Skip to main content
Guide

Is Attentive HIPAA Compliant? Patient SMS Marketing

Attentive is not HIPAA compliant. Its own content policy prohibits protected health information outright. What that means for clinics running patient SMS marketing.

10 min read

No, Attentive is not HIPAA compliant, and the reason is stronger than a missing signature. Attentive's own content policy explicitly prohibits sending or collecting protected health information as defined by HIPAA, and its API documentation lists health information among the data types customers may not transmit. This is a contractual bar, not an oversight, so a covered entity cannot lawfully run patient SMS through it. Curve is the HIPAA-compliant tracking and attribution layer that lets healthcare marketers measure SMS-driven conversions without patient data reaching platforms that never agreed to hold it, with a signed BAA on every plan.

The direct answer, in more detail

Attentive is a conversational SMS and email marketing platform built for retail and direct-to-consumer commerce. It is very good at that. It is also unusually clear about what it will not accept.

Attentive's content policy defines Sensitive Data broadly, covering government identifiers, financial account details, biometric and genetic data, and health information. It then states directly that customers may not send or collect any protected health information as defined by HIPAA, describing that in the statute's own terms: information relating to an individual's past, present, or future physical or mental health condition, the provision of health care to an individual, or payment for that care.

The restriction is repeated at the technical layer. Attentive's developer documentation for the Custom Events API and Custom Attributes API states that identifier data cannot contain sensitive or special categories of information, and lists health information explicitly among the prohibited types.

So the verdict is not the usual "the vendor has not signed a BAA, so proceed carefully." It is that the vendor has told you in writing not to send this category of data at all. Sending it anyway is a breach of your agreement with Attentive before it is anything else, and it leaves you with no contractual protection when the question of liability arrives.

Where Attentive is genuinely fine

HIPAA applies to covered entities and their business associates. A supplement brand, a fitness company, a cosmetics retailer, or a wellness subscription box is usually neither, and the health-adjacency of the product does not by itself pull the business into HIPAA. Those companies run Attentive without a HIPAA problem.

The line is crossed when your business provides or bills for care. A telehealth company that connects patients to prescribers, a dental group, a med spa performing medical procedures, a behavioral health practice, a pharmacy: these are covered entities or work directly with them, and the identity of the people on their SMS list carries meaning that a sneaker brand's list does not.

State law narrows the safe zone further, and this catches people out. Washington's My Health My Data Act and comparable statutes reach consumer health data well beyond the HIPAA definition and apply to businesses that are not covered entities at all. A supplement brand outside HIPAA can still be inside those laws, and SMS lists built from health-topic browsing are exactly what those laws were written about.

The list itself is the disclosure

The instinct in healthcare SMS marketing is to focus on message content. Do not put a diagnosis in the text and you are fine. That instinct is wrong, and it is the single most useful thing to understand about this category.

Consider a weight-management clinic. A visitor lands on a page about GLP-1 treatment, an Attentive sign-up unit fires, and the visitor submits their phone number to get an offer. Nothing clinical was typed. But the platform now holds a phone number, an identifiable person, associated with a subscription event that originated on a page about a specific treatment. If that subscriber is then placed in a segment named after the treatment, or sent a campaign that only goes to people interested in it, the segment membership is itself a statement about that person's health interest.

That is the same theory driving healthcare pixel litigation, which has cumulatively crossed $100 million in settlements, with Advocate Aurora settling at roughly $12.225 million. Plaintiffs do not need to show that a diagnosis was transmitted. They need to show that an identifiable person's health interest was disclosed to a third party who had no right to it.

Message content matters too, of course. Appointment reminders, refill nudges, and "your results are ready" messages are unambiguous PHI. But a marketing team that only polices message bodies has policed the smaller half of the problem.

What a BAA would and would not cover here

Attentive does not offer one, so this section is partly hypothetical, but the reasoning matters when you go shopping for a replacement.

A BAA permits a vendor to receive and process PHI on your behalf and imposes safeguard, breach notification, and subcontractor obligations on them. It does not make SMS a secure channel. Text messages traverse carrier networks, land on unlocked lock screens, and sit in message histories on shared family devices. Vendors that do sign BAAs for messaging generally advise against putting clinical detail in the message body at all, recommending instead that the message carry a link to an authenticated portal. That advice is correct regardless of who signed what.

A BAA also does not address consent. SMS marketing sits under the TCPA and carrier rules, which impose their own express written consent requirements entirely separate from HIPAA. Healthcare messaging has to satisfy both regimes at once, and a HIPAA authorization is not a TCPA consent.

Finally, a BAA covers the vendor's handling of the data. It does not cover what you choose to send, how you name your segments, or what your website sends to the platform in the first place. Those are your controls to build.

The architecture that works

The workable pattern separates the marketing channel from the clinical channel and keeps the two from sharing meaning.

  • Route patient communication to a BAA-covered system. Appointment reminders, intake follow-ups, results notifications, and anything tied to an individual's care go through a vendor that has signed a BAA and is built for it. This is a different product category from marketing SMS, and treating them as one tool is where most exposure begins.
  • Keep the marketing list generic. If you run promotional SMS at all, the subscription should not encode a service line. One general list, neutral segment names, and campaign content that speaks to the practice rather than to a treatment.
  • Never sync clinical attributes into the marketing platform. Custom attributes are the quiet failure. Someone maps appointment type, medication, or eligibility status into the SMS platform so campaigns can be personalized, and PHI enters a system that contractually forbids it.
  • Decide where the sign-up unit lives. A sign-up overlay on a condition-specific landing page ties the phone number to the condition at the moment of capture. Put capture on general pages, or handle condition-specific intake through a form that lands in your BAA-covered stack.

The failure mode here, as everywhere, is convenience creep. Each individual mapping feels like a personalization win. Together they rebuild a patient database inside a marketing tool.

Where the ad tracking problem shows up

SMS platforms are not just outbound channels. They install a tag on your website to identify visitors, capture sign-ups, and fire behavioral events back into the platform. That tag sees the same page URLs and the same browsing behavior your ad pixels see.

Then the loop closes on the advertising side. Marketing teams sync SMS audiences to Meta and Google for retargeting and lookalike modeling. Meta and Google do not sign BAAs for their advertising products. An audience built from people who subscribed on a treatment page, pushed into an ad platform as a custom audience, is a disclosure of health interest to a vendor with no agreement in place, made by the marketing team rather than by anyone in compliance.

Meta's own policies add friction on top. Meta requires prior authorization for prescription drug advertising and limits it to pharma manufacturers, online pharmacies, and telehealth providers. It rejects branded pharmaceutical weight-loss terms and most before-and-after weight-loss imagery. Teams often route around those rejections by leaning harder on owned channels and audience syncs, which quietly increases the compliance exposure while reducing the policy friction.

The underlying mechanism is the same one we describe in our verdict on whether Klaviyo is HIPAA compliant for DTC health brands: the messaging platform is downstream of a collection layer that was never designed to withhold anything.

How Curve handles measurement for healthcare SMS programs

Curve is HIPAA-compliant ad tracking, attribution, and analytics for healthcare. It does not send text messages. It solves the layer underneath: knowing which campaigns produced patients, without patient data reaching platforms that have not signed for it.

The Curve tracking script installs on your site in place of the Meta Pixel and Google tag. Events go to Curve's US-hosted infrastructure rather than straight to the ad platforms. From there:

  • Per-destination field mapping controls what forwards. Only fields you explicitly map reach a given destination, configured separately for each one. Page URLs, form values, and service-line detail stay behind unless you deliberately map them. The default is that nothing goes.
  • Identifiers are hashed. Phone, email, and name are SHA-256 hashed to each platform's conversion API requirements before forwarding, which is what makes phone-based matching workable without shipping raw numbers around.
  • Neutral event aliases replace descriptive names. An SMS-driven booking can forward as a generic conversion rather than one naming the treatment, so the ad platform interface never displays the service line.
  • PHI-pattern detection monitors payloads. Curve flags PHI-shaped values such as SSNs, MRN-style identifiers, dates, and long numeric sequences. It is a monitoring layer that tells you when something upstream changed. The protection is the field mapping plus the hashing.
  • Bridge tokens preserve attribution across handoffs. When someone taps an SMS link and lands on a separate booking or intake tool, attribution normally breaks exactly when it becomes valuable. Bridge tokens carry it across.
  • Offline conversion uploads close the loop. Bulk CRM or EHR outcomes match back to the original ad click by click ID, so you can report revenue without exporting a patient list into a marketing platform.

Clean conversions forward server-side to Meta CAPI, Google Ads Enhanced Conversions, TikTok Events API, Microsoft, and LinkedIn. Because the path is server-side, it is unaffected by ad blockers and browser tracking prevention, which usually raises measured conversion volume rather than lowering it. Every Curve plan includes a signed BAA. For the routing side of this, see our guide to HIPAA-compliant lead routing from ad click to CRM.

What to check in your own SMS program

  1. Read your segment and list names as evidence. If a segment name would tell a stranger something clinical about everyone in it, rename it and rebuild the logic.
  2. Audit every custom attribute synced into the platform. Appointment type, medication, provider, and eligibility status are the usual offenders.
  3. Check where sign-up units appear. Condition-specific landing pages tie the phone number to the condition at capture.
  4. Separate transactional patient messaging from marketing entirely and confirm the transactional vendor has signed a BAA.
  5. Review every audience sync to an ad platform. Ask what the audience membership implies about the people in it.
  6. Watch the network tab during a test sign-up and read what actually leaves for third-party domains.
  7. Confirm your consent capture satisfies TCPA independently of any HIPAA analysis. They are separate obligations.

Frequently asked questions

Does Attentive sign a BAA for healthcare customers?

Attentive's published policies prohibit protected health information rather than provide for it, and we found no public commitment to sign a BAA. If your situation depends on the answer, ask Attentive directly and get it in writing, because published policies can change.

Can I use Attentive if my text messages never mention a condition?

Not safely, if you are a covered entity. The prohibition is on the data, not only the message body. A phone number tied to a treatment-page sign-up or a condition-based segment is health information about an identifiable person, whatever the message says.

We are a supplement brand. Does this apply to us?

Probably not under HIPAA, since you are unlikely to be a covered entity. State consumer health privacy laws reach further and apply to businesses outside HIPAA entirely, so the list hygiene described here is still worth applying.

Is appointment reminder texting the same question?

No, and it is a more clear-cut one. Appointment reminders are patient communication tied to an individual's care, which is squarely PHI. That belongs in a system whose vendor has signed a BAA and is designed for clinical messaging, not in a marketing SMS platform.

What happens to campaign measurement if I stop syncing audiences to ad platforms?

Conversion optimization is unaffected, because it runs on conversion events and hashed matching keys rather than audience lists. You lose retargeting audiences built from health-topic behavior, which you should not be running anyway. Server-side conversion delivery typically improves match rates and measured volume.

Can consent from the patient fix this?

A HIPAA authorization can permit specific disclosures, but it has to be specific, informed, and documented, and it does not create a business associate relationship where the vendor has contractually refused to accept the data. Consent is not a workaround for a vendor prohibition.

Where to start

Attentive is a capable SMS marketing platform that has told its customers in writing not to send protected health information through it. For a covered entity that is a clear answer: route patient communication to a vendor built for it, keep any promotional list generic, and stop syncing clinical attributes and health-derived audiences into marketing tools.

What remains is the measurement problem, and that is what Curve solves. Server-side collection, per-destination field mapping, hashed identifiers, neutral event aliases, and bridge-token attribution let you prove which campaigns produced patients without a single identifiable health signal reaching a platform that never agreed to hold it. A signed BAA is included on every plan. Run our free compliance scanner against your site to see what is leaving right now, or visit curvecompliance.com to talk through your stack.

Reviewed August 2026. Vendor BAA policies change. Confirm current terms with the vendor.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit