GoodRx told its users it would never share their health data with advertisers, then uploaded lists of people who had bought heart and blood pressure medication to Facebook. The FTC fined it $1.5 million. That case is the clearest picture of healthcare marketing compliance going wrong: nobody set out to break a law, a marketing tool simply sent data somewhere it shouldn't.
Three bodies of rules matter to a practice or healthcare brand: HIPAA's marketing provisions, HHS guidance on website tracking, and the FTC's standards for claims and data sharing. Each one fails in a different place.
Healthcare marketing compliance starts with what counts as marketing
Under HIPAA, marketing means a communication about a product or service that encourages the recipient to buy or use it, as the HIPAA Journal's breakdown of the marketing rules sets out. The definition is broad on purpose, and it separates marketing from treatment and payment.
That separation is where mistakes begin. A message that feels like patient care to your clinical team can still be marketing in the legal sense.
Your team should be able to answer one question about every campaign: is this a communication about a product or service, and does it use information that identifies a patient? If both answers are yes, you're in authorization territory.
When you need a patient's written authorization
You need written authorization before using or disclosing protected health information (PHI) for marketing, with two exceptions: face-to-face communications made directly to the individual, and promotional gifts of nominal value. That's the rule as summarized by the HIPAA Journal.
A second rule is stricter. You can't disclose PHI to another organisation in exchange for direct or indirect remuneration so that organisation can market its own products.
Several things don't need authorization because they count as healthcare operations:
- Refill reminders
- Recommendations for alternative treatments or providers
- Descriptions of health-related products or services, and payment information
- Case management and care coordination
Email is where most practices test these lines. Our guide to what HIPAA requires of healthcare email marketing walks through which messages sit on which side.
The same sources point out that HIPAA isn't the only layer. FDA rules apply to drugs, devices and supplements, the FTC Act bars deceptive practices, and state opt-in and opt-out requirements sit on top.
Tracking pixels and analytics on your website
Your website is the highest-risk marketing asset you own, because the tools that make advertising measurable are the same tools that move visitor data to outside companies. The guidance treats a business associate agreement (BAA) as mandatory wherever PHI is involved.
HHS issued its first bulletin on online tracking technologies in December 2022. A revision in March 2024 narrowed it after criticism that the original was overly broad, according to Dentons' summary of the revised guidance.
The revision matters in practice. Pages that don't require a login don't automatically trigger HIPAA. A hospital's job listing or visiting hours page generally involves no PHI. But an unauthenticated symptom checker or scheduling tool may pass PHI to a tracking vendor.
The revised guidance also says that connecting a device's IP address to a visit to a page about a specific health condition isn't, on its own, enough to count as individually identifiable health information. Without further health-related data, that's a narrower exposure than many marketers feared.
So the audit is by page and by tool, not site-wide. List every tracker, then ask what each one can see on the booking form, the intake form and any symptom tool.
If a vendor refuses to sign a BAA, the guidance allows an intermediary such as a customer data platform that will sign one and de-identify the data before it reaches the vendor. Pick the intermediary before launch, not after a complaint.
What the FTC enforces beyond HIPAA
The FTC polices what you say and what you do with data, whether or not HIPAA applies to you. Three areas produce most of the exposure.
Health claims need evidence
Any claim about efficacy or safety needs what the FTC calls competent and reliable scientific evidence. In its health products compliance guidance, the agency defines that as tests, analyses, research or studies conducted objectively by experts in the relevant field and generally accepted as reliable.
Randomized, controlled human trials are generally the most reliable form of proof. Animal and lab studies alone aren't enough, and anecdotes and consumer surveys never substantiate a health claim.
For an ad that says a treatment "works", the question is whether you could hand over the trial that shows it.
Testimonials and endorsements
A testimonial can't carry a claim you couldn't make yourself. The FTC's guidance states that advertisers shouldn't make claims through testimonials or expert endorsements that would be deceptive or unsubstantiated if made directly.
If a patient's result is better than what's typical, you have to disclose clearly what people can expect. Any material connection between an endorser and the advertiser has to be disclosed clearly and conspicuously.
That includes the free consultation you gave in return for a review, and the influencer you pay to post.
Sharing health data with advertisers
The GoodRx order is the template. According to the FTC's February 2023 announcement, the company shared health information with Facebook, Google, Criteo, Branch and Twilio, despite promising not to. It was also charged with failing to notify consumers, the FTC and the media of those disclosures under the Health Breach Notification Rule.
The order permanently bars GoodRx from sharing health data with third parties for advertising. It also requires express written consent for any other sharing, bans the use of dark patterns to obtain that consent, and makes the company direct third parties to delete the data already shared.
Notice that GoodRx was found to have broken its own privacy promises. Your privacy policy is a marketing claim too, and it has to match what your ad tags do.
A pre-launch check for any healthcare campaign

Photo by Gustavo Fring on Pexels
Run this before a campaign goes live, and again whenever a new tag or vendor is added:
- Does the message encourage someone to buy or use a service, and does it draw on patient information? If yes, confirm you have written authorization.
- Is any PHI leaving your systems for an advertising or analytics vendor, and is there a BAA or an authorization behind it?
- Can every efficacy or safety claim be backed by the kind of evidence the FTC describes?
- Are testimonials typical, or do they carry a disclosure of typical results? Are material connections disclosed?
- Does your privacy policy say what your tags actually do?
The channel changes where each question bites. Paid search and social carry their own traps, which we cover in building a compliant healthcare Google Ads strategy and our practical guide to healthcare social media marketing.
Building compliance into the marketing stack
Retrofitting compliance is slower than designing for it. Decide up front which forms collect PHI, which pages carry trackers, and who signs off on claims, and the campaign work after that gets faster.
We lay out how the website, search and paid layers fit together in a healthcare digital growth stack. If you'd rather have it designed that way from the start, our digital marketing and growth service is where that work happens.
Start with the tracker inventory. It's the one task that turns up problems nobody knew existed.
Frequently asked questions
What if a tracking vendor won't sign a BAA?
The HHS guidance allows an intermediary, such as a customer data platform, that will sign a BAA and de-identify the data before passing it to the vendor. Without that, PHI shouldn't reach the vendor at all.
Are refill reminders marketing under HIPAA?
Generally no. Refill reminders, recommendations for alternative treatments or providers, and care coordination communications are treated as healthcare operations and don't need authorization, according to the HIPAA Journal.
Can a patient testimonial be used in an ad?
Yes, if it reflects the patient's honest experience and doesn't make a claim you couldn't substantiate yourself. If the result isn't typical, say so clearly, and disclose any material connection to the endorser.
Sources
- What are the HIPAA Marketing Rules? — The HIPAA Journal
- HHS-OCR Revises its Guidance on Use of Online Tracking Technologies — Dentons





























