GLOSSARY

HIPAA-Compliant Marketing

What is HIPAA-Compliant Marketing?

DefinitionHIPAA-compliant marketing means health data (conditions, prescriptions, intake answers) is not shared with ad platforms absent a Business Associate Agreement and explicit authorization. Standard pixels on health pages routinely violate this.

HIPAA-compliant marketing means running ads and conversion tracking without exposing protected health information (PHI) to ad platforms, which in practice requires that health data is never shared absent a Business Associate Agreement and, where applicable, the patient’s explicit authorization.

What counts as PHI in a marketing context

PHI is individually identifiable health information held by a covered entity or its business associate. The subtlety for advertisers is that health information plus an identifier is enough, so the tracking signals marketers treat as routine can qualify. The fact that a specific person (identified by an email, a device ID, an IP address, or a cookie) viewed a GLP-1 eligibility page, started an intake, or requested a particular prescription can itself be PHI, because it reveals something about that individual’s health. A standard advertising pixel dropped on a condition page or an intake flow routinely transmits exactly that combination to Meta or Google, which is how ordinary health pages leak PHI without anyone intending it.

BAAs and authorization

HIPAA lets a covered entity share PHI with a vendor only under a Business Associate Agreement (BAA), a contract binding that vendor to the same safeguards, and using PHI for marketing generally requires the individual’s explicit written authorization. The practical problem is that the major ad platforms do not sign BAAs for their standard advertising products, so there is usually no lawful path to send them PHI at all. HHS’s Office for Civil Rights has issued guidance on online tracking technologies warning that disclosing PHI to such vendors without a BAA or valid authorization can raise serious HIPAA concerns, so the safe operating assumption is simply that identifiable health data must not reach an ad platform. Enforcement is not only HIPAA, either: the FTC has pursued health apps that fall outside HIPAA under its own authority, so the obligation reaches broadly across health advertisers.

Compliant vs non-compliant tracking

Non-compliantCompliant
Browser pixel on intake and condition pagesServer-side events filtered before they leave your stack
Sending condition, medication, or quiz answers as event parametersSending only event name, value, and a hashed identifier via CAPI
Trusting the platform to “just not use” sensitive fieldsNever transmitting the sensitive fields in the first place

The compliant pattern is not “track less” but “track the conversion, not the condition”: a brand can still tell the platform a $299 purchase happened, it just cannot tell it what the purchase was for.

Why it matters for health and DTC brands

The cost of getting this wrong is established, not hypothetical. The FTC penalized GoodRx ($1.5M) and BetterHelp ($7.8M) in 2023 for sending intake and prescription data to Meta and Google, deceptive because their privacy policies promised otherwise, and by industry estimates pixel violations have cost healthcare $100M+ since 2023. The durable fix is architectural: run server-side tracking so you control every field, implement it through CAPI sending the minimum viable event, and keep quiz and intake answers off ad pixels entirely. Compliant tracking is the data-side counterpart to compliant messaging, where staying on the right side of a structure/function claim and holding required accreditations like LegitScript certification protect the account. None of this is legal advice; confirm your specific setup with qualified counsel, because the facts of each data flow decide whether it complies.

Related terms

Ready to lower CAC and scale spend profitably?

A 30-minute call with a senior strategist. Free account audit included. No pitch deck - a written plan you can keep, whether you work with us or not.

Book a free strategy call
30 minutes Free account audit Written plan either way
Book a free strategy call