HIPAA questions are often answered with a word instead of an analysis: “consent,” “de-identified,” “BAA,” or “never.” That is how healthcare marketing teams end up both over-restricting ordinary work and underestimating risky data flows.
The better approach is to follow the data and the purpose. Who is the regulated entity? What information is involved? Is it protected health information in this context? Why is it being used or disclosed? Who receives it? Is there remuneration? What provision, exception, or authorization supports the activity?
This article reflects federal HIPAA sources reviewed on September 6, 2026. It is general information, not legal advice. State privacy, consumer-health-data, telehealth, professional, and advertising rules may add obligations. Qualified healthcare privacy counsel should review the actual workflow before publication or launch.
HIPAA does not apply to every practice or every health-related fact
The HIPAA Rules apply to covered entities and business associates. A healthcare provider is generally a covered entity when it conducts specified standard transactions electronically; health plans and healthcare clearinghouses are also covered entities. Business associates perform certain functions or services for covered entities involving PHI.
PHI is individually identifiable health information held or transmitted by a covered entity or business associate in the regulated context. A name, email address, IP address, or photograph is not automatically PHI everywhere on the internet. Connected to care, payment, or health information in a regulated entity’s records or disclosures, it may be.
That distinction matters. A public newsletter signup may present one analysis. Exporting a list of patients who received a named procedure for an advertising audience presents another. The fact that both files contain email addresses does not make them equivalent.
“Marketing” has a specific HIPAA definition
HHS describes marketing generally as a communication about a product or service that encourages recipients to purchase or use it. The Privacy Rule then provides important exceptions, including certain communications about a covered entity’s own health-related products or services and certain treatment or case-management activities.
Some marketing communications still require an individual’s authorization, and arrangements involving disclosure of PHI to another entity in exchange for remuneration for that entity’s marketing receive stricter treatment. Face-to-face marketing communications by a covered entity and promotional gifts of nominal value are addressed separately in the rule.
Do not reduce this to “practice newsletters are allowed” or “promotional emails require authorization.” The same copy can receive a different analysis depending on how the audience was created, what PHI is used, whether another party is promoted, and whether payment is involved.
A worked example: a new orthopedic service
A hospital wants to tell existing patients that its own orthopedic group now offers a new service. HHS uses a similar example to illustrate that a communication about a covered entity’s own health-related service may fall outside HIPAA’s marketing definition.
Now change the facts. The hospital selects only people whose records indicate a particular diagnosis, includes details that reveal that condition, pays an outside platform to match the list for advertising, or promotes a third party’s product under a paid arrangement. Each change introduces a new question. The first example is not a blanket permission for the later data flow.
The review must cover both the communication and the audience-building process.
Authorization is not a generic media release
When HIPAA authorization is required, 45 CFR § 164.508 specifies core elements and required statements. These include a meaningful description of the information, who may disclose it, who may receive it, the purpose, an expiration date or event, signature and date, revocation information, and notice about the potential for redisclosure. Additional rules apply in certain circumstances, including remuneration related to marketing.
A treatment consent, website terms checkbox, general “media release,” or permission given in conversation is not automatically a valid HIPAA authorization. Nor should a marketer copy a form from another practice. Counsel must tailor the document and process to the actual use and applicable state law.
Revocation is generally prospective and does not undo action already taken in reliance on a valid authorization. Decabrand nevertheless recommends removing revoked content from controlled digital properties promptly where feasible and documenting what cannot be recalled. That is an operating recommendation, not a universal HIPAA deadline.
De-identification is a method, not a visual judgment
The Privacy Rule recognizes two paths for de-identification: the Safe Harbor method and Expert Determination. Safe Harbor requires removal of specified identifiers and no actual knowledge that remaining information could identify the individual. Expert Determination requires a person with appropriate statistical and scientific knowledge to determine and document that re-identification risk is very small.
Blurring a face does not necessarily de-identify a patient story. A rare condition, location, date, distinctive mark, narrative detail, or combination of facts may still identify someone. “Anonymous case study” is a label, not a method.
For public marketing, a properly reviewed authorization may be more appropriate than asking a content team to make a de-identification judgment it is not qualified to make.
A BAA defines a relationship; it does not legalize the purpose
A vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity may be a business associate and may require a Business Associate Agreement. The agreement must address permitted uses, safeguards, incident reporting, subcontractors, and return or destruction, among other terms.
But a BAA is not a privacy shield. If a disclosure is impermissible, signing a BAA does not fix it. A vendor also does not become an appropriate business associate merely because it offers to sign a standard form; the role and permitted purpose have to fit the rule.
Map every marketing vendor and data flow. Review CRM fields, call recordings, form submissions, scheduling integrations, email and SMS platforms, analytics, pixels, audience uploads, agencies, and subcontractors. Paid acquisition deserves particular attention because the data questions sit behind the more visible problem of wasted Google Ads spend. HHS’s online-tracking bulletin remains important and legally nuanced: it notes that a federal court vacated part of the agency’s prior interpretation concerning certain unauthenticated public webpages.
Do not publish a static penalty chart
HIPAA civil monetary penalty amounts are adjusted and enforcement outcomes depend on the facts, legal authority, culpability, corrective action, and other factors. A fixed table copied into an evergreen marketing article becomes inaccurate.
The practical point does not require a dramatic ceiling: OCR can investigate complaints, impose corrective action, enter resolution agreements, and pursue civil money penalties where authorized. Criminal provisions may apply in specific circumstances. Check current HHS and Federal Register materials with counsel rather than relying on a blog’s dollar figure.
Build one documented release decision
For each marketing program involving patient or health-related data, preserve:
- the audience and purpose;
- the source fields and every recipient;
- the HIPAA provision, exception, or authorization relied upon;
- vendor roles, agreements, safeguards, and retention;
- the final content and approval record; and
- the re-review date or change trigger.
If the team cannot describe the flow on one page, it is not ready to launch. “The vendor is HIPAA compliant” and “the patient consented” are not substitutes for that record.
Privacy earns restraint
Patient information is not valuable because it makes targeting more precise. It is sensitive because it exists within a relationship of trust. The same restraint applies when a patient speaks first: an online review is not permission to confirm care publicly.
Good HIPAA marketing analysis preserves that trust without pretending every communication is forbidden. Follow the entity, data, purpose, recipient, and permission. The answer becomes narrower, more defensible, and usually more respectful.
Primary sources
Questions this article answers
Is every name or email address PHI?
No. An identifier is not automatically PHI in every context. HIPAA protects individually identifiable health information held or transmitted by a covered entity or business associate in the regulated context.
Does HIPAA require authorization for every message promoting a practice service?
No. The Privacy Rule's marketing definition includes exceptions, including certain communications about a covered entity's own health-related products or services. The data, purpose, recipient, and any remuneration still require specific review.
Does a BAA make a marketing activity permissible?
No. A BAA governs certain work performed by a business associate on behalf of a covered entity. It does not create permission for an otherwise impermissible use or disclosure of PHI.
Part of the Healthcare Marketing Trust & Compliance collection
Practical guidance for persuasive marketing that respects privacy, evidence, consent, platform rules, and patient trust.
Explore the topic hub