A practice manager finds a great new laser treatment. She pulls a list of past patients who might be a good fit. She sends a warm, well-written email announcing the service.
It feels like smart marketing. It might also be a HIPAA violation.
This mix-up happens more than most practices realize.
Understanding HIPAA and marketing rules isn’t just a legal box to check. It protects your patients and your practice’s reputation.
Let’s break down exactly when patient authorization is required, and how to build campaigns that stay compliant from day one.
HIPAA and Marketing Takeaways
- HIPAA requires patient authorization for nearly all marketing communications that use protected health information.
- The only two exceptions are face-to-face conversations and promotional gifts of nominal value.
- If a third party pays for a marketing message, your authorization form must disclose that payment.
- Separate general practice promotion from patient-specific marketing that uses PHI.
- Every marketing vendor touching Protected Health Information or PHI needs a signed Business Associate Agreement.
- Website tracking pixels can collect PHI without you realizing it. Audit them regularly.
- Before-and-after photos and testimonials always need documented, written consent.
- HIPAA compliant marketing builds the trust that also supports stronger plastic surgery SEO.
What Counts as “Marketing” Under HIPAA?
HIPAA and marketing rules start with a definition.
Marketing is any communication that encourages someone to buy or use a product or service.
Here’s where it gets tricky. Not every patient-facing message counts as marketing.
- A reminder about an upcoming appointment isn’t marketing.
- A message describing your practice’s other services, sent using that patient’s health information, usually is.
The line matters because it determines whether you need signed authorization first. Right or wrong guessing here is exactly how practices get into trouble.
When Is Patient Authorization Required for Marketing?
The federal government has answered this question directly.
According to HHS.gov, the HIPAA Privacy Rule requires authorization for all marketing communications that use protected health information, with only two exceptions.
Exception 1: Face-to-Face Communication
If you’re talking with a patient in person, you can mention other treatments or services without written authorization.
That in-office conversation about a new filler line? Fair game.
Exception 2: Promotional Gifts of Nominal Value
A small branded item, like a tote bag or a pen at checkout, doesn’t require authorization either.
The key word is nominal. This isn’t a loophole for expensive giveaways.
The Remuneration Rule
If a third party pays you to send a marketing message, the law adds one more requirement.
Your authorization form must disclose that payment. Patients deserve to know when a message is sponsored.
Outside these narrow exceptions, HIPAA and marketing rules require documented, written authorization before you use PHI to promote your services.
HIPAA Compliant Marketing Rules: A Practical Checklist
Knowing the HIPAA and marketing rule is one thing. Building it into daily operations is another.
Here’s how to keep your plastic surgery marketing compliant, step by step.
- Get written authorization first.
Before using any patient health information in a campaign, get a signed authorization. Keep it on file. - Separate general promotion from patient-specific marketing.
A blog post about a new procedure doesn’t need authorization. An email to patients who had that procedure does. - Sign a Business Associate Agreement (BAA) with every marketing vendor.
If your agency, CRM, or email platform touches PHI, a BAA is non-negotiable. - Audit your website’s tracking tags.
Pixels on procedure pages can quietly collect PHI. Review what data your ad platforms actually receive. - Train your front desk and marketing team.
Most violations aren’t malicious. They come from staff who don’t realize a message crosses the line. - Document consent for photos and testimonials.
Before-and-after images and patient stories need explicit, written permission before they go public. - Review remarketing campaigns closely.
Retargeting ads based on which procedure pages someone visited can expose sensitive health interest data.
Common HIPAA and Healthcare Marketing Mistakes
Even well-meaning practices slip up on HIPAA and marketing rules. Watch for these patterns.
Using a patient list to promote a new service without authorization is one of the most common mistakes.
So is assuming online reviews or social media comments are private enough to respond to with specifics.
Posting a patient’s transformation photo because they “seemed happy” about it, without paperwork, is another frequent misstep.
So is trusting a vendor’s word that they’re “HIPAA compliant” without a signed BAA to back it up.
None of these mistakes require bad intent.
They require a gap in process. Closing that gap on HIPAA and marketing compliance is what separates practices that market confidently from those bracing for a complaint.
Why HIPAA Compliant Marketing Strengthens Your Plastic Surgery SEO
Compliance and growth aren’t in conflict. They’re connected.
Search engines and patients both reward trust signals. A practice with clear privacy practices, documented consent, and transparent marketing builds the kind of credibility that supports long-term plastic surgery SEO, not just short-term ad clicks.
Privacy-first marketing is also where the industry is heading regardless.
Third-party tracking is under more scrutiny every year. Practices that build consent-based systems now won’t scramble later.
If you’re not sure whether your current campaigns meet HIPAA and marketing standards, it’s worth a second look.
Reach out to our team and we can walk through your setup together, no pressure, just a clear answer on where you stand.
The Bottom Line
HIPAA and marketing rules aren’t designed to slow your practice down. They’re designed to protect the trust patients place in you.
Getting HIPAA and marketing right from the start saves you from costly cleanup later.
- Get written authorization before using PHI in a campaign.
- Know your two narrow exceptions.
- Vet every vendor.
- Train your team.
Do that, and your next campaign won’t be one send away from a violation. It’ll be one more reason patients trust your practice.
HIPAA and FAQs
Only with written authorization, unless the message doesn’t rely on their protected health information at all. A general newsletter to your full list is different from targeting patients based on a specific procedure they had.
Yes, if the photos are tied to identifiable patient health information. You need documented, written authorization before posting any patient photo, even if the patient seems enthusiastic about sharing it.