HIPAA-Compliant Marketing
What is HIPAA-Compliant Marketing?
HIPAA-compliant marketing means running ads and conversion tracking without exposing protected health information (PHI) to ad platforms, which in practice requires that health data is never shared absent a Business Associate Agreement and, where applicable, the patient’s explicit authorization.
What counts as PHI in a marketing context
PHI is individually identifiable health information held by a covered entity or its business associate. The subtlety for advertisers is that health information plus an identifier is enough, so the tracking signals marketers treat as routine can qualify. The fact that a specific person (identified by an email, a device ID, an IP address, or a cookie) viewed a GLP-1 eligibility page, started an intake, or requested a particular prescription can itself be PHI, because it reveals something about that individual’s health. A standard advertising pixel dropped on a condition page or an intake flow routinely transmits exactly that combination to Meta or Google, which is how ordinary health pages leak PHI without anyone intending it.
BAAs and authorization
HIPAA lets a covered entity share PHI with a vendor only under a Business Associate Agreement (BAA), a contract binding that vendor to the same safeguards, and using PHI for marketing generally requires the individual’s explicit written authorization. The practical problem is that the major ad platforms do not sign BAAs for their standard advertising products, so there is usually no lawful path to send them PHI at all. HHS’s Office for Civil Rights has issued guidance on online tracking technologies warning that disclosing PHI to such vendors without a BAA or valid authorization can raise serious HIPAA concerns, so the safe operating assumption is simply that identifiable health data must not reach an ad platform. Enforcement is not only HIPAA, either: the FTC has pursued health apps that fall outside HIPAA under its own authority, so the obligation reaches broadly across health advertisers.
Compliant vs non-compliant tracking
| Non-compliant | Compliant |
|---|---|
| Browser pixel on intake and condition pages | Server-side events filtered before they leave your stack |
| Sending condition, medication, or quiz answers as event parameters | Sending only event name, value, and a hashed identifier via CAPI |
| Trusting the platform to “just not use” sensitive fields | Never transmitting the sensitive fields in the first place |
The compliant pattern is not “track less” but “track the conversion, not the condition”: a brand can still tell the platform a $299 purchase happened, it just cannot tell it what the purchase was for.
Why it matters for health and DTC brands
The cost of getting this wrong is established, not hypothetical. The FTC penalized GoodRx ($1.5M) and BetterHelp ($7.8M) in 2023 for sending intake and prescription data to Meta and Google, deceptive because their privacy policies promised otherwise, and by industry estimates pixel violations have cost healthcare $100M+ since 2023. The durable fix is architectural: run server-side tracking so you control every field, implement it through CAPI sending the minimum viable event, and keep quiz and intake answers off ad pixels entirely. Compliant tracking is the data-side counterpart to compliant messaging, where staying on the right side of a structure/function claim and holding required accreditations like LegitScript certification protect the account. None of this is legal advice; confirm your specific setup with qualified counsel, because the facts of each data flow decide whether it complies.
Related terms
Ready to lower CAC and scale spend profitably?
A 30-minute call with a senior strategist. Free account audit included. No pitch deck - a written plan you can keep, whether you work with us or not.
Book a free strategy call