HIPAA for healthcare marketing teams: what in-house marketers can and cannot do with patient data
In-house marketers stay HIPAA compliant by working from aggregate or de-identified data by default, getting a signed HIPAA authorization before using any patient's story, photo or data in marketing, keeping PHI out of ad platforms and analytics tags, replying to reviews without confirming anyone is a patient, and keeping every business account in the practice's name so access can be removed cleanly. Most good healthcare marketing needs very little PHI; the trouble starts when convenience pulls patient data into tools that were never meant to hold it.
- Using or disclosing PHI for marketing needs written authorization (45 CFR 164.508(a)(3)), with narrow exceptions such as face-to-face communication.
- Telling your own patients about your own health services is generally not "marketing" under HIPAA (164.501), unless a third party pays you for it. TCPA and email laws still apply.
- Never upload patient lists to ad platforms for audiences or lookalikes without authorization; the platforms are not your business associates.
- Lead forms, call recordings and booking data should be treated as PHI and kept in tools covered by a BAA.
- Ad, analytics, social and website accounts belong to the practice, with named users, so offboarding is one step.
- Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
- Dallas, Texas LLC
- 10-person US client team · Central Time (CST)
- 25+ US healthcare clients
- BAA signed with every client
- HIPAA compliance training across client and delivery teams
- Contracts and invoices in USD
-
Primary Care · North Dallas, TXCase study →
-
MedSpa · North Dallas, TX
-
Skin Care · Beverly Hills, CA
-
Dental · Christiansburg, VACase study →
-
Pediatrics · Blacksburg, VACase study →
-
Pediatric Dentistry · Blacksburg, VACase study →
-
Dental · Roanoke, VACase study →
-
Functional Medicine · Telehealth · USACase study →
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
When marketing becomes a HIPAA question
Short answer: HIPAA does not regulate your billboard or your blog. It regulates what you do with protected health information. Marketing becomes a HIPAA question the moment patient data is involved: a patient list, a photo, a review reply, a lead form, a call recording or a tracking tag.
This page applies our four-stage HIPAA framework to in-house marketing coordinators, managers and social media staff at practices and groups. If you work with an outside agency, also read what to require from agencies and vendors.
What counts as "marketing" under HIPAA
HIPAA defines marketing as a communication about a product or service that encourages people to buy or use it (164.501). Several communications are carved out when no third party pays the practice to make them, including describing health-related services the practice itself provides and communications for treatment or care coordination. Using or disclosing PHI for anything that does count as marketing requires the patient's written authorization (164.508(a)(3)), except face-to-face communication and promotional gifts of nominal value. If a third party pays you, the authorization must say so.
In practice: a newsletter to your own patients about a new laser service is generally a permitted communication. Sharing your patient list with a skincare brand, uploading it to an ad platform or featuring a patient's photo in an ad is not, without authorization.
The four stages for marketing staff
Stage 1 · Onboard
Training as necessary for the role (164.530(b)) means a marketing-specific session: what PHI looks like in marketing tools, the authorization rule, review replies, photos, tracking technology, ad audiences and how to report a mistake. Sign the confidentiality agreement. Add a short tour of which tools are approved for PHI and which are not.
Stage 2 · Access
Default to no EHR access. Marketing works from aggregate reports: new patients by source, bookings by service, show rates, review counts. Minimum necessary (164.502(b), 164.514(d)) supports that design. Where a marketer must touch PHI, such as a CRM with lead records or a review tool with patient phone numbers, give them a named login with MFA on a tool covered by a BAA. Business accounts (Google Ads, Meta Business, analytics, Google Business Profile, social, email platform, website admin) belong to the practice, with staff added as users.
Stage 3 · Operate
The channel rules are in the next section. The working habit: ask "does this tool or this asset contain anything that identifies a patient?" before you upload, post or share it.
Stage 4 · Offboard
Remove the person from every marketing account on the last day, transfer ownership of anything set up under a personal login, rotate shared passwords and revoke API keys or integrations they created. The offboarding checklist has a marketing section.
Daily rules for reviews, testimonials, data and tracking
| Activity | Rule |
|---|---|
| Review replies | Never confirm the reviewer is a patient or mention a visit, treatment or result. Thank, invite offline contact, stop. See the review response guide. |
| Review requests | Send through a review tool covered by a BAA if it receives patient names and numbers from your systems. Ask everyone, not only happy patients, to stay within platform rules. |
| Testimonials and photos | Signed HIPAA marketing authorization first, kept six years. Check FTC endorsement rules and your state board. See our photo compliance guide. |
| Email and SMS to patients | Own-service announcements are generally permitted under HIPAA. CAN-SPAM applies to email; texts need TCPA consent. No individual health details in the message. |
| Ad audiences | No patient list uploads, lookalikes from patient lists or retargeting built from booking or portal pages without authorization. |
| Website tracking | No pixels on booking, portal, intake or thank-you pages that reveal a condition. Do not send form fields. See the tracking guide. |
| Lead forms and call tracking | Treat as PHI. Vendors sign a BAA. Recordings and transcripts stay out of ad platforms. |
| Reporting | Aggregate numbers only in decks and dashboards shared outside the practice. |
Where the tracking guidance stands
OCR published guidance on online tracking technologies in December 2022 and updated it in March 2024. In June 2024 a federal district court in Texas vacated the portion saying HIPAA applies when a tracker collects an IP address plus a visit to an unauthenticated public page about a health condition or provider, and HHS withdrew its appeal that August. The remainder stands: tracking on authenticated and PHI-bearing pages still needs a BAA with the vendor or patient authorization. State privacy laws and the FTC may reach further. Campaign-level detail: HIPAA-safe Google Ads and HIPAA-safe Meta ads.
Printable marketing team HIPAA checklist
Stage 1 · Onboard
- Marketing-specific HIPAA training completed and logged
- Confidentiality agreement signed
- List of tools approved for PHI reviewed with the new hire
Stage 2 · Access
- No EHR access unless the role requires it and it is approved
- Named user (not shared login) on every ad, analytics, social, email and website account
- MFA on every marketing account
- All business accounts owned by the practice
Stage 3 · Operate
- Signed authorization on file for every testimonial, photo and patient story
- Review replies never confirm patient status
- No patient lists uploaded to ad platforms
- No pixels on booking, portal or intake pages; no form fields sent to analytics
- Form, CRM, call-tracking and review vendors each have a BAA
- Reports shared outside the practice are aggregate only
Stage 4 · Offboard
- User removed from every marketing account on the last day
- Ownership transferred for anything under a personal login
- Shared passwords rotated; API keys and integrations reviewed
- Local exports of lead or patient data deleted and confirmed
Med spa teams can go further with our med spa marketing page, med spa marketing statistics for 2026, the med spa Google presence report and the med spa HIPAA advertising guide. State advertising rules: Florida, Texas, or the 50-state overview. Managers: see HIPAA for practice managers. More in all US guides, or book a call.
Sources
- 45 CFR 164.501 (definition of marketing and exceptions): law.cornell.edu/cfr/text/45/164.501
- 45 CFR 164.508(a)(3) (authorization required for marketing): law.cornell.edu/cfr/text/45/164.508
- 45 CFR 164.502(b) and 164.514(d) (minimum necessary): law.cornell.edu/cfr/text/45/164.514
- 45 CFR 164.530 (training, documentation): law.cornell.edu/cfr/text/45/164.530
- HHS, Marketing guidance: hhs.gov
- HHS, Use of Online Tracking Technologies: hhs.gov
- OCR withdrawal of appeal in AHA v. Becerra (August 2024), summarized by Quarles: quarles.com
- OCR, Memorial Hermann Health System: hhs.gov
- OCR, Manasa Health Center: hhs.gov
- OCR, Elite Dental Associates: hhs.gov
Related pages from the US team
HIPAA compliance by role
The full four-stage framework and the roles-by-stages matrix.
HIPAA-safe website tracking
Page-by-page tag setup after the 2024 court ruling.
HIPAA-compliant healthcare marketing
Authorizations, testimonials, email and ads in depth.
What to require from agencies and vendors
BAA terms and data-flow questions for outside partners.
Responding to negative reviews under HIPAA
Templates that never confirm someone is a patient.
Every practice welcome — Goals-Driven engagements from $499/mo
We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.
Common questions
Can we email existing patients about a new treatment we offer?
Generally yes. HIPAA's definition of marketing excludes communications describing a health-related product or service that the practice itself provides, as long as no third party pays the practice to send them. You still need to follow CAN-SPAM for email and TCPA consent rules for texts, honor opt-outs, and keep the message free of individual health details.
Can we use a patient testimonial on our website?
Yes, with a signed HIPAA authorization that covers marketing use of the patient's name, story, photo or video, and that tells them they can revoke it. Keep the signed form on file for six years. FTC rules on endorsements and your state board's advertising rules also apply.
Is website lead form data PHI?
When a healthcare provider covered by HIPAA collects a person's contact details along with information about the care they want, the safest approach is to treat it as PHI. Use a form and CRM vendor that will sign a Business Associate Agreement and never pass form fields to analytics or ad platforms.
Can marketing staff see the EHR?
Usually not. The minimum necessary standard asks practices to limit each role's access to the PHI it needs. Marketing can work from aggregate reports such as new patients by source, bookings by service and review counts, prepared by someone with appropriate access.
Are Meta and Google pixels banned on healthcare websites?
Not banned outright. A 2024 court ruling vacated the part of OCR's guidance covering certain tracking on unauthenticated public pages, but tracking on booking, portal, intake and other PHI-bearing pages still raises HIPAA issues, and many ad platforms will not sign a BAA. Keep pixels off those pages and never send form contents or health details.
What should we do with marketing accounts when a marketer leaves?
Remove their user from every ad, analytics, social, email, CRM, website and review account the same day, rotate any shared passwords, and confirm the practice is the owner of each account. If the departing person created accounts under a personal login, transfer ownership before their last day.
A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.
Want measurable marketing that keeps PHI out of ad platforms?
A 30-minute call with the Ichelon Consulting US team. We will look at your tracking, forms and lead flow and show you what we would change. BAA signed before we start.