Notes

HIPAA-Compliant Email Marketing: What a Clinic Can Actually Send

Email marketing is used compliantly when the list was built with proper consent, the message reveals nothing about an individual's condition, the segment itself is not derived from health information, and the platform has signed an agreement covering the sending features you use. The platform is the easiest part. The list and the subject line are where clinics get into trouble.

Key takeaways

Contents

  1. What makes clinic email compliant?
  2. What is safe to send, and what is not
  3. Where the risk actually sits
  4. Platforms and what to ask them
  5. What goes wrong
  6. What it costs
  7. Read your subject lines on a lock screen
HIPAA-Compliant Email Marketing: What a Clinic Can Actually Send

Your practice has three thousand past patients and an email platform. Somebody suggests a campaign to everyone who had a particular procedure last year. It is the obvious idea, and it is the one to be careful with.

I am a marketing consultant and not a lawyer. This is a map for your privacy officer.

What makes clinic email compliant?

Clinic email is compliant when four things hold: the recipient consented in a way you can evidence, the content discloses no individual health information, the segmentation is not itself built from health information without authorization, and the sending platform has an agreement covering those features. HHS sets out the underlying requirements under business associates, and the HIPAA marketing provisions govern when authorization is needed for promotional messages.

What is safe to send, and what is not

What a clinic can and cannot send by email
The segment matters as much as the message.
MessageSafe?Why
Practice newsletter on general topicsYesNo individual health information involved
Appointment reminder with no reason for visitUsuallyMinimum necessary, commonly permitted
"Time for your implant follow-up"NoReveals a condition in the subject line
Campaign segmented by procedure receivedNot without authorizationThe segment is health information
Recall by date, with no condition namedYesNothing about the person's health
Review request after any visitYesKeep it generic, and never incentivised

The fourth row is the one that surprises people. Even if the email text is neutral, building the audience from "patients who had procedure X" uses health information to decide who receives marketing, and that is what the rules address.

Where the risk actually sits

Where the risk sits in healthcare email marketing
Most problems here are the list and the subject line, not the platform.

Five places, in rough order of how often they cause trouble: how the list was built and who can export it; whether the segment was derived from clinical data; what the subject line says on a lock screen; whether the platform's agreement covers the sending features; and whether tracking links carry parameters that reveal the topic to third parties.

That last one connects to the wider website question in is Google Analytics HIPAA compliant, and the storage question to HIPAA-compliant CRM.

Platforms and what to ask them

I am not listing vendor verdicts. Terms change, and most "HIPAA-compliant email" pages are marketing rather than legal documents. Ask these five questions of any platform:

  1. Will you sign a business associate agreement on the plan I am buying?
  2. Which features are covered services, and are marketing sends among them?
  3. Are AI writing, prediction and enrichment features covered, or excluded?
  4. Can I restrict who can export a list, and is that logged?
  5. Can I disable link tracking parameters that would reveal the campaign topic?

Question two is where several well-known platforms quietly say no: a BAA exists, but transactional messages are covered and marketing campaigns are not.

What goes wrong

CauseWhat actually happensHidden costWhat you seeRisk level
Segmenting by procedure or conditionHealth information used to target marketingThe campaign itself is the exposureA list named after a treatmentHigh
Condition named in the subject lineVisible on a lock screen to anyone nearbyA disclosure with no technical fixSubject lines that read like a chartHigh
BAA covers transactional sends onlyMarketing campaigns fall outside itThe agreement protects the wrong half"Marketing is a separate product"High
List exported to a spreadsheetPHI leaves every control you builtUntraceable copiesExports nobody loggedHigh
Purchased or appended listsNo consent, possibly no relationshipRegulatory and reputationalSudden list growthHigh
Tracking parameters naming the campaignTopic revealed to third partiesUndoes an otherwise clean setuputm_campaign=implant-recallMedium

What it costs

RouteTypical costTimeWhat it depends on
Reconfigure your current platformStaff timeDaysWhether marketing sends are covered
Move to a platform that covers themSubscription plus migrationWeeksList size and integrations
Keep campaigns generic by designNothingImmediateDiscipline on segmentation
I review the marketing sideAudit at $500 per ad account with a 90-day plan, credited toward the first monthScoped in the auditPlatform, list sources, tracking
AUDIT · $500 PER AD ACCOUNT

The audit covers your ad account, the tracking and the path from enquiry to booked patient, and ends with a 90-day plan. It is credited toward the first month if you continue with me.

You work with me directly. There are no account managers and no juniors.

Read your subject lines on a lock screen

Take your last five campaigns and read the subject lines the way a phone displays them, next to the name of your clinic. Then ask how each audience was built. Those two checks catch almost everything that goes wrong here, and neither needs a lawyer. For the automation side, see HIPAA-compliant marketing automation, or start with the audit.

Written by Lev Brovtsev, independent performance marketing consultant. I do the work myself. Last updated: September 2026.

Frequently asked questions

Can a clinic send marketing emails to patients?

Yes, with consent and without disclosing individual health information. Certain promotional messages require authorization under the HIPAA marketing rules, so check the category before sending.

Is Mailchimp or a similar platform HIPAA compliant?

Compliance is a property of the agreement and the configuration, never of the product. Ask whether a BAA is offered on your plan and whether marketing sends are inside the covered services.

Can I segment my list by treatment?

Not without authorization. The segment is built from health information even if the email content is neutral.

What about appointment reminders?

Reminders are generally permitted as part of treatment, provided they do not reveal more than necessary. Keep the reason for the visit out of the subject line.

Are review requests allowed?

Yes, if generic and not incentivised. The FTC's rule on consumer reviews and testimonials applies to incentives regardless of HIPAA.

Do we need consent for a newsletter?

You need a lawful basis and an evidence trail, plus an unsubscribe mechanism. In practice, a consent record at intake is the cleanest route.

Who does the work if I hire you?

I review the marketing side: lists, segmentation, tracking parameters and what reaches ad platforms. Platform agreements stay with you and your compliance partner.

How do I verify a campaign is safe?

Read the subject line as if it appeared on a stranger's lock screen, then ask how the audience was built. If either answer involves a condition, stop.

Related

Dental PPC ConsultantDental SEO That Produces Implant Patients, Not PDFsDental Implant Marketing for 5-Figure Cases