HIPAA & Regulatory Compliance for Marketers
HIPAA, FDA OPDP, the Anti-Kickback Statute, and a growing list of state laws govern every healthcare marketing decision. This module covers what the rules actually say, the enforcement patterns to learn from, and the compliance workflow that survives examination.
What you will learn in this module
- What HIPAA actually covers and who is a covered entity / business associate
- Protected Health Information (PHI) and the 18 identifiers
- The OCR 2022/2024 tracking technology guidance and its marketing implications
- Pixel and analytics tools: what is and is not permitted
- Business Associate Agreements (BAAs) for marketing tech
- Marketing rules under HIPAA: authorization, communications, fundraising exception
- FDA OPDP rules for pharma marketers
- The Anti-Kickback Statute and the patient inducement landmines
- State law overlays: CCPA, CDPA, Washington My Health My Data Act
- Common enforcement patterns: pixel settlements, Cerebral, GoodRx, BetterHelp
- A working healthcare marketing compliance workflow
1. What HIPAA covers and who must comply
HIPAA (the Health Insurance Portability and Accountability Act of 1996) and the HITECH Act of 2009 created the federal framework for protecting health information. The Privacy Rule, Security Rule, Breach Notification Rule, and Omnibus Rule together govern most healthcare data handling.
HIPAA applies to two categories:
- Covered Entities (CEs): Health plans, health care clearinghouses, and health care providers who electronically transmit any health information in connection with covered transactions. Almost every hospital, physician practice, dentist, pharmacy, and health insurer is a covered entity.
- Business Associates (BAs): Anyone who handles PHI on behalf of a covered entity. Marketing agencies, MarTech vendors, analytics platforms, call centers, and cloud providers are often business associates if they touch PHI.
Many digital health and consumer wellness companies are not covered entities. The FTC's Health Breach Notification Rule extends similar obligations to health apps, but the legal framework is different. Know which framework applies to your company.
2. Protected Health Information and the 18 identifiers
PHI is individually identifiable health information held or transmitted by a covered entity or business associate. HHS defines 18 identifiers; data is generally PHI if it includes one or more of these in combination with health information:
- Names
- Geographic subdivisions smaller than a state (most ZIP+4 combinations qualify)
- Dates (except year)
- Telephone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers
- Device identifiers
- URLs
- IP addresses
- Biometric identifiers
- Full-face photos
- Any other unique identifying number or code
Two consequences:
- IP address is a HIPAA identifier. This means most ad platform tracking is PHI-relevant when paired with health information.
- De-identification under Safe Harbor requires removing all 18 identifiers; under Expert Determination requires statistical assurance of re-identification risk.
3. OCR's 2022/2024 tracking technology guidance
HHS Office for Civil Rights issued a December 2022 bulletin (revised March 2024) clarifying that tracking technologies (pixels, cookies, analytics scripts, SDKs) that disclose PHI to third parties without authorization are HIPAA violations.
The key positions:
- On user-authenticated pages (patient portal, appointment scheduling, etc.) information transmitted to a tracking technology vendor is presumptively PHI.
- On unauthenticated webpages (general marketing pages, condition info pages), tracking may still be problematic if combined with information that ties a visitor to a specific health condition.
- Tracking-technology vendors that handle PHI must be under a Business Associate Agreement.
- Health-information disclosures to advertising platforms without authorization are violations.
The American Hospital Association sued HHS over the unauthenticated-page portion of the guidance; in June 2024 a federal court vacated the unauthenticated-page provision. The authenticated-page provisions remain in force and are the operating reality for healthcare marketers.
4. Pixel and analytics tools: what is and is not permitted
Operating rules for tracking technology on healthcare web properties:
| Tool / pattern | Acceptable use |
|---|---|
| Meta Pixel on authenticated pages | Generally not permitted without authorization |
| Google Analytics on authenticated pages | Permitted with BAA (Google does not sign BAAs for GA4 directly; must use server-side architectures or HIPAA-compliant analytics) |
| Pixel / GA4 on marketing pages with condition or treatment info | Risky; review case-by-case |
| Server-side tracking (Stape, server-side GTM with PHI scrubbing) | Workable if PHI is removed before transmission |
| HIPAA-compliant analytics (Freshpaint, Trustpilot Health, Heap with HIPAA add-on) | Designed for healthcare; appropriate with BAA |
| Conversions API with hashed identifiers | Risky if any identifiers correlate to PHI in the destination platform |
5. Business Associate Agreements (BAAs) for MarTech
If a vendor touches PHI, you need a BAA. Practical checklist for evaluating MarTech under HIPAA:
- Does the vendor sign BAAs at all? Many consumer-grade tools do not.
- Does the BAA cover the specific product / SKU you intend to use? (Salesforce signs BAAs but not for all products; Microsoft Azure signs BAAs but Bing Ads does not.)
- Does the vendor provide a HIPAA-compliant configuration guide? (Different settings may be required.)
- Does the vendor have HITRUST or SOC 2 certification?
- Are there contractual restrictions on the vendor's use of the data, including model training?
6. Marketing under HIPAA: authorization, communications, fundraising
HIPAA's definition of "marketing" is specific: a communication about a product or service that encourages purchase or use. Several types of communications are excluded from the definition (and therefore permitted without authorization):
- Treatment communications about a particular product or service from a covered entity.
- Case management or care coordination for the individual.
- Recommendations of alternative treatments, providers, or settings.
- Refill reminders or related communications (with certain payment restrictions).
Communications that fall in the "marketing" definition require written authorization from the patient. Authorization requires specific content and is auditable.
Fundraising by hospitals has a separate exception: limited demographic info, dates of service, treating physician, department of service, and outcome can be used without authorization, with required opt-out language in each communication.
7. FDA OPDP rules for pharma marketing
The FDA's Office of Prescription Drug Promotion governs all promotion of prescription drugs. Master rules:
- Fair balance: Benefits and risks must be presented with comparable prominence.
- Brief summary / important safety information: Specific content requirements; for DTC TV ads, the "major statement" must include the most serious risks.
- Indication-specific: Promotional content must be specific to the approved indication.
- Substantial evidence: Claims must be supported by adequate and well-controlled studies.
- Off-label promotion: Prohibited; complicated for new uses and biologics.
- Form 2253: Promotional materials must be submitted to FDA at time of first use.
The DTC TV ad format is increasingly contested; FDA has signaled changes around the brief-summary requirement and digital advertising rules. Pharma marketers should track OPDP letters and warning-letter trends closely.
8. Anti-Kickback Statute and patient inducement
The federal Anti-Kickback Statute (AKS) prohibits remuneration to induce referrals for federal health care program business. The Beneficiary Inducement CMP prohibits offering remuneration to a Medicare or Medicaid beneficiary likely to influence selection of a provider.
Marketing implications:
- "Free screening" offers can trigger AKS if they induce a downstream billable service.
- Gift cards, sweepstakes, and contests for federal health care program patients are heavily restricted.
- Co-pay assistance from pharma to federally-insured patients is prohibited; charitable foundation routes have specific guardrails.
- Referral fee structures between providers are restricted under Stark Law.
9. State law overlays
State laws compound HIPAA in ways healthcare marketers must track:
- California CCPA / CPRA — PHI under HIPAA is exempt, but other health data (consumer health apps, wellness data) is in scope.
- Washington My Health My Data Act (2023) — The most aggressive state health-privacy law; reaches consumer health data beyond HIPAA. Effective March 2024.
- Texas, Connecticut, Nevada, Florida — All have specific health-data provisions.
- State medical board rules — Restrict physician advertising, especially around "specialist" claims, before/after photos, and patient testimonials.
10. Common enforcement patterns
- Cerebral (FTC, 2024) — Sharing sensitive mental health data with advertisers via pixels; $7M settlement.
- BetterHelp (FTC, 2023) — Sharing user information including responses to intake questions with Facebook, Snapchat, Pinterest; $7.8M settlement.
- GoodRx (FTC, 2023) — First Health Breach Notification Rule case; $1.5M civil penalty; sharing prescription data with Facebook/Google.
- Hospital pixel class actions — Advocate Aurora, Novant, Community Health Network, and dozens of others settled in the $50M - $300M+ range.
- OCR HIPAA enforcement — Trend of resolution agreements and settlements involving inadequate risk analysis, lack of BAAs, and impermissible disclosures.
11. A working healthcare marketing compliance workflow
The operating components of a working program:
- A current inventory of every digital marketing tool deployed, its data flow, and BAA status.
- A privacy-impact assessment process for new MarTech procurement.
- A tagging governance program that ensures pixels are only deployed where permitted.
- Pre-launch compliance review of every campaign, including landing pages, ad copy, and tracking.
- An annual HIPAA risk analysis that includes marketing surfaces.
- A breach-response plan that explicitly covers marketing-technology data flows.
- Marketer training on HIPAA, FDA OPDP (if pharma), and state law overlays.
Sources & further reading
- OCR Guidance on Online Tracking Technologies (2024)
- OCR Guidance on Marketing under HIPAA
- FTC blog on pixel tracking in healthcare
- FDA OPDP
- HHS OIG Anti-Kickback Safe Harbors
- Washington My Health My Data Act
- FTC Health Breach Notification Rule
- AMA Code of Medical Ethics
- Freshpaint Healthcare Privacy hub (vendor; useful reference)
- Healthcare IT News
- Books: M. Peter Adler, HIPAA and Privacy Law; Adam Greene, HIPAA Compliance
- Search OCR resolution agreements at HHS Enforcement Actions
Part of the Healthcare Marketing series · RGM Training