Peptide and Hormone Clinic Ads: Policy Boundaries
Peptide and hormone clinics can advertise, but not by naming the compound. What Google and Meta actually restrict, and how to track the funnel without exposing PHI.
Peptide and hormone clinics can advertise on Google and Meta, but only inside a narrow lane: you can promote the consultation, the clinic, and the category of care, and you generally cannot promote the specific compound. That single distinction explains most disapprovals in this vertical. Curve is the HIPAA-compliant tracking and analytics layer that lets these clinics measure the resulting funnel without sending a prospective patient's treatment interest to an ad platform, with a signed Business Associate Agreement on every plan.
Why this category is harder than it looks
Most clinic owners assume the problem is a keyword list. Remove a few words, get approved, move on. The reality is that three separate rule systems apply to the same ad at the same time, and they fail in different ways.
The first is drug policy. Ad platforms restrict who may promote prescription drugs at all, and they restrict harder when a product has no FDA approval for the use being advertised. The second is sensitive category policy, which limits how you may target and personalize when the subject matter concerns health. The third is the privacy layer, which has nothing to do with approval and everything to do with what your website transmits about the person reading it. A clinic can be perfectly compliant with the first two and still be carrying serious exposure on the third.
Peptides sit awkwardly in all three. Many are compounded, several are marketed for uses that have not been approved, and the audience research that makes these campaigns work is exactly the kind of health inference the platforms restrict.
What Google restricts
Prescription drug terms and certification
Google gates promotion of prescription drugs behind certification, and certification is limited to specific entity types in specific countries. A clinic that is not certified should assume that naming a prescription compound in ad copy, in a keyword, or on the landing page it points to is a disapproval risk. This is not limited to the ad text. Google reviews the destination, and a landing page that opens with the compound name will attach the same policy problem to an ad whose copy was clean.
Unapproved and speculative substances
Google maintains policy against advertising unapproved pharmaceuticals and supplements. Peptides marketed for performance, recovery, longevity, or fat loss frequently land here, particularly when the copy names a compound that is sold elsewhere as "research use only." Reviewers are not weighing your clinical intent. They are pattern matching against a substance list.
Personalized advertising and health inference
Google's personalized advertising policy restricts targeting built on inferred health status. In practice this rules out remarketing audiences defined by visits to pages about a specific hormone or treatment, and custom audiences assembled from patient lists in ways that imply a condition. The safe pattern is to target intent and geography, not diagnosis.
Landing page experience
Frequently overlooked and frequently the actual cause. Aggressive claims, missing risk information, unclear provider identity, and pricing that appears only after a quiz all degrade the page in review. Two clinics with identical ad copy can get opposite outcomes because one landing page names the physician and the clinical process and the other reads like a supplement store.
What Meta restricts
Meta requires prior authorization for prescription drug advertising, and it admits only pharmaceutical manufacturers, online pharmacies, and telehealth providers. If your clinic does not fit one of those descriptions, prescription drug promotion is closed to you regardless of how the copy is written. Many peptide and hormone clinics do qualify as telehealth providers, and it is worth checking before assuming you are locked out.
Beyond authorization, Meta's rules bite in three familiar places. Personal attributes policy prohibits copy that asserts or implies knowledge of the reader's health status, which is why "your testosterone is low" fails and "learn about low testosterone" passes. Meta also rejects branded pharmaceutical weight-loss terms and most before-and-after weight-loss imagery, which matters for any peptide clinic whose funnel touches body composition. And targeting options based on sensitive health categories are restricted, which removes the interest-based audiences most clinics reach for first.
The Meta failure mode worth internalizing is that rejections in this category often arrive without a useful reason string. You will get a generic policy citation and be left to guess whether the trigger was a word, an image, the audience, or the page. Building a copy variant matrix in advance, so you can isolate one change at a time, is more productive than appealing.
The compliant framing that actually runs
Clinics that sustain spend in this category converge on a similar structure. It is worth stating plainly because it is less restrictive than it first sounds.
- Advertise the consultation, not the compound. The offer is an evaluation with a licensed provider. What gets prescribed, if anything, is a clinical decision that happens after the ad.
- Speak to symptoms in the second person only as a question, never as an assertion. "Tired, gaining weight, sleeping badly? Talk to a provider" survives review far more often than copy that tells the reader what is wrong with them.
- Keep compound names off the ad and off the first landing page. Clinical detail belongs behind the consultation or deeper in an education section, not in the headline that a policy reviewer sees first.
- Show the clinical apparatus. Named providers, licensure, lab work, follow-up cadence. This helps with review and it helps with conversion, which is unusual for a compliance constraint.
- Balance benefit with risk on the rendered page. Not in a collapsed accordion, not on a linked page. What a person scrolling on a phone actually sees.
- Target geography and intent. Not inferred condition, not lookalikes built from a patient list you assembled by treatment type.
The exposure nobody disapproves you for
Here is the uncomfortable part. Everything above is about getting an ad approved. None of it addresses what your website sends back to the ad platform after the click, and that is where the larger legal risk sits.
A standard Meta Pixel or Google tag on a hormone clinic site sends the page URL with every event. On these sites the URL routinely names the service line, because that is how the site was built: a page for testosterone therapy, a page for a specific peptide protocol, a page for menopause care. It sends form submissions, including whatever fields the form contains. It sends a persistent identifier that ties the whole session to one browser, and it does so alongside an IP address.
Meta and Google do not sign BAAs for their advertising products. That means every one of those calls discloses an identifiable person's interest in a specific treatment to a vendor with no BAA in place. This is the mechanism behind healthcare pixel litigation that has cumulatively produced more than $100 million in settlements, and it applies whether or not your ads were ever disapproved. The claim that "we do not collect health information on the form" is rarely a complete defense, because the URL and the referrer already carried the inference.
For the underlying mechanics, see our explanation of why client-side pixels create HIPAA exposure and the direct answer on whether the Meta Pixel or Conversions API is safe for healthcare.
How Curve handles peptide and hormone clinic tracking
Curve is HIPAA-compliant ad tracking, attribution, and analytics built for healthcare. It replaces the client-side pixel with a server-side path, which creates a decision point between your site and the ad platform where none existed before.
- Server-side collection. The Curve tracking script installs in place of the Meta Pixel and Google tag. Events go to Curve's US-hosted infrastructure instead of straight to the platforms, so nothing is disclosed by default.
- Per-destination field mapping. Only fields you explicitly map are forwarded to a given destination. A URL naming a peptide protocol, a quiz answer, and a free-text symptom box all stay behind unless you deliberately map them, which you would not.
- Neutral event aliases. The ad platform receives a neutral conversion name rather than one that identifies the service line. Your Meta interface shows a conversion, not a treatment category, which also keeps the service line out of shared reporting screenshots.
- Identifier hashing. Email, phone, and name are SHA-256 hashed to each platform's conversion API requirements before anything is sent.
- Bridge tokens. Attribution survives the handoff when a prospective patient clicks out to a separate intake or booking tool such as IntakeQ, Calendly, or Jane App. This is where hormone clinic funnels normally lose the chain, because the consultation booking lives on a different domain.
- PHI-pattern detection. Payloads are monitored for PHI-shaped values such as SSNs, MRN-style identifiers, dates, and long numeric sequences, so you find out when a form field changed rather than discovering it during a legal review.
- Offline conversion uploads. Bulk upload of downstream outcomes from your CRM or EHR with click ID matching, so campaigns optimize toward patients who actually start a protocol instead of people who filled in a form.
Clean conversions forward server-side to Meta CAPI, Google Ads Enhanced Conversions, TikTok Events API, Microsoft, and LinkedIn. A signed BAA is included on every plan. If you want the technical shape of that path, see our conversion API architecture overview.
Frequently asked questions
Can we name the peptide in our ad copy at all?
Assume not, unless you hold the relevant platform certification or authorization and the compound is approved for the advertised use. Naming a compounded or unapproved peptide is one of the most reliable ways to get disapproved on both Google and Meta. Advertise the consultation instead.
Our landing page names the compound. Does that matter if the ad does not?
Yes. Both platforms review the destination as part of the ad. A clean ad pointing at a page built around a compound name inherits the page's policy problem, and it also puts that compound name into every pixel event fired on the page.
Is testosterone therapy treated differently from peptides?
Somewhat. Testosterone is an approved drug with recognized indications, so the substance itself is less likely to trip an unapproved product rule, but it remains a prescription drug subject to certification and authorization requirements. The copy constraints around asserting a reader's health status apply identically.
Can we build a remarketing audience from visitors to our hormone therapy page?
Not safely. That audience is defined by inferred health status, which sits inside the platforms' restricted personalization rules, and building it requires the pixel to have recorded who visited that page in the first place. Use geography and general intent, and let server-side conversion signal do the optimization work.
We use a separate booking tool. Does that remove the pixel problem?
No, and it usually adds an attribution problem on top. If the booking tool loads its own pixel, the exposure simply moves. If it does not, you lose the connection between ad click and booked consultation. Bridge tokens are the mechanism that keeps attribution intact without putting a pixel on the intake experience.
Does a signed BAA with our EHR cover our advertising?
No. A BAA covers the vendor that signed it. Your EHR having one says nothing about what your marketing site transmits to Meta or Google, and those two do not sign BAAs for their advertising products.
How do we know what our current setup is leaking?
Load your own landing pages with the browser network tab open and read the outbound requests to the ad platforms. Look at the URL parameter, the referrer, and any form field values in the payload. Our free scanner does a faster version of the same check.
Where to start
Separate the two problems before trying to fix either. Ad approval is a copy and landing page exercise: move the compound out of the headline, make the offer a consultation, describe symptoms as questions rather than assertions, and target place and intent rather than inferred condition. Data exposure is an architecture exercise, and no amount of copy editing touches it.
Curve handles the second. Server-side collection, per-destination field mapping, neutral event aliases, hashed identifiers, and bridge-token attribution let a peptide or hormone clinic measure its funnel properly without disclosing who is interested in what. Run the free compliance scanner against your landing pages to see what is currently being transmitted, or visit curvecompliance.com to talk through your setup.
Reviewed August 2026. This is general information, not legal or regulatory advice. Platform policies and FDA positions change; consult qualified counsel about your specific promotional materials and data practices.
Related articles
- GuideGoogle Ads for Functional Medicine Clinics: Navigating Restricted Health Categories
- GuideDental Practice Facebook Ads After Meta 2026 Restrictions: What DSOs and Solo Dentists Can Still Do
- GuideFertility Clinic Google Ads: Keyword Strategy for IVF, IUI, and Reproductive Endocrinology
- GuideUrgent Care Facebook Ads: Meta Campaign Strategies for Walk-In Clinics and Multi-Location Groups
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit