
HIPAA-Compliant Marketing, Done Right
Marketing a healthcare, aesthetic, or dental practice means working inside HIPAA, FTC substantiation, and platform rules at the same time. This is the hub that shows how to grow without crossing any of those lines.
The short version
Compliance is a build gate, not a disclaimer
In most industries, marketing compliance is a footer link. In healthcare and aesthetics, a mistake is not a bad quarter, it is a regulatory letter, a fine, or a breach of a patient's trust. So we treat compliance as a gate every asset passes through before it ships, not a warning bolted on after.
Four ideas govern almost everything here. Get these right and the rest of compliant marketing follows. The guides below take each one from principle to practice, with the specific rules for reviews, photos, tracking, and claims.
Protected health information is the line
The moment a marketing asset reveals that a specific person is your patient, or anything about their condition or treatment, you are handling protected health information. Reviews, testimonials, before-and-after photos, retargeting pixels, and intake forms are all places that line gets crossed by accident.
Consent is specific, written, and revocable
A blanket photo release does not cover a specific use. Patient stories and images require a written authorization that names the exact content, where it will appear, and the patient's right to revoke, and you keep that documentation on file.
Claims must be truthful and substantiated
The FTC requires health and beauty claims to be truthful and backed by evidence. Results language stays honest and individual, with no guarantees, and higher-scrutiny categories like GLP-1 weight loss carry extra care.
The tech stack is part of compliance
Tracking pixels, analytics, and forms can transmit protected health information to third parties without anyone intending it. HIPAA-aware tracking and intake are as much a part of compliant marketing as the words on the page.
The compliance library
Each guide goes deep on one area, written for practice owners and marketers, educational rather than legal advice.
HIPAA marketing, common questions
Does HIPAA even apply to a med spa?
Not automatically, and this is the most misunderstood question in the category. HIPAA applies to a health care provider only if that provider transmits health information in electronic form in connection with a transaction for which HHS has adopted a standard, such as a claim, an eligibility inquiry, or a referral authorization. HHS is explicit that using electronic technology like email does not by itself make a provider a covered entity: the transmission has to be in connection with one of those standard transactions. A purely cash-pay med spa that never bills insurance electronically may therefore fall outside HIPAA entirely, while one that bills any insurance, or uses a billing service that does, is almost certainly inside it. That is not a reason to relax. State medical-privacy laws, state board advertising rules, the FTC Act, and the FTC Health Breach Notification Rule can all still apply to a practice HIPAA does not reach, and patients do not draw the distinction. Confirm your own status with your compliance counsel rather than inferring it from a marketing page.
Can a med spa use patient testimonials, and what consent is required?
Yes, with a specific written authorization rather than a general release. A testimonial that identifies someone as your patient discloses protected health information, so the authorization has to name the exact content being used, state where it will appear, and preserve the patient's right to revoke it. A blanket photo release signed at intake does not cover a specific later use. Keep the signed authorization on file for as long as the asset is published, and stop using the asset when consent is withdrawn.
How should a med spa store patient consent forms?
Wherever you store them, the storage has to be access-controlled, auditable, and covered by a business associate agreement if a vendor touches it. Consent forms are patient records: a shared cloud drive without access controls, a personal email inbox, or a marketing tool with no agreement in place are all common and avoidable failures. Retain the authorization for as long as the content is live, and be able to produce it for a specific asset on request, which in practice means filing consent against the asset rather than only against the patient.
What does a med spa actually have to do to be HIPAA compliant in marketing?
Four things, in this order: know whether HIPAA applies to you, get specific written authorization before any patient becomes identifiable in an asset, keep claims truthful and substantiated, and make sure the tech stack is not leaking protected health information through pixels, analytics, or forms. The fourth is the one practices miss, because it happens without anyone deciding to do it.
Can Meta and Google ads for a med spa be run compliantly?
Yes, provided targeting is built on intent and geography rather than health status, and the creative is honest about results. Health and beauty is a restricted advertising category on both platforms, and the fastest way to lose an account is wording around weight loss, GLP-1 medications, or prescription treatments. Compliance here is a platform-policy question as much as a HIPAA one, and both matter: the ads have to stay approved to be worth anything.
What makes before-and-after photos a compliance risk?
A before-and-after photo is protected health information about an identifiable patient, so it requires specific written consent naming the exact images and where they will appear, plus disclaimers that results vary. A generic release is not enough, and publishing an image without documented authorization creates both HIPAA and, depending on the claim, FTC exposure.
Do website analytics and ad pixels really create HIPAA problems?
They can, and they do it silently. Standard tracking pixels and analytics can transmit what a visitor viewed or submitted, and on a healthcare site that data can amount to protected health information shared with a third party. HIPAA-aware tracking, careful form design, and the right data agreements are how a practice site stays compliant while still measuring what matters.
Is this legal advice?
No. These resources explain how we build marketing that respects HIPAA, FTC substantiation, and platform rules, and they are educational rather than legal advice. For a determination about your specific practice, consult your own compliance counsel. We build to a conservative standard and coordinate with your counsel when one is involved.
Sources
- HHS, Covered Entities and Business Associateschecked 2026-08-13
- CMS, Are You a Covered Entity?checked 2026-08-13
- HHS, Summary of the HIPAA Privacy Rulechecked 2026-08-13
Grow without crossing the line
Start with a free strategy plan. We build every asset compliance-first, so your license is the first stakeholder in the campaign, not an afterthought.