HIPAA Marketing Compliance: 6 Authorization Elements for US Clinics

September 1, 2026 · Rooted Up

HIPAA Marketing Compliance: 6 Authorization Elements for US Clinics

HIPAA marketing compliance requires written patient authorization before you use protected health information to promote products or services, with only a handful of narrow exceptions. If your team runs any campaign touching PHI, pause third-party list sharing today, verify your authorization forms disclose remuneration, and confirm every template meets 45 CFR 164.508 before the next send.


TL;DR:

  • A handwritten, detailed authorization form is required for any marketing use of PHI, including disclosures of remuneration, with only face-to-face and nominal gifts exceptions.
  • Campaigns promoting products or services are classified as marketing based on intent and content, not channel or format, requiring prior authorization unless exempted.
  • Selling patient lists or sharing PHI with third parties for marketing purposes is prohibited without explicit patient consent, and in-kind benefits count as remuneration.
  • Maintaining standardized documentation of classifications, authorizations, revocations, and vendor agreements is essential for proof and compliance during audits.
  • Most violations result from improper forms or undisclosed payments, so routine procedures like consistent templates and signed vendor contracts significantly reduce legal risk.

Table of Contents

What Does HIPAA Mean by "Marketing"?

The Privacy Rule defines marketing as a communication about a product or service that encourages someone to purchase it. That sounds simple until you try to classify a real campaign. A dermatology practice sending a newsletter about a new laser treatment is marketing. The same practice reminding a patient to book a follow-up visit is not.

The dividing line isn't the channel or the format. It's intent and content. HHS guidance makes clear that a label like "patient education" or "wellness update" doesn't protect a communication if its actual purpose is to sell something. OCR looks past the subject line to what the message is actually trying to accomplish.

Here's how that plays out in practice:

The practical takeaway: document your reasoning every time a campaign touches PHI. If you can't clearly state why a communication qualifies as treatment or operations rather than marketing, treat it as marketing and get authorization first.

When Do You Need Written Authorization?

Under 45 CFR 164.508, any use of PHI for marketing purposes requires the individual's written authorization unless it falls into one of the exceptions covered below. An HHS FAQ confirms this is the default rule, not a fallback: authorization is required except in two narrow situations, face-to-face communications and promotional gifts of nominal value.

A valid authorization has to include specific elements, not just a signature line. Missing any of these makes the form defective and the underlying use unauthorized.

  1. A specific, meaningful description of the PHI to be used or disclosed.
  2. The name of who is authorized to make the disclosure and who may receive it.
  3. A clear statement of the purpose of the requested use.
  4. An expiration date or event.
  5. The individual's signature and date.
  6. A statement disclosing any direct or indirect remuneration received from a third party, when applicable.

Compound authorizations, where marketing consent gets bundled with a general treatment consent form, are one of the most common errors auditors flag. Revocation rights also need to be built in: patients can revoke authorization at any time, and your systems need a way to flag and honor that revocation before the next campaign touches their record.

Pro Tip: Build a single standardized authorization template for every marketing use case rather than letting individual departments draft their own. Inconsistent forms are the number one reason authorizations get invalidated during an OCR review.

Which Marketing Activities Don't Require Authorization?

Four situations let you communicate with patients about products or services without a signed authorization, but each comes with real limits.

The "own products and services" exception trips up more marketers than any other. If your organization pays for the communication out of its own budget, you're likely fine. If a pharmaceutical company or device manufacturer is funding the outreach, that third-party payment usually pulls the communication back into marketing territory, and authorization becomes mandatory again.

What Counts as Remuneration, and Why Does Selling PHI Matter?

Remuneration isn't limited to cash. It includes in-kind benefits, free services, discounted licensing, or any other value exchanged in return for using PHI to communicate with patients. Direct payment from a drug manufacturer for a mailing campaign is the obvious case. Indirect remuneration, like a vendor covering your printing costs in exchange for promoting its product, counts just as much.

HHS guidance is unambiguous on the bigger issue: selling lists of patients to third parties for their own marketing use is prohibited without patient authorization. This isn't a gray area. A practice that sells its patient roster to a marketing firm, even one operating in an adjacent health category, needs signed authorization from every patient on that list.

Watch for these common danger zones:

Nearly every enforcement action involving marketing traces back to one of these arrangements, where remuneration existed but the required disclosure never made it into the authorization form. Before launching any co-branded or vendor-funded campaign, ask directly whether money or value changed hands, then confirm that fact is written into the authorization language patients actually sign.

How Do You Build a HIPAA-Compliant Marketing Workflow?

Turning the regulation into a repeatable process is what actually keeps a marketing team out of trouble. Here's the sequence that works.

  1. Classify before you draft. Every campaign touching PHI needs a written determination: is this treatment, operations, or marketing? Log the reasoning, not just the conclusion.
  2. Capture authorization correctly. Use one standardized form with all six required elements, store it against the patient's record, and build a revocation workflow that actually stops the next send.
  3. Lock down vendor relationships. Any outside platform touching PHI needs a signed business associate agreement, with scope limits spelling out exactly what the vendor can and cannot do with patient data. Tools built for HIPAA-compliant email or compliant text messaging simplify this considerably compared to general-purpose marketing platforms.
  4. Apply data minimums. Segment lists so campaigns only touch the PHI fields necessary, encrypt data in transit and at rest, and restrict access to staff who need it for that specific campaign.
  5. Route everything through approval. A legal or privacy reviewer signs off before launch, campaigns get tested on a small segment first, and every approval gets logged with a timestamp and reviewer name.

Pro Tip: If your outreach involves SMS, layer HIPAA authorization requirements on top of separate consent rules under the TCPA. Reviewing a practical TCPA playbook alongside your HIPAA checklist catches gaps that a HIPAA-only review misses.

What Records Do You Need to Keep, and For How Long?

Documentation is what turns "we followed the rule" into something you can actually prove during an OCR inquiry. Keep signed authorizations, the classification determination for each campaign, legal signoffs, and every business associate agreement tied to a vendor touching PHI.

Retention policy matters here as much as the documents themselves:

Searchable, campaign-tagged records save days of scrambling if OCR ever asks for proof on short notice.

What Happens If You Get It Wrong?

OCR enforcement in this space concentrates on unauthorized disclosures tied to remuneration: selling patient lists, running vendor-funded campaigns without disclosure, or using compound consent forms that never actually secured valid marketing authorization. Penalties scale with how negligent the violation looks, and a documented, good-faith compliance process is your best evidence that a mistake wasn't willful.

HIPAA isn't the only law in play. State privacy and consumer protection statutes often layer additional consent or disclosure requirements on top of federal rules, and anti-kickback statutes can turn a remuneration arrangement into a separate legal problem entirely. Coordinate with legal counsel any time a campaign involves payment from a device manufacturer, pharmaceutical company, or referral partner.

Pro Tip: Treat every enforcement notice as a signal to audit your entire authorization template library, not just the campaign named in the complaint. If one form was defective, others built from the same base almost certainly are too.

How Rooted Up Applies These Rules in Real Campaigns

Solo healthcare providers rarely have a compliance department. Rooted Up builds consent capture, business associate agreements, and secure campaign operations into the marketing workflow itself, so authorization tracking and vendor scope limits aren't an afterthought bolted on after launch.

For providers managing this alone, cheap wins exist right now: standardize one authorization template, confirm your appointment reminder system stays within the treatment exception rather than drifting into promotional territory, and audit which vendors actually hold signed BAAs. Small clinics can close most of their exposure with these three steps before spending a dollar on new tools.

Why Most Compliance Advice Gets This Backwards

Most compliance content treats HIPAA marketing rules as a legal hurdle to clear once and forget. That's backwards. The regulation rewards documented process, not perfect prediction. You won't always guess correctly whether a borderline communication counts as operations or marketing, but a written classification decision, made before launch and logged for later review, protects you even when the call turns out wrong.

Three-stage HIPAA campaign review process

The conventional advice to "get a lawyer to review everything" also overstates what's needed. Most violations trace back to sloppy authorization forms and undisclosed remuneration, not novel legal questions. A marketing team that standardizes one authorization template, confirms every vendor has a signed BAA, and logs remuneration arrangements will avoid the vast majority of real enforcement risk.

Prioritize the boring stuff first: consistent forms, clean vendor contracts, and a habit of writing down why a campaign was classified the way it was. That habit outperforms any last-minute legal scramble.

— Jason

Get HIPAA-Compliant Marketing Off Your Plate

Rooted Up is the alternative to hiring outside legal counsel every time you launch a campaign. For solo healthcare providers, that means one monthly plan covering consent workflow setup, business associate agreements with your marketing vendors, and campaign operations built around HIPAA rules from the start, rather than reviewed after the fact.

Rooted Up

Instead of piecing together authorization templates, vendor contracts, and approval steps on your own, Rooted Up handles the operational side while you keep your focus on patient care. Newsletters, review outreach, and appointment communications all run through the same compliance-first process, backed by tools like AI-assisted email drafting built for approval trails rather than guesswork. If your current campaigns touch PHI without a documented authorization process behind them, that's the exposure to fix first. Request a compliance-first marketing audit through Rooted Up's services page and find out exactly where your current setup stands.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

Recommended

Marketing handled, so you can do the work you love.

See our plans