An agency account manager emails your practice manager on a Tuesday: "Send us the patient list as a CSV — first name, last name, email, and last visit date. We'll build a lookalike audience for the new aesthetics line." Your practice manager, who is not a privacy officer, forwards it. That single attachment is the reason HIPAA for marketing agencies has become one of the most common vendor-risk gaps in outpatient practices.

This article is for the person who signs the agency contract and answers for it later. It covers when a marketing vendor becomes a business associate, when the message itself needs patient authorization, what to put in the agreement, and what your file needs to contain if OCR asks. No clinical advice, no theory — just the workflow.

The Two Rules That Collide When You Hire an Agency

Most practices treat this as one question. It's two, and they have different answers, different paperwork, and different failure modes.

Rule one: the agency is probably a business associate

Under 45 CFR 160.103, a business associate is any person or entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity for a covered function. Not "stores." Not "has a database." Transmits counts. Maintains counts.

An agency that gets read access to your patient portal analytics, drafts a recall email using your appointment list, manages your CRM, responds to online reviews from patients, or installs a script on your website that fires when someone books an appointment is handling PHI. HHS's guidance on who qualifies as a business associate is broader than most agency principals believe.

What does not make them a business associate: designing a brochure with no patient data, buying billboard space, running a general awareness campaign with no PHI input, or writing service-line copy from your clinical staff's dictation with no patient identifiers.

Rule two: the message itself may be "marketing" under the Privacy Rule

Even with a signed BAA, you cannot use PHI for marketing without patient authorization in most cases. The Privacy Rule defines marketing at 45 CFR 164.501 and requires authorization at 164.508(a)(3) for communications about a product or service that encourage the recipient to purchase or use it.

There are carve-outs. Treatment communications, care coordination, refill reminders where any payment is limited to the reasonable cost of making the communication, face-to-face communications, and promotional gifts of nominal value are excluded. But if a third party — a device maker, a supplement brand, a weight-loss program — pays your practice to send a communication, that is subsidized marketing, the authorization must disclose the remuneration, and no BAA cures it.

A BAA solves the vendor question. It does not solve the message question. Practices routinely get this backwards.

Does a Marketing Agency Need a HIPAA Business Associate Agreement?

Yes, if the agency will create, receive, maintain, or transmit protected health information on your behalf. That includes agencies that manage your patient email list, operate your CRM or intake forms, run appointment-request landing pages, respond to patient reviews, or deploy tracking code on authenticated pages such as a portal login. Execute the BAA before any PHI moves — including before you grant a test login. Agencies that only handle de-identified content, general branding, or public awareness campaigns with no patient data do not need one, but you should document that determination in writing rather than assume it.

The Pixel Problem on Your Website

This is where agencies and practices argue most, so be precise.

OCR published a bulletin on online tracking technologies in December 2022 and revised it in March 2024. In June 2024, a federal district court in the Northern District of Texas vacated the portion of that bulletin addressing unauthenticated public webpages — the theory that an IP address plus a visit to a page about a health condition was automatically PHI. HHS updated its tracking technologies guidance page to note the ruling.

Here is what did not change. Tracking code on authenticated pages — patient portal, logged-in scheduling, bill pay behind credentials — still involves PHI, full stop. Tracking that captures form submissions containing name, email, phone, or reason for visit still involves PHI. And the vacatur addressed OCR's interpretation, not your state's privacy statute, not the FTC Act, and not your patients' expectations.

Practical position: treat any pixel or tag that can associate an individual with your practice as a PHI flow until your agency proves otherwise. Ask for a tag inventory — every script, every vendor, every page it fires on, and what fields it collects. If the agency cannot produce that inventory in a week, that tells you something about their controls.

Separately, if a vendor runs a standalone health app, symptom quiz, or wellness portal that sits outside your covered functions, the FTC's Health Breach Notification Rule may reach it, and the FTC has been active on health-data sharing with ad platforms. Two regulators, one bad pixel.

Reviews, Testimonials, and Before-and-After Photos

Your agency wants social proof. Social proof is made of PHI.

OCR has settled multiple cases with practices — dental offices in particular — that disclosed patient details while responding to negative online reviews. The pattern is always the same: a reviewer complains, someone at the practice or the agency corrects the record publicly, and the response confirms the person was a patient and discloses treatment details. Confirming someone is your patient is itself a disclosure.

Set one rule and put it in the BAA and the scope of work: the agency never responds to a review with anything beyond a generic, non-confirming template. Something like an invitation to call the office. No dates, no treatment references, no "our records show."

For testimonials and clinical photography, you need a HIPAA authorization under 164.508 that names the specific uses, the channels, an expiration, and the right to revoke. A model release drafted by the agency's general counsel is not a HIPAA authorization. Keep signed authorizations in the patient record, not in the agency's Dropbox, and give the agency only the approved asset.

HIPAA for Marketing Agencies: BAA Clauses Worth Negotiating

The required elements of a business associate contract live at 45 CFR 164.504(e), and HHS publishes sample provisions. Those are the floor. For an agency specifically, add these:

  • No ad-platform transmission without written approval. Name the platforms. Prohibit uploading PHI-derived audiences, hashed or not.
  • Breach notice in 5 calendar days, not 60. The regulation at 164.410 gives a business associate up to 60 days from discovery. You have 60 days total to notify patients. Compress the vendor's window contractually.
  • Tag and script change control. No new tracking code on your properties without written sign-off from your privacy officer.
  • Named subcontractor list with a duty to update. See the next section.
  • Right to audit or receive an annual attestation covering workforce training, access controls, and encryption.
  • Data return or destruction within 30 days of termination, with written certification.
  • Prohibition on any use of PHI for the agency's own analytics, case studies, or model training.

If you are papering three or four agency and freelancer relationships this quarter and your last template came from a 2016 email thread, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription — which matters when you need one agreement today, not a platform.

The Subcontractor Chain Nobody Maps

Your agency does not do its own email delivery. It does not host its own CRM. It probably uses a freelance developer, a call-tracking service, and a scheduling widget.

Under 164.308(b)(2) and 164.502(e)(1)(ii), the agency must obtain BAAs with any subcontractor that handles PHI on its behalf. Your job is to verify that chain exists, not to assume it. Ask for the list. Then check the hard cases.

Major ad networks and consumer analytics products generally do not sign BAAs for their advertising and analytics offerings. Some large cloud providers will sign a BAA covering a specific, enumerated list of services — and their advertising products are not on that list. If your agency claims a platform "is HIPAA compliant," ask for the executed BAA and the service coverage schedule. There is no government certification for compliance, and no product is compliant on its own; the configuration and the contract are what matter.

A Ten-Business-Day Onboarding Workflow

  1. Day 1 — Scope memo. Privacy officer writes one page: what data the agency will touch, which systems, which people. If the answer is "none," document that and stop.
  2. Day 2 — BAA sent. Your template, not theirs. Redlines go to counsel, not to the practice manager.
  3. Day 3 — Subcontractor and tag inventory requested. Give a firm deadline.
  4. Day 5 — Access design. Minimum necessary under 164.502(b). Named individual accounts, no shared logins, no exports of full patient tables. Read-only where possible.
  5. Day 7 — Training attestation. Every agency staffer touching your systems attests to HIPAA training. Date and name, in your file.
  6. Day 8 — BAA executed and countersigned. Both signatures, dated, stored with your vendor register.
  7. Day 9 — Access provisioned. Not before day 8. Log the provisioning date and the approver.
  8. Day 10 — Campaign review gate defined. Every campaign that touches patient data gets privacy officer sign-off before launch, on a standing form.

What Your Evidence File Should Contain

Assume an investigator asks for your agency relationship in twelve months. Produce, in one folder:

  • Executed BAA with both signature dates
  • The scope memo and any business associate determination for vendors you decided were not BAs
  • Current subcontractor list and the date it was last refreshed
  • Website tag inventory with the date of the last review
  • Access provisioning log and quarterly access review sign-offs
  • Training attestations for agency personnel
  • Campaign approval forms for any patient-data campaign
  • Signed patient authorizations for every testimonial or photo in circulation
  • Your risk analysis entry reflecting this vendor's data flow

If your risk analysis does not name the agency and describe the flow, the rest of the folder looks like paperwork instead of a program. Practices that need to rebuild that documentation set from scratch can automate the risk analysis and policy set rather than assembling it in a spreadsheet over six months.

Offboarding: The Clause People Forget

Agency relationships end, often abruptly. The day you terminate, someone still has your CRM login, a spreadsheet of patient emails on a laptop, and admin rights to your website.

Run a written offboarding checklist within five business days: revoke every named account, rotate shared credentials and API keys, remove the agency's tags from your site, request written certification of PHI destruction, and confirm any exports were deleted from personal devices and cloud storage. File the certification. An unreturned patient list at a former vendor is a breach waiting for a laptop theft.

Your Next Three Moves

First, pull your vendor register and mark every marketing, web, SEO, and creative relationship. Second, for each one, answer in writing whether they touch PHI — and if yes, whether a signed BAA exists with a date on it. Third, close the gaps this quarter, starting with the agency that has a login to your patient-facing systems.

Getting HIPAA for marketing agencies right is mostly a paperwork and access-control discipline, not a technical one. If the missing piece is the agreement itself, build a signature-ready BAA in six steps, export it, and get it countersigned before the next campaign brief lands.