HIPAA-Compliant Marketing: What Your Practice Can (and Can't) Do

HIPAA compliant marketing
TL;DR
  • Demographic and geographic ad targeting is fine. HIPAA kicks in the moment patient data touches your marketing, and that includes the tracking pixels on your website.
  • Google and Meta will not sign a Business Associate Agreement for advertising, so retargeting and lookalikes built from patient information are off the table.
  • One 2023 study found 98.6% of hospital websites ran third-party trackers. Regulators noticed. Remove pixels from every patient-facing page today.
  • Testimonials and before-and-after photos need a written HIPAA authorization, not just a casual thumbs-up.

HIPAA-compliant marketing is not complicated, but almost everything written about it is either a legal lecture or a software pitch. Here is the practical version: what a medical practice can run without patient authorization, what it cannot, and the tracking-pixel mistake that turned routine websites into federal enforcement cases.

What HIPAA actually calls marketing

Under the Privacy Rule, marketing means using protected health information (PHI) to promote a product or service. The moment a communication is built on who your patients are, what they were treated for, or when they visited, you need written authorization first. The HHS marketing guidance carves out a few exceptions: treatment communications, appointment reminders, and face-to-face conversations are not marketing.

Before any campaign, ask three questions. Does this use patient data in any form? Could someone infer a person is a patient from receiving it? Is a third party touching that data without a signed Business Associate Agreement (BAA)? If any answer is yes, stop and restructure.

The tracking-pixel problem is the one that gets practices in trouble

The enforcement wave of the last few years was not about postcards. It was about pixels. A Health Affairs study found third-party tracking on 98.6% of U.S. hospital websites. HHS responded with its online tracking technologies bulletin, and the FTC hit GoodRx and BetterHelp for sharing health data with ad platforms.

The problem: a Meta pixel or default analytics tag on your scheduling page, patient portal, or a condition-specific page can transmit an identifiable visitor plus a health context to an ad platform that never signed a BAA. That combination can be a reportable breach.

Unplug these today:

  • Ad pixels (Meta, TikTok, LinkedIn) on the patient portal, intake forms, and scheduling pages
  • Analytics tags configured to capture identifiers on symptom or treatment pages
  • Chat widgets and call trackers that record health details without a BAA
  • Any lookalike or custom audience ever built from a patient list

Channel by channel: what is allowed

ChannelOK without authorization?The compliant version
Google search adsYesKeyword and geo targeting only; send clicks to marketing pages, not the portal
Meta ads (demographic)YesAge, location, interest targeting; no patient lists, no pixel on patient pages
Retargeting site visitorsRarelyOnly from non-patient marketing pages with clear consent; safest answer is no
Lookalikes from patient listsNoNone. Ad platforms will not sign a BAA
Email newsletterYes, carefullyGeneral health content to an opted-in list; no segmenting by condition without authorization
Appointment reminders / recallsYesTreatment communication, not marketing; keep it about their care
Patient testimonialsNoWritten HIPAA authorization per patient, revocable, specific to the use
Review requestsYesPHI-free ask scripts; never confirm someone is a patient when responding
Three statistics on healthcare tracking pixels, HIPAA penalties, and ad platform BAAs

How to advertise without touching PHI

Compliant patient acquisition is an architecture decision. Keep your marketing site and your patient systems separate: pixels and analytics live on marketing pages only, and the portal stays clean. Target ads by geography, age, and interest, never by patient data. Capture leads with first-party forms that feed a CRM covered by a signed BAA. Review requests and reminders go out through systems that are inside your compliance perimeter, not bolted on.

A compliant stack in practice looks like this:

  • Marketing site: pixels allowed, no patient data, kept separate from the portal
  • Patient portal and scheduling: zero third-party tags, full stop
  • CRM, email, and chat: HIPAA-capable vendors with signed BAAs
  • Ads: keyword, geographic, and demographic targeting only, pointed at marketing pages
  • Measurement: call and form counts stripped of identifiers, never platform pixels on patient pages

This is exactly how we structure medical practice marketing services for clinics: the growth engine runs at full speed because the compliance lines were drawn first, and organic visibility comes from medical practice SEO rather than risky audience tricks. For the review side, we published word-for-word PHI-free scripts in our guide to HIPAA-safe Google reviews.

Honest take: most of what ranks for this topic is software vendors trying to scare you into a subscription. You usually do not need another tool. You need tracking moved off patient pages, authorizations where the law requires them, and BAAs with the vendors that touch data. That is an afternoon of disciplined cleanup, not a platform.

Your 10-point HIPAA marketing checklist

  • Inventory every script and pixel on every page of your site
  • Remove ad pixels from portal, intake, scheduling, and condition pages
  • Configure analytics so no identifiers pair with health-context pages
  • Get signed BAAs from your CRM, email, chat, and call-tracking vendors
  • Delete any ad audience ever built from patient data
  • Use written authorization forms for testimonials and photos
  • Rewrite review responses so they never confirm patient status
  • Keep ad targeting to geography, demographics, and interests
  • Train front desk staff on PHI-free review and referral asks
  • Re-run the pixel inventory quarterly; tags creep back in

Want more patients without the compliance risk?

We build HIPAA-aware patient acquisition for medical practices: clean tracking, compliant ads, and rankings that compound.

Book a Strategy Call

Sources: HHS, HIPAA Marketing Guidance · HHS, Online Tracking Technologies Bulletin · Health Affairs, Hospital Website Tracking Study · FTC, BetterHelp Enforcement

Will Google or Meta sign a BAA for advertising?

No. Neither platform signs Business Associate Agreements for their advertising products, which is why patient data can never flow into ad targeting, pixels on patient pages, custom audiences, or lookalikes. Advertise with demographic, geographic, and interest targeting instead, and keep every tag off patient-facing pages.

Only in a narrow, carefully built way: audiences from purely informational marketing pages, with consent and with no health condition implied by the page itself. Retargeting visitors of a treatment or scheduling page implies those people sought that care, which is exactly the pattern regulators have penalized. For most practices the safest answer is to skip retargeting entirely.

Yes. A testimonial, review quote used in your ads, or before-and-after photo identifies someone as a patient, which is PHI. You need a written, specific, revocable HIPAA authorization, not just a photo release. Keep signed forms on file and honor revocations quickly.

No. Targeting by age, gender, location, or interests uses the ad platform’s own data, not yours, so HIPAA is not triggered. The line is crossed when your patient information, including behavior tracked on patient-facing pages of your website, feeds the targeting.

About the team: BRD Media is a Chicago-area digital marketing team that publishes its pricing, keeps every account in the client's name, and reports on booked appointments instead of vanity metrics.

Related reading: How to Market a Medical Practice: The First 90 Days · HIPAA-Safe Google Reviews for Medical Practices

See BRD Media first in Google

Add us as a preferred source and our SEO breakdowns rank higher in your own Search results, AI Mode and AI Overviews.

Add BRD Media as a preferred source