athenahealth

athenahealth.com

Compare

https://athenahealth.com

Scanned Apr 15, 2026 · 38.4s

Your website score is

0/100
Critical

Grade

F0

Banner

Yes

Regulatory Compliance

Multi-regulation overview — click any regulation for details

Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.

Tag Leak detected 12 user data leaks before consent on athenahealth.com, including Coveo (Advertising Tracker), Salesforce (Advertising Tracker), Marfeel.

Security Headers

3/6 present

Strict-Transport-Security

max-age=15768000

Content-Security-Policy

Add a Content-Security-Policy header to prevent XSS and code injection attacks

X-Frame-Options

SAMEORIGIN

X-Content-Type-Options

nosniff

Referrer-Policy

Set a Referrer-Policy header to control how much referrer information is shared

Permissions-Policy

Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation

Google Consent Mode

Not Detected

Google Consent Mode v2 was not found on this page. GCM v2 allows Google's tags to adjust their behavior based on user consent, and is required for compliant advertising measurement in the EU. Without it, your Google Ads and GA4 conversions may be impacted after consent is declined.

Post-Rejection Audit

Reject Button

Found

Post-Rejection Fires

11 vendors

Consent Mode

Not Detected

GTM Load

Not detected

Consent Mode V2: Not Detected

Google Consent Mode was not detected on this site.

Vendors firing after rejection (11)

VendorCategoryTimingURL
Google — GA4analytics18142mswww.googletagmanager.com
LinkedIn — LinkedIn Insight Tagadvertising18142mssnap.licdn.com
X (Twitter) — Twitter/X Pixeladvertising18142msstatic.ads-twitter.com
Meta — Meta Pixeladvertising18150msconnect.facebook.net
Reddit — Reddit Pixeladvertising19184msalb.reddit.com
X (Twitter) — Twitter/X Pixeladvertising19290mst.co
Google — Google Adsadvertising20206mswww.googleadservices.com
Google — Google Adsadvertising20206mswww.google.com
Microsoft — Microsoft Adsadvertising21641msbat.bing.com
Google — Google Adsadvertising21843msgoogleads.g.doubleclick.net
Meta — Meta Pixeladvertising22335mswww.facebook.com

Consent Record Audit

Pass

Consent record stored after interaction

GDPR Art. 7(1)

Found: OptanonConsent (OneTrust)

Record contains timestamp

Art. 7(1)

Timestamp field detected

Record contains consent state

Art. 7(1)

Accept/reject state detected

Record contains consent categories

Art. 7(1)

Consent categories (analytics, marketing, etc.) not found in record

Consent withdrawal mechanism accessible

GDPR Art. 7(3)

Cookie settings link / floating button found

Consent record and withdrawal mechanism are both correctly implemented

Tracker categories detected

Advertising8 vendors
Analytics3 vendors
Marketing3 vendors
Security3
Functional1 vendor
Critical10
Coveo (Advertising Tracker)
criticalNetworkAdvertisingCoveo (Advertising Tracker)

Coveo (advertising) loaded before consent

Host: athenahealthprod.analytics.orghipaa.coveo.comFired: 2084ms after load
Salesforce (Advertising Tracker)
criticalNetworkAdvertisingSalesforce (Advertising Tracker)

Salesforce (advertising) loaded before consent

Host: athenahealth.us-4.evergage.comFired: 3963ms after load
Marfeel
criticalCookieAnalyticsMarfeel

Marfeel cookie "_sfid_65d4" set before consent — This cookie is used to store for temporary session

Cookie: _sfid_65d4Domain: .www.athenahealth.comRetention: Session
Google — GA4
criticalPost-RejectionAnalyticsGoogle — GA4

Google — GA4 fires after user rejected consent

Fired: 18142ms after load
LinkedIn — LinkedIn Insight Tag
criticalPost-RejectionAdvertisingLinkedIn — LinkedIn Insight Tag

LinkedIn — LinkedIn Insight Tag fires after user rejected consent

Fired: 18142ms after load
X (Twitter) — Twitter/X Pixel
criticalPost-RejectionAdvertisingX (Twitter) — Twitter/X Pixel

X (Twitter) — Twitter/X Pixel fires after user rejected consent

Fired: 18142ms after load
Meta — Meta Pixel
criticalPost-RejectionAdvertisingMeta — Meta Pixel

Meta — Meta Pixel fires after user rejected consent

Fired: 18150ms after load
Reddit — Reddit Pixel
criticalPost-RejectionAdvertisingReddit — Reddit Pixel

Reddit — Reddit Pixel fires after user rejected consent

Fired: 19184ms after load
Google — Google Ads
criticalPost-RejectionAdvertisingGoogle — Google Ads

Google — Google Ads fires after user rejected consent

Fired: 20206ms after load
Microsoft — Microsoft Ads
criticalPost-RejectionAdvertisingMicrosoft — Microsoft Ads

Microsoft — Microsoft Ads fires after user rejected consent

Fired: 21641ms after load
Warnings9
vendor logo
warningNetwork

Unknown third-party request to assets.adobedtm.com before consent

Host: assets.adobedtm.comFired: 564ms after load
vendor logo
warningNetwork

Unknown third-party request to athenahealth.my.site.com before consent

Host: athenahealth.my.site.comFired: 4965ms after load
vendor logo
warningNetwork

Unknown third-party request to athenahealth.my.salesforce-scrt.com before consent

Host: athenahealth.my.salesforce-scrt.comFired: 5481ms after load
warningStorage

localStorage key "visitorId" written before consent

Key: visitorIdType: localStorageFired: 1536ms after load
warningStorage

localStorage key "__coveo.analytics.history" written before consent

Key: __coveo.analytics.historyType: localStorageFired: 2067ms after load
warningStorage

sessionStorage key "com.adobe.reactor.core.visitorTracking.landingPage" written before consent

Key: com.adobe.reactor.core.visitorTracking.landingPageType: sessionStorageFired: 2131ms after load
warningStorage

sessionStorage key "com.adobe.reactor.core.visitorTracking.trafficSource" written before consent

Key: com.adobe.reactor.core.visitorTracking.trafficSourceType: sessionStorageFired: 2131ms after load
warningStorage

localStorage key "com.adobe.reactor.dataElements.OneTrust | Active Groups" written before consent

Key: com.adobe.reactor.dataElements.OneTrust | Active GroupsType: localStorageFired: 4595ms after load
warningStorage

localStorage key "00DA0000000HrDQ_WEB_STORAGE" written before consent

Key: 00DA0000000HrDQ_WEB_STORAGEType: localStorageFired: 6551ms after load
Info10
Google (Cdn)
Google (Cdn)2 findings

fonts.googleapis.com, fonts.gstatic.com

Google (Cdn)
infoNetworkGoogle (Cdn)

Google (cdn) loaded before consent

Host: fonts.googleapis.comFired: 540ms after load
Google (Cdn)
infoNetworkGoogle (Cdn)

Google (cdn) loaded before consent

Host: fonts.gstatic.comFired: 997ms after load
Brightcove (Cdn)
Brightcove (Cdn)2 findings

players.brightcove.net, edge.api.brightcove.com

Brightcove (Cdn)
infoNetworkBrightcove (Cdn)

Brightcove (cdn) loaded before consent

Host: players.brightcove.netFired: 2070ms after load
Brightcove (Cdn)
infoNetworkBrightcove (Cdn)

Brightcove (cdn) loaded before consent

Host: edge.api.brightcove.comFired: 3867ms after load
OneTrust
OneTrust2 findings

cdn.cookielaw.org, OptanonConsent

OneTrust
infoNetworkConsent MgmtOneTrust

OneTrust (OneTrust) loaded before consent: OneTrust cookie consent management

Host: cdn.cookielaw.orgFired: 2258ms after load
OneTrust
infoCookieConsent MgmtOneTrust

OneTrust cookie "OptanonConsent" set before consent

Cookie: OptanonConsentDomain: .athenahealth.com
Salesforce (Cdn)
infoNetworkSalesforce (Cdn)

Salesforce (cdn) loaded before consent

Host: cdn.evgnet.comFired: 2261ms after load
OneTrust CMP
infoNetworkConsent MgmtOneTrust CMP

OneTrust CMP (OneTrust) loaded before consent: OneTrust geo-lookup — determines which consent banner to show based on user location

Host: geolocation.onetrust.comFired: 4284ms after load
infoStorageFunctionallocalStorage availability probe

localStorage availability probe (null) wrote "__storage_test__" to localStorage before consent

Key: __storage_test__Type: localStorageFired: 1534ms after load
infoCookieFunctional

AWS Application Load Balancer — necessary for infrastructure

Cookie: AWSALBTGCORSDomain: athenahealth.us-4.evergage.com
Compliant10
OneTrust
CompliantCookieConsent MgmtOneTrust

OneTrust cookie "OptanonAlertBoxClosed" set correctly after consent

Cookie: OptanonAlertBoxClosedDomain: .athenahealth.com
Adobe Audience Manager
Adobe Audience Manager3 findings

demdex, AMCVS_5E9E381753ABFD030A490D4B%40AdobeOrg, dpm

Adobe Audience Manager
CompliantCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "demdex" set correctly after consent

Cookie: demdexDomain: .demdex.netRetention: 180 days after last activity or 10 years when opting out
Adobe Audience Manager
CompliantCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "AMCVS_5E9E381753ABFD030A490D4B%40AdobeOrg" set correctly after consent

Cookie: AMCVS_5E9E381753ABFD030A490D4B%40AdobeOrgDomain: .athenahealth.comRetention: Session
Adobe Audience Manager
CompliantCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "dpm" set correctly after consent

Cookie: dpmDomain: .dpm.demdex.netRetention: 180 days
Adobe Advertising
CompliantCookieMarketingAdobe Advertising

Adobe Advertising cookie "everest_g_v2" set correctly after consent

Cookie: everest_g_v2Domain: .everesttech.netRetention: 2 years
Adobe Analytics
Adobe Analytics5 findings

s_ecid, AMCV_5E9E381753ABFD030A490D4B%40AdobeOrg, s_tp, s_ppv, s_sq

Adobe Analytics
CompliantCookieMarketingAdobe Analytics

Adobe Analytics cookie "s_ecid" set correctly after consent

Cookie: s_ecidDomain: .athenahealth.comRetention: 2 years
Adobe Analytics
CompliantCookieAnalyticsAdobe Analytics

Adobe Analytics cookie "AMCV_5E9E381753ABFD030A490D4B%40AdobeOrg" set correctly after consent

Cookie: AMCV_5E9E381753ABFD030A490D4B%40AdobeOrgDomain: .athenahealth.com
Adobe Analytics
CompliantCookieAnalyticsAdobe Analytics

Adobe Analytics cookie "s_tp" set correctly after consent

Cookie: s_tpDomain: .athenahealth.comRetention: session
Adobe Analytics
CompliantCookieAnalyticsAdobe Analytics

Adobe Analytics cookie "s_ppv" set correctly after consent

Cookie: s_ppvDomain: .athenahealth.comRetention: session
Adobe Analytics
CompliantCookieAnalyticsAdobe Analytics

Adobe Analytics cookie "s_sq" set correctly after consent

Cookie: s_sqDomain: .athenahealth.com

Is this your site?

Run a full multi-page scan with monitoring and get detailed remediation steps

Scan athenahealth.com

This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com