Written by: Aaron Rovner, Founder, Saas Hero | Last updated: September 6, 2026

Key Takeaways

  • HIPAA compliance now shapes every marketing pixel, vendor contract, and email platform used by B2B healthtech teams, driven by the 2025 Security Rule overhaul and FTC enforcement actions.
  • The 5 Pillars framework (Authorization, BAA, Data Minimization, Secure Channels, and Vendor Management) gives you a clear way to evaluate every campaign and vendor relationship before data flows.
  • Key 2026 regulatory updates include proposed mandatory MFA and encryption under the HIPAA Security Rule, plus the FTC Health Breach Notification Rule treating unauthorized data disclosures as breaches.
  • Channel-specific compliance requires BAA-covered platforms for email, server-side tracking without client-side pixels on health-revealing pages, and strict avoidance of patient data uploads to ad platforms like LinkedIn and Google.
  • Schedule A Discovery Call to discuss how SaaSHero builds HIPAA-compliant growth programs for B2B healthtech companies.

HIPAA Compliant Marketing For Healthtech: Core Concepts And The 5 Pillars Framework

HIPAA compliant marketing in healthcare means promoting products or services while strictly protecting Protected Health Information (PHI) under federal law. Several definitions guide every decision in this space.

PHI includes any of 18 identifiers such as names, email addresses, IP addresses, and dates combined with health information. A user’s health condition combined with their email address counts as PHI.

Covered Entity means health plans, clearinghouses, and providers transmitting health data electronically. Most B2B healthtech companies function as Business Associates when a Covered Entity uses their product and PHI flows through it.

Business Associate Agreement (BAA) is a contract required before any vendor creates, receives, maintains, or transmits PHI on your behalf.

Marketing Vs. Healthcare Communications follows a simple rule: promotional messages using PHI require written patient authorization, while treatment communications are exempt.

The remainder of this guide uses The 5 Pillars Of HIPAA-Compliant Healthtech Marketing as the backbone and then applies them to regulations, channels, and vendor management.

  1. Authorization: obtain valid written consent before using PHI for marketing.
  2. BAA: execute vendor contracts before any PHI flows.
  3. Data Minimization: collect and transmit only what is necessary.
  4. Secure Channels: use encrypted, BAA-covered infrastructure for all PHI.
  5. Vendor Management: audit and document every third-party relationship.

2026 Regulatory Updates Every Healthtech Marketer Must Know

The HIPAA Security Rule Rewrite (Proposed, Not Yet Final). The NPRM published January 6, 2025 would introduce mandatory changes to the HIPAA Security Rule that 2026 planning should address:

  • Make multi-factor authentication mandatory across all systems, removing the “addressable” category.
  • Require encryption of all ePHI at rest and in transit.
  • Mandate vulnerability scanning every 6 months and annual penetration testing.
  • Require written technology asset inventories and network maps.
  • Set a 72-hour critical system restoration requirement.

Important: As of September 2026, the final rule has not been published. The latest Unified Agenda projects final action in July 2027, with compliance likely required by early 2028. These provisions are not current mandates. Organizations that prepare now will face lower implementation costs and lower risk when the rule finalizes.

The FTC Health Breach Notification Rule (In Effect Since July 29, 2024). The amended HBNR treats unauthorized disclosures, not just hacks, as breaches. The FTC’s position is clear: sharing identifiable health data with Meta, Google, or any ad platform without explicit consent violates both the FTC Act and the HBNR. The enforcement record confirms this pattern: GoodRx paid a $1.5M penalty, BetterHelp issued $7.8M in consumer refunds, Premom paid $200K, and Cerebral paid over $7M. On July 29, 2026, the FTC, the State of Utah, and Los Angeles County filed a complaint against Hims & Hers alleging the company shared customer lists identified by health condition with Meta and Snap for targeted advertising. This complaint signals accelerating enforcement activity.

Understanding what counts as “marketing” under HIPAA is the first step to knowing which of your communications require authorization.

Marketing Vs. Healthcare Communications: What Requires Authorization

Under the HIPAA Privacy Rule (45 CFR 164.508), marketing means “a communication about a product or service that encourages recipients to purchase or use the product or service.” Using PHI for these communications requires written patient authorization.

The following communications are exempt from authorization:

  • Appointment reminders and recall notices.
  • Treatment follow-ups and care coordination.
  • Refill reminders when payment is reasonably related to communication cost.
  • Face-to-face communications and nominal-value gifts.
  • Communications about the covered entity’s own health-related products or services.

The following activities require authorization:

  • Promotional emails about new products or services sent to patient lists.
  • Testimonial or before/after photo publication.
  • Using patient lists to build lookalike audiences on ad platforms.
  • Segmenting campaigns by diagnosis or treatment history.

B2B healthtech marketers selling to providers rather than patients still must protect PHI. Your platform must never transmit PHI from your provider clients’ patients to advertising tools, and your own marketing stack must use the 5 Pillars to prevent that transmission.

Channel-Specific Compliance Playbook

Each marketing channel carries distinct PHI risks. The following playbook applies the 5 Pillars to the four channels where B2B healthtech teams most often expose PHI: email, LinkedIn, Google Ads, and web analytics.

HIPAA Compliant Email Marketing

Email is the channel where BAA gaps are most common and most consequential. The following 5 steps form the core program, and a compliant setup also requires separating marketing email from patient-communication email at the architectural level.

  1. Use an email platform that signs a BAA. HubSpot offers a BAA only on its Enterprise tier with specific add-ons; Mailchimp and ActiveCampaign do not offer BAAs and must not carry PHI.
  2. Keep PHI out of subject lines and email bodies. Use generic copy with secure portal links, such as “You have a new message from your care team.”
  3. Segment promotional campaigns by stated preferences and engagement only. Avoid segmentation by diagnosis or treatment history.
  4. Obtain written authorization before sending any PHI-driven promotional content. A generic intake consent form does not satisfy this requirement.
  5. Authenticate with SPF, DKIM, and DMARC to prevent spoofing and protect deliverability.

A practical architecture separates marketing email, which includes newsletters, educational content, and event invites with no PHI by design, from patient-communication email, which includes appointment confirmations, results, and treatment messages. Marketing email can run on a non-BAA platform, while patient-communication email must use a BAA-covered platform with encryption at rest and audit logs.

While email is the most common BAA gap, social advertising introduces its own risks, especially around audience targeting.

LinkedIn And Social Ads

LinkedIn functions as a demand-creation channel for most B2B healthtech teams. The compliance rules for social advertising are straightforward but frequently violated:

  • Avoid uploading patient lists, including hashed emails, as custom audiences. Hashing does not constitute de-identification under HIPAA if the hashed value can be re-linked to a patient record, and the BetterHelp enforcement action confirmed that hashed emails passed from a health-context list to Meta can still fuel lookalike audiences.
  • Use first-party data and lookalike audiences built from non-PHI sources such as your own employee lists or prospect lists from purchased firmographic data.
  • Confirm that LinkedIn does not sign BAAs for its advertising products, and verify before deploying the LinkedIn Insight Tag on any page that could reveal health context.
  • For B2B healthtech selling to providers, target by firmographic criteria such as hospital size, title, and region, never by patient data.

For a deeper dive into LinkedIn-specific execution for healthtech, see SaaSHero’s guide to healthtech LinkedIn marketing. Google Ads presents a different set of constraints, since Google does not offer a BAA for its advertising products.

Google Ads And Retargeting

Google does not offer a BAA for Google Ads or Google Analytics. The compliance architecture for paid search follows a clear set of rules:

Analytics completes the channel picture and requires its own architecture.

HIPAA Compliant Analytics For Healthtech

HIPAA compliant analytics for healthtech requires a shift away from client-side tracking on health-revealing pages. The compliant architecture has five components:

Working With Vendors And BAAs: Practical Checklist For Healthtech Teams

Every vendor that creates, receives, maintains, or transmits PHI on your behalf must sign a BAA before any data flows. This group includes email platforms, analytics tools, CRMs, form vendors, and scheduling systems. Marketing agencies that produce ads and report on aggregate performance generally do not need a BAA, but agencies that can access your CRM or patient data do.

For a comprehensive guide to vetting HIPAA-compliant marketing agencies, see SaaSHero’s HIPAA Marketing Agencies: 2026 Vetting Guide & Shortlist.

The following BAA checklist applies to every vendor relationship in a healthtech marketing stack and reflects the Vendor Management pillar:

  • Confirm the BAA covers the specific product you use. Google’s Workspace BAA does not cover GA4 or Google Ads.
  • Verify the vendor contract prohibits using your PHI for the vendor’s own marketing purposes.
  • Ensure subcontractors are bound by the same terms.
  • Document breach notification procedures and timelines.
  • Review BAAs annually and after any material change in vendor services.

Talk With SaaSHero About Vendor Management to see how BAA oversight fits into a full growth program.

Common Violations And How To Avoid Them

The table below maps frequent compliance failures to their compliant alternatives. Use it as a quick audit checklist for your current marketing stack.

Common Violation Compliant Alternative
Meta Pixel on patient portal or booking pages Server-side tracking with PHI scrubbing, with no client-side pixels on sensitive pages
Uploading patient email lists to ad platforms for lookalike audiences First-party data from non-PHI sources and contextual targeting
Using Mailchimp or ActiveCampaign for patient communications BAA-covered platform such as HubSpot Enterprise or Twilio with HIPAA configuration
Segmenting promotional emails by diagnosis or treatment Segmentation by stated preferences and engagement only
Responding to reviews by confirming patient status Generic response routing to a private channel, without confirming identity or describing care

Illustrative Scenarios: How B2B Healthtech Companies Stay Compliant

Consider how three different types of B2B healthtech companies apply these principles across channels and vendors.

Scenario 1: Telehealth Platform (Mid-Market). A telehealth SaaS selling to hospital systems runs LinkedIn ads targeting healthcare administrators using only firmographic data such as hospital size, title, and region, never patient data. Their website uses server-side tracking with a BAA-covered analytics platform, and conversion events are stripped of PHI before reaching Google Ads via offline conversion imports.

Scenario 2: Medical Device SaaS (Growth Stage). A medical device software company runs email marketing to existing provider clients, segmenting by product usage and engagement rather than patient outcomes. Their email platform signs a BAA, and all promotional content avoids referencing patient-specific data.

Scenario 3: Health Data Analytics Firm (Enterprise). An analytics company handling PHI for multiple health systems uses a Customer Data Platform that signs a BAA and de-identifies data before passing it to advertising platforms. This setup follows the OCR-sanctioned intermediary model that allows clean conversion signals to reach ad platforms without transmitting ePHI.

Frequently Asked Questions

What Is The New HIPAA Rule In 2026?

The proposed HIPAA Security Rule update, described in the regulatory updates section above, would mandate MFA and encryption and add testing, inventory, and restoration requirements. As of September 2026, the final rule has not been published, and the latest Unified Agenda projects final action in July 2027 with compliance likely required by early 2028. Early preparation reduces both implementation cost and operational risk.

What Are The Requirements For HIPAA Authorization For Marketing?

A valid marketing authorization under HIPAA must be written in plain language and include a description of the PHI to be used or disclosed, the purpose of the marketing communication, the identity of who may disclose and receive the PHI, an expiration date or event, the patient’s signature and date, a statement of the right to revoke, and the consequences of refusing to sign. If third-party remuneration is involved, meaning a company paid the covered entity to send the communication, the authorization must explicitly state that payment was received. Organizations must retain authorizations for at least six years and keep them separate from general treatment consent forms.

Which Marketing Activities Do Not Require Patient Authorization?

Communications such as appointment reminders and treatment follow-ups are exempt from HIPAA’s marketing definition and do not require written patient authorization, as listed in the earlier section on Marketing Vs. Healthcare Communications. For B2B healthtech companies selling to providers rather than patients, these exemptions apply to your provider clients’ patient communications. Your own marketing stack still must prevent PHI from reaching ad platforms or non-BAA-covered vendors.

How Do I Track Website Visitors Without Violating HIPAA?

The compliant architecture for HIPAA-safe analytics uses the same five components outlined in the analytics section. First, remove client-side pixels such as Meta Pixel, GA4, Hotjar, Microsoft Clarity, and the LinkedIn Insight Tag from any page that could reveal health context, including condition pages, booking flows, intake forms, and patient portals. Second, implement server-side tracking via a gateway on BAA-covered infrastructure, where you control what data leaves before it reaches any external destination. Third, scrub outbound data at the server layer by stripping health-revealing URLs, page titles, IP addresses, and form values before forwarding events to analytics or ad platforms. Fourth, use analytics platforms that sign BAAs for the specific product you use, and upload only stripped conversion events such as click ID plus a non-PHI conversion category to ad platforms via offline conversion imports. Finally, document suppression rules, consent logs, and data flow maps so you can demonstrate your compliance program.

What Is The FTC Health Breach Notification Rule?

The FTC Health Breach Notification Rule (HBNR), codified at 16 CFR Part 318 and amended in April 2024 with an effective date of July 29, 2024, requires vendors of personal health records and related entities not covered by HIPAA to notify individuals, the FTC, and in some cases the media when there is a breach of unsecured individually identifiable health information. The 2024 amendments clarified that unauthorized disclosures, including sharing data with advertising platforms, constitute breaches, not just hacking incidents. For breaches affecting 500 or more individuals, notice to the FTC and affected individuals is due together, no later than 60 days after discovery. As noted earlier, the FTC treats unauthorized disclosures as breaches, and enforcement actions have centered on sharing data with ad platforms.

Do I Need A BAA With My Marketing Agency?

You need a BAA with your marketing agency only when the agency creates, receives, maintains, or transmits PHI on your behalf. Agencies that produce ads, manage campaigns, and report on aggregate performance generally do not need a BAA because they do not see PHI. When an agency has access to your CRM, patient data, booking systems, or any platform that contains PHI, a BAA is required before that access is granted. The practical test is whether the agency can see identifiable patient information in the course of doing its work. If the answer is yes, a BAA must be in place before any data flows.

Conclusion: Compliance As An Execution Discipline

HIPAA compliant healthtech marketing is an operational discipline that touches every channel, vendor, and measurement decision a B2B growth team makes. The 5 Pillars framework (Authorization, BAA, Data Minimization, Secure Channels, and Vendor Management) provides a structure to evaluate every campaign and vendor relationship before data flows.

The 2026 regulatory environment makes this discipline non-negotiable. FTC and other regulators have collected over $100 million in penalties from health-data privacy cases since 2023, with tracking pixels at the center of every major action. The proposed HIPAA Security Rule overhaul will raise the technical bar further when it finalizes. Marketers who thrive will build compliance into channel execution, vendor management, and measurement architecture instead of pausing growth while they react.

B2B healthtech companies that need a growth team fluent in HIPAA and capable of executing compliant campaigns across paid media, creative, landing pages, and reporting can rely on SaaSHero. The team brings eight years of B2B SaaS experience and a CRM-data-driven approach that aligns with HIPAA’s data minimization principles. SaaSHero manages the full acquisition engine, including paid search, paid social, creative, landing pages, and attribution, so you do not have to coordinate compliance across multiple vendors.

Get A Free Consultation On Your 2026 Pipeline Goals and see how SaaSHero builds HIPAA-compliant growth programs for B2B healthtech teams.

Read Next