🇮🇳 India 🇺🇸 US
Healthcare SEO AI search (AIO) Local SEO & Google Business Profile Content marketing Performance marketing Google Ads Meta Ads Email & SMS marketing Reputation management Website design Branding YouTube & video Marketing consulting
Dental practices Pediatric practices Primary care Med spas Dermatology IVF & fertility Dallas (HQ) Houston New York All US cities and specialties
US healthcare marketing statistics Med spa consumer behavior report Dental patient experience report Google benchmarks: 9 specialties Free tools All US research US case studies
Software
Healthcare practices Pharma Medical devices
About Ichelon Consulting US How we work Santosh Reddy, Director Ravi Kumarraju, Partner & Director
Book a call with the US team Call +1 (724) 612-3694
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Ichelon Consulting US · HIPAA by role

HIPAA for healthcare marketing teams: what in-house marketers can and cannot do with patient data

In-house marketers stay HIPAA compliant by working from aggregate or de-identified data by default, getting a signed HIPAA authorization before using any patient's story, photo or data in marketing, keeping PHI out of ad platforms and analytics tags, replying to reviews without confirming anyone is a patient, and keeping every business account in the practice's name so access can be removed cleanly. Most good healthcare marketing needs very little PHI; the trouble starts when convenience pulls patient data into tools that were never meant to hold it.

Guide for US practice owners · Published October 4, 2026

TL;DR
  • Using or disclosing PHI for marketing needs written authorization (45 CFR 164.508(a)(3)), with narrow exceptions such as face-to-face communication.
  • Telling your own patients about your own health services is generally not "marketing" under HIPAA (164.501), unless a third party pays you for it. TCPA and email laws still apply.
  • Never upload patient lists to ad platforms for audiences or lookalikes without authorization; the platforms are not your business associates.
  • Lead forms, call recordings and booking data should be treated as PHI and kept in tools covered by a BAA.
  • Ad, analytics, social and website accounts belong to the practice, with named users, so offboarding is one step.
  • Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
Ichelon Consulting US
  • Dallas, Texas LLC
  • 10-person US client team · Central Time (CST)
  • 25+ US healthcare clients
  • BAA signed with every client
  • HIPAA compliance training across client and delivery teams
  • Contracts and invoices in USD
How we work with US practices →
Trusted by US practices · case studies → 25+ US clients · 8 shown · TX · CA · VA · nationwide telehealth
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
The basics

When marketing becomes a HIPAA question

Short answer: HIPAA does not regulate your billboard or your blog. It regulates what you do with protected health information. Marketing becomes a HIPAA question the moment patient data is involved: a patient list, a photo, a review reply, a lead form, a call recording or a tracking tag.

This page applies our four-stage HIPAA framework to in-house marketing coordinators, managers and social media staff at practices and groups. If you work with an outside agency, also read what to require from agencies and vendors.

What counts as "marketing" under HIPAA

HIPAA defines marketing as a communication about a product or service that encourages people to buy or use it (164.501). Several communications are carved out when no third party pays the practice to make them, including describing health-related services the practice itself provides and communications for treatment or care coordination. Using or disclosing PHI for anything that does count as marketing requires the patient's written authorization (164.508(a)(3)), except face-to-face communication and promotional gifts of nominal value. If a third party pays you, the authorization must say so.

In practice: a newsletter to your own patients about a new laser service is generally a permitted communication. Sharing your patient list with a skincare brand, uploading it to an ad platform or featuring a patient's photo in an ad is not, without authorization.

The four stages

The four stages for marketing staff

Stage 1 · Onboard

Training as necessary for the role (164.530(b)) means a marketing-specific session: what PHI looks like in marketing tools, the authorization rule, review replies, photos, tracking technology, ad audiences and how to report a mistake. Sign the confidentiality agreement. Add a short tour of which tools are approved for PHI and which are not.

Stage 2 · Access

Default to no EHR access. Marketing works from aggregate reports: new patients by source, bookings by service, show rates, review counts. Minimum necessary (164.502(b), 164.514(d)) supports that design. Where a marketer must touch PHI, such as a CRM with lead records or a review tool with patient phone numbers, give them a named login with MFA on a tool covered by a BAA. Business accounts (Google Ads, Meta Business, analytics, Google Business Profile, social, email platform, website admin) belong to the practice, with staff added as users.

Stage 3 · Operate

The channel rules are in the next section. The working habit: ask "does this tool or this asset contain anything that identifies a patient?" before you upload, post or share it.

Stage 4 · Offboard

Remove the person from every marketing account on the last day, transfer ownership of anything set up under a personal login, rotate shared passwords and revoke API keys or integrations they created. The offboarding checklist has a marketing section.

Operate

Daily rules for reviews, testimonials, data and tracking

ActivityRule
Review repliesNever confirm the reviewer is a patient or mention a visit, treatment or result. Thank, invite offline contact, stop. See the review response guide.
Review requestsSend through a review tool covered by a BAA if it receives patient names and numbers from your systems. Ask everyone, not only happy patients, to stay within platform rules.
Testimonials and photosSigned HIPAA marketing authorization first, kept six years. Check FTC endorsement rules and your state board. See our photo compliance guide.
Email and SMS to patientsOwn-service announcements are generally permitted under HIPAA. CAN-SPAM applies to email; texts need TCPA consent. No individual health details in the message.
Ad audiencesNo patient list uploads, lookalikes from patient lists or retargeting built from booking or portal pages without authorization.
Website trackingNo pixels on booking, portal, intake or thank-you pages that reveal a condition. Do not send form fields. See the tracking guide.
Lead forms and call trackingTreat as PHI. Vendors sign a BAA. Recordings and transcripts stay out of ad platforms.
ReportingAggregate numbers only in decks and dashboards shared outside the practice.

Where the tracking guidance stands

OCR published guidance on online tracking technologies in December 2022 and updated it in March 2024. In June 2024 a federal district court in Texas vacated the portion saying HIPAA applies when a tracker collects an IP address plus a visit to an unauthenticated public page about a health condition or provider, and HHS withdrew its appeal that August. The remainder stands: tracking on authenticated and PHI-bearing pages still needs a BAA with the vendor or patient authorization. State privacy laws and the FTC may reach further. Campaign-level detail: HIPAA-safe Google Ads and HIPAA-safe Meta ads.

OCR case: a press release. Memorial Hermann Health System in Texas paid $2.4 million after senior management approved a press release that included a patient's name in its title. OCR said leadership should have known that was a clear Privacy Rule violation. Communications teams are not exempt.
OCR case: review replies. Manasa Health Center in New Jersey paid $30,000 for disclosing four patients' PHI in replies to Google reviews; Elite Dental Associates in Dallas paid $10,000 for similar Yelp replies.
Checklist

Printable marketing team HIPAA checklist

Stage 1 · Onboard

  • Marketing-specific HIPAA training completed and logged
  • Confidentiality agreement signed
  • List of tools approved for PHI reviewed with the new hire

Stage 2 · Access

  • No EHR access unless the role requires it and it is approved
  • Named user (not shared login) on every ad, analytics, social, email and website account
  • MFA on every marketing account
  • All business accounts owned by the practice

Stage 3 · Operate

  • Signed authorization on file for every testimonial, photo and patient story
  • Review replies never confirm patient status
  • No patient lists uploaded to ad platforms
  • No pixels on booking, portal or intake pages; no form fields sent to analytics
  • Form, CRM, call-tracking and review vendors each have a BAA
  • Reports shared outside the practice are aggregate only

Stage 4 · Offboard

  • User removed from every marketing account on the last day
  • Ownership transferred for anything under a personal login
  • Shared passwords rotated; API keys and integrations reviewed
  • Local exports of lead or patient data deleted and confirmed

Med spa teams can go further with our med spa marketing page, med spa marketing statistics for 2026, the med spa Google presence report and the med spa HIPAA advertising guide. State advertising rules: Florida, Texas, or the 50-state overview. Managers: see HIPAA for practice managers. More in all US guides, or book a call.

Sources

Sources

Keep reading

Related pages from the US team

HIPAA compliance by role

The full four-stage framework and the roles-by-stages matrix.

HIPAA-safe website tracking

Page-by-page tag setup after the 2024 court ruling.

HIPAA-compliant healthcare marketing

Authorizations, testimonials, email and ads in depth.

What to require from agencies and vendors

BAA terms and data-flow questions for outside partners.

Responding to negative reviews under HIPAA

Templates that never confirm someone is a patient.

How we work

Every practice welcome — Goals-Driven engagements from $499/mo

We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.

Read the full engagement model →

FAQ

Common questions

Can we email existing patients about a new treatment we offer?

Generally yes. HIPAA's definition of marketing excludes communications describing a health-related product or service that the practice itself provides, as long as no third party pays the practice to send them. You still need to follow CAN-SPAM for email and TCPA consent rules for texts, honor opt-outs, and keep the message free of individual health details.

Can we use a patient testimonial on our website?

Yes, with a signed HIPAA authorization that covers marketing use of the patient's name, story, photo or video, and that tells them they can revoke it. Keep the signed form on file for six years. FTC rules on endorsements and your state board's advertising rules also apply.

Is website lead form data PHI?

When a healthcare provider covered by HIPAA collects a person's contact details along with information about the care they want, the safest approach is to treat it as PHI. Use a form and CRM vendor that will sign a Business Associate Agreement and never pass form fields to analytics or ad platforms.

Can marketing staff see the EHR?

Usually not. The minimum necessary standard asks practices to limit each role's access to the PHI it needs. Marketing can work from aggregate reports such as new patients by source, bookings by service and review counts, prepared by someone with appropriate access.

Are Meta and Google pixels banned on healthcare websites?

Not banned outright. A 2024 court ruling vacated the part of OCR's guidance covering certain tracking on unauthenticated public pages, but tracking on booking, portal, intake and other PHI-bearing pages still raises HIPAA issues, and many ad platforms will not sign a BAA. Keep pixels off those pages and never send form contents or health details.

What should we do with marketing accounts when a marketer leaves?

Remove their user from every ad, analytics, social, email, CRM, website and review account the same day, rotate any shared passwords, and confirm the practice is the owner of each account. If the departing person created accounts under a personal login, transfer ownership before their last day.

A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.

Want measurable marketing that keeps PHI out of ad platforms?

A 30-minute call with the Ichelon Consulting US team. We will look at your tracking, forms and lead flow and show you what we would change. BAA signed before we start.

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership