Compliance · Briefing

What HIPAA compliant marketing actually requires

What HIPAA covers in a marketing stack, what the 2024 court ruling changed, and how to measure campaigns without moving protected health information.

Ilia PushinPublished Sep 23, 2026Updated Sep 23, 20268 min read
A padlock with a white marble body and a glass shackle, on a light grey background.
Short answer

HIPAA compliant marketing means a covered entity or its business associates never sends protected health information to an advertising or analytics vendor without a business associate agreement, and never lets a marketing pixel record enough to link a named or identifiable person to a health condition. HIPAA itself does not mention marketing directly. It restricts protected health information, and the question for a marketing stack is whether tracking technology, form data or a client list counts as protected health information in context. A federal court partly vacated the 2022 and 2024 HHS guidance on tracking technologies in June 2024, so an IP address alone on an unauthenticated public page is no longer treated as protected health information by that guidance. Tracking on authenticated pages, such as a patient portal or a logged-in booking flow, is still covered and still needs a signed agreement with any vendor that receives the data. This is general information about a still-developing area of law, not legal advice for a specific practice.

Key takeaways

  • HIPAA restricts Protected Health Information, not marketing as a category, so the same tool can be compliant on one page and a violation on another.
  • A June 2024 court ruling narrowed HHS guidance for unauthenticated pages; authenticated pages like a patient portal remain fully covered.
  • Most standard ad and analytics vendors will not sign a Business Associate Agreement, so the safer default is keeping PHI out of that data flow entirely.
  • State laws, such as Washington's My Health My Data Act, can apply to health marketing even when HIPAA does not.

What HIPAA actually covers in a marketing stack

HIPAA does not have a marketing chapter. The Privacy Rule and Security Rule, codified at 45 CFR Part 160 and Part 164, protect Protected Health Information, PHI, and govern how a covered entity or a business associate may use, disclose and share it. The compliance question for a marketing stack is never “is this HIPAA compliant marketing” in the abstract. It is narrower: does this specific piece of data, in this specific tool, count as PHI under Part 164, and if so, has the right paperwork been signed before it moves.

Definition

Protected Health Information is individually identifiable health information created or received by a covered entity, held or transmitted in any form, that relates to a person’s health condition, care or payment for care.

3 covered entity types exist under HIPAA: health plans, health care clearinghouses and health care providers who transmit health information electronically in connection with certain transactions. A clinic, hospital or health system that bills insurance is almost always a covered entity. A wellness app, a supplement brand or a direct-to-consumer telehealth company may not be, depending on what it does and who it bills, which is why a lot of health marketing sits outside HIPAA entirely and inside other rules instead, covered later in this briefing.

Data stops being PHI once it is properly de-identified. The Office for Civil Rights recognizes 2 methods, under 45 CFR 164.514(b): Expert Determination, where a qualified statistician certifies the re-identification risk is very small, and Safe Harbor, where all 18 identifiers listed in the regulation, name, dates, phone number, email, IP address, device identifiers and 12 others, are removed. Marketing data run through neither method is not de-identified, whatever a vendor’s dashboard calls it.

Where PHI shows up in analytics and ad pixels

A standard analytics or advertising pixel, Google Ads, Meta Ads, Google Analytics, most session-recording tools, was not built for a healthcare compliance boundary. It captures the page a visitor viewed, an IP address, a device identifier and, if a form is present, whatever the visitor typed.

On an unauthenticated marketing page, a symptom or condition page with no login, that combination is a live legal question, whether the tool involved is the Meta Pixel, Google Tag Manager, the LinkedIn Insight Tag or a session-recording tool like Microsoft Clarity. In December 2022, the Department of Health and Human Services Office for Civil Rights, HHS OCR, issued a bulletin stating that tracking technology data could constitute PHI even on public pages, if it let a vendor connect an individual to health information. On 20 June 2024, in American Hospital Association v. Becerra, a federal court in the Northern District of Texas vacated the part of that guidance treating an IP address plus a visit to an unauthenticated public page about a specific condition as PHI on its own. HHS OCR withdrew its appeal of that ruling to the Fifth Circuit Court of Appeals in September 2024, and no new appeal has revived that part of the guidance since.

Regulation

As of this writing, the vacated portion of HHS OCR’s guidance no longer applies: an IP address alone, tied to a visit to an unauthenticated public page, is not automatically PHI. Tracking on authenticated pages, a patient portal, a billing login or a booking flow behind a login, remains squarely covered, and the underlying question, does this data identify a person and their health information, still applies everywhere HIPAA reaches.

On an authenticated page the analysis does not change. If a patient portal, an appointment scheduler behind login, or an intake form loads a standard advertising pixel, and that pixel can associate a logged-in identity with a health condition, a provider name or an appointment type, that is very likely an impermissible disclosure of PHI to the vendor operating the pixel, regardless of what the June 2024 court ruling did to the public-page portion of the guidance. A companion piece on the operations layer behind healthcare patient acquisition covers the same boundary from the patient-journey side, including how it interacts with Google Ads and Microsoft Advertising policy.

Business associate agreements with vendors

A vendor that creates, receives, maintains or transmits PHI on behalf of a covered entity is a business associate under 45 CFR 160.103, and 45 CFR 164.502(e) requires a signed Business Associate Agreement, a BAA, before that relationship starts. Most mainstream advertising and analytics vendors, standard Google Ads, standard Meta Ads, Google Analytics, most off-the-shelf email platforms, will not sign a BAA, because their business model depends on using data in ways a BAA would restrict. Some larger platforms, including Google Cloud and Microsoft Azure, offer a BAA for specific enterprise products, but that BAA typically does not extend to the advertising side of the same company.

Situation What it means for the vendor relationship
Vendor processes PHI, will sign a BAA Proceed, with the BAA executed before data flows, not after
Vendor processes PHI, will not sign a BAA Do not send PHI to this vendor; redesign the integration so it never receives PHI
Vendor never receives PHI No BAA required under 45 CFR 164.502(e); confirm this with a technical review, not an assumption
Definition

A Business Associate Agreement is a contract required by HIPAA between a covered entity and any vendor that creates, receives, maintains or transmits Protected Health Information on the covered entity’s behalf, and it must specify permitted uses, safeguards and breach notification duties.

The safer default for most marketing stacks is the third row: keep PHI out of the vendor relationship entirely, rather than trying to negotiate a BAA with an advertising platform that was not built to offer one. Microsoft, for example, makes a HIPAA BAA available to Azure customers through its Product Terms and Data Protection Addendum, but that same BAA does not extend to Microsoft Advertising. That single decision, keep PHI off the advertising side entirely, removes most of the practical risk in a marketing analytics setup.

What sits beyond HIPAA

HIPAA is not the only rule in play, and a marketing team that treats it as the whole picture can still end up out of compliance. Washington State’s My Health My Data Act, in force since 31 March 2024, reaches any entity that markets to Washington consumers, HIPAA covered entity or not, and specifically bans using a geofence, defined under RCW 19.373 as a virtual boundary of 2,000 feet or less around a health care location, to identify, track or advertise to people who visit it. The Federal Trade Commission’s Health Breach Notification Rule, updated with an effective date of 29 July 2024, separately covers health apps and similar consumer services outside HIPAA’s reach whenever they share identifiable health data with a vendor, including an advertising platform, without consent, with up to 60 days to notify both affected users and the Federal Trade Commission for a breach touching 500 or more people.

A practical setup that keeps measurement without moving PHI

3 changes cover most of the gap for a typical practice or health system marketing stack.

Change 1: separate the 2 environments. Split the unauthenticated marketing site from any authenticated patient area at the infrastructure level, not just the navigation level, so a pixel added to the marketing site cannot fire inside the portal by accident. This single boundary is the difference the June 2024 court ruling actually turned on.

Change 2: move tracking server-side. Replace client-side pixels with server-side, first-party event tracking wherever an authenticated flow is involved, using a mechanism like Google Ads Enhanced Conversions or the Meta Conversions API configured to send only stripped events, and remove identifiers, name, email, phone, appointment type, before any event reaches an advertising platform. A booking confirmation event can report that a booking happened and which campaign referred the visitor, without reporting who booked or what they booked for.

Change 3: sign the paperwork before launch. Put a Business Associate Agreement in place with every vendor that could plausibly receive PHI, including the Practice Management System, the appointment reminder service and any call tracking tool, before that tool goes live, and review the full list of signed agreements at least once a year against the tools actually running.

Example from practice

A documented boundary between the marketing site and the authenticated patient experience, confirmed by testing what data a pixel actually sends from each side, is the fastest way to know whether a stack has a real problem or a theoretical one.

None of this is a one-time project. New marketing tools get added by whoever runs the next campaign, and a tool added without this review is how a compliant stack quietly stops being one. Pairing the technical boundary with a standing rule, no new tracking tool goes live without a PHI check, keeps the setup accurate as the stack changes. A related operations discipline, the same one used to build a marketing operations audit checklist, applies directly here: map every tool that touches patient data, then decide, tool by tool, whether it needs a BAA or needs to be kept away from PHI entirely. The same mapping exercise sits behind a 2-week test of AI patient intake triage, where the tools handling patient requests get inventoried before any workflow change.

This briefing explains what the Department of Health and Human Services, the Office for Civil Rights and the Federal Trade Commission currently say, and how the relevant rules generally work. It is general information about a still-developing area of law, not legal advice for a specific practice, vendor contract or incident, and a qualified health care attorney should review any BAA or tracking setup before it goes live. Our Marketing-Operational System practice builds this kind of tool inventory and reporting boundary as part of a wider operations audit, working alongside your counsel rather than in place of it.

FAQ

Does HIPAA compliant marketing mean no tracking pixels at all?

No. It means Protected Health Information never reaches a pixel or vendor without a signed Business Associate Agreement. Standard analytics can run on general marketing pages if no identifiable health information is disclosed there.

Is an IP address alone considered PHI under HIPAA?

Not on an unauthenticated public page, after a June 2024 court ruling narrowed HHS guidance on this point. On an authenticated page, such as a patient portal, the same combination is still treated as protected.

Will Google or Meta sign a Business Associate Agreement for standard ad accounts?

Generally no. Standard advertising products from major platforms are not offered under a BAA, which is why PHI should not be sent to them through a pixel or an ad platform integration.

Does this guidance apply outside the United States?

No. HIPAA is a United States federal law. Similar goals are covered elsewhere by rules such as GDPR in the EU, which set different requirements for health data in marketing.

Sources

  1. HHS Office for Civil Rights, Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
  2. HHS Office for Civil Rights, The HIPAA Privacy Rule
  3. HHS Office for Civil Rights, Guidance Regarding Methods for De-identification of Protected Health Information
  4. American Hospital Association, Judge rules in favor of AHA vacating HHS online tracking bulletin
  5. Federal Trade Commission, Updated Health Breach Notification Rule
  6. Washington State Legislature, RCW 19.373 My Health My Data Act
  7. Microsoft Learn, HIPAA and HITECH Act compliance offering for Azure
Written and reviewed by Ilia Pushin · Last reviewed Sep 23, 2026Drafted with AI assistance, edited and fact-checked by the author.This article is for general information. It is not legal, financial or medical advice.
Ilia PushinFounder, Pushers · Co-founder and COO, ARBI ExchangeIlia builds operating systems for growing companies in fintech and healthcare. Since 2021 he has run cross-border payments at ARBI Exchange, a licensed currency exchange in Thailand, including KYC and AML and the move into new jurisdictions.About the authorLinkedIn
Working on this problem in your company?Discuss it with us