LearnJune 5, 2026

What HIPAA Marketing Rules Require Before You Advertise

HIPAA requires written patient authorization before you use protected health information for marketing. That covers patient photos, testimonials that identify someone as a patient, patient lists shared with advertisers, and remarketing pixels that send patient data to ad platforms. The exceptions are narrow.

What counts as marketing under HIPAA

The regulation defines marketing as "a communication about a product or service that encourages recipients of the communication to purchase or use the product or service" (45 CFR 164.501). If that communication uses protected health information, meaning anything that identifies a person as your patient, 45 CFR 164.508(a)(3) requires the patient's written authorization first.

Only two marketing communications are exempt from the authorization requirement: a face-to-face conversation between you and the patient, and a promotional gift of nominal value. Everything else that meets the marketing definition and touches PHI needs a signature.

Some communications are excluded from the marketing definition entirely. Treatment communications, including case management, care coordination, and recommending alternative treatments or providers, are not marketing. Neither are refill reminders, provided any payment you receive for sending them is reasonably related to your cost of sending them, or descriptions of health-related products and services you yourself provide.

  • Marketing plus PHI equals written authorization, with two exceptions: face-to-face communication and nominal gifts
  • Treatment, care coordination, and referrals to alternative providers are not marketing
  • Refill reminders are excluded only when payment is limited to your cost of sending them
  • Describing your own health-related services to your patients is excluded

Patient photos and before-and-after images need a signed authorization

A photo of an identifiable patient confirms that person received care from you. That makes it protected health information, and putting it in an ad, on your website, or on social media is a marketing use. Under 45 CFR 164.508, that use requires a valid written authorization before the image goes anywhere public.

General intake consent does not cover this. The authorization must describe the specific information being used, who can use it, who receives it, and the purpose, all in plain language. A blanket "we may use your information" clause fails that specificity standard.

The practical rule: no signed, marketing-specific authorization on file, no photo published. This applies to before-and-after galleries, event photos taken in your clinic, and any image where a patient is recognizable.

Testimonials and reviews follow the same rule

When you republish a patient's story, quote, or video testimonial in your own marketing, you are using PHI to promote a service. That requires the same written authorization as a photo, with the same core elements under 45 CFR 164.508(c).

A patient posting their own review on Google or Yelp is their choice and not your HIPAA problem. Your exposure starts when you respond in a way that confirms they are a patient, or when you copy that review into your website, ads, or email. Confirm nothing in public replies, and get authorization before repurposing any review.

Selling or sharing patient lists is a sale of PHI

Disclosing your patient list to a marketing partner, ad agency, or data broker in exchange for anything of value is treated as a sale of protected health information. Under 45 CFR 164.508(a)(4), each patient must authorize it, and the authorization must state that the disclosure will result in remuneration to you.

The same remuneration logic applies inside ordinary marketing. If a third party pays you to send a promotional communication about their product, 45 CFR 164.508(a)(3) requires the authorization to state that such payment is involved.

Uploading patient emails to an ad platform for a custom audience is a disclosure of PHI to that platform. Without individual authorizations, that upload is not permitted.

Remarketing pixels and tracking tools are the current enforcement front

HHS took the position in guidance first issued in December 2022 that "disclosures of PHI to tracking technology vendors for marketing purposes, without individuals' HIPAA-compliant authorizations, would constitute impermissible disclosures." That covers ad pixels, cookies, and similar scripts that send visitor data to advertising platforms.

On June 20, 2024, a federal court in Texas vacated the guidance in the American Hospital Association case, ruling that HHS overstepped its authority and that metadata from a search of a public-facing webpage does not meet the definition of individually identifiable health information.

The court ruling narrowed HHS's reach on public, unauthenticated pages. It did not repeal HIPAA. Data flowing from authenticated surfaces such as patient portals, booking flows, and logged-in pages still carries real compliance risk when it reaches ad vendors. A cookie banner is not a HIPAA authorization. The conservative posture for a practice: keep remarketing pixels off any page where a person's identity connects to their care.

What a valid marketing authorization must contain

Under 45 CFR 164.508(c), a valid authorization must describe the information to be used in a "specific and meaningful fashion," name who may use it and who receives it, state each purpose, carry an expiration date or event, and be signed and dated by the patient. It must be written in plain language and explain the patient's right to revoke.

Build one standing template covering photos, testimonials, and promotional use, and store signed copies with the patient record. Getting this document right once removes the ambiguity from every future campaign.

This is the compliance floor most growth vendors skip past. At Rank & Rejuvenate we treat authorization workflows as part of the booking system, because a campaign that produces appointments and a complaint to the Office for Civil Rights is not a win.

Common questions

Does my standard intake consent form cover marketing use?

No. A marketing authorization under 45 CFR 164.508(c) must specifically describe the information being used, who will use it, who receives it, the purpose, and an expiration, and it must be signed and dated. A general treatment consent lacks that specificity, so photos, testimonials, and list disclosures need their own signed authorization.

Can I run Facebook or Google ads at all under HIPAA?

Yes. Advertising to general audiences by geography, age, or interest involves no patient data and no HIPAA issue. The problems start when patient information flows to the platform: uploading patient emails for custom audiences, or running remarketing pixels on booking pages and portals. Keep campaigns audience-targeted and keep trackers off authenticated pages.

Are appointment reminders and recall messages considered marketing?

No. Communications for treatment, case management, and care coordination are excluded from the marketing definition in 45 CFR 164.501, and refill reminders are excluded when any payment you receive is limited to your cost of sending them. Reminding an existing patient about their own care is operations, not promotion, and needs no authorization.

Your schedule, predictable

Start with a free growth audit: your rankings, your reviews, your booking flow, and exactly where the patients are going instead. No contract. No pitch deck.