HIPAA Marketing Rules: What Needs Patient Authorization
Your marketing agency emails on a Tuesday afternoon asking for "the patient list — just names and emails, nothing clinical." They want to run a re-engagement campaign for the new aesthetics service line. The request sounds harmless. Under the hipaa marketing rules at 45 CFR 164.501 and 164.508, that export is a disclosure of protected health information for marketing, and unless you have signed authorizations from every person on that list, you cannot hand it over.
This article is for the person who has to answer that email. It covers what counts as marketing under the Privacy Rule, which communications are carved out, what a compliant authorization contains, how vendor contracts fit in, and what documented evidence a regulator or an auditor would expect to see in your file.
The Two-Part Test That Decides Whether You Need an Authorization
The Privacy Rule defines marketing as a communication about a product or service that encourages the recipient to purchase or use it. Start there, then apply two questions to every campaign.
Question one: does the communication encourage the purchase or use of a product or service? A postcard announcing your new sleep study program does. A recall notice telling a patient their annual eye exam is due does not — it is a treatment communication.
Question two: is a third party paying you to send it? This is the question practices miss. If a device manufacturer, pharmaceutical company, supplement supplier, or lab pays your practice — in cash or in kind — to send a communication describing that company's product, the communication becomes marketing even when it is otherwise clinically appropriate. Financial remuneration from a third party whose product is being described flips an exempt treatment message into one that requires prior written authorization.
HHS maintains the governing summary on its marketing guidance page. Print it and keep it with your Notice of Privacy Practices file.
Do You Need Patient Authorization to Send Marketing Emails?
Yes, if the email meets the definition of marketing. You need a signed HIPAA authorization before you use or disclose PHI to send a communication that encourages a patient to buy or use a product or service, unless one of these applies:
- Treatment communications — messages about the patient's own treatment, case management, care coordination, or alternative therapies, sent with no third-party payment.
- Refill reminders — communications about a drug the patient is currently prescribed, where any payment received is reasonably related to the practice's cost of making the communication.
- Face-to-face communications — anything you hand to or say directly to the patient in the exam room.
- Promotional gifts of nominal value — the branded pen, the toothbrush, the tote bag.
- Health plan communications about the plan's own products, benefits, or network.
- General advertising that does not use PHI at all — a billboard, a paid search ad, an untargeted social post.
The last bullet is the practical release valve. Advertising your practice broadly is not restricted by HIPAA at all, because no PHI is used to select the audience. The moment you filter by diagnosis, procedure, visit date, medication, or payer, you are using PHI and the hipaa marketing rules apply.
The Refill Reminder Cost Limit, Concretely
The refill reminder exception is narrow and it has a money ceiling. Payment from a third party is permitted only up to the reasonable cost of labor, supplies, and postage for making the communication. Profit margin voids the exception. If a pharmaceutical partner offers your practice a flat per-message fee that exceeds your actual send cost, document the decline and route the program through authorizations instead.
Testimonials, Google Reviews, and Before-and-After Photos
Three of the most common real-world violations in outpatient practices have nothing to do with email lists.
Responding to a Negative Online Review
A patient posts a one-star review claiming they waited ninety minutes and were overcharged. Your office manager replies with the appointment date and a correction about what was billed. That reply is a disclosure of PHI to the entire internet without authorization. OCR has settled multiple cases with small dental and behavioral health practices over exactly this conduct, including a 2019 settlement with a Dallas dental practice for disclosing patient information in responses to reviews. The penalties were modest in dollar terms and expensive in corrective action plans and reputational cost.
Write the rule into your social media policy in one sentence: staff may never confirm, deny, or describe a person's status as a patient in any public forum. An acceptable reply is a generic invitation to contact the office directly. Nothing more.
Patient Stories and Images
A testimonial on your website, a before-and-after photo, a patient quote in a brochure, a video interview — each requires a signed HIPAA authorization under 164.508, not a generic photo release from your marketing agency's template folder. The authorization must name the specific uses. "Website and social media" is acceptable if written; "promotional purposes" alone is too vague to defend.
Set an expiration. A five-year term with a documented re-consent workflow is easier to manage than "none," and it forces you to review whether that photo is still on the site.
Revocation Has to Actually Work
Every authorization carries a right to revoke in writing. If a patient revokes, you must stop the prospective use. That means someone owns the task of pulling the image off the website, the Instagram grid, the printed brochure in the waiting room, and the agency's asset library. Assign that owner by name in your policy, and log the date each asset came down.
Your Marketing Vendors Are Business Associates
Run your marketing stack against the business associate definition. The agency that segments your patient list, the email platform that stores those addresses, the CRM, the appointment-reminder texting service, the call-tracking provider, the review-solicitation tool, the analytics vendor with access to identifiable visit data — each creates, receives, maintains, or transmits PHI on your behalf. Each needs a signed business associate agreement before a single record moves.
The gap I see most often in privacy audits: the practice has a BAA with the EHR and the billing clearinghouse, and nothing with the three marketing vendors added in the last eighteen months. If that is your situation, you can produce a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX the same afternoon — one-time purchase, no subscription — rather than waiting on outside counsel to redline a template.
The BAA does not authorize marketing. It permits the vendor to handle PHI for the permitted purposes you specify. Authorization from patients is still required for anything that meets the marketing definition. Two separate controls, both mandatory.
Website Tracking Pixels: Where This Gets Uncomfortable
Advertising pixels, session-replay scripts, and analytics tags installed on your website or patient portal can transmit IP addresses, device identifiers, and page URLs to ad platforms. When that data relates to an individual's health condition or care, OCR's position has been that the transmission is a disclosure of PHI requiring either authorization or a business associate relationship — and ad platforms typically will not sign BAAs.
HHS published a bulletin on online tracking technologies in December 2022 and revised it in March 2024. In June 2024 a federal district court in Texas vacated the portion of that guidance addressing unauthenticated public web pages, so the legal picture on your public marketing site is unsettled. What is not unsettled: tracking behind a patient portal login, on a scheduling page tied to a specific condition, or on any page where the visitor identifies themselves and their health interest in the same session.
The FTC has enforced separately against health companies over ad-tech data sharing using Section 5 and the Health Breach Notification Rule. Its health privacy business guidance is worth reading alongside the HIPAA material, because the FTC reaches marketing conduct that HIPAA does not.
A Ninety-Minute Pixel Audit
- Open your site in a browser with developer tools and list every third-party script firing on the home page, the appointment page, and the portal login.
- Match each script to a vendor and to a signed BAA. No BAA and no authorization means remove or restrict it.
- Confirm no PHI appears in URL query strings — condition names in a URL get transmitted with every referrer header.
- Screenshot the before and after state, date it, and file it as evidence of remediation.
Fundraising Runs on a Different Rule
If your organization solicits donations, 164.514(f) governs — not the marketing provision. You may use demographic information, dates of service, department of service, treating physician, outcome information, and health insurance status for fundraising without authorization, provided your Notice of Privacy Practices says so and every solicitation includes a clear opt-out that is not burdensome. Once someone opts out, you may not solicit them again. Diagnosis and treatment detail beyond those listed categories requires authorization.
What a Compliant Marketing Authorization Contains
Your form fails if it is missing a core element. Include all of these:
- A specific description of the information to be used or disclosed
- The name of your practice as the discloser and the name of the recipient
- A specific description of the purpose — "to feature the patient's photograph and first name in practice advertising"
- An expiration date or expiration event
- A statement of the right to revoke in writing, and how to do it
- A statement that treatment, payment, enrollment, and eligibility are not conditioned on signing
- A statement that information disclosed may be redisclosed and no longer protected
- If a third party is paying you, an explicit statement that the practice receives remuneration
- The individual's signature and date, plus authority description if signed by a personal representative
Retain signed authorizations for six years from the later of creation or last effective date. Your Notice of Privacy Practices must also state that marketing uses require authorization — check yours; many templates predate the 2013 Omnibus Rule language.
Assign It, Date It, Prove It
Compliance with the hipaa marketing rules lives or dies on ownership. Put four items on your privacy officer's calendar for Q1:
- Campaign inventory — every active email, text, mail, and paid ad program, with a written determination of marketing vs. exempt and the reasoning. One page.
- Vendor reconciliation — every marketing and communication vendor matched to an executed BAA with a date.
- Authorization audit — every published testimonial, photo, and video matched to a signed, unexpired authorization. Unmatched assets come down.
- Staff training — a fifteen-minute session on public review responses, with a sign-in sheet.
Those four artifacts are what "we have a program" looks like when someone asks for evidence. If you also need the surrounding documentation set, automated risk analysis reports and policy generation will fill the gaps around the marketing policy itself.
Start with the vendor list, because it is the fastest fix with the clearest artifact. Pull the names of every marketing, messaging, and analytics vendor touching patient data, and generate the business associate agreements you are missing before you approve the next campaign.