Breach Liability for Clinic Marketing Teams
A marketing decision can create a reportable HIPAA breach with no security incident involved. Who is liable, what the deadlines are, and how the notification math works.
A clinic marketing team can create a reportable HIPAA breach without anyone being hacked, because an impermissible disclosure of unsecured PHI is a breach on its own, presumed reportable unless a documented four-factor analysis shows a low probability of compromise. Liability sits with the covered entity, and separately with any business associate involved, which includes your agency and most of your marketing tools. Curve is HIPAA-compliant ad tracking with a signed BAA on every plan, and it exists because the tracking layer is where these disclosures happen at scale and without anyone noticing.
What counts as a breach
The Breach Notification Rule defines a breach as the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the Privacy Rule. There is no requirement that anyone acted maliciously, that a system was compromised, or that a patient was harmed.
Once an impermissible disclosure occurs, a breach is presumed. The only way out is a documented risk assessment covering four factors:
- The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.
- The unauthorized person who used the PHI or to whom the disclosure was made.
- Whether the PHI was actually acquired or viewed.
- The extent to which the risk has been mitigated.
Two features of that test matter for marketing scenarios specifically. The burden runs against you: absent the documented analysis, notification is required. And factor two goes badly when the recipient is an advertising platform, because the data was not only received, it was ingested into systems built to use it.
The deadlines
The clock starts at discovery, not at occurrence, and discovery includes what you should have known through reasonable diligence.
- Individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery.
- Breaches affecting 500 or more individuals require notice to OCR within 60 days of discovery, plus notice to prominent media outlets in the states and jurisdictions where affected individuals reside, on the same timeline.
- Breaches affecting fewer than 500 are logged and submitted to OCR no later than 60 days after the end of the calendar year in which they were discovered.
- Business associates must notify the covered entity, and the timing is set by the BAA. If your BAA gives the vendor 60 days to tell you, your own 60-day clock is already gone.
The 60 days is a ceiling, not a target. OCR has repeatedly treated delay inside the window as a factor when the facts supported faster notice.
Marketing decisions that have produced reportable breaches
A tracking tag on a health-related page. The largest by orders of magnitude. Advocate Aurora Health notified roughly 3 million patients after a tracking-related disclosure, treating every MyChart and LiveWell user and every scheduling widget user as potentially affected. Cerebral notified more than 3.17 million individuals over pixel transmissions spanning October 2019 through January 2023. Novant Health's portal pixel affected up to 1.36 million patients. Kaiser Permanente's covered 13.4 million.
A patient list sent to an uncovered vendor. Northcutt Dental-Fairhope disclosed the names and addresses of 3,657 patients to a campaign manager and used a third-party marketing company to reach 5,385 people, settling with OCR at $62,500. Raleigh Orthopaedic Clinic settled at $750,000 after handing records covering 17,300 patients to a vendor on an oral agreement with no BAA.
Photos and testimonials published without authorization. Cadia Healthcare's $182,000 settlement covered both the impermissible disclosure of roughly 150 residents' information in social media success stories and the separate failure to notify those individuals afterward. That second finding is the one marketing teams miss: the notification obligation applies to a marketing disclosure exactly as it would to a stolen laptop.
Email and SMS mistakes. A campaign sent to a condition-specific segment with recipients in the To or CC field discloses to every recipient that everyone else on the list shares that condition. It is small in record count and unambiguous in nature.
Automation moving data to tools with no BAA. Form submissions routed through middleware into a spreadsheet, a chat tool, or a CRM that never signed a BAA is a disclosure at every hop. Our assessment of whether Zapier is HIPAA compliant for healthcare marketing works through what that chain looks like in practice.
Who is actually liable
Three answers, because it depends on the party.
The covered entity holds the notification obligation and cannot delegate it. Even where a vendor caused the disclosure, the clinic notifies the patients. Contractual indemnity may shift the cost afterward; it does not shift the duty.
Business associates have direct liability under HITECH for a defined set of provisions, including impermissible uses and disclosures and their own breach notification duties. Your marketing agency, if it handles PHI or has access to systems containing it, is a business associate. Agency access to ad accounts and CRMs is the most commonly missed instance of this.
Individuals are rarely the target. Criminal liability under 42 U.S.C. 1320d-6 does attach to individuals, with the top tier reaching $250,000 and ten years for disclosure for commercial advantage or personal gain, but marketing mistakes are overwhelmingly handled as organizational matters. The realistic individual consequence is employment, not prosecution.
One more chain to check: your business associates must obtain equivalent assurances from their own subcontractors. A gap three links down is still your exposure, and reading only the contract in front of you will not find it. Ask for the subprocessor list.
What a breach actually costs
The notification itself is the first line, and at tracking-case scale it is substantial: mail or email to every affected individual, a substitute notice on your website, media notification above 500 individuals, and call center capacity for the questions that follow.
Then the regulatory line. OCR's civil monetary penalty tiers, effective January 28, 2026, run from $145 to $2,190,294 per violation category per year, with tier placement turning on what you knew and whether you corrected within 30 days.
Then the litigation line, which has been the largest. Private class actions over tracking do not depend on HIPAA, which has no private right of action. They run on state wiretap and consumer protection statutes. Advocate Aurora settled at $12.225 million, Novant at $6.6 million, Sutter Health at $21.5 million, and Kaiser at a base of $46 million. Cumulative healthcare pixel settlements have crossed $100 million.
And the permanent line. Breaches affecting 500 or more individuals are published on the HHS breach portal, which is public, searchable, and monitored by the plaintiffs' bar.
How Curve keeps marketing out of the notification path
Notification is triggered by an impermissible disclosure of PHI. If the data reaching the ad platform contains no PHI, there is nothing to assess and nothing to notify.
Curve's tracking script installs in place of the Meta Pixel and Google tag, so events go to Curve's US-hosted infrastructure rather than directly to platforms that will not sign a BAA. Per-destination field mapping controls what forwards, with nothing sent by default and only explicitly mapped fields moving. Identifiers are SHA-256 hashed per each platform's conversion API requirements. Neutral event aliases mean the platform receives a generic conversion name rather than a service line. PHI-pattern detection flags payloads containing PHI-shaped values such as SSNs, MRN-style identifiers, and long numeric sequences.
That last control is the one that maps to breach liability directly. The costliest feature of tracking breaches is duration: transmissions run for years before anyone looks, and the class period is measured from the day the tag went live. Detection converts a multi-year window into a short one, which changes both the notification population and the penalty tier. Curve includes a signed BAA on every plan, so the layer holding attribution data is a covered vendor rather than an uncovered one.
For the mechanics of moving lead data without creating disclosures, see our guide to routing ad clicks to a CRM without PHI, and for the underlying architecture, why client-side pixels create a HIPAA violation.
What a marketing team should own
Compliance functions rarely have visibility into the marketing stack, which is why gaps concentrate there. Four things belong to marketing rather than to legal.
A current inventory of every script on your web properties, updated whenever a tag is added. A current list of every vendor receiving form, appointment, or contact data, with BAA status against each. A defined escalation path for the moment someone notices unexpected data leaving, because the 30-day correction window is short and it starts at discovery. And a rule that no new marketing tool goes live before its BAA is executed, since a pilot with real patient data is the violation, not a prelude to one.
Our marketing compliance checklist is written for dental groups and transfers cleanly to any clinic marketing function.
Frequently asked questions
Is a tracking pixel disclosure really a reportable breach?
It is an impermissible disclosure if PHI reached a vendor without a BAA, and an impermissible disclosure is presumed to be a breach unless a documented four-factor analysis shows a low probability of compromise. The organizations that notified millions of patients reached that conclusion on their own facts.
Can a marketing employee be personally fined?
Civil penalties are assessed against the covered entity or business associate, not the individual. Criminal liability under HIPAA does attach to individuals, but it is reserved for knowing misuse, particularly for commercial advantage, and it is rare in marketing contexts.
Our agency caused the problem. Do they notify the patients?
No. The business associate notifies you, on the timeline your BAA specifies, and you notify the patients. That obligation stays with the covered entity regardless of fault.
When does the 60-day clock actually start?
At discovery, which includes the point at which you would have known through reasonable diligence. An organization that never audits its own site does not get an indefinite extension by not looking.
Does removing the tag reduce the number of people we have to notify?
It stops the population from growing. It does not reduce it retroactively, because everyone whose data was transmitted while the tag was live remains affected. Speed of detection is what controls the number.
What if we cannot tell exactly whose data was transmitted?
That uncertainty generally pushes toward broader notification, which is why the large tracking cases covered every portal user rather than a narrower set. Logging that establishes what was actually sent, and to which destination, is worth building before you need it.
Where to start
Build the inventory first. Every script on your properties, every vendor receiving patient-adjacent data, and BAA status for each. That single document is what the four-factor analysis depends on, and most teams cannot produce it today.
Run our free compliance scanner for the technical half of it, which reports what is currently loading on your site and transmitting data. To see how the ad tracking layer works when it sits behind a signed BAA and flags PHI-shaped values before they travel, visit curvecompliance.com.
Reviewed August 2026. This is general information, not legal advice. Breach determinations depend on a documented analysis of specific facts. Consult qualified counsel and your privacy officer before deciding whether an incident is reportable.
Related articles
- GuideCompounded Semaglutide Advertising Rules: What Clinics Can and Cannot Claim in 2026
- GuideBehavioral Health Lead Generation: Why Third-Party Rehab Leads Create HIPAA Liability
- ArticleHealthcare Compliance Weekly: $18.5M in Data Breach Settlements and the Biggest HIPAA Security Rule Overhaul in a Decade
- GuideData Breach Liability: What Every Med Spa Owner Must Know About Marketing Data
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit