
HIPAA-compliant marketing is not complicated, but almost everything written about it is either a legal lecture or a software pitch. Here is the practical version: what a medical practice can run without patient authorization, what it cannot, and the tracking-pixel mistake that turned routine websites into federal enforcement cases.
Under the Privacy Rule, marketing means using protected health information (PHI) to promote a product or service. The moment a communication is built on who your patients are, what they were treated for, or when they visited, you need written authorization first. The HHS marketing guidance carves out a few exceptions: treatment communications, appointment reminders, and face-to-face conversations are not marketing.
Before any campaign, ask three questions. Does this use patient data in any form? Could someone infer a person is a patient from receiving it? Is a third party touching that data without a signed Business Associate Agreement (BAA)? If any answer is yes, stop and restructure.
The enforcement wave of the last few years was not about postcards. It was about pixels. A Health Affairs study found third-party tracking on 98.6% of U.S. hospital websites. HHS responded with its online tracking technologies bulletin, and the FTC hit GoodRx and BetterHelp for sharing health data with ad platforms.
The problem: a Meta pixel or default analytics tag on your scheduling page, patient portal, or a condition-specific page can transmit an identifiable visitor plus a health context to an ad platform that never signed a BAA. That combination can be a reportable breach.
Unplug these today:
| Channel | OK without authorization? | The compliant version |
|---|---|---|
| Google search ads | Yes | Keyword and geo targeting only; send clicks to marketing pages, not the portal |
| Meta ads (demographic) | Yes | Age, location, interest targeting; no patient lists, no pixel on patient pages |
| Retargeting site visitors | Rarely | Only from non-patient marketing pages with clear consent; safest answer is no |
| Lookalikes from patient lists | No | None. Ad platforms will not sign a BAA |
| Email newsletter | Yes, carefully | General health content to an opted-in list; no segmenting by condition without authorization |
| Appointment reminders / recalls | Yes | Treatment communication, not marketing; keep it about their care |
| Patient testimonials | No | Written HIPAA authorization per patient, revocable, specific to the use |
| Review requests | Yes | PHI-free ask scripts; never confirm someone is a patient when responding |
Compliant patient acquisition is an architecture decision. Keep your marketing site and your patient systems separate: pixels and analytics live on marketing pages only, and the portal stays clean. Target ads by geography, age, and interest, never by patient data. Capture leads with first-party forms that feed a CRM covered by a signed BAA. Review requests and reminders go out through systems that are inside your compliance perimeter, not bolted on.
A compliant stack in practice looks like this:
This is exactly how we structure medical practice marketing services for clinics: the growth engine runs at full speed because the compliance lines were drawn first, and organic visibility comes from medical practice SEO rather than risky audience tricks. For the review side, we published word-for-word PHI-free scripts in our guide to HIPAA-safe Google reviews.
We build HIPAA-aware patient acquisition for medical practices: clean tracking, compliant ads, and rankings that compound.
Book a Strategy CallSources: HHS, HIPAA Marketing Guidance · HHS, Online Tracking Technologies Bulletin · Health Affairs, Hospital Website Tracking Study · FTC, BetterHelp Enforcement
No. Neither platform signs Business Associate Agreements for their advertising products, which is why patient data can never flow into ad targeting, pixels on patient pages, custom audiences, or lookalikes. Advertise with demographic, geographic, and interest targeting instead, and keep every tag off patient-facing pages.
Only in a narrow, carefully built way: audiences from purely informational marketing pages, with consent and with no health condition implied by the page itself. Retargeting visitors of a treatment or scheduling page implies those people sought that care, which is exactly the pattern regulators have penalized. For most practices the safest answer is to skip retargeting entirely.
Yes. A testimonial, review quote used in your ads, or before-and-after photo identifies someone as a patient, which is PHI. You need a written, specific, revocable HIPAA authorization, not just a photo release. Keep signed forms on file and honor revocations quickly.
No. Targeting by age, gender, location, or interests uses the ad platform’s own data, not yours, so HIPAA is not triggered. The line is crossed when your patient information, including behavior tracked on patient-facing pages of your website, feeds the targeting.
About the team: BRD Media is a Chicago-area digital marketing team that publishes its pricing, keeps every account in the client's name, and reports on booked appointments instead of vanity metrics.
Related reading: How to Market a Medical Practice: The First 90 Days · HIPAA-Safe Google Reviews for Medical Practices
See BRD Media first in Google
Add us as a preferred source and our SEO breakdowns rank higher in your own Search results, AI Mode and AI Overviews.