HIPAA & patient privacy
Most marketing work should never touch patient data at all.
Where it has to, there is a Business Associate Agreement and a documented process. Where it does not, we design it out rather than securing something that did not need to exist.
Our commitments
What we do, and what we decline.
We sign a Business Associate Agreement where one is required
If an engagement puts us in a position to create, receive, maintain or transmit protected health information on your behalf, we execute a BAA before that work begins, not after. If you are not sure whether a piece of work crosses that line, ask us and we will tell you our reading rather than proceeding quietly.
We prefer not to touch PHI at all
Most marketing work does not require it. Where we can accomplish the same outcome without access to patient records, scheduling systems or identified data, that is the design we propose. Reducing the surface is better than securing a surface that did not need to exist.
Patient imagery requires documented, channel-specific consent
Before-and-after photography and video are published only with written consent that names the channels the image will appear in. A verbal yes at the chair is not sufficient and we will not publish on one. We maintain the documentation rather than assuming your practice has it filed somewhere.
Consent is revocable and we act on revocation
If a patient withdraws consent, the asset comes down across the channels we control, and we tell you which channels we do not control so you can act on those.
Reviews and testimonials are never solicited with PHI
Review requests go out on your systems, under your control, without us handling patient identity or condition information. We design the process; your practice runs it.
We do not use patient data for targeting
No uploading of patient lists to advertising platforms, no custom audiences built from practice records, no lookalike audiences derived from them. This is a common practice in the wider marketing industry and we decline it in healthcare.
Tracking technology
Not every page on your site is the same risk.
The most common mistake we see is a single analytics configuration applied uniformly across a healthcare site. These four contexts are genuinely different and we treat them differently.
Public, unauthenticated pages
Standard analytics on general-information pages is ordinary practice. The regulatory position on this narrowed after a federal court vacated part of OCR's 2022 tracking-technology guidance in June 2024, but that ruling addressed unauthenticated public pages specifically and does not make every deployment safe.
Patient portals and authenticated areas
Tracking behind a login, or any tool that captures information tied to an identifiable individual and their care, remains live exposure. We do not install third-party tracking there, and we will say so if asked to.
Condition-specific pages
Pages about a specific diagnosis or treatment can associate a visitor's identifiers with a health condition. We treat these conservatively and configure them differently from general pages rather than applying one site-wide default.
Forms and call tracking
Anything that collects a name plus a clinical intent is a design decision, not a plugin choice. We scope where that data goes, who processes it and under what agreement, before it is switched on.
Texting and email
HIPAA authorization is not TCPA consent.
These are separate regimes and both apply. Conflating them is the most common compliance error in healthcare marketing automation, and it is the reason we are careful about what we promise on any messaging surface.
- HIPAA authorization is not TCPA consent. They are separate regimes and both apply. An authorization to use health information for marketing does not permit a marketing text.
- Appointment reminders and recall generally sit in the easier transactional category. Marketing messages require prior express written consent that names the organization and discloses the marketing purpose.
- That consent cannot be bundled into an intake form as a condition of treatment.
- Opt-outs are honored immediately, and we build the process to make that the default rather than a manual step.
FAQ
Common questions.
Do we need a BAA with our marketing agency?
It depends on whether the agency handles protected health information. Many marketing engagements genuinely do not. Building a website and running local search work usually involves no patient data at all. Where the work does touch PHI, a BAA is required and we sign one. We would rather scope the work so it is unnecessary, and tell you plainly when it is not.
Can we use patient before-and-after photos in marketing?
Yes, with documented written consent that names the specific channels the images will appear in. Consent for a website gallery is not consent for a paid social campaign. We keep that documentation and we will not publish an image without it, including when a patient has agreed verbally.
Are tracking pixels on our website a HIPAA problem?
It depends where they sit. A federal court vacated part of OCR's 2022 guidance in June 2024 as it applied to unauthenticated public pages, which narrowed the exposure considerably. Tracking inside a patient portal, or any tool capturing information tied to an identifiable person and their care, remains a live risk. We configure these differently rather than applying one setting site-wide.
Can you text our patients marketing offers?
Only with prior express written consent that names your organization, discloses the marketing purpose, and is not bundled into an intake form. A HIPAA authorization does not satisfy this, because TCPA is a separate regime. Appointment reminders and recall are a different and easier category.
Is this legal advice?
No. This page describes how we work and what we will and will not do. It is not a legal opinion and it is not a substitute for your own counsel, who knows your state, your specialty and your systems. Where our reading of a rule is conservative, we will tell you that it is conservative rather than presenting it as settled.
This page describes how we work. It is not legal advice and does not replace your own counsel. See also our privacy policy and terms. Questions about a specific situation: hello@decabrand.com.
Have a specific compliance question?
Ask before you build the thing. It is considerably cheaper than asking afterwards.