The governing rule: connect ad spend to the patient journey, to the first appointment in the practice system, and to the treatment revenue, then attribute it with data-driven models and feed the real value back so Google and Meta optimize toward patients who book and get treated.
This is healthcare-adjacent, so the privacy boundary was a first-class design decision: only the conversion event and its value, with hashed identifiers, go to the ad platforms. No treatment details, no clinical information, nothing that could be considered patient health data, ever leaves to Google or Meta. Identity is resolved deterministically and first-party, stitched at the point of booking.
What we deliberately did not do: no patient health data sent to ad platforms, no probabilistic device fingerprinting, and (importantly) no over-building. A practice group's traffic does not justify the high-throughput event-streaming stack a large e-commerce brand needs, so we did not use one.