Meta health and wellness ad restrictions: what data is safe to send with offline conversions
Not legal or medical advice, just what tends to get clinic and wellness accounts into trouble on Meta, and what it means for the offline conversions you send.
Here's the tension. Offline conversions are powerful precisely because they carry real outcomes: a booked consultation, a treatment that was paid for. But in a health business, an outcome is exactly the kind of data that can reveal something about a person. So the question isn't "should I send offline conversions?". It's "what's the minimum I have to attach for the platform to learn?".
Most of the time the trouble isn't the ad. It's the data going out with it. Three classic mistakes:
The page link names the treatment. A URL like /implant-consultation-thank-you goes out with the event, and now Meta knows exactly what the visitor booked.
The event name gives it away. "Book_Implant_Consult" says more than anyone intended.
The form sends symptoms, a condition, or a name alongside the health detail.
Meta sees a pattern of health information flowing in and restricts the account. And the worst bit: it can look like a random ban when it's really a consistent leak.
So what's the minimum for an offline conversion to work? Three things. Who it's about, in a form that can be matched but not read: a hashed email and phone. Which ad it came from: the ad click. And, where it matters, what it was worth: a value. That's enough for the platform to learn "this click led to someone who showed up and paid". Nothing about the treatment, the condition or the person's name has to travel.
The fix on the sending side is to send less, and make what you send neutral. Cut page links down to the domain, so the path never goes out. Use neutral event names, like L_1 for a lead. Send only an approved list of fields. Never send symptoms, treatment or name.
Check your own site first. The thank-you page URL is often where the treatment name leaks, and it goes out with every event by default in a lot of setups.
To make it concrete, here's a made-up event before and after cleaning.
Before: the page is yourclinic.com/treatments/implants/thank-you, the event is called Book_Implant_Consult, and a form field called "reason for visit" says "missing teeth".
After: the page is yourclinic.com, the event is L_1, the reason for visit isn't sent, and what's attached is a hashed email, a hashed phone, the ad click and the value.
Same conversion, same match, and nothing in it that describes anyone's health. If you take the "after" version to a reviewer, it explains itself. And if the "before" version is what your pixel sends today, you know what to fix first. One more habit: whenever the site changes (a new landing page, a new plugin), check Test Events again. New pages are how the "before" version creeps back.
Has your account been restricted? What did Meta say it was about?
More on this: Meta offline conversions, and the complete guide to offline conversion tracking.