IGSendMail
All articlesIndustry Guides

How to Run HIPAA-Compliant Email Marketing

HIPAA-compliant email marketing comes down to three things: keep protected health information out of marketing emails, get written authorization before any marketing use of PHI, and sign a BAA with every vendor in the data path. This guide covers what counts as PHI, the list-separation architecture most practices use, the operational safeguards required, and the mistakes that cause reportable breaches.

How to Run HIPAA-Compliant Email Marketing
Erin Moore
Erin Moore
September 28, 20269 min read
Share:

HIPAA-compliant email marketing means never putting protected health information into a marketing email, obtaining written authorization before any marketing use of PHI, and signing a business associate agreement with any vendor that could touch that data. Most healthcare marketing stays compliant by never mixing clinical data with promotional sends at all.

This is a practical overview, not legal advice. HIPAA interpretation depends on your specific data, workflows and state law — have your compliance officer or healthcare counsel review your program before you launch it.

What HIPAA actually restricts

HIPAA doesn't ban email marketing. It restricts what you may do with protected health information — individually identifiable health data held or transmitted by a covered entity or its business associates.

Two rules do most of the work:

  • The Privacy Rule governs who may use or disclose PHI and for what purpose. Marketing is a restricted purpose requiring written authorization, with narrow exceptions.
  • The Security Rule governs how electronic PHI must be protected — access controls, encryption, audit logging, and the administrative safeguards around them.

The definition of PHI is broader than most marketers expect. It isn't just diagnoses and lab results. If a data point is tied to an individual and relates to their health, care, or payment for care, it's PHI.

Data pointPHI in a marketing context?Notes
Email address alone, from a general newsletter formGenerally noNot tied to care or treatment
Email address on a patient listYesMembership in the list itself reveals a care relationship
Appointment date and provider nameYesRelates to treatment
Segment tag like "diabetes program"YesReveals condition
Website visitor who read a cardiology pageOften yesTracking pixels on patient portals have drawn enforcement attention
Public newsletter subscriber, no patient relationshipNoKeep this list strictly separate

The three things you must get right

1. Sign a BAA with every vendor in the path

A business associate agreement is a contract making your vendor legally responsible for safeguarding PHI. If your email platform stores, transmits or processes anything that qualifies as PHI, you need one — and most mainstream marketing platforms will not sign one, which is a real constraint on tool choice.

The BAA requirement follows the data, not the vendor category. Your email platform, your CRM, your form builder, your analytics tool, your hosting provider, and any integration middleware that passes records between them all need coverage if PHI flows through.

The practical alternative most healthcare organizations choose: architect so that PHI never enters the marketing stack at all. If your marketing platform only ever holds names and email addresses collected through a public newsletter form, with no patient status, no conditions and no appointment data, the compliance surface shrinks dramatically.

2. Get written authorization for marketing uses

Using PHI for marketing generally requires prior written authorization from the individual. That authorization must be specific — it names what information will be used, who will use it, for what purpose, and when it expires. A checkbox saying "send me offers" buried in an intake form does not meet the standard.

There are meaningful exceptions. Communications about treatment, care coordination, case management, and information about health-related products or services already included in the patient's benefit plan are generally not treated as marketing. Face-to-face communications and promotional gifts of nominal value are also carved out.

The bright line worth remembering: if you receive payment from a third party for making the communication, it's marketing and it needs authorization, full stop.

3. Never put PHI in the email body

Standard email is not a secure channel. Even with a BAA in place and everything else correct, sending diagnostic details, test results or treatment specifics through ordinary marketing email is a bad idea and often a violation.

The safe pattern is notify and redirect: the email says something has changed and to log in to the secure portal. The email itself carries no clinical content.

  • Bad: "Your A1C results are elevated — here's a program that can help."
  • Acceptable: "You have a new message in your patient portal. Log in to view it."
  • Bad subject line: "Your dermatology follow-up for eczema"
  • Acceptable subject line: "A new message is waiting in your portal"

Remember that subject lines and preview text appear on lock screens and in shared household inboxes. Treat them as public.

A compliant architecture that still lets you market

Here's the separation that keeps most healthcare organizations both compliant and effective:

  1. Two entirely separate lists. A general marketing list (newsletter subscribers, community education signups, event attendees) with no patient data, and a patient communication system that lives inside your EHR or portal.
  2. No sync between them. Resist the integration that would push patient records into your marketing tool. That single connection converts your whole marketing stack into a HIPAA-regulated system.
  3. Segment on non-PHI attributes only. Geography, self-declared interests from a public form, engagement behavior, service line curiosity expressed voluntarily.
  4. Let subscribers self-select topics. A preference center where someone voluntarily checks "women's health" on a public newsletter is materially different from you tagging them based on their chart.
  5. Send transactional and clinical messages through the portal, not the marketing platform.

This architecture is why healthcare content marketing works so well: educational articles, community classes, wellness guides and provider spotlights need zero PHI and reach exactly the people considering care.

Operational safeguards to put in place

  • Access controls. Role-based permissions on the marketing platform, with unique logins. No shared accounts, ever.
  • Audit logging. You need a record of who exported what and when.
  • Encryption in transit and at rest, plus TLS enforcement on outbound mail.
  • Authentication. SPF, DKIM and DMARC aren't HIPAA requirements, but healthcare is a heavily phished sector and DMARC at enforcement stops criminals from spoofing your practice to your patients.
  • Vendor review cadence. Re-verify BAAs annually and whenever you add a tool.
  • Staff training and a documented incident response plan. A misdirected email to the wrong segment may be a reportable breach, and the clock starts immediately.
  • Test sends to internal seed addresses only — never to a random patient address.

The mistakes that cause breaches

  • CC instead of BCC. Exposing a patient list in the To or CC field is one of the most common healthcare email breaches, and it's entirely avoidable with a proper sending platform.
  • Descriptive segment names in merge tags. A personalization token that renders a condition name into the email body.
  • Tracking pixels on patient portal pages. Third-party analytics and ad pixels on authenticated pages have been an active enforcement area.
  • Uploading an EHR export "just to test." The moment PHI enters a non-BAA platform, you have an incident.
  • Assuming a vendor is compliant because it says "HIPAA-ready." Only a signed BAA means anything.

Also remember HIPAA isn't the only rule that applies. CAN-SPAM still requires a working unsubscribe, a physical address, and honest subject lines. State privacy laws add further requirements. Healthcare marketing sits at the intersection of several regimes.

For platform-level guidance on list separation, consent tracking and compliant sending workflows, see the resources on email marketing for healthcare.

What you can market freely

The picture isn't as restrictive as it first sounds. Without touching PHI, you can promote community health education, new provider announcements, facility openings, wellness classes, screening awareness campaigns, insurance acceptance updates, seasonal health content, and patient stories with proper written consent. That's a full content program.

Frequently asked questions

Do I need a BAA for my email marketing platform?

Only if protected health information passes through it. If your marketing list contains nothing but names and email addresses from a public newsletter form, with no patient status or clinical data, a BAA generally isn't required — but confirm that with your compliance officer.

Can I email patients about appointments without violating HIPAA?

Yes. Treatment-related communications like appointment reminders are generally permitted without marketing authorization, but keep clinical detail out of the message body and subject line, and send them through your patient communication system rather than a marketing platform.

Is a patient's email address considered PHI?

On its own, in a general marketing context, usually not. But an email address on a list defined by patient status or condition is PHI, because membership in that list itself reveals health information about the person.

What happens if I accidentally send PHI in a marketing email?

Treat it as a potential breach immediately: document what was sent and to whom, notify your privacy officer, and follow your incident response plan. Breach notification obligations have strict timelines, so speed matters more than certainty about severity.

Does HIPAA replace CAN-SPAM for healthcare email?

No, they stack. You still need a functioning unsubscribe link, a valid physical mailing address, and non-deceptive subject lines on every commercial message, alongside your HIPAA obligations.

Need a sending platform that keeps your marketing list cleanly separated and reliably delivered? Get started with IGSendMail — automatic SPF, DKIM and DMARC, high inbox deliverability, GDPR and CAN-SPAM compliant workflows, and unlimited contacts on paid plans from $19/mo.

Enjoyed this article?

Get The Send: one email a month with the best of the blog and one practical tip.

No spam. Unsubscribe with one click.