Notes
HIPAA-Compliant Email Marketing: What a Clinic Can Actually Send
Email marketing is used compliantly when the list was built with proper consent, the message reveals nothing about an individual's condition, the segment itself is not derived from health information, and the platform has signed an agreement covering the sending features you use. The platform is the easiest part. The list and the subject line are where clinics get into trouble.
Key takeaways
- A general newsletter to patients is usually fine. A campaign segmented by procedure received is usually not.
- The subject line is visible on a lock screen. Treat it as public.
- Segmenting by condition or treatment makes the segment itself health information, whatever the email says.
- Marketing sends are often excluded from a platform's covered services even when a BAA exists.
- Marketing communications about products or services can require authorization under the HIPAA marketing rules.
Contents
Your practice has three thousand past patients and an email platform. Somebody suggests a campaign to everyone who had a particular procedure last year. It is the obvious idea, and it is the one to be careful with.
I am a marketing consultant and not a lawyer. This is a map for your privacy officer.
What makes clinic email compliant?
Clinic email is compliant when four things hold: the recipient consented in a way you can evidence, the content discloses no individual health information, the segmentation is not itself built from health information without authorization, and the sending platform has an agreement covering those features. HHS sets out the underlying requirements under business associates, and the HIPAA marketing provisions govern when authorization is needed for promotional messages.
What is safe to send, and what is not
| Message | Safe? | Why |
|---|---|---|
| Practice newsletter on general topics | Yes | No individual health information involved |
| Appointment reminder with no reason for visit | Usually | Minimum necessary, commonly permitted |
| "Time for your implant follow-up" | No | Reveals a condition in the subject line |
| Campaign segmented by procedure received | Not without authorization | The segment is health information |
| Recall by date, with no condition named | Yes | Nothing about the person's health |
| Review request after any visit | Yes | Keep it generic, and never incentivised |
The fourth row is the one that surprises people. Even if the email text is neutral, building the audience from "patients who had procedure X" uses health information to decide who receives marketing, and that is what the rules address.
Where the risk actually sits
Five places, in rough order of how often they cause trouble: how the list was built and who can export it; whether the segment was derived from clinical data; what the subject line says on a lock screen; whether the platform's agreement covers the sending features; and whether tracking links carry parameters that reveal the topic to third parties.
That last one connects to the wider website question in is Google Analytics HIPAA compliant, and the storage question to HIPAA-compliant CRM.
Platforms and what to ask them
I am not listing vendor verdicts. Terms change, and most "HIPAA-compliant email" pages are marketing rather than legal documents. Ask these five questions of any platform:
- Will you sign a business associate agreement on the plan I am buying?
- Which features are covered services, and are marketing sends among them?
- Are AI writing, prediction and enrichment features covered, or excluded?
- Can I restrict who can export a list, and is that logged?
- Can I disable link tracking parameters that would reveal the campaign topic?
Question two is where several well-known platforms quietly say no: a BAA exists, but transactional messages are covered and marketing campaigns are not.
What goes wrong
| Cause | What actually happens | Hidden cost | What you see | Risk level |
|---|---|---|---|---|
| Segmenting by procedure or condition | Health information used to target marketing | The campaign itself is the exposure | A list named after a treatment | High |
| Condition named in the subject line | Visible on a lock screen to anyone nearby | A disclosure with no technical fix | Subject lines that read like a chart | High |
| BAA covers transactional sends only | Marketing campaigns fall outside it | The agreement protects the wrong half | "Marketing is a separate product" | High |
| List exported to a spreadsheet | PHI leaves every control you built | Untraceable copies | Exports nobody logged | High |
| Purchased or appended lists | No consent, possibly no relationship | Regulatory and reputational | Sudden list growth | High |
| Tracking parameters naming the campaign | Topic revealed to third parties | Undoes an otherwise clean setup | utm_campaign=implant-recall | Medium |
What it costs
| Route | Typical cost | Time | What it depends on |
|---|---|---|---|
| Reconfigure your current platform | Staff time | Days | Whether marketing sends are covered |
| Move to a platform that covers them | Subscription plus migration | Weeks | List size and integrations |
| Keep campaigns generic by design | Nothing | Immediate | Discipline on segmentation |
| I review the marketing side | Audit at $500 per ad account with a 90-day plan, credited toward the first month | Scoped in the audit | Platform, list sources, tracking |
The audit covers your ad account, the tracking and the path from enquiry to booked patient, and ends with a 90-day plan. It is credited toward the first month if you continue with me.
You work with me directly. There are no account managers and no juniors.
Read your subject lines on a lock screen
Take your last five campaigns and read the subject lines the way a phone displays them, next to the name of your clinic. Then ask how each audience was built. Those two checks catch almost everything that goes wrong here, and neither needs a lawyer. For the automation side, see HIPAA-compliant marketing automation, or start with the audit.
Frequently asked questions
Can a clinic send marketing emails to patients?
Yes, with consent and without disclosing individual health information. Certain promotional messages require authorization under the HIPAA marketing rules, so check the category before sending.
Is Mailchimp or a similar platform HIPAA compliant?
Compliance is a property of the agreement and the configuration, never of the product. Ask whether a BAA is offered on your plan and whether marketing sends are inside the covered services.
Can I segment my list by treatment?
Not without authorization. The segment is built from health information even if the email content is neutral.
What about appointment reminders?
Reminders are generally permitted as part of treatment, provided they do not reveal more than necessary. Keep the reason for the visit out of the subject line.
Are review requests allowed?
Yes, if generic and not incentivised. The FTC's rule on consumer reviews and testimonials applies to incentives regardless of HIPAA.
Do we need consent for a newsletter?
You need a lawful basis and an evidence trail, plus an unsubscribe mechanism. In practice, a consent record at intake is the cleanest route.
Who does the work if I hire you?
I review the marketing side: lists, segmentation, tracking parameters and what reaches ad platforms. Platform agreements stay with you and your compliance partner.
How do I verify a campaign is safe?
Read the subject line as if it appeared on a stranger's lock screen, then ask how the audience was built. If either answer involves a condition, stop.