APEX VAULT.

Stop sending patient data to Meta and Google. Keep your ads running.

Your healthcare website forwards patient browsing data to Meta and Google every day. Plaintiff firms use that exact data flow to file under state wiretap statutes and state consumer-health-privacy laws — $100M+ has settled to date, and the docket is moving down-market into independent practices. Most settlements pay out quietly through E&O and cyber liability insurance, which is why most practice owners hear about it from their carrier, not the news. Apex Vault sanitizes outbound events at the perimeter. Your campaigns stay live; the signal stops at your boundary.

Book a 15-min demo Scan your site → See pricing For 1+ location healthcare practices, MSO platforms, hospital systems, specialty pharma.
Active class-action docket
$100M+
Public docket · most settle quietly through insurance

Every tracking pixel on a healthcare site is a class-action defendant. State wiretap statutes and state consumer-health-privacy laws have produced a multi-year settlement docket against hospital systems, multi-location MSOs, specialty pharma, and digital-health platforms.

Cyber-insurance carriers are writing tracking-technology exclusions into 2026 renewal underwriting. The do-nothing path ends with your counsel pulling paid media entirely — typically within six months of the first plaintiff letter.

The proxy that sits between your site and every third-party tracker.

Tracking events enter raw, leave sanitized. Identity stitching at the destination is architecturally prevented. Your ad accounts continue receiving conversion signal Meta and Google can model against.

Your site
Healthcare website
IP · URL · Fingerprint
Sanitization boundary
Apex Vault
Strip every
matchable signal
Destinations
First-party analytics + Conversion APIs
UUID · Value · Timestamp

Your campaigns keep running

Meta Advantage+, Google Performance Max, Smart Bidding continue to optimize against aggregate conversion signal.

You finally see the user journey

First-party analytics replaces GA4 — visibility into user behavior without forwarding it to Google (which won't sign a BAA for its ad or analytics products). Full per-visitor paths. Unsampled. Inside your perimeter. Yours.

The class-action surface goes away

No matchable identifier crosses the wire. No identity stitching at the destination. Outside the statutory "sale" definition.

Find your tier.

Tier 01

Independent Practice

1–4 location practices. Multi-tenant deployment, templated BAA, 7-day install. Public pricing.

$5K + $1K–$2.5K/mo →
Tier 02

MSO Platform

5–25 location operators. Single-tenant, negotiated BAA, dedicated pen test pre-go-live. 9-week cycle.

Request tier sheet →
Tier 03

Enterprise

Hospital systems, specialty pharma, multi-brand. Bespoke single-tenant, custom hardening, Letter of Attestation at go-live.

Request tier sheet →

Posture

CSA CCM / CAIQ self-attested SOC 2 Type 1 — next milestone Validation Standard at go-live Tech E&O + Cyber Liability Full security & attestation →