HIPAA-Compliant Marketing: Ads, Tracking and BAAs
HIPAA-compliant marketing means getting patient authorization, sending ad platforms no PHI, and signing a BAA with every vendor that handles PHI for you.
HIPAA-compliant marketing is healthcare marketing that gets a patient's written authorization before using or disclosing their protected health information (PHI) for marketing, sends ad platforms no PHI, and has a business associate agreement (BAA) with every vendor that handles PHI for you. In practice that is three jobs: knowing what HIPAA counts as marketing, keeping health information out of ad pixels and audiences, and checking which tools sign a BAA. Curve Compliance runs HIPAA-compliant ad tracking for healthcare: it sends conversions server-side to Meta, Google Ads, TikTok, Microsoft Advertising and LinkedIn, and signs a BAA on every plan.
Book a call. Curve Compliance replaces browser ad pixels with server-side conversion tracking for Meta, Google Ads, TikTok, Microsoft Advertising and LinkedIn, and signs a BAA on every plan. Book a call with Curve.
What HIPAA counts as marketing
The HIPAA Privacy Rule defines marketing in 45 CFR 164.501: "to make a communication about a product or service that encourages recipients of the communication to purchase or use the product or service." The same definition carves out some communications, as the table shows.
| Communication | Marketing under 164.501? | Authorization needed? |
|---|---|---|
| A message that encourages people to buy or use a product or service | Yes | Yes, before any PHI is used or disclosed for it |
| A refill reminder for a drug the patient is currently prescribed | No, if any payment is reasonably related to the expense of making it | Not under the marketing rule |
| Treatment messages, such as recommending alternative treatments or providers; descriptions of the covered entity's own health-related services; care coordination | No, unless paid for as in the next row | Not under the marketing rule |
| Those treatment or service messages, paid for by the third party whose product they describe | Yes | Yes, and it must say payment is involved |
| A face-to-face marketing communication, or a promotional gift of nominal value | Yes | No, under 164.508(a)(3)(i) |
The authorization rule is 45 CFR 164.508(a)(3): a covered entity "must obtain an authorization for any use or disclosure of protected health information for marketing." A valid authorization contains the elements in 164.508(c), among them a specific description of the information, who may receive it, the purpose, an expiration date, and the patient's signature and date.
HIPAA applies to covered entities, such as health plans and many health care providers, and to their business associates. It does not ban advertising; it limits what you do with PHI. A search ad bought on a keyword uses no patient data. A patient list uploaded to an ad platform, or a booking a pixel sends to one, is patient data leaving your hands. Whether a campaign falls under these rules is a legal question, so talk to your counsel. For penalty tiers, see the HIPAA marketing penalties reference table.
Tracking pixels and PHI: the OCR bulletin and AHA v. Becerra
The HHS Office for Civil Rights (OCR) explains how HIPAA applies to pixels in its bulletin Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates, first issued in December 2022 and revised on March 18, 2024. The core rule: "Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors." It ties that straight to marketing: "disclosures of PHI to tracking technology vendors for marketing purposes, without individuals' HIPAA-compliant authorizations, would constitute impermissible disclosures."
The bulletin sorts pages by risk:
- Logged-in pages. Tracking technologies on patient portals, telehealth platforms and other user-authenticated pages "generally have access to PHI."
- Booking and symptom-checker pages. Pages that let people "schedule appointments or use a symptom-checker tool without entering credentials may have access to PHI in certain circumstances," such as an email address or the reason for care. In HHS's booking example, "the tracking technology vendor is a business associate, and a BAA is required."
- Mobile apps. Information a regulated entity's app collects "generally is PHI."
- General information pages. Tracking on pages about job postings or visiting hours generally involves no PHI.
Four more lines matter to marketers. Cookie banners "do not constitute a valid HIPAA authorization." A line in your privacy policy is not permission either. A tracking vendor's promise to remove PHI after it receives it is "insufficient." And if a tracking vendor won't sign a BAA, HHS says you can sign one with another vendor that de-identifies the tracking data and passes only de-identified information on.
On June 20, 2024, in American Hospital Association v. Becerra, the Northern District of Texas vacated one piece of the revised bulletin: the position that HIPAA applies when tracking connects a visitor's IP address with a visit to a public, logged-out page about specific health conditions or health care providers. The court wrote that the vacatur "is not intended to, and should not be construed as, limiting the legal operability of other guidance" in the bulletin. HHS appealed, and the appeal was voluntarily dismissed on September 4, 2024, so the ruling stands. HHS's page now opens with a notice of the ruling, and its guidance on portals, booking pages, apps, BAAs and cookie banners is still there. The annotated HHS tracking bulletin goes passage by passage.
Meta and Google health ad rules
Meta's rule is in its Business Tools Terms (effective November 3, 2025), which cover the "Meta Pixel, Conversions API, Facebook SDK for App Events, Offline Conversions and App Events API." In Section 1.h you promise not to share data that "includes or is based on, directly or otherwise, health information." The names of your "events, conversions, and any custom audiences you create must not reflect, imply or be based on" it either. Sending events from a server instead of a browser does not change those terms, because the Conversions API is covered too.
If Meta has already acted on your data, start with the notice you saw: data sharing restrictions applied, purchase events restricted for health and wellness or core setup. For ad copy, see personal attributes rejections and Health and wellness rejections; and why server-side tracking does not get around a health restriction. The HIPAA-compliant Facebook ads guide covers the full Meta workflow.
Google treats Health as a sensitive interest category under its personalized advertising policy. Its Health in personalized advertising page lists personal health content such as physical or mental health conditions, treatments for chronic conditions, health issues tied to intimate body parts or functions, and disabilities. The list also names "Invasive medical procedures, including cosmetic surgery, surgical procedures, or injections." Ads in the category can't use advertiser-curated audiences: Customer Match, your data segments, audience expansion and lookalike segments. Predefined Google audiences, such as in-market, affinity and life events, still work, because Google excludes sensitive signals from them.
See what Google's health audience notice means and Healthcare and medicines disapprovals. The HIPAA-compliant Google Ads guide covers tracking, targeting and calls in one place, and Ad Account Rescue covers restriction notices platform by platform.
Which marketing tools sign a BAA
A BAA is the contract HIPAA requires before a vendor handles PHI for you; what a BAA must contain lists its terms. The BAA Directory answers the question for 120 tools from each vendor's own pages: 26 sign a BAA, 49 sign one only on specific plans or products, 30 do not, and for 15 the directory found no statement to quote. Common marketing tools, as checked between September 29 and October 7, 2026:
| Tool | Category | Signs a BAA? | What the vendor says |
|---|---|---|---|
| Meta | Ad platform | No | Business Tools Terms bar data that includes or is based on health information. |
| Google Ads | Ad platform | No | Google does not intend its call features to create HIPAA obligations. |
| TikTok | Ad platform | No | Does not allow advertisers to share health information. |
| Microsoft Advertising | Ad platform | No | No BAA for UET; keep UET tags off pages subject to HIPAA. |
| LinkedIn Ads | Ad platform | No | Ads Agreement bars Sensitive Data, including via the Insight Tag on pages that collect medical data. |
| Google Analytics 4 | Analytics | No | Google does not offer BAAs for Google Analytics. |
| Google Tag Manager | Tag manager | No public statement | Use Policy bars uploading data that personally identifies an individual. |
| HubSpot | CRM and email | Specific plans | Enterprise subscriptions with Sensitive Data turned on. |
| GoHighLevel | CRM and email | Specific plans | Paid HIPAA add-on, which includes a signed BAA. |
| Mailchimp | No | Data Processing Addendum bars health information. | |
| Jotform | Forms | Specific plans | Gold and Enterprise, with HIPAA features turned on. |
| Calendly | Scheduling | No | No BAA currently offered; not intended for collecting PHI. |
| CallRail | Call tracking | Specific plans | Signs with each of its Healthcare plan clients. |
| Webflow | Website builder | No | Terms say it does not offer HIPAA compliant services. |
| Curve Compliance | HIPAA ad tracking | Yes, every plan | Signs before live tracking begins. |
A BAA covers only the vendor that signs it and the services it lists, so check each tool; a Google Workspace BAA, for example, does not extend to Google Ads or Google Analytics. And a BAA with your form or scheduling tool does not cover an ad pixel on the same page, because the pixel sends data to a different company. For email and automation platforms, see HIPAA-compliant marketing automation: who signs a BAA. Vendors change their terms, so confirm them before you send PHI.
A HIPAA-compliant marketing checklist
- Map where PHI can appear: forms, booking pages, symptom checkers, portals and apps.
- Get a signed authorization before any PHI is used or disclosed for marketing.
- Take browser ad pixels off pages that can see PHI and send conversions server-side through a vendor that signs a BAA.
- Keep health information out of event names, conversions and audiences. Meta's terms bar it on every route.
- Use predefined audiences for health ads on Google.
- Sign a BAA with every tool that handles PHI.
- Don't treat a cookie banner as authorization, and cover tracking in your risk analysis, one of the obligations the bulletin lists.
How Curve Compliance does it
Curve Compliance is HIPAA-compliant ad tracking for healthcare. It signs a BAA with you and replaces browser ad pixels with one script.
- Server-side delivery. Conversions go to Meta Conversions API, Google Ads, TikTok, Microsoft Advertising and LinkedIn from Curve's servers, not from the patient's browser.
- A fixed list of fields per platform. Contact identifiers are off by default and SHA-256 hashed when on, and events can use neutral names.
- PHI-like pattern detection. Condition names, form answers and emails in URLs are flagged before data reaches an ad platform, so they can be stopped at the source.
- Event Logs show what Curve sent to each platform and what each accepted.
- Attribution through booking. The ad click is kept when a visitor books in IntakeQ, Jane App, Acuity or other schedulers, so a booking made days later still matches the ad.
- Forms, consent and replay. Curve Forms for HIPAA-hosted intake and lead forms, consent management, and session replay and heatmaps under the same BAA.
Curve's team reviews what your website sends to Meta, Google and TikTok with you, shows what is likely triggering a flag, and does the setup, typically in about a week; timing varies case by case. The Curve Compliance entry in the directory shows what Curve's BAA covers. To see which pixels your site loads today, run the free website scan.
Book a call. Curve's team will go through what your site sends to Meta, Google and TikTok today and set up HIPAA-compliant conversion tracking, with a BAA signed on every plan. Book a call with Curve.
Sources (checked October 8, 2026): 45 CFR 164.501 and 45 CFR 164.508 on eCFR; HHS OCR, Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates; American Hospital Association v. Becerra, No. 4:23-cv-01110-P (N.D. Tex. June 20, 2024) and its docket; Meta Business Tools Terms; Google Ads Help, Restricted targeting in Personalized advertising and Health in personalized advertising. Vendor BAA answers come from the BAA Directory, which quotes each vendor's own page.
Frequently Asked Questions
What is HIPAA-compliant marketing?
Marketing that gets written patient authorization before PHI is used for marketing, keeps PHI out of ad pixels and audiences, and has a BAA with every vendor that handles PHI. Curve Compliance runs HIPAA-compliant ad tracking under a BAA on every plan.
Is HIPAA-compliant digital advertising possible?
Yes. HIPAA does not ban advertising; it limits what you do with PHI. Keep PHI out of targeting, send conversions server-side with neutral event names, and use predefined audiences for health ads on Google. Curve Compliance runs the conversion tracking under a BAA.
Do I need a BAA with Google or Meta?
Neither signs one for advertising. Meta's Business Tools Terms bar health information, Google offers no BAA for Google Analytics and disclaims HIPAA obligations for its Google Ads call features, and a Google Workspace BAA does not extend to Google Ads. So send them no PHI, through a vendor that signs a BAA with you.
Are tracking pixels allowed on a healthcare website?
On some pages. HHS says tracking on pages such as job postings or visiting hours generally involves no PHI. On logged-in pages, booking pages, symptom checkers and apps, a pixel can disclose PHI. Ad platforms don't sign a BAA, so the workable route is to take their pixels off those pages and send conversions server-side, with no health information in the events.
Does a cookie consent banner count as HIPAA authorization?
No. HHS says these banners "do not constitute a valid HIPAA authorization." A valid one meets 45 CFR 164.508(c), including the patient's signature and date.
Can I upload a patient list to Meta or Google for ads?
Meta's terms say custom audiences "must not reflect, imply or be based on" health information, and Google bars Customer Match and other advertiser-curated audiences for ads in its Health category. Under HIPAA, using PHI for marketing also needs each patient's authorization.
Did AHA v. Becerra make pixels HIPAA compliant?
No. The court vacated one piece of the HHS bulletin, about IP addresses on public pages about health conditions or providers, and wrote that the vacatur does not limit the rest. The guidance on booking pages, portals, apps and BAAs stands.
Does Curve Compliance sign a BAA?
Yes, on every plan, before live tracking begins. Curve's team does the setup, typically in about a week. Book a call to get started.
Related articles
Check your own site
See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.
Stay Compliant. Scale Confidently.
Curve's team sets up HIPAA-compliant ad tracking for you, and most customers are live in about a week.
Book a free tracking audit