The plain-English rules — what HIPAA actually restricts in marketing, where the tracking-pixel trap is, and how to grow a practice without a violation.
Less than most clinic owners fear, and more than most agencies check. HIPAA doesn’t regulate advertising — it regulates protected health information: anything that identifies a person and relates to their health or care. A name on a schedule. A diagnosis. A before/after photo. The bare fact that someone is your patient at all.
The marketing rule itself — 45 CFR 164.508(a)(3) — is short: before a covered practice uses or discloses PHI for marketing, it needs the patient’s written authorization. Two exceptions: face-to-face conversations, and promotional gifts of nominal value. And if a third party is paying you to send the message, the authorization has to say so.
| Marketing activity | HIPAA status |
|---|---|
| Blog posts, condition pages, general health content | Fine — no PHI involved |
| Ads targeted by condition context (keywords, geography, interests) | Fine — no patient data used |
| Wellness newsletter to an opt-in list | Fine — as long as you don’t segment it using clinical records |
| Emailing patients about a new service based on their diagnosis history | Authorization required |
| Patient testimonial, story, or before/after photo | Written authorization required, before publication |
| Uploading your patient list to Meta or Google as a custom audience | Authorization required — in practice, don’t |
| Ad pixels on the patient portal or booking flow | The trap — treat as off-limits (next section) |
This is an operator’s field guide, not legal advice. For edge cases — especially whether your entity is covered at all — spend the hour with a healthcare attorney.
This is where otherwise-careful clinics get caught, because the tools install themselves quietly — a pixel from an old campaign, analytics from the web designer, a chat widget from the phone vendor. In December 2022, HHS’s Office for Civil Rights published a bulletin on online tracking technologies (updated March 18, 2024). Its core position: trackers on authenticated pages — the patient portal, e-check-in, anything behind a login — collect PHI, and sending PHI to a vendor requires a business associate agreement. Ad platforms generally won’t sign one for a pixel, which means there’s no compliant way to feed them that data.
Then a court pushed back. In AHA v. Becerra (N.D. Tex., June 20, 2024), a federal judge vacated the bulletin’s “proscribed combination” — OCR’s claim that an IP address plus a visit to a public webpage about a health condition is automatically PHI. HHS withdrew its appeal in August 2024. So an analytics tag on your public blog is not, by itself, a federal violation.
Here’s what the ruling didn’t do: it didn’t touch authenticated pages, it didn’t repeal the marketing rule, and it didn’t stop plaintiffs’ firms from filing pixel suits against providers under state privacy and wiretap laws. The careful setup costs you almost nothing in growth:
Testimonials: yes, with a signature first. A patient’s story, name, or identifiable photo is PHI, and using it in marketing requires a specific written HIPAA authorization — not a clause buried in the intake packet. Get it signed before anything goes live, name where the content will appear, and take the material down if the patient later revokes. Ask a happy patient directly and most will say yes; the form takes two minutes.
Reviews are the sharper edge. Replying to a Google review in any way that confirms the reviewer is your patient is a disclosure — even if they named themselves first, even if the review is false. In June 2023, OCR settled with Manasa Health Center, a New Jersey psychiatric practice, for $30,000 after it disclosed patients’ diagnosis and treatment information while replying to negative Google reviews.
The reply that keeps you safe is boring on purpose: thank the reviewer, state that privacy law prevents you from discussing any individual’s care, and offer a phone number to take it offline. Never confirm patienthood, never correct clinical details in public — the correction is the violation.
Almost everything that actually fills a calendar. Our best-performing clinic campaigns — 10%+ sustained CTR at roughly $0.11 a click — run entirely on condition-context targeting: the ad matches the condition the person is researching, and no patient record of ours or anyone else’s is involved.
One honest boundary: if a growth partner’s plan for your clinic depends on uploading your patient list to an ad platform or wiring your booking data into a pixel, walk away — including if that partner is us. That play isn’t a grey area worth testing; it’s the violation.
Separately from HIPAA, both platforms treat health as a restricted category — Google’s personalised-advertising policy bars targeting people based on health conditions, and Meta limits the website events and optimisation options available to health-and-wellness advertisers. In practice that pushes clinics toward exactly the playbook that’s also compliant: broad condition-context targeting and strong creative rather than data tricks. Which platform earns your budget depends on whether your specialty lives on existing demand or created demand — we broke that down, with campaign data, in Meta vs. Google Ads for clinics.
Eight items. An afternoon with your web person and your practice manager covers most of them.
None of this slows growth — it removes the one risk that can undo it. It’s the same stack we install in our clinic engagements, and it’s why procurement conversations get easier, not harder.
Yes — HIPAA restricts using protected health information, not advertising itself. Run Meta ads on condition-context targeting: geography, interests, creative that speaks to the condition someone is researching. The line is patient data. Uploading your patient list as a custom audience without written authorization, or putting the Meta pixel on portal and booking pages, is where clinics get burned.
Not inherently. Per HHS OCR's December 2022 bulletin (updated March 2024), trackers on authenticated pages like patient portals generally collect PHI, which requires a business associate agreement — and ad platforms generally won't sign one. In June 2024 a federal court (AHA v. Becerra) vacated OCR's position that an IP address plus a visit to a public health page is automatically PHI. Careful clinics still keep trackers off portals and booking flows.
Only with a written authorization signed before the photo is used. An identifiable photo tied to treatment is protected health information, and HIPAA's marketing rule requires authorization for marketing uses of PHI. Even a cash-pay med spa that may fall outside HIPAA's covered-entity definition should get the same signed consent — state privacy law and patient trust don't care about the technicality.
Not directly — until the agency touches PHI on a clinic's behalf. The moment it handles patient lists, CRM records, call recordings, or booking data, it becomes a business associate: it must sign a BAA and protect that data to HIPAA standards. If an agency pitching your clinic doesn't know what a BAA is, that's the whole interview.
Google captures demand, Meta creates it — with real campaign data.
The per-specialty math on unanswered calls and slow follow-up.
AI phone agent vs answering service vs front-desk hire — the honest buyer’s guide.