Guide · Updated · 9 min read

Meta health and wellness restrictions, explained

Meta limits what a health site can send, by domain, in three levels. Here is what triggers it, how to check, and the fix that holds.

The short answer

Meta restricts the data a health or wellness site can send, and it does it per domain, in three levels. The sites it hits hardest lose purchase and lead events. The fix that holds is to send a clean, server-side signal with neutral names and no health detail in the payload.

DataCops is a tool that sends Meta only the facts it needs to count a conversion, so a health or wellness site stops handing Meta the things that get a domain restricted.

How DataCops does it, with Health mode on:

  • A fixed list of allowed fields. Every conversion goes through the same cleaning step. Anything not on the list is dropped, so a new form field or page cannot slip through.
  • No page paths, titles or form answers. Paths, query strings, the referrer, page titles, product and content names, cart items and every form answer are removed. A link like clinic.com/ivf/book?step=2 goes as clinic.com.
  • Neutral event names for Meta. A Lead goes as L_1, a booking as S_1, a Purchase as P_1. The name tells Meta nothing about the service.
  • Server-side, with matching kept. Click ID and hashed email, phone and customer ID still go, so Meta can match the sale.
  • Your own tools keep the full record. HubSpot, Klaviyo and your webhook still get the whole lead. Only ad platforms get the cleaned version.
  • Proof. Every cleaned send is marked in the delivery log.
  • Ads Warmup. Upload your existing customers (up to 20,000 rows), see a 0 to 10 match score, and send them to Meta, Google Ads and TikTok so a new campaign starts warm.
  • Real people only. Every visit gets a bot verdict, with a Real people only switch per ad platform (off by default).

Best for: supplement, telehealth, clinic, med spa, weight loss and mental health sites that advertise on Meta and want to send less, on purpose.

What Meta is actually restricting

Meta does not want websites to send it sensitive health information. Its Business Help Center lists the kinds: diseases and conditions, sexual and reproductive health, mental health, medical devices, procedures and treatments, medications and supplements, and places that point to treatment. Meta says it runs a filter that tries to stop that data reaching its ad ranking systems.

The restriction sits on the data source, the domain or app that sends the events. It is not set per ad or per pixel. That is why one flagged page can change what the whole site is allowed to send.

Already restricted? Read what happened to one of our customers and the recovery plan.

Four public write-ups agree on this, and they come from analytics and tracking vendors, so read them as reports, not rulings.

The three levels

LevelWhat Meta does
Core setup (mild)Removes URL detail after the domain, such as UTM parameters, and custom parameters like category, plan type or city.
Standard event (moderate)Can block standard events such as Lead, Add to cart and Purchase. Upper-funnel events like page views keep arriving.
Full (severe)Can block all event sharing from the site or app in certain regions.

Brands in the second level report the worst of it: the events your campaigns optimize for stop arriving, so optimization falls back on weaker signals such as landing page views.

What gets a site flagged

The vendor reports line up on the same list. Meta's classifier looks at:

  • URLs and paths. Health terms in the address, such as a treatment or condition.
  • Event payloads. A product name or condition in a custom parameter, even when the event name looks neutral.
  • Names you set yourself. Custom audiences and custom conversions named after a drug or a condition.
  • Page content. Product descriptions and condition language on the site.
  • Form answers. A symptom typed into a form that reaches the payload.

Who is affected goes beyond clinics. The reports name supplements, weight loss and GLP-1, telehealth and online pharmacy, med spas, mental health, reproductive health and CBD. Treat a site selling any of these as exposed.

How to check if you are restricted

  1. Check your email and Events Manager. Meta says it informs the advertiser by email and with a notice in Events Manager.
  2. Open Settings for the data source. It shows whether the source is listed under a restricted category.
  3. Look at the events themselves. If Lead or Purchase stopped arriving and upper-funnel events did not, that matches the second level.
  4. Read what you send. Open one real event payload and look for product names, paths and condition words.

The DataCops Meta health restriction checker helps with the last step.

What does not work

  • Renaming events alone. One guide puts it plainly: renaming Purchase changes the label Meta sees, not the payload underneath it.
  • Counting on an appeal. There is a review button. One vendor reports no genuine health seller got the category removed across 125+ accounts it reviewed. That is one vendor's sample, so weigh it as such, but it is a reason not to build your plan on it.
  • Hiding the product in a custom name. Meta can infer sensitive information from behaviour and matching as well as from words.
  • Moving to a second domain to get around the flag. One vendor suggests it. We do not, because it works against what Meta asks of you and can put more of your setup at risk.

What works

  1. Clean the payload, not just the label. Remove product names, condition terms, paths, titles and form answers from everything sent to Meta.
  2. Use neutral event names. Names with no tie to a product or condition.
  3. Send from the server. Conversions API, with the browser and server events deduplicated by a shared event ID.
  4. Keep the matching fields. Click ID and hashed email or phone, so Meta can still match the sale.
  5. Rename your audiences and custom conversions. Take drug and condition names out of them.
  6. Keep the full record in your own systems. Send ad platforms only what they need.

Reported recovery is slow. One vendor says algorithm stabilization takes two to three weeks after a clean setup. That is their observation, not a guarantee.

What you lose, and how to measure it

Polar Analytics reports that brands lost lookalike audiences built from buyers and saw weaker attribution, and that many brands report a large drop in ad efficiency. It gives a range, but no method behind the range, so use your own numbers.

  • Judge on your own sales. Use your store or CRM revenue by source, not Meta's report alone.
  • Test outside Meta. A geo test compares regions with and without ads.
  • Rebuild audiences from first-party data. Your own customer list is yours to use, within your consent rules. Ads Warmup does this with a CSV.

How DataCops Health mode works

Health mode is one switch per website. When it is on, every conversion goes through the same cleaning step before it leaves.

What ad platforms still get: the ad click ID (fbclid, gclid), hashed email, phone and customer ID, the value, currency, order ID, event ID and time, the network details and consent signals matching needs, and your homepage address only.

What never leaves your site: page paths, query strings, the referrer, page titles, product and content names, cart items and every form answer.

You can see the log of what was sent per event. Read the full product page: Meta health and wellness restrictions.

Tools these guides point to

Each row says what the vendor's own article describes. We have not tested the other tools, so check their pages before you choose.

ToolWhat its own article describesServer-side to MetaCleans the payload for health sites
DataCopsHealth mode: fixed allowed fields, neutral event names, delivery log, Ads WarmupYesYes, on by detection or by your switch
Polar AnalyticsA first-party pixel that captures Shopify purchases, plus Conversions API and geo-lift testingYesNot stated in its article
CustomerLabsFirst-party data platform: hides sensitive URLs, hashes identifiers, swaps flagged event namesYesYes, per its article
Aixel and ZappushGuides describing payload cleansing and neutral events as the fixDescribes itDescribes it

What else the same install does

  • First-party collection. One script and one DNS record put collection on your own domain.
  • The click is kept. Click IDs are kept on the server for up to 90 days, and a signed server-set cookie lasts up to 400 days where enabled.
  • Counted once. The browser and the server share one event ID, so a conversion is not counted twice.
  • Every ad platform. The same cleaned conversion goes to Google Ads and TikTok through their server-side APIs.
  • Edge capture. With your DNS on Cloudflare, the free Worker reads the click at the edge. It captures; it does not block.
  • Consent and analytics. A first-party consent manager on IAB TCF v2.2 and first-party analytics (a GA4 alternative) from the same script.

What DataCops cannot do

  • It cannot remove a restriction Meta has already applied. Meta decides.
  • It does not make a sensitive ad acceptable. Ad content rules still apply to your ads.
  • It is not legal advice or a compliance certificate. Check your own obligations.
  • Cleaning applies to ad platforms. It does not change what you collect in your own CRM.

Sources

FAQ

What are Meta's health and wellness restrictions?

They are limits Meta puts on the data a website or app can send through the Meta pixel and the Conversions API when the site falls in a sensitive category such as health. Meta applies them to the data source, not to one ad.

How do I know if my domain is restricted?

Meta tells advertisers by email and with a notice in Events Manager. In Events Manager settings you can see whether your data source is listed under a restricted category.

Can I appeal the restriction?

There is a review request in Events Manager. One vendor that reviewed 125+ ad accounts reports it found no genuine health or wellness seller that had the category removed by appeal. Treat appeal as a long shot for a real health business and fix what you send instead.

Does renaming my Purchase event fix it?

No, not on its own. If the payload still carries a product name or condition term, renaming the event only changes the label. The fix is to clean the payload as well.

Is DataCops a way around Meta's rules?

No. Health mode makes you send less. Meta says it does not want sensitive health information sent through its business tools, and Health mode removes the page paths, names and form answers that carry it.

Will Health mode remove an existing restriction?

DataCops cannot promise that. Meta decides. Health mode sends a clean signal from the start, and keeps a log of what was sent that you can use if you ask Meta to review.

Does Health mode turn itself on?

It is off by default. When you connect an ad platform, DataCops reads your homepage and turns it on by itself only when it is confident the site is a health business. It never turns it off, and your own setting is never changed.

Is this legal advice?

No. Check your own rules and ask a lawyer where they apply to you.

Send Meta a clean signal

Health mode: neutral names, no page paths, no form answers.

Setup in 5 minutes. No credit card.

Live traffic quality

Updated just now

Visits · last 24h

487
Real users
35873.5%
Bots · auto-filtered
12926.5%

Without filtering, 26.5% of your reported traffic is bot noise inflating dashboards and draining ad spend.

Don't trust your analytics!

Make confident, data-driven decisions withactionable ad spend insights.

Setup in 2 minutes
No credit card