A patient testimonial on your homepage can trigger a HIPAA violation before you spend a dollar on ads. That happens the moment it names a condition without a signed authorization behind it.
That's the real shape of HIPAA compliant marketing. A short, specific list of things need written permission first, a signed vendor contract behind them, or both.
Nothing else in a normal marketing plan is off limits. The confusion usually isn't about dramatic mistakes.
It shows up in testimonials, tracking pixels, appointment texts and ad platforms, the ordinary tools a marketing plan runs on every week. Here's where the line actually sits.
What HIPAA compliant marketing actually restricts
HIPAA defines marketing narrowly: a communication whose purpose is to get the recipient to buy or use a product or service.
Ordinary care messages don't qualify on their own. An appointment reminder is treatment, not marketing.
The line moves the moment money changes hands for that message. Once a third party pays you to send it, even something that reads like patient education becomes marketing.
That message then needs the patient's written authorization before it goes out. Two narrow exceptions sit outside that rule under 45 CFR 164.508: a face-to-face conversation, and a promotional item of nominal value.
Everything else that fits the marketing definition needs sign-off first. If remuneration is involved, the authorization itself has to say so.
Why patient testimonials need a signed authorization
A testimonial that names someone, shows their face, or describes their condition is protected health information being used to sell your services. That needs its own authorization, separate from anything a patient signed for treatment.
A compliance guide for healthcare marketers lays out exactly what a valid authorization has to name:
- Whose information appears in the testimonial, and which specific details are included
- Which channels it's allowed to run on, from the website to paid social
- How long the authorization lasts before it expires
- The patient's right to revoke it, and what happens to material already published
Treat that checklist as a template rather than guesswork. Leave a channel off the form, and posting the same quote there later isn't covered.
A testimonial doesn't need a name to count as identifying. Voices, images, dates and a situation detailed enough to be recognizable all trigger the same authorization requirement, even before the material ever reaches a healthcare social media strategy.
Tracking pixels and ad platforms after the 2024 court ruling
Ad tags and analytics scripts collect exactly the kind of data HIPAA cares about: an IP address sitting next to a visit to a page about a specific condition.
For a while, OCR's position was that this combination made the tag a problem on its own, login required or not.
A federal court narrowed that in 2024. Hospital associations sued, and the ruling vacated the part of OCR's bulletin that asked providers to guess why an anonymous visitor landed on a health-condition page.
A Holland & Knight analysis of the case described that standard as demanding clairvoyance from marketers who can't know a stranger's reason for clicking.
What survived the ruling is everything involving actual protected health information, plus anything sitting behind a login: a patient portal or a scheduling tool included.
That same analysis still tells regulated entities to check their privacy policies against what their tracking tools actually do, and to vet a vendor's access to that data before signing on.
If you're building a compliant healthcare Google Ads strategy, that authenticated-versus-public line is the one to design around.
Public pages carry less legal risk than they did a couple of years ago. Anything a patient reaches after signing in never stopped being covered.
A vendor touching that data still needs a signed agreement before it sees what a patient typed in.
Email and text campaigns run on two different consent rules

Photo by Markus Winkler on Pexels
Texting a patient and emailing one look similar, but they answer to different regulators.
The TCPA decides whether you were allowed to send the message at all. HIPAA decides what you were allowed to put inside it.
Appointment confirmations and pre-registration texts get a specific carve-out from the TCPA's consent requirement, since they count as treatment rather than telemarketing.
A TCPA guide for healthcare providers puts genuinely promotional texts in a stricter bucket: those need prior express written consent, on top of whatever HIPAA authorization the content itself requires, plus a working opt-out.
The same guide points to a practical fix: get broad consent up front, covering calls and unencrypted texts alike, so a practice isn't chasing separate sign-offs for every campaign later.
Email sits outside the TCPA, with one catch worth knowing. Courts have started treating a forwarded email as a text message the same way they'd treat an actual one.
Mixing the two rules up is how a practice ends up sending a compliant text with no consent behind it, or a signed consent form covering the wrong kind of message.
When a marketing vendor needs a business associate agreement
Any vendor that creates, receives, or transmits protected health information on your behalf needs a signed business associate agreement before that data moves, not after something goes wrong.
That covers more of a marketing stack than most teams assume, especially once it touches something as ordinary as a website form asking for a patient's contact details.
The safer default treats every platform touching patient data as PHI-adjacent until proven otherwise, and works only with vendors willing to sign that agreement.
The same discipline applies to whoever manages a HIPAA compliant patient portal or app. A marketing integration pulling data out of that system inherits the obligations the system was already built under.
Hiring decisions matter here too. A freelancer running your ad accounts and a full healthcare marketing agency answer to the same rules.
Only one of them is likely to already have a BAA process built into onboarding a healthcare client. That's worth asking about before a contract gets signed, not after the first campaign launches.
A digital marketing and growth partner should be able to answer that question without hesitation.
Frequently asked questions
Do I need a new authorization if I reuse a testimonial on a different channel?
Yes, if the original authorization only named specific channels. A valid authorization spells out where a testimonial can run.
Posting the same quote somewhere it doesn't cover means getting a new sign-off first, not assuming the old one stretches.
Does a testimonial need to name the patient to require authorization?
No. Voices, images, dates and details specific enough to be recognizable count the same way a name does.
Any one of them is enough to trigger the authorization requirement before the testimonial runs anywhere.
Does a HIPAA authorization also give me permission to text a patient?
No. HIPAA and the TCPA answer separate questions.
HIPAA authorization covers using someone's health information in a message, while TCPA consent covers whether you were allowed to text them at all. A promotional campaign needs both.
Do appointment reminder texts need patient authorization?
No. Appointment confirmations and pre-registration texts count as treatment communications.
They sit outside the marketing definition and outside the TCPA's stricter consent rule for promotional messages.
Cover photo by Leeloo The First on Pexels
Sources
- 45 CFR § 164.508 - Uses and disclosures for which an authorization is required — Cornell Law School Legal Information Institute
- HIPAA and Healthcare Advertising: Compliance Guide for Marketers — Accountable HQ





























