RGM-HC-02 · Healthcare Marketing · Module 2 of 6
RGM° · Training

HIPAA & Regulatory Compliance for Marketers

HIPAA, FDA OPDP, the Anti-Kickback Statute, and a growing list of state laws govern every healthcare marketing decision. This module covers what the rules actually say, the enforcement patterns to learn from, and the compliance workflow that survives examination.

What you will learn in this module

  1. What HIPAA actually covers and who is a covered entity / business associate
  2. Protected Health Information (PHI) and the 18 identifiers
  3. The OCR 2022/2024 tracking technology guidance and its marketing implications
  4. Pixel and analytics tools: what is and is not permitted
  5. Business Associate Agreements (BAAs) for marketing tech
  6. Marketing rules under HIPAA: authorization, communications, fundraising exception
  7. FDA OPDP rules for pharma marketers
  8. The Anti-Kickback Statute and the patient inducement landmines
  9. State law overlays: CCPA, CDPA, Washington My Health My Data Act
  10. Common enforcement patterns: pixel settlements, Cerebral, GoodRx, BetterHelp
  11. A working healthcare marketing compliance workflow

1. What HIPAA covers and who must comply

HIPAA (the Health Insurance Portability and Accountability Act of 1996) and the HITECH Act of 2009 created the federal framework for protecting health information. The Privacy Rule, Security Rule, Breach Notification Rule, and Omnibus Rule together govern most healthcare data handling.

HIPAA applies to two categories:

Many digital health and consumer wellness companies are not covered entities. The FTC's Health Breach Notification Rule extends similar obligations to health apps, but the legal framework is different. Know which framework applies to your company.

2. Protected Health Information and the 18 identifiers

PHI is individually identifiable health information held or transmitted by a covered entity or business associate. HHS defines 18 identifiers; data is generally PHI if it includes one or more of these in combination with health information:

  1. Names
  2. Geographic subdivisions smaller than a state (most ZIP+4 combinations qualify)
  3. Dates (except year)
  4. Telephone numbers
  5. Fax numbers
  6. Email addresses
  7. Social Security numbers
  8. Medical record numbers
  9. Health plan beneficiary numbers
  10. Account numbers
  11. Certificate/license numbers
  12. Vehicle identifiers
  13. Device identifiers
  14. URLs
  15. IP addresses
  16. Biometric identifiers
  17. Full-face photos
  18. Any other unique identifying number or code

Two consequences:

3. OCR's 2022/2024 tracking technology guidance

HHS Office for Civil Rights issued a December 2022 bulletin (revised March 2024) clarifying that tracking technologies (pixels, cookies, analytics scripts, SDKs) that disclose PHI to third parties without authorization are HIPAA violations.

The key positions:

The American Hospital Association sued HHS over the unauthenticated-page portion of the guidance; in June 2024 a federal court vacated the unauthenticated-page provision. The authenticated-page provisions remain in force and are the operating reality for healthcare marketers.

Anti-pattern: A health system that deploys Meta Pixel, Google Analytics, and TikTok pixel on its appointment-scheduling pages, sending appointment-type, provider, and IP-address combinations to ad platforms without authorization or BAAs. This pattern is what generated the Meta Pixel hospital settlements ($300M+ in plaintiff class actions) and OCR enforcement.

4. Pixel and analytics tools: what is and is not permitted

Operating rules for tracking technology on healthcare web properties:

Tool / patternAcceptable use
Meta Pixel on authenticated pagesGenerally not permitted without authorization
Google Analytics on authenticated pagesPermitted with BAA (Google does not sign BAAs for GA4 directly; must use server-side architectures or HIPAA-compliant analytics)
Pixel / GA4 on marketing pages with condition or treatment infoRisky; review case-by-case
Server-side tracking (Stape, server-side GTM with PHI scrubbing)Workable if PHI is removed before transmission
HIPAA-compliant analytics (Freshpaint, Trustpilot Health, Heap with HIPAA add-on)Designed for healthcare; appropriate with BAA
Conversions API with hashed identifiersRisky if any identifiers correlate to PHI in the destination platform

5. Business Associate Agreements (BAAs) for MarTech

If a vendor touches PHI, you need a BAA. Practical checklist for evaluating MarTech under HIPAA:

  1. Does the vendor sign BAAs at all? Many consumer-grade tools do not.
  2. Does the BAA cover the specific product / SKU you intend to use? (Salesforce signs BAAs but not for all products; Microsoft Azure signs BAAs but Bing Ads does not.)
  3. Does the vendor provide a HIPAA-compliant configuration guide? (Different settings may be required.)
  4. Does the vendor have HITRUST or SOC 2 certification?
  5. Are there contractual restrictions on the vendor's use of the data, including model training?

6. Marketing under HIPAA: authorization, communications, fundraising

HIPAA's definition of "marketing" is specific: a communication about a product or service that encourages purchase or use. Several types of communications are excluded from the definition (and therefore permitted without authorization):

Communications that fall in the "marketing" definition require written authorization from the patient. Authorization requires specific content and is auditable.

Fundraising by hospitals has a separate exception: limited demographic info, dates of service, treating physician, department of service, and outcome can be used without authorization, with required opt-out language in each communication.

7. FDA OPDP rules for pharma marketing

The FDA's Office of Prescription Drug Promotion governs all promotion of prescription drugs. Master rules:

The DTC TV ad format is increasingly contested; FDA has signaled changes around the brief-summary requirement and digital advertising rules. Pharma marketers should track OPDP letters and warning-letter trends closely.

8. Anti-Kickback Statute and patient inducement

The federal Anti-Kickback Statute (AKS) prohibits remuneration to induce referrals for federal health care program business. The Beneficiary Inducement CMP prohibits offering remuneration to a Medicare or Medicaid beneficiary likely to influence selection of a provider.

Marketing implications:

9. State law overlays

State laws compound HIPAA in ways healthcare marketers must track:

10. Common enforcement patterns

11. A working healthcare marketing compliance workflow

The operating components of a working program:

  1. A current inventory of every digital marketing tool deployed, its data flow, and BAA status.
  2. A privacy-impact assessment process for new MarTech procurement.
  3. A tagging governance program that ensures pixels are only deployed where permitted.
  4. Pre-launch compliance review of every campaign, including landing pages, ad copy, and tracking.
  5. An annual HIPAA risk analysis that includes marketing surfaces.
  6. A breach-response plan that explicitly covers marketing-technology data flows.
  7. Marketer training on HIPAA, FDA OPDP (if pharma), and state law overlays.
How to use this module: The OCR pixel guidance summary in Section 3, the MarTech BAA checklist in Section 5, and the enforcement-pattern list in Section 10 are the three artifacts. Read OCR's tracking technology guidance and the FTC's health-data enforcement actions annually.

Sources & further reading


Part of the Healthcare Marketing series · RGM Training