HIPAA dental practice advertising compliance guide
A field guide for dental practice owners, DSOs, dental marketing leads and agencies that support them. Reviewed against the current Office for Civil Rights guidance on online tracking, the Privacy Rule marketing provisions at 45 CFR 164.501 and 508, and the state dental-board advertising rules that layer on top of federal HIPAA.
- A dental before-and-after photograph that identifies the patient — face, distinctive smile, on-record intraoral scan — is Protected Health Information under 45 CFR 164.514, and requires a HIPAA marketing authorisation under 45 CFR 164.508 before it appears on a website, ad or social post.
- Dental practices are covered entities the moment they transmit health information electronically for a HIPAA transaction (insurance claim, eligibility check, remittance). That is almost every US dental practice, which means the Privacy Rule applies to marketing communications, not just clinical ones.
- Referral marketing that pays a fee — to a patient or another provider — sits at the intersection of the federal Anti-Kickback Statute (where any federally reimbursed care is involved), state dental board fee-splitting rules, and the Privacy Rule limits on remuneration-based communications. Design the programme before you launch it.
- Review-generation vendors, dental CRM platforms, appointment schedulers, patient-communication tools, and marketing agencies that touch a patient list are business associates under 45 CFR 160.103 and require a signed BAA. Consumer ad platforms will not sign one — architect around that.
- Not legal advice. Consult a healthcare-marketing attorney and your state dental board before publishing any patient-facing creative.
On this page
- Why HIPAA covers your dental practice
- What is PHI in a dental workflow
- Before-and-after photography — the authorisation stack
- Referral marketing, review generation and patient loyalty
- Tracking on a dental website — the OCR guidance in practice
- BAA scoping for dental martech
- State dental board layer
- A working compliance checklist for the marketing team
-
Primary Care · North Dallas, TXCase study →
-
MedSpa · North Dallas, TX
-
Skin Care · Beverly Hills, CA
-
Dental · Christiansburg, VACase study →
-
Pediatrics · Blacksburg, VACase study →
-
Pediatric Dentistry · Blacksburg, VACase study →
-
Dental · Roanoke, VACase study →
-
Functional Medicine · Telehealth · USACase study →
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Why HIPAA applies to your dental practice — and to your marketing
A dental practice becomes a HIPAA covered entity the moment it transmits health information electronically in connection with any HIPAA transaction — a claim, eligibility check, referral certification, remittance advice, or coordination-of-benefits enquiry. Because virtually every US dental practice interacts with a payer digitally, virtually every US dental practice is a covered entity under 45 CFR 160.103.
Once the Privacy Rule applies, it applies across the board — clinical, administrative and marketing. Marketing teams sometimes assume the rule stops at the treatment room. It does not. The Privacy Rule marketing definition at 45 CFR 164.501 controls what the practice may say, to whom, and under what terms. The Security Rule at 45 CFR 164.308 controls how the practice safeguards the electronic PHI that supports marketing (contact lists, appointment feeds, review invitations).
The Business Associate rules at 45 CFR 164.502(e) and 164.504(e) then extend the perimeter to every vendor the practice hands PHI to. A marketing agency, a review-generation tool, a CRM, a scheduling platform, a patient-communication text service, a call-tracking provider — each is a business associate the moment it receives PHI on behalf of the practice.
The practical implication for a growing practice
Every marketing initiative in a dental practice — a new-patient campaign, a whitening promotion, an Invisalign clinic day, a paediatric back-to-school outreach — has three layers to clear. HIPAA governs what PHI can enter the campaign and which vendors can process it. State dental board rules govern the words used, the claims made, and the disclosures required. FTC and state UDAP rules govern truthfulness, substantiation and endorsement disclosures. This guide is scoped to HIPAA. State board and FTC rules cross-link at the end.
What counts as PHI in a dental workflow
Protected Health Information is any individually identifiable health information held or transmitted by a covered entity or business associate. In a dental workflow, PHI includes far more than clinical charts. The following are all PHI when linked to an identifiable individual.
- Patient name, address (down to a 3-digit ZIP prefix in most cases), telephone number, email address, insurance member ID.
- Appointment date, provider seen, procedure scheduled, treatment plan estimate.
- Intraoral photographs, extraoral photographs, panoramic radiographs, CBCT scans, intraoral scans (STL files carry patient metadata).
- Full-face photographs — explicitly listed at 45 CFR 164.514(b)(2)(i)(P).
- Voice recordings from a call-tracking provider that includes a caller's identity plus a treatment enquiry.
- Website analytics events where an IP address plus a procedure-page URL is captured and forwarded to a non-BAA vendor.
Dental practices frequently under-scope PHI because clinical staff associate the term with the chart. Growth and marketing teams must scope it wider: any dataset that could be re-associated with an individual by any reasonable means is PHI in the hands of a covered entity or business associate.
Before-and-after photography — the authorisation stack
Smile-makeover, orthodontic, veneer, implant and full-mouth-rehabilitation photography is the single highest-leverage creative asset in dental marketing. It is also the single highest-risk asset from a Privacy Rule standpoint. Practices that get this right run at scale without incident; practices that get it wrong end up in a state dental board complaint, an OCR enquiry, or both.
The authorisation stack for a marketing photograph has four layers.
1. HIPAA marketing authorisation — 45 CFR 164.508
A HIPAA authorisation specific to marketing use must describe the PHI to be used (photographs of the specified date range and treatment), identify the covered entity and any specific recipients (website, social channels, ad networks), state the purpose (marketing of the practice's services), carry an expiration date or event, be signed and dated by the patient, contain a statement of the right to revoke, contain a statement that treatment cannot be conditioned on the authorisation, and contain a statement that PHI once disclosed may be re-disclosed by the recipient. Where the practice receives remuneration in exchange for use — for example, a manufacturer co-marketing arrangement — the authorisation must state that fact.
2. State dental board disclosure
Most state dental boards require accompanying disclosures for before-and-after imagery — commonly a statement that results are not typical, that the photograph is a genuine result of the practice's own work (not stock imagery), and that no digital retouching materially alters the clinical outcome. State rules vary. Cross-reference the state medical/dental board guide for the jurisdiction you advertise in.
3. Platform-level content rules
Consumer platforms have their own advertising rules on before-and-after imagery. Google Ads restrictions on personalisation for health and wellness, and platform-level restrictions on close-up cosmetic imagery, apply on top of HIPAA. A photograph legal under HIPAA can still be paused by the platform.
4. Minor patients — parental authorisation
For any patient under 18, the parental or legal-guardian signature is required on the HIPAA authorisation, and state law may separately require the patient's own assent above certain ages. Orthodontic marketing that features paediatric patients has to clear both.
Referral marketing, review generation and patient loyalty
Referral programmes and review-generation campaigns are the two most productive channels in dental practice growth and the two that require the most careful compliance scoping.
Cash-for-referral versus loyalty perks
Federal Anti-Kickback Statute liability at 42 USC 1320a-7b generally applies where any federal health-care programme reimburses the underlying care. Many dental practices treat only privately insured or self-pay patients and therefore have a narrower federal exposure. State dental board fee-splitting rules apply regardless of payer — most state boards limit or prohibit paying a patient a percentage of the fee for a referred case, and require disclosure where any inducement is offered. HIPAA layers on top: a communication to a patient encouraging them to refer another individual is marketing under 45 CFR 164.501 unless it fits an exception, and any use of the practice's patient list to run such a programme requires a lawful basis.
A safer working pattern
- Small, non-cash gestures of appreciation for existing patients, disclosed transparently, not tied to a specific referred case.
- Written arrangements with adjacent specialist providers (orthodontists to general dentists, general dentists to oral surgeons) documented as professional referral relationships, not paid marketing.
- Review-generation campaigns that invite the patient at the appropriate stage, use a HIPAA-safe patient-communication vendor operating under a BAA, and do not gate compensation on a positive review (FTC endorsement rules).
Review responses that stay compliant
Responding to an online review is a marketing communication under most state dental board interpretations. A response that confirms the reviewer is a patient of the practice — even by acknowledging a specific procedure they mentioned — is a disclosure of PHI. The safer response pattern is a generic acknowledgement that does not confirm the person is a patient, does not disclose any clinical detail, and directs the reviewer to a private channel to address any specifics. This applies equally to positive and negative reviews.
Tracking on a dental website — OCR guidance in practice
The December 2022 Office for Civil Rights bulletin on online tracking technologies, and its March 2024 update, both apply to dental websites. For a general practice site the highest-risk surfaces are the appointment-booking flow, the procedure-specific pages (implants, root canal, orthodontics, sleep dentistry, cosmetic cases), and any patient-portal login page.
A visitor reading a page titled "sleep apnoea appliance" while a tracking pixel captures the IP address and the URL is generating an event that OCR has explicitly described as PHI in the hands of a non-BAA third party. That the visitor has never booked, called or identified themselves is not the point — the combination of an IP address and a URL that relates to health, health care, or payment for health care is enough.
The dental-specific fix
- Move all consumer ad-platform tags off procedure and portal pages. Keep them on the top-level marketing pages if you must, but with URL rewriting.
- Route conversion events through a server-side tagging container hosted on a first-party subdomain, under the practice's control or under a business associate's control.
- Field-level allow-list what leaves the server. For dental conversion, an event token, an aggregate value, and a hashed anonymous ID are usually enough for platform optimisation.
- Turn on Consent Mode and honour the visitor's opt-out state before any event fires.
- Log what left, retain for at least six years, and include the server-side pipeline in the annual HIPAA risk analysis under 45 CFR 164.308(a)(1)(ii)(A).
BAA scoping for dental martech
A dental practice typically has more business associates than it thinks. A first-pass scoping should include the practice management system, the imaging system, the intraoral-scanner cloud, the CBCT vendor's cloud, the electronic claims clearinghouse, the appointment-reminder service, the review-generation tool, the two-way patient text platform, the call-tracking provider, the CRM, the email service, the website hosting, the analytics platform, and the marketing agency.
For each, the practice needs to know three things. Is a BAA on file? Does the vendor's HIPAA program cover the specific product or module the practice uses? Is the annual security posture documented (SOC 2, HITRUST, or equivalent)?
Where BAAs are hardest to get
- Consumer ad platforms — Google Ads, Meta Ads, TikTok Ads for Business, LinkedIn Ads, X Ads — will not sign a BAA for their standard ad products. Architect around this with the server-side pattern above.
- Consumer analytics products — not the enterprise or measurement-protocol variants — typically will not sign either.
- Some review-generation SaaS tools have a HIPAA add-on tier; the base tier does not qualify. Confirm before onboarding.
- Some call-tracking providers will sign a BAA on a specific plan; verify the specific product code.
State dental board rules that layer on top
State dental boards regulate the words used in dental advertising. HIPAA sits underneath as a federal floor. Common state board rules include:
- Prohibitions on false, deceptive, or misleading advertising — often defined broadly enough to cover unrepresentative case galleries.
- Requirements to disclose specialty status accurately — "cosmetic dentistry" is not an ADA-recognised specialty, and some states require language reflecting that.
- Disclosures on before-and-after photography — typical-result language, no material retouching, and same-patient imagery.
- Fee-splitting and inducement prohibitions that affect referral and loyalty programme design.
- Testimonial rules — many states require that testimonials reflect the honest current opinion of the patient and disclose any compensation.
Cross-reference the specific state dental board rule set for every state the practice advertises into. A multi-office group needs a state-by-state creative review matrix, not a single national approval.
A working compliance checklist for a dental marketing team
Photography
Every identifiable image has a signed HIPAA marketing authorisation on file, referencing the specific channels of use and stored for six years.
Website tracking
Ad-platform tags off portal and procedure pages. Server-side tagging with field-level allow-listing forwards only anonymised conversion events.
Reviews
Review-generation vendor operates under a BAA. Response templates never confirm patient status or clinical detail publicly.
Referral programme
Documented and reviewed against state fee-splitting rules. No cash inducement per referred case. Federally reimbursed care excluded from any inducement structure.
Text and email
Patient-communication vendor under a BAA. TCPA-safe consent flow for automated texts. CAN-SPAM header, sender-address and unsubscribe compliance on every email.
Annual risk analysis
Marketing surface is included in the practice's annual HIPAA risk analysis. Findings are documented and corrective actions are tracked.
Dental HIPAA marketing — common questions
Is a dental before-and-after photo PHI?
A dental intraoral or facial photograph that identifies the individual is PHI. A full-face photograph is one of the 18 Safe Harbor identifiers at 45 CFR 164.514(b)(2)(i)(P), and an intraoral photograph paired with a treatment description is identifiable through the dental record. Publishing such a photograph requires a HIPAA authorisation under 45 CFR 164.508 that describes the marketing use specifically.
Can a dental practice send appointment reminders by text without an authorisation?
Appointment reminders for the individual's own treatment fall inside the treatment communication carve-out of the HIPAA marketing definition, but the TCPA still applies. The practice needs prior express consent for automated or auto-dialed texts, and prior express written consent if the content is promotional as well as clinical.
Does a dental office need a BAA with a review-generation vendor?
A review-generation vendor that receives a patient list from the practice — even just names and mobile numbers linked to an appointment date — is receiving PHI and is a business associate under 45 CFR 160.103. A signed BAA is required, and the vendor must be able to demonstrate HIPAA safeguards.
What does the OCR tracking-technology guidance mean for a dental website?
A dental website with tracking pixels on procedure pages (implants, orthodontics, sleep apnoea) or on the appointment-booking flow is likely disclosing PHI to the ad platform when an IP address is combined with a URL that reveals treatment intent. Server-side tagging with URL rewriting and field-level allow-listing is the standard fix.
Can we run a referral programme that pays patients for new patient introductions?
Cash-for-referral programmes intersect with both the Anti-Kickback Statute (for federally reimbursed care) and state dental board rules on split-fee and inducement. Patient loyalty perks unrelated to referrals, and professional referrals between licensed providers under a written arrangement, are safer patterns to consider with counsel.
How do smile-makeover Instagram posts stay HIPAA-aligned?
Every post that shows an identifiable patient must sit on a written HIPAA authorisation specific to marketing use, plus a state dental board disclosure where required (typical results, retouching notice). De-identified case galleries — teeth only, no identifying facial features — sit outside HIPAA, but still trigger truth-in-advertising rules.
Can we use a patient testimonial video in a paid campaign?
Yes, with a marketing authorisation that specifies paid use and any remuneration paid to the patient, an FTC endorsement disclosure if the patient was compensated, and a state dental board disclaimer on typical results.
Scope your dental practice's HIPAA-safe marketing engagement
Book a 30-minute call with the US practice lead, email us, or WhatsApp us in your time zone. Retainers custom-scoped per engagement · from USD ~$250/month equivalent (approx Rs 20,000).