Compliance · Clinic guide

HIPAA-compliant marketing: what clinics can and can’t do.

The plain-English rules — what HIPAA actually restricts in marketing, where the tracking-pixel trap is, and how to grow a practice without a violation.

HIPAA does not stop clinics from marketing — it restricts using patients’ protected health information to do it. A clinic can advertise services, publish health content, and target ads by condition context. It cannot use patient data — lists, records, portal tracking data, identifiable photos or stories — for marketing without written authorization.

What does HIPAA actually restrict in marketing?

Less than most clinic owners fear, and more than most agencies check. HIPAA doesn’t regulate advertising — it regulates protected health information: anything that identifies a person and relates to their health or care. A name on a schedule. A diagnosis. A before/after photo. The bare fact that someone is your patient at all.

The marketing rule itself — 45 CFR 164.508(a)(3) — is short: before a covered practice uses or discloses PHI for marketing, it needs the patient’s written authorization. Two exceptions: face-to-face conversations, and promotional gifts of nominal value. And if a third party is paying you to send the message, the authorization has to say so.

Marketing activityHIPAA status
Blog posts, condition pages, general health contentFine — no PHI involved
Ads targeted by condition context (keywords, geography, interests)Fine — no patient data used
Wellness newsletter to an opt-in listFine — as long as you don’t segment it using clinical records
Emailing patients about a new service based on their diagnosis historyAuthorization required
Patient testimonial, story, or before/after photoWritten authorization required, before publication
Uploading your patient list to Meta or Google as a custom audienceAuthorization required — in practice, don’t
Ad pixels on the patient portal or booking flowThe trap — treat as off-limits (next section)

This is an operator’s field guide, not legal advice. For edge cases — especially whether your entity is covered at all — spend the hour with a healthcare attorney.

Can I keep the Meta pixel and Google Analytics on my clinic site?

This is where otherwise-careful clinics get caught, because the tools install themselves quietly — a pixel from an old campaign, analytics from the web designer, a chat widget from the phone vendor. In December 2022, HHS’s Office for Civil Rights published a bulletin on online tracking technologies (updated March 18, 2024). Its core position: trackers on authenticated pages — the patient portal, e-check-in, anything behind a login — collect PHI, and sending PHI to a vendor requires a business associate agreement. Ad platforms generally won’t sign one for a pixel, which means there’s no compliant way to feed them that data.

Then a court pushed back. In AHA v. Becerra (N.D. Tex., June 20, 2024), a federal judge vacated the bulletin’s “proscribed combination” — OCR’s claim that an IP address plus a visit to a public webpage about a health condition is automatically PHI. HHS withdrew its appeal in August 2024. So an analytics tag on your public blog is not, by itself, a federal violation.

Here’s what the ruling didn’t do: it didn’t touch authenticated pages, it didn’t repeal the marketing rule, and it didn’t stop plaintiffs’ firms from filing pixel suits against providers under state privacy and wiretap laws. The careful setup costs you almost nothing in growth:

  1. Audit every tag. Crawl your own site and list each pixel, analytics script, heatmap, chat widget, and call-tracking snippet — what it collects, and who receives it.
  2. Strip trackers from sensitive pages. Nothing third-party on the portal, intake forms, appointment-booking flow, or confirmation pages unless that vendor has signed a BAA.
  3. Get BAAs from every vendor that touches PHI. CRM, email platform, call tracking, chat, transcription — if it can see a patient’s name, it signs.
  4. Ask for consent anyway. A visible cookie choice on public pages is cheap goodwill — and it’s the direction state privacy law is already moving.

Can we use patient testimonials — and reply to Google reviews?

Testimonials: yes, with a signature first. A patient’s story, name, or identifiable photo is PHI, and using it in marketing requires a specific written HIPAA authorization — not a clause buried in the intake packet. Get it signed before anything goes live, name where the content will appear, and take the material down if the patient later revokes. Ask a happy patient directly and most will say yes; the form takes two minutes.

Reviews are the sharper edge. Replying to a Google review in any way that confirms the reviewer is your patient is a disclosure — even if they named themselves first, even if the review is false. In June 2023, OCR settled with Manasa Health Center, a New Jersey psychiatric practice, for $30,000 after it disclosed patients’ diagnosis and treatment information while replying to negative Google reviews.

The reply that keeps you safe is boring on purpose: thank the reviewer, state that privacy law prevents you from discussing any individual’s care, and offer a phone number to take it offline. Never confirm patienthood, never correct clinical details in public — the correction is the violation.

What can a clinic still do aggressively?

Almost everything that actually fills a calendar. Our best-performing clinic campaigns — 10%+ sustained CTR at roughly $0.11 a click — run entirely on condition-context targeting: the ad matches the condition the person is researching, and no patient record of ours or anyone else’s is involved.

  • Condition-level ad targeting without PHI. Keywords, geography, interests, creative that speaks to the problem. The message does the targeting — your data doesn’t have to.
  • First-party content. Condition pages, procedure explainers, video. It compounds, it’s un-bannable, and it feeds the whole patient-acquisition system.
  • Missed-call capture and speed-to-lead. Answering faster isn’t a privacy question when it runs inside your own systems, under BAAs.
  • Referral programs done right. Reward the referrer without ever disclosing to anyone else who is or isn’t a patient — and check anti-kickback rules if you bill federal programs.
  • Review-generation workflows. Asking every patient for an honest review is a normal operational communication. Do it systematically.
  • Email to opt-in lists. Wellness newsletters, new-service announcements — built from sign-ups, not from segmenting charts.

One honest boundary: if a growth partner’s plan for your clinic depends on uploading your patient list to an ad platform or wiring your booking data into a pixel, walk away — including if that partner is us. That play isn’t a grey area worth testing; it’s the violation.

How do Meta and Google treat healthcare advertisers?

Separately from HIPAA, both platforms treat health as a restricted category — Google’s personalised-advertising policy bars targeting people based on health conditions, and Meta limits the website events and optimisation options available to health-and-wellness advertisers. In practice that pushes clinics toward exactly the playbook that’s also compliant: broad condition-context targeting and strong creative rather than data tricks. Which platform earns your budget depends on whether your specialty lives on existing demand or created demand — we broke that down, with campaign data, in Meta vs. Google Ads for clinics.

What does a HIPAA-compliant marketing setup look like?

Eight items. An afternoon with your web person and your practice manager covers most of them.

  • Map every tag on your site. Pixels, analytics, heatmaps, chat, call tracking — written down, with what each sends and to whom.
  • Keep third-party trackers off sensitive pages. Portal, intake, booking, confirmations — clean unless the vendor signed a BAA.
  • BAAs on file for every vendor that touches PHI. CRM, email, phones, chat, transcription. No signature, no data.
  • A real authorization form for stories and photos. Specific, signed before publication, honoured on revocation.
  • A review-reply script that confirms nothing. Trained into everyone who touches the Google profile.
  • No patient lists in ad platforms. Custom audiences from your CRM need authorization — assume you don’t have it.
  • Marketing data separated from clinical data. Newsletter lists from opt-ins, never from segmenting the chart.
  • Re-audit on every new tool. Each new widget restarts the question. Document the decision each time.

None of this slows growth — it removes the one risk that can undo it. It’s the same stack we install in our clinic engagements, and it’s why procurement conversations get easier, not harder.

Common questions.

Can clinics use Facebook ads under HIPAA?

Yes — HIPAA restricts using protected health information, not advertising itself. Run Meta ads on condition-context targeting: geography, interests, creative that speaks to the condition someone is researching. The line is patient data. Uploading your patient list as a custom audience without written authorization, or putting the Meta pixel on portal and booking pages, is where clinics get burned.

Do Google Analytics and tracking pixels violate HIPAA?

Not inherently. Per HHS OCR's December 2022 bulletin (updated March 2024), trackers on authenticated pages like patient portals generally collect PHI, which requires a business associate agreement — and ad platforms generally won't sign one. In June 2024 a federal court (AHA v. Becerra) vacated OCR's position that an IP address plus a visit to a public health page is automatically PHI. Careful clinics still keep trackers off portals and booking flows.

Can a med spa use patient before/after photos in marketing?

Only with a written authorization signed before the photo is used. An identifiable photo tied to treatment is protected health information, and HIPAA's marketing rule requires authorization for marketing uses of PHI. Even a cash-pay med spa that may fall outside HIPAA's covered-entity definition should get the same signed consent — state privacy law and patient trust don't care about the technicality.

Does HIPAA apply to marketing agencies?

Not directly — until the agency touches PHI on a clinic's behalf. The moment it handles patient lists, CRM records, call recordings, or booking data, it becomes a business associate: it must sign a BAA and protect that data to HIPAA standards. If an agency pitching your clinic doesn't know what a BAA is, that's the whole interview.

Keep reading

More from the playbook.