads match at a stable rate and the log has no recurring errors. After 60: Google Ads shows stages next to keywords, and the expensive keywords that never produce a Stage 2 become obvious. After 90: spend has moved toward the clicks that become patients. This is the same method behind the one result I quote: I inherited an underperforming account and rebuilt it; cost per acquisition came down by about 78% while spend grew.
The Salesforce version of the build is written up step by step in GCLID to Salesforce offline conversion import, and the wider method in the Google Ads offline conversion tracking guide.
The monthly check you can run yourself
- Open ten recent CRM records from paid traffic. Count how many have a click ID. You want eight or more. Below about 80% coverage, bidding learns from a biased sample and capture is broken somewhere.
- Open the upload log. Any repeating error is a leak.
- Read the conversion action names aloud. If one names a procedure, rename it.
- Put Stage 2 in Google Ads next to Stage 2 in the CRM for the month. They will not match exactly. They should move together. If they do not, read why Google Ads conversions and CRM numbers disagree.
- Ask who last reviewed the payload, and when.
The audit covers your ad account, the tracking and the path from enquiry to booked patient, and ends with a 90-day plan. It is credited toward the first month if you continue with me.
You work with me directly. There are no account managers and no juniors.
If you want this checked by someone who builds these feeds, my audit covers capture at every entry point, the payload, the conversion action setup and the upload log, and ends with a 90-day plan. The audit is $500 per ad account, comes with a 90-day plan, and is credited toward the first month if you continue with me. You work with me directly; there is no team behind the curtain. You can book a call or write first if you would rather send your questions in writing. The service itself is described on the HIPAA-compliant conversion tracking page.
Before you send Google another conversion
Every form fill you report today teaches Google to find more form fillers. Every day the feed is missing, that lesson gets more expensive to unlearn. Pull ten CRM records, check for the click ID, and read your conversion action names. If either check fails, fix capture first, then send the smallest payload that still tells the truth. If you want a second pair of eyes on it, start with the audit.
Frequently asked questions
Is a GCLID protected health information?
On its own it is a pseudonymous string. Combined with an outcome at a healthcare provider it can relate to an identifiable person, because Google can connect it to a user. That is why stage names stay neutral and why counsel should review the payload and decide.
Do I need a business associate agreement with Google for this?
Google does not offer one for Google Ads. The design goal is therefore to avoid sending anything that would require it. Whether your specific feed meets that bar is a decision for your privacy officer or counsel, with the payload in front of them.
What does it cost to set up?
It depends on how many entry points you have, the quality of your CRM's API and whether phone calls are tracked. For scale: Specialist freelancers on Upwork list tag and tracking work at $20 to $49 an hour (median $30); senior US consultants quote $85 to $175 an hour, and 2026 agency price guides put one-time tracking setup between $500 and $5,000. I quote a fixed price after the audit. The build is a one-time project with light monthly monitoring.
Can my office manager do this without a developer?
Manual file uploads are possible with no code if your CRM can export ID, stage and time. The part that usually needs technical help is capture, getting the ID into the CRM from every form, widget and call.
How fast does bidding improve?
Expect about 30 days of clean data before changing what Google bids toward, then several weeks of adjustment. Long surgical cycles take longer because the deeper stages arrive later.
What if a patient takes four months to decide?
Google accepts a click for up to 90 days. For longer cycles, upload an earlier verified stage, such as a completed consultation, inside that window, and keep the final stage for your own reporting.
Who does the work?
I do. Mapping, capture fixes, the sender and the monitoring. Nothing is handed to a junior or subcontracted.
How do I verify the results myself?
Three places: the upload log, the click ID field in your CRM, and the stage columns in Google Ads. If the three agree in direction month to month, the feed is working. You should never have to take anyone's word for it, including mine.