What needs a patient's authorization

HHS defines marketing as a communication about a product or service that encourages people to buy or use it, and the Privacy Rule's limits attach to the patient information a campaign uses. So compliance in healthcare marketing is decided campaign by campaign: the same campaign can need nothing from HIPAA or every patient's signature, depending on what it draws on.

What the practice doesWhat HIPAA requires
Service pages, ads and search results built from the practice's own facts Nothing from its marketing rules: no patient information is used.
An email or mailing to its patients about its own services: a new treatment, a new location, a discount only patients get No authorization: the Privacy Rule does not count it as marketing, unless a company whose product it describes pays the practice to send it. The email platform or mail house that sends it receives the patient list, so it needs a business associate agreement.
A message about another company's product, or a patient list given or sold to another company for its marketing Each patient's written authorization, which has to say so when the practice is paid.
A tracking tag or ad audience fed from an appointment form, a symptom checker, or the patient portal and its login page A business associate agreement and a Privacy Rule permission for that vendor, or each patient's authorization. A cookie banner is neither.
A patient's story, photo or before-and-after image The patient's written permission for that specific use; treatment consent or a positive review does not cover it.
A reply to a patient's online review No confirmation that the reviewer is a patient and nothing about their care: HHS has settled cases over replies that disclosed patient information.

Two things need no authorization even when they are marketing: a face-to-face conversation with the patient, and a promotional gift of nominal value.

When HIPAA applies to a marketing vendor

The HIPAA Rules apply to covered entities and business associates. A vendor becomes a business associate when it performs covered work involving protected health information for a covered entity. A business associate agreement safeguards that relationship; each use of the data still needs its own basis under the Privacy Rule.

A marketing company that never receives protected health information is not a business associate, so calling it “HIPAA compliant” describes nothing about it. One that receives PHI needs the agreement, the least data the work requires, and the controls around that data.

The Google reviews workflow separates neutral requests, public replies, and private escalation. Selected HIPAA violation cases show the controls HHS reported as failing.

Tracking tags, forms and ad platforms

HHS's online tracking guidance sorts pages by what a tag can see. On a patient portal or any page behind a login, a tag generally has access to protected health information. On many public pages it does not, and HIPAA then does not regulate it. The exceptions are pages where a visitor gives health or identifying information without logging in: an appointment form or a symptom checker, where a tag can capture an email address or the reason for the visit, and the portal's login and registration pages, which may be the homepage, where it can capture the name and email the patient enters. A June 20, 2024 federal court order vacated the part of the guidance that treated an IP address plus a visit to a public page about a condition or a provider as enough to trigger HIPAA.

Where a tag does reach PHI, a line in the privacy policy does not permit the disclosure, a cookie banner is not an authorization, and a vendor's promise to remove or de-identify the PHI after receiving it does not repair the transfer. The vendor needs a business associate agreement and the disclosure a Privacy Rule permission, or each patient's authorization. When an analytics or ad platform will not sign an agreement, HHS describes another route: a vendor that will, such as a customer data platform, de-identifies the data, stripping identifiers such as email addresses, IP addresses and device IDs, and passes on only de-identified information.

Privacy duties can also arise outside HIPAA. The FTC Health Breach Notification Rule and state laws such as Washington's My Health My Data Act may apply to other organizations and health information. The practice's privacy officer or counsel determines which apply.

Testimonials and before-and-after photos

Before publishing a patient story, record what will be disclosed, where it will appear, how long the permission lasts, and who approved it under the practice's policy and applicable law. Secure permission for that marketing use rather than relying on general treatment consent, a social media post, or a positive review.

HIPAA defines de-identification through specific methods. HHS recognizes the Expert Determination and Safe Harbor methods under the Privacy Rule. If a case description, image, date, or unusual fact can still identify the person, a casual “anonymous case study” label does not settle the question.

Replies to online reviews

A reviewer's disclosure covers the reviewer's speech. The practice needs its own basis to confirm the relationship, correct the medical record in public, or add facts. HHS has resolved enforcement matters involving providers that disclosed PHI while responding to negative online reviews, including New Vision Dental and Manasa Health Center. The safe operational pattern is a neutral public response followed by an approved private escalation path; the public response leaves patient status unconfirmed.

Before a form, tag or vendor goes live

  1. Write down the page, user action, fields, events, and destinations.
  2. Remove health-detail fields from ordinary marketing forms unless the approved workflow truly needs them.
  3. Separate patient communication from acquisition measurement where possible.
  4. Identify every vendor and subprocessor that can receive the data, including email and logs.
  5. Have the practice's privacy officer decide permissions, agreements, notices, and retention for the real configuration.
  6. Test the rendered page and network behavior before launch; recheck after tag, form, or vendor changes.

Once the practice has approved that boundary, its healthcare SEO agency can build the public pages and the measurement inside the approved legal determination.

Does HIPAA allow marketing?

Yes. In healthcare marketing, HIPAA governs patient information, not promotion: a practice can advertise its services, rank in search and publish service pages without any patient's information. What needs a patient's written authorization, with narrow exceptions, is using or disclosing that patient's protected health information for marketing.

What counts as marketing under HIPAA?

HHS defines marketing as a communication about a product or service that encourages its recipients to buy or use it. A practice's messages to its patients about its own services, their treatment or their care are excluded unless a company whose product the message describes pays for it, and giving or selling a patient list to another company for its marketing always needs each patient's authorization.

Are Google Ads HIPAA compliant?

A practice can run Google Ads within HIPAA as long as its tags send the ad platform no protected health information. A conversion tag or an audience fed from an appointment form, a symptom checker, or a patient portal and its login page does send it, and then the ad platform needs a business associate agreement and a Privacy Rule permission, or each patient's authorization; a cookie banner is neither.

Is SEO HIPAA compliant?

SEO works on public pages and search data that hold no patient information, so the work itself needs none. HIPAA reaches it through measurement: an appointment form or an analytics tag that sends protected health information to a vendor, which is checked before the form or the tag goes live.

Does a marketing agency need a business associate agreement?

Only if it receives protected health information for the practice. A vendor becomes a business associate when its work for a covered entity involves PHI, and signing an agreement does not make one of a vendor that never receives any. For an agency that never touches PHI, a HIPAA badge describes nothing.

Can a practice use patient testimonials and photos?

With the patient's written permission for that use, recorded with what is disclosed, where it appears and for how long. General treatment consent, a social media post or a positive review is not that permission, and a photo or a detail that can identify the patient is not anonymous because it is labeled so.

How should a practice reply to a negative review?

Without confirming that the reviewer is a patient or adding anything about their care. HHS has settled with practices that disclosed patient information in review replies, New Vision Dental and Manasa Health Center among them; a neutral public reply and a private channel for the rest keep the practice clear of that.