In 2017 and 2018, an Alabama dental practice handed patient data to a political campaign. Names and addresses for 3,657 patients went to the campaign manager. Names and email addresses for 5,385 patients went to a marketing firm that sent campaign emails. The result: a $62,500 settlement with the HHS Office for Civil Rights (OCR) in 2022 and a two-year corrective action plan.
OCR did not penalize the marketing firm in that case. But a marketing vendor that handles PHI (Protected Health Information) for a healthcare client can face direct liability of its own as a business associate.
If your agency touches healthcare clients, HIPAA already applies to you. Here is what triggers it, what enforcement actually costs, and how to close the gaps.
The Business Associate Trigger
HIPAA defines a business associate at 45 CFR 160.103: anyone who creates, receives, maintains, or transmits PHI on behalf of a covered entity. That includes marketing agencies.
The definition is function-based, not industry-based. If you run a healthcare client's email campaigns, you are a business associate. If you manage their CRM, you are a business associate. If you build intake forms, you are a business associate. If you handle ad targeting, you are a business associate. It does not matter that your agency also handles restaurant clients.
7 Ways Healthcare Marketing Agencies Touch PHI Without Realizing It
- Website contact forms that collect patient names, conditions, or appointment requests.
- Customer support software that stores patient names, emails, and service history.
- Email marketing lists built from patient databases.
- Retargeting pixels that track users who visit condition-specific pages.
- Social media management where patients message the practice account with health details.
- Review collection that captures patient names, photos, and treatment outcomes.
- Review responses that confirm someone is a patient or reference their care.
Every one of these can trigger HIPAA obligations for your agency. Most agency owners have no idea until a client asks for a BAA (Business Associate Agreement) or a breach lands. That is not shameful. It is the starting point, and the checklist below is most of the fix.
Real Fines for Marketing-Related HIPAA Violations
$62,500 - Patient Data Used in a Political Campaign
Northcutt Dental in Fairhope, Alabama shared an Excel file containing 3,657 patient names and addresses with a campaign manager. The practice then used a third-party marketing company, Solutionreach, to send campaign emails, disclosing the names and email addresses of 5,385 patients in the process (the original mailing list plus 1,727 additional patients). The dentist was running for state senate and used his patient list for campaign outreach.
OCR announced a $62,500 settlement and a two-year corrective action plan in March 2022. The HHS enforcement page is public record.
$50,000 - Responding to a Google Review with PHI
A dental practice in Charlotte, North Carolina responded to a negative online review and disclosed the patient's full name, dental condition, treatment details, and appointment history.
OCR told the practice the response was an impermissible disclosure and instructed it to remove the post. The practice never took it down, refused OCR's data request, and ignored an administrative subpoena. OCR imposed a $50,000 civil monetary penalty at the willful neglect, not corrected tier, the most serious HIPAA penalty category.
$30,000 - A Psychiatrist's Google Review Replies
Manasa Health Center in Kendall Park, New Jersey disclosed the PHI of four patients in responses to negative Google reviews. The disclosed information included diagnoses and treatment details for mental health conditions.
OCR settled the case in June 2023 for $30,000 and a two-year corrective action plan. If your agency drafts review responses that confirm someone is a patient or reference their treatment, you are the one creating the violation.
What HIPAA Requires From Your Agency
The BAA (Non-Negotiable)
Before your agency touches any PHI, you need a signed Business Associate Agreement with every healthcare client. This is not optional. Under 45 CFR 164.502(e), a covered entity cannot share PHI with a business associate without one.
A BAA defines what PHI you can access, how you protect it, breach procedures, and your obligation to return or destroy data when the contract ends. Skipping it is one of the 7 BAA mistakes that lead to HIPAA fines.
Tracking Pixels, Retargeting, and the FTC Crackdown
In 2023, the FTC went after both GoodRx and BetterHelp over health data shared through tracking pixels. GoodRx paid a $1.5 million civil penalty under the FTC's Health Breach Notification Rule for failing to report its unauthorized disclosures of health data to Facebook, Google, and other companies. BetterHelp agreed to pay $7.8 million, returned to consumers as refunds, to settle FTC charges that it shared sensitive mental health data with Facebook and Snapchat after promising to keep it private. Neither case was brought under HIPAA, which is the point: even where HIPAA does not reach, the FTC does.
That same year, the FTC and HHS sent a joint warning letter to approximately 130 hospital systems and telehealth providers about tracking technology risks.
If a user visits a page about "depression treatment" and that visit gets sent to Meta for retargeting, that transmission may create serious compliance risk. HHS treated this kind of tracking data as PHI in its online tracking guidance, but a federal court vacated part of that guidance in June 2024 (American Hospital Association v. Becerra, N.D. Tex.). The vacated part is the position that an IP address combined with a visit to a public, no-login health webpage is PHI by itself. HHS says it is evaluating next steps. The rest of the guidance still stands: tracking on patient portals, login pages, appointment schedulers, and intake forms can still transmit PHI. And the FTC polices the same pixels under its own rules no matter what HIPAA says.
Under 45 CFR 164.508(a)(3), using PHI for marketing requires written patient authorization. Retargeting ads do not fit either of the rule's narrow exceptions (face-to-face communications and promotional gifts of nominal value).
Patient Testimonials and Authorization Forms
Patient testimonials become PHI the moment they include a name, photo, or description of treatment. You need a signed HIPAA authorization form before publishing any testimonial, video, before-and-after photo, or case study.
The authorization must specify what information will be used, where it will appear, and the patient's right to revoke consent. Generic intake paperwork does not meet this standard. See HIPAA authorization form requirements.
HIPAA Compliance Checklist for Healthcare Marketing Agencies
- Sign a BAA with every healthcare client before accessing any patient data.
- Audit tracking pixels on healthcare client websites and remove any that transmit health-related browsing data to third parties.
- Collect signed HIPAA authorizations before using any patient reviews, photos, or case studies.
- Train your team on what counts as PHI: names, emails, appointment dates, conditions, and treatments. Treat IP addresses tied to health-related pages as sensitive too. A 2024 court ruling narrowed HHS's position that this data is automatically PHI on public webpages, but it can still be PHI behind logins and in patient portals, and it can still draw FTC scrutiny.
- Encrypt PHI in transit and at rest: email, cloud storage, CRM databases, shared drives. The Security Rule treats encryption as addressable, which does not mean optional: you implement it or document an equivalent alternative.
- Segregate healthcare client data from other client data in your CRM and project management tools.
- Draft review response templates that never confirm a patient relationship or reference treatment.
- Document everything: policies, training records, authorization forms, BAA copies, pixel audits.
- Build a breach response plan. As a business associate, you must notify your healthcare client (the covered entity) without unreasonable delay, and no later than 60 days after you discover a breach. The covered entity then notifies affected individuals and HHS. Your BAA may require faster notice, so check the contract.
- Review and update annually. HIPAA compliance is not a one-time project.
For platform-specific rules, see HIPAA and social media compliance.
Frequently Asked Questions
Do marketing agencies need to be HIPAA compliant?
Yes. Any agency that handles PHI on behalf of a healthcare provider is a business associate under HIPAA. This includes agencies managing email lists, CRM data, website forms, social media accounts, or ad campaigns for healthcare clients.
Can I use patient testimonials in healthcare marketing?
Only with a signed HIPAA authorization. The authorization must specify what information will be disclosed, the purpose, and where it will be published. Verbal consent or a generic intake form signature does not satisfy this requirement. See HIPAA authorization form requirements.
What happens if my agency causes a HIPAA breach?
Your agency can be held directly liable as a business associate. Under the 2026 inflation-adjusted amounts, civil penalties start at $145 per violation and run up to $73,011 per violation for most violation categories, with a calendar-year cap of $2,190,294 for repeated violations of the same requirement. The most serious category, willful neglect that is not corrected, starts at $73,011 per violation. Criminal penalties can reach $250,000 in fines and 10 years imprisonment when someone knowingly obtains or discloses PHI with intent to sell it or use it for commercial advantage, personal gain, or malicious harm. For what enforcement actually looked like last year, see our breakdown of the $6.6 million in HIPAA fines in 2025; OCR ultimately closed the year with 21 enforcement actions totaling more than $8.3 million. Enforcement is not slowing down.
Are Google Analytics and Meta Pixel HIPAA compliant?
Not by default. Neither Google nor Meta signs a BAA for their standard analytics and advertising products. If these tools capture data linkable to a health condition, they may be transmitting PHI without authorization, depending on the page and whether the visitor can be identified. Evaluate server-side tracking, de-identification, or HIPAA-compliant analytics alternatives.
Can I respond to negative reviews for a healthcare client?
Yes, but the response cannot confirm or deny that the reviewer is a patient, reference treatment details, or disclose identifying information. Thank the reviewer, state a commitment to quality care, and invite offline contact. Anything beyond that risks a violation, as the $30,000 and $50,000 fines above demonstrate.
Conclusion
None of this requires a compliance department. It requires a BAA with every healthcare client, clean tracking, signed authorizations, and proof you did it.
Running an agency is enough work without decoding federal privacy regulations on the side. If you have healthcare clients, or want them, schedule a free 30-minute HIPAA Review Call with Chuck. We will walk through where your agency touches PHI and what to fix first. No obligation, no pressure.
Sources
- 45 CFR 160.103 - Business Associate Definition - Electronic Code of Federal Regulations.
- 45 CFR 164.508 - Uses and Disclosures for Which an Authorization Is Required (Marketing) - Electronic Code of Federal Regulations.
- HHS Guidance on Marketing Under HIPAA - U.S. Department of Health and Human Services.
- HHS Guidance on Use of Online Tracking Technologies (carries the June 2024 court vacatur notice) - U.S. Department of Health and Human Services.
- FTC/HHS Warn Hospitals and Telehealth Providers About HIPAA Risks from Online Trackers - Federal Trade Commission, July 2023.
- Four HIPAA Enforcement Actions Hold Healthcare Providers Accountable - HHS Office for Civil Rights, March 2022 (covers the Northcutt Dental settlement and the Charlotte penalty).
- Northcutt Dental Enforcement Action - HHS Office for Civil Rights, March 2022.
- Manasa Health Center Enforcement Action - HHS Office for Civil Rights, June 2023.
- Annual Civil Monetary Penalties Inflation Adjustment - Federal Register, January 28, 2026.