GA4 setup for hospital websites: events, conversions and consent
GA4 for hospitals should track actions that signal a patient trying to book: successful appointment form submissions, booking confirmations, call clicks and WhatsApp clicks as key events, plus doctor profile, package and location page views. Use consistent event names with category parameters, implement Consent Mode, keep personal and health data out, link Google Ads, and report alongside CRM appointment data.
Most hospital websites in India have Google Analytics installed and very few have it set up to answer the questions management actually asks: how many appointment requests came from the website this month, from which channel, for which specialty, and how many of those patients turned up. GA4 can answer most of that, but only if you decide what to track, name events consistently, keep health data and personal data out, and connect it to your ads and your back-office numbers.
This article is part of the AI in healthcare operations series, best read in order from the pillar.
This guide is the setup I would want on any hospital or clinic website: the events, the naming, the key events (what GA4 used to call conversions), Google Tag Manager steps, Consent Mode, privacy safeguards, UTMs, Google Ads linking, reporting and QA. It assumes a website with appointment forms, phone numbers, WhatsApp buttons, doctor profiles and perhaps a separate booking engine. If your website is still mainly a brochure, start with why the hospital website is a booking product, because analytics can only measure the journeys the site supports.
What should a hospital track in GA4?
Track the actions that signal a patient moving towards an appointment, plus the content views that tell you which specialties and doctors attract interest. Everything else is noise. A practical list:
- Appointment form submissions: successful submissions only, not button clicks.
- Booking steps: for multi-step booking, each step (specialty chosen, doctor chosen, slot chosen, details entered, confirmed).
- Call clicks: taps on tel: links, especially on mobile.
- WhatsApp clicks: clicks on wa.me links or the WhatsApp widget.
- Doctor profile views: with the doctor’s specialty as a parameter.
- Health check package views: and package enquiry or purchase.
- Location page views: for groups with several sites or clinics.
- Directions clicks: clicks to open maps.
- PDF downloads: price lists, preparation instructions, brochures.
- Callback requests and chat starts: if you have them.
Notice what is not on the list: symptoms entered into forms, the condition a patient selects, search terms typed into a symptom checker. Those are health data and they do not belong in GA4. More on that below.
What event names and parameters should you use?
Consistency matters more than the exact names. Use lower case with underscores, reuse Google’s recommended event names where one fits (such as generate_lead), and keep parameter values to categories, never free text. This is the naming scheme I use as a starting point.
| Event name | When it fires | Parameters | Key event? |
|---|---|---|---|
| generate_lead | Appointment or enquiry form submitted successfully | form_name, specialty, location, lead_type (appointment, callback, package) | Yes |
| booking_step | Each step of a booking engine | step_number, step_name, specialty, location | No |
| booking_confirmed | Booking confirmation page or event | specialty, location, consult_type (in-person, video) | Yes |
| click_call | Tap on a tel: link | phone_type (main, emergency, department), page_type, location | Yes |
| click_whatsapp | Click on a WhatsApp link or widget | page_type, specialty, location | Yes |
| view_doctor_profile | Doctor profile page view | specialty, location, doctor_id (internal code, not name if you prefer) | No |
| view_package | Health check package page view | package_category, location | No |
| view_location | Location or branch page view | location | No |
| click_directions | Click to open maps | location | No |
| file_download | PDF download (enhanced measurement) | file_name, file_extension | No |
| request_callback | Callback form submitted | specialty, location | Yes, or fold into generate_lead |
Register the parameters you want in reports (specialty, location, lead_type, page_type) as event-scoped custom dimensions in GA4 admin, otherwise you will not see them in standard reports. Keep specialty values to a fixed list (cardiology, orthopaedics, obstetrics and gynaecology and so on). A free-text “department” field will quickly produce dozens of spellings.
A note on doctor profile tracking: doctor pages are among the highest-intent pages on most hospital sites. My guide to doctor pages that get booked covers what the page should contain; the analytics job is to show which profiles get views but no bookings.
Which events should be key events?
GA4 renamed “conversions” to “key events” in 2024; the term “conversion” now refers to what you import into Google Ads. Mark only the actions that represent a real attempt to book or contact:
- generate_lead (form submitted successfully)
- booking_confirmed
- click_call
- click_whatsapp
Do not mark page views, scroll depth or PDF downloads as key events. They inflate the numbers and train Google Ads bidding towards cheap, low-intent actions. Also be honest in reporting that click_call and click_whatsapp are intents, not completed contacts. A tap on a phone number does not mean the call connected or that anyone answered. Closing that gap needs call tracking and offline data, which I cover in call tracking and offline conversion import for hospitals.
How do you set this up in Google Tag Manager?
Tag Manager keeps tracking out of the website code and lets the marketing team change it without a developer for every edit. The steps:
- Create one GTM container for the website and install the two snippets on every page. If your booking engine is on a separate domain or system, install the same container there if you can.
- Add the Google tag (GA4 configuration) with your measurement ID, firing on all pages, after consent defaults are set.
- Ask the developer for a dataLayer push on successful form submission, for example an event called form_success with form_name, specialty and location. This is far more reliable than tracking button clicks or “thank you” URLs.
- Create triggers: a Custom Event trigger for form_success; Click triggers for links whose URL starts with tel: or contains wa.me or api.whatsapp.com; a Page View trigger on doctor profile URLs; a Custom Event for each booking step pushed by the booking engine.
- Create GA4 event tags for each event in the table, mapping dataLayer variables to parameters.
- Turn on enhanced measurement selectively in GA4: keep page views, scrolls, outbound clicks and file downloads; consider turning off form interactions if your own form_success event is in place, to avoid duplicate or misleading form events.
- Preview and debug with GTM Preview mode and GA4 DebugView before publishing.
- Publish with a version name and notes so you know what changed and when.
How should Consent Mode v2 work on a hospital website?
Google’s Consent Mode lets your tags adjust their behaviour based on a visitor’s consent choices. Version 2 added two signals, ad_user_data and ad_personalization, alongside ad_storage and analytics_storage. Google has required advertisers to send these signals for users in the European Economic Area, the UK and Switzerland since March 2024 in order to keep using audience and measurement features for those users. For a hospital with international patient traffic from those regions, that applies directly.
For domestic Indian traffic, Consent Mode is not a Google requirement in the same way, but it is still the right foundation. The DPDP Act, 2023 and the DPDP Rules notified in November 2025 require valid consent for processing personal data, with the substantive notice and consent obligations applying from May 2027. A hospital that sets up consent properly now avoids re-engineering its tracking later. The practical side is covered in DPDP consent for hospital marketing.
Basic or advanced?
| Mode | What happens before consent | What happens if consent is denied | Trade-off |
|---|---|---|---|
| Basic | Google tags do not load | No data sent | Simplest privacy position; less modelled data |
| Advanced | Tags load with consent defaulted to denied | Cookieless pings are sent for modelling | Better modelling; you must be comfortable with cookieless pings under your privacy notice |
Implementation, in outline: set consent defaults (denied for ad_storage, ad_user_data and ad_personalization at minimum) before any Google tag fires; show a clear consent banner; update consent when the visitor chooses; and make sure your consent platform passes the update to GTM. Google’s consent mode setup guide has the technical details. For hospitals, I recommend defaulting advertising signals to denied for everyone, and thinking carefully before switching on ad personalisation at all, because remarketing on health-related browsing is restricted by Google’s personalised advertising policy and sensitive under DPDP. See privacy-safe remarketing in healthcare.
How do you keep health data and personal data out of GA4?
Google’s Analytics policy prohibits sending any data that Google could use or recognise as personally identifiable information, including email addresses and phone numbers, and specifically warns about PII in page URLs, page titles, custom dimensions and form inputs. For hospitals the risk goes beyond PII: combining a visit with a condition is health data even if no name is attached.
Common leaks on hospital sites
- Form fields in URLs: forms that submit with GET put name, phone and “symptoms” into the thank-you page URL, which GA4 records. Use POST and a clean thank-you URL.
- Search parameters: internal site search for “breast lump” or a patient’s name stored as a search term.
- Booking engine URLs: appointment IDs, patient IDs or mobile numbers in query strings.
- Patient portal pages: report pages or bill pages with identifiers in the URL or title. Do not run marketing analytics on logged-in patient areas at all.
- Event parameters with free text: sending the “reason for visit” field as a parameter.
- UTMs with personal data: links in WhatsApp or email campaigns that include a phone number or name in utm_content.
Safeguards
- Turn on GA4 data redaction for email addresses and add query parameters to redact.
- Strip or rewrite sensitive query parameters in GTM before they reach GA4.
- Send only category values (specialty, location) as parameters, never free text.
- Exclude patient portal and payment pages from the GA4 tag.
- Keep the User ID feature off unless legal has reviewed it.
- Audit page path and event reports monthly for anything that looks like a name, number or condition.
What UTM conventions should a hospital use?
Without consistent UTMs, half your traffic ends up in “direct” or “unassigned”. Write the conventions down and share them with every agency and unit.
- All lower case, words separated by hyphens or underscores, never spaces.
- utm_source: the platform (google, facebook, instagram, whatsapp, newsletter, practo, justdial, partner-name).
- utm_medium: the channel type, using GA4’s default channel definitions (cpc, paid_social, email, sms, referral, qr).
- utm_campaign: a structured name such as ortho_knee_hyd_2026q4 (specialty, service, city, period).
- utm_content: the creative or placement (video-a, carousel-b, gbp-post).
- Never put personal data in any UTM.
- Do not tag internal links on your own site; it overwrites the original source.
- Tag Google Business Profile links (website and appointment links) so map and local traffic is visible separately.
Keep a shared Google Sheet as a UTM builder with drop-down values, so nobody types free text.
How do you link GA4 with Google Ads?
- In GA4 Admin, link the Google Ads account under product links. Enable auto-tagging in Google Ads so GCLIDs are captured.
- Decide where Google Ads conversions come from. Many hospitals use GA4 key events imported into Google Ads; others use the Google Ads conversion tag directly. Do not count the same action twice as a primary conversion.
- Mark booking_confirmed and generate_lead as primary, and click_call and click_whatsapp as secondary (observed but not bid on) until you can verify they lead to appointments.
- Use Google Ads call extensions or call assets with Google forwarding numbers if you want call duration based conversions.
- Check that Consent Mode signals are passing correctly, since they affect what Google Ads can measure and model.
The step that changes performance most is importing what happened after the lead: appointment booked, appointment honoured, procedure done. That needs the GCLID captured in a hidden form field and stored in your CRM, then uploaded back to Google Ads. It is the subject of my guide to offline conversion import. For campaign setup itself, see Google Ads for doctors in India.
What about booking engines on another domain?
Many hospitals send patients from the main site to a booking engine or patient app on a different domain. Without configuration, GA4 sees that as a new visit and the booking gets credited to “referral” from your own website, losing the original source.
- Configure cross-domain measurement in GA4 (Admin, Data streams, Configure tag settings, Configure your domains) and list both domains.
- Use the same GA4 property and ideally the same GTM container on both.
- Add the booking domain and any payment gateway domains to the unwanted referrals list, so returning from payment does not start a new session from the gateway.
- If the vendor will not install your tags, ask for a server-side confirmation (a webhook or daily export with booking reference and GCLID or UTM values) that you can match in your CRM.
- Test end to end with a real test booking from a tagged link and confirm the source survives to booking_confirmed.
Which data retention settings should you choose?
Standard GA4 properties offer 2 months or 14 months for event-level data retention, which governs how far back you can go in explorations. Standard reports use aggregated data and are not limited in the same way. Most hospitals should choose 14 months so they can compare seasons (monsoon, festival periods, academic calendar) in explorations. If your privacy notice or policy requires shorter retention, reflect that. If you need longer raw history, export to BigQuery under your own retention rules. Also set the “reset user data on new activity” option deliberately rather than leaving it to chance.
How should you report it in Looker Studio?
Build one dashboard that management can read in two minutes. A structure that works:
- Page 1, summary: sessions, key events by type, key event rate, and month-on-month change, filtered by location.
- Page 2, channels: key events by default channel group and by campaign.
- Page 3, specialties and doctors: doctor profile views, leads by specialty, profile views to lead ratio.
- Page 4, booking funnel: booking_step counts by step, showing drop-off.
- Page 5, back-office outcomes: appointments and honoured appointments from your CRM or HIS in a Google Sheet, joined by month, specialty and source.
Page 5 is the one that matters. GA4 measures enquiries; the hospital earns from honoured appointments and treatments. Keep the distinction clear, as I explain in enquiry to appointment, the number that matters and cost per honoured appointment. The free enquiry to appointment funnel calculator helps set targets for each stage.
QA checklist before you trust the numbers
- Every key event fires once per real action in DebugView, not twice.
- Form events fire only on successful submission, not on failed validation.
- Call and WhatsApp clicks fire on mobile and desktop, including sticky buttons and headers.
- Specialty and location parameters are populated and match the fixed list.
- No page path, title or parameter contains names, phone numbers, emails, IDs or conditions.
- Consent defaults are set before the Google tag, and consent updates register in Tag Assistant.
- Cross-domain links carry the linker parameter, and a test booking keeps its original source.
- Payment gateway and booking domains are in the unwanted referrals list.
- Internal traffic (hospital IP ranges, agency offices) is defined and filtered.
- Google Ads link is active, auto-tagging is on, and conversions are not double counted.
- Data retention is set to the period you chose.
- GA4 lead counts are within a sensible range of the CRM’s website lead count for the same week.
Mistakes to avoid
- Tracking button clicks as leads. A click on “Submit” with a validation error is not a lead.
- Too many key events. Marking scrolls or downloads as key events makes reports look good and bidding worse.
- Sending condition or symptom data. Even without names, this is health data and breaches the spirit, and often the letter, of Google’s policies.
- Each agency running its own tags. Multiple GA4 properties and pixels added by different vendors produce conflicting numbers. One container, one owner.
- Ignoring calls. For many Indian hospitals, phone calls are the largest enquiry channel. If GA4 shows only form leads, it undercounts the website’s contribution.
- Reporting GA4 numbers as patients. GA4 shows intent; your CRM and HIS show patients. Present both, clearly labelled.
- Never reviewing the setup. Website changes break tracking silently. Re-run the QA checklist after every release.
How to measure whether the setup is good
What good looks like: the GA4 lead count and the CRM website lead count agree within a small, explained margin; every lead in the CRM carries a source; Google Ads bids on confirmed bookings or imported appointments rather than clicks; the management dashboard shows enquiries, appointments and honoured appointments side by side; and a monthly privacy audit finds nothing sensitive in the data. When you reach that point, you can move on to the harder question of how different touchpoints contribute over time, covered in what patient journey attribution is and what you can and cannot know about attribution in healthcare.
Getting started
If your current GA4 setup is untidy, do not try to fix everything at once. Start with three things this month: a reliable generate_lead event on successful form submissions, call and WhatsApp click tracking, and a check that no personal or health data is reaching GA4. Then add Consent Mode, cross-domain booking and Google Ads imports. Within a quarter you should be able to answer the question every hospital leadership team asks: what did the website actually bring in?
Frequently asked questions
Track successful appointment form submissions, booking engine steps and confirmations, call clicks, WhatsApp clicks, doctor profile views, health check package views, location page views, directions clicks and PDF downloads. Use category parameters such as specialty and location, and never send symptoms, conditions or personal details.
Mark successful lead form submissions, confirmed bookings, call clicks and WhatsApp clicks as key events. Avoid marking page views, scrolls or downloads, because they inflate results and push ad bidding towards low-intent actions. Treat call and WhatsApp clicks as intent, not completed contact.
Google requires Consent Mode v2 signals for users in the EEA, UK and Switzerland. For domestic Indian traffic it is not a Google requirement in the same way, but it is the right foundation for DPDP compliance, whose substantive consent obligations apply from May 2027. Hospitals with international patients should implement it now.
No. Google Analytics prohibits sending personally identifiable information such as names, phone numbers and emails, including in URLs and parameters. Hospitals should also avoid sending conditions, symptoms or reasons for visit, since these are health data. Use category values like specialty instead, and exclude patient portals.
In Google Tag Manager, create a click trigger for links containing wa.me or api.whatsapp.com, and fire a GA4 event such as click_whatsapp with page type, specialty and location parameters. Test in Preview mode and DebugView, then mark it as a key event if WhatsApp is a main enquiry channel.
Configure cross-domain measurement in your GA4 data stream settings with both domains, use the same GA4 property and Tag Manager container if possible, and add the booking and payment domains to the unwanted referrals list. If the vendor cannot install tags, use a booking export matched in your CRM.
Standard GA4 properties allow 2 or 14 months for event-level data used in explorations. Most hospitals choose 14 months to compare seasonal patterns year on year, unless their privacy policy requires shorter retention. Aggregated standard reports are not limited in the same way, and BigQuery export can hold longer history.
Either works, but not both as primary for the same action. Many hospitals import GA4 key events into Google Ads for simplicity. The bigger gain comes from importing offline outcomes such as honoured appointments using the GCLID stored in the CRM, so bidding optimises for patients, not form fills.
Common reasons are consent choices, ad blockers, duplicate submissions, form events firing on failed validation, phone and walk-in leads that never touch the website form, and booking engines without cross-domain tracking. A small, explained gap is normal. A large one means the tracking setup needs review.
Yes. Connect GA4 and Google Ads directly, and bring appointment and honoured appointment counts from your CRM or HIS through a Google Sheet. Show channels, specialties, doctor profile performance and booking funnel drop-off, with back-office outcomes alongside website enquiries so leadership sees patients, not just leads.
Read my takes first in Google Search

