HIPAA does not ban healthcare marketing. It restricts using protected health information (PHI) for marketing without written authorization, and it makes you responsible for any vendor that touches that data. Most practices get into trouble through tracking and email tools, not through advertising itself.

That distinction matters, because the two most common beliefs about HIPAA marketing are both wrong: that pixels are automatically illegal, and that a 2024 court ruling made them automatically fine. The truth sits between those, and this guide walks through exactly where.

Who Do HIPAA’s Marketing Rules Actually Apply To?

HIPAA applies to covered entities — providers who bill electronically, health plans, and clearinghouses — and to the business associates that handle protected health information on their behalf. Your marketing agency, CRM, email platform, and form host are all potential business associates.

Two things surprise practices here. First, liability flows downhill: if a vendor you hired mishandles PHI, that is your exposure as well as theirs. Second, falling outside HIPAA is not the safe harbor people assume. Health-adjacent companies that were never covered entities have drawn the largest recent penalties in this space — from the FTC, not OCR. More on that below.

So the useful question is not “am I a covered entity?” It’s “where does identifiable health information travel once someone interacts with my marketing?”

What Counts as PHI in Healthcare Marketing?

PHI is health information that is tied to an identifiable person and held by a covered entity or its business associate. In a marketing context, the identifier is usually what trips practices up, not the medical detail.

Names, email addresses, phone numbers, and IP addresses can all act as identifiers. When one of them is combined with something that reveals a health condition, treatment, or provider relationship, you are likely handling PHI. A few practical examples of how that happens inside ordinary marketing:

Note that last one. Under HHS guidance, simply confirming that a person is your patient is a disclosure — even if you say nothing clinical.

The escape hatch is de-identification. HIPAA recognizes two methods: Expert Determination, where a qualified statistician certifies the re-identification risk is very small, and Safe Harbor, which requires removing 18 specified identifiers — names, geographic detail below state level, dates more precise than a year, contact details, device and IP identifiers, and more. Data that clears either bar is no longer PHI and falls outside these restrictions. This is why aggregate reporting is straightforward while user-level conversion tracking is not.

HIPAA also defines “marketing” narrowly. Communications about treatment, care coordination, and certain health care operations generally fall outside the definition and don’t require authorization. Promoting a third party’s product or service for payment generally does. This is why appointment reminders and recall notices are treated very differently from a paid promotion.

Not sure what your website is currently sending to Google, Meta, or your CRM? Request a free HIPAA marketing and tracking audit — we’ll map every tag firing on your site and flag the ones that create exposure.

Are Tracking Pixels Like GA4 and Meta Pixel a HIPAA Violation?

Not automatically — and the rules here changed in a way most articles still describe incorrectly.

In December 2022, the HHS Office for Civil Rights (OCR) issued a bulletin on online tracking technologies, updated in March 2024. Its most aggressive position was that when a tracking tool connected a visitor’s IP address with a visit to an unauthenticated public webpage about a specific health condition or provider, that combination could itself be PHI.

In June 2024, a federal court in the Northern District of Texas disagreed. In American Hospital Association v. Becerra, the court declared that specific position unlawful and vacated it. HHS filed an appeal in August 2024, then withdrew it days later — so the vacatur stands.

Here is what practices consistently get wrong about that outcome:

What the ruling changed. The IP-address-plus-public-page theory is no longer enforceable. Someone browsing your public “cardiology services” page does not, by that fact alone, generate PHI.

What the ruling did not change. The rest of the bulletin remains intact. Tracking on authenticated pages — patient portals, logged-in scheduling, anything behind a credential — is still squarely within HIPAA’s scope. So is any tracking that captures actual form contents, appointment details, or user identifiers you can tie back to a person.

What the ruling has nothing to do with. HIPAA is not your only exposure. The FTC reaches health data through the FTC Act and the Health Breach Notification Rule regardless of whether you are a covered entity. State privacy laws and a steady stream of wiretapping and session-replay class actions apply on top. A vacated HIPAA theory does not make sloppy data sharing safe.

The practical read for 2026: the legal panic around public marketing pages has eased, and the operational discipline around authenticated pages, form data, and conversion events has not.

Do You Need a BAA for Google Analytics or Meta?

If a vendor will handle PHI on your behalf, HIPAA requires a Business Associate Agreement. The complication is that the major advertising platforms generally do not sign BAAs for their standard advertising and analytics products.

That leaves you two workable paths, and one that isn’t:

  1. Keep PHI out of those tools entirely. Send only de-identified, aggregate signals. No patient identifiers, no condition-revealing parameters, no raw form data.
  2. Route events through infrastructure you control. Server-side tracking lets you receive the event first, strip or hash identifiers, and forward only what’s permitted. It’s more work than pasting a tag, and it is the approach that survives scrutiny.
  3. Assume a checkbox in a settings panel solves it. It does not. Features like IP anonymization reduce risk but do not convert a non-BAA vendor into a compliant one.

Getting this right is measurement work, not legal paperwork. Building conversion tracking that ties marketing spend to booked appointments without leaking patient data is the core of HIPAA-safe analytics and reporting — and it’s what makes it possible to know your real cost per acquired patient without creating liability.

What Are the HIPAA Rules for Email and SMS Marketing?

Treatment and care-related messages generally don’t require marketing authorization; promotional messages to patients generally do. Beyond that, three operational rules matter more than most practices realize.

Content minimization. Standard email is not a secure channel. Keep condition details, appointment specifics, and anything clinical out of the message body and subject line. “A message from our office — please log in” is safer than naming the service.

List construction. Building a segment from diagnosis or treatment history and mailing it a promotion is a use of PHI for marketing. A general newsletter to people who opted in is not the same thing, and the difference is how the list was built.

Vendor coverage. Your email and SMS platform is a business associate if it touches PHI, and needs a BAA. Many mainstream marketing platforms will not sign one; healthcare-capable platforms will.

Recall campaigns, reactivation sequences, and appointment reminders are usually the highest-return messages a practice sends — and they’re generally permitted. The compliance work is in how the list, the platform, and the message body are configured, which is exactly what a properly built healthcare email and automation setup is designed to handle.

Can You Use Patient Reviews and Testimonials?

You can — with written authorization from the patient, and with real discipline in how you respond publicly.

Three rules cover most situations:

Asking every patient for a review is both permitted and effective. Review recency carries real weight in local rankings, and AI search systems read review language to understand what your practice is known for. Automating a compliant, non-selective request into your visit workflow is standard CRM and automation work.

Is Retargeting Allowed for Medical Practices?

Retargeting is permitted in principle and risky in practice, because the risk scales with how specific your audience is.

Retargeting everyone who visited your homepage is low exposure. Retargeting everyone who visited your addiction treatment intake page is a different matter: the audience definition itself reveals something sensitive about each member, and the platform building that audience has not signed a BAA.

Two guardrails keep this workable. Build audiences from broad, non-condition-specific pages rather than treatment-specific ones. And never upload patient lists to ad platforms as custom audiences — that is a direct disclosure of PHI to a vendor with no agreement in place.

Ad platforms also impose their own healthcare restrictions independent of HIPAA, which is why compliant campaign structure is a specialist skill rather than a settings choice.

Running ads, email, and analytics on a stack you inherited? MediBrandly rebuilds healthcare marketing infrastructure so it measures properly and holds up to scrutiny — from compliant tracking to CRM workflows. Book a free strategy consultation →

What Are the Penalties for Getting This Wrong?

HIPAA civil penalties are organized in four tiers, scaling with culpability — from violations the entity did not know about, up to willful neglect that was never corrected. The dollar amounts are adjusted for inflation annually, and the highest tier carries the steepest per-violation exposure. Current figures are published by HHS.

The more instructive enforcement, though, has come from the FTC — and it has landed on companies that were not HIPAA covered entities:

In July 2023, the FTC and HHS jointly warned roughly 130 hospital systems and telehealth providers about the risks of online tracking technologies.

The pattern is worth internalizing: enforcement has focused on health data flowing to advertising platforms, and being outside HIPAA’s definition of a covered entity has not been a defense.

Six step decision path for deciding whether marketing data counts as protected health information
Is It PHI? A Marketing Decision Path · MediBrandly

The Compliance Checklist

Marketing ActivityGenerally PermittedRequires CareAvoid
Appointment reminders and recall✅ Treatment/operations communicationKeep clinical detail out of the messageNaming conditions in subject lines
Analytics on public pages✅ Post-AHA v. BecerraStrip identifiers; watch form-field captureSending raw form data to third parties
Analytics on patient portalStill fully in HIPAA scopeStandard third-party tags behind login
Asking all patients for reviewsNon-selective, automated requestGating reviews by sentiment
Replying to reviews publicly✅ Neutral repliesNever confirm treatmentClinical detail in a public reply
Publishing testimonialsWritten authorization requiredRepublishing without permission
Broad-page retargetingKeep audiences non-condition-specificRetargeting from treatment-specific pages
Custom audience uploadsUploading patient lists to ad platforms
Email/SMS platformsBAA required if PHI is touchedNon-BAA platforms holding patient data

Five steps to a defensible setup

  1. Inventory every tag. Open your site and list what actually fires — analytics, ad pixels, chat widgets, heatmaps, tag managers. Most practices find tools nobody remembers installing.
  2. Separate authenticated from public. Ensure no third-party tracking runs behind a login or on pages that capture form contents.
  3. Move conversions server-side. Receive events on infrastructure you control, strip or hash identifiers, forward only what’s permitted.
  4. Get BAAs where they’re needed. Email, SMS, CRM, hosting, forms — any vendor touching PHI.
  5. Document the decisions. Write down what you send, where, and why. Enforcement rewards the organization that can show its reasoning.

For reference, our own website legal and privacy notices show the disclosure language we publish on this site.

Frequently Asked Questions

Is HIPAA-compliant marketing even possible? Yes. HIPAA restricts using protected health information for marketing without authorization; it does not restrict advertising your practice. Compliant programs run on de-identified measurement, BAA-covered vendors, and careful message content, and they perform just as well.

Did the 2024 court ruling make tracking pixels legal? Partly. AHA v. Becerra vacated OCR’s position that an IP address plus a visit to an unauthenticated public health page is PHI. The rest of the guidance stands, authenticated pages remain in scope, and FTC and state-law exposure is unaffected.

Do I need a BAA with Google or Meta? Those platforms generally do not sign BAAs for standard advertising and analytics products. The workable approach is to keep PHI out of them entirely, using server-side event routing to strip identifiers before anything is forwarded.

Can I reply to a negative patient review online? Yes, but never confirm that the person was a patient or reference any clinical detail. A brief, neutral reply inviting the reviewer to contact the office directly is the standard compliant pattern.

Are appointment reminders considered marketing under HIPAA? Generally no. Treatment and care-coordination communications typically fall outside HIPAA’s definition of marketing, which is why reminders and recall campaigns are usually permitted without separate marketing authorization.

What’s the most common HIPAA marketing mistake practices make? Third-party tracking left running on pages that capture form submissions or sit behind a patient login. It’s usually unintentional, installed years earlier, and invisible until someone audits what the site is actually transmitting.


Get a Clear Picture of What Your Site Is Sending

Most practices we audit are not reckless — they simply inherited a marketing stack nobody has reviewed since it was installed. The fix is rarely to stop marketing. It’s to rebuild measurement so it’s both accurate and defensible.

We’ll map every tag on your site, identify where patient data is leaking to vendors without agreements, and show you a compliant way to track what’s actually producing patients.

Request your free HIPAA marketing and tracking audit → or email info@medibrandly.com. Curious what compliant measurement looks like in practice? See our analytics and reporting service.

This guide is general information for healthcare marketers, not legal advice. Confirm your specific obligations with qualified counsel.