A lot of privacy trouble in medical marketing has nothing to do with hackers. It starts with good intentions: a free tracking pixel added to measure ads, a “reason for visit” box on the contact form, a quick reply to a one-star review. Each one feels harmless. Yet each can expose patient information you’re legally bound to protect. Good healthcare marketing compliance means catching those everyday risks before they turn into a complaint, a fine or a headline.
This guide covers four spots where everyday marketing touches patient privacy in physician, dental and therapy practices. For ideas on attracting more patients, see our guide to medical practice marketing. This isn’t legal advice, so run final decisions past your privacy officer or a healthcare attorney.

What Healthcare Marketing Compliance Actually Covers
HIPAA applies to “covered entities,” which include most providers that bill insurance electronically. It also reaches their business associates, meaning any vendor that handles patient data on your behalf. That list can include your web host, form builder, CRM, call-tracking service, email platform and marketing agency. Each one needs a signed business associate agreement (BAA) before patient data flows its way.
Protected health information is broader than most people think. A name paired with an appointment time can qualify. So can a diagnosis, or even the plain fact that someone is your patient. That last point matters most with online reviews.
The good news is that HIPAA doesn’t ban marketing. Telling your own patients about your own services, such as a new sleep clinic or flu shot hours, is generally fine. However, most other marketing uses of patient information require the patient’s written authorization, including any message a third party pays you to send. Meanwhile, state licensing boards and the FTC police advertising for honesty. In short, healthcare marketing compliance sits where privacy law and advertising law overlap.

Tracking Pixels: The Risk That Hides in Plain Sight
Tracking pixels are small bits of code from companies like Meta and Google. They report what visitors do on your site so you can measure ads and build audiences. The trouble is what they can send along: IP addresses, page addresses, clicks and sometimes form entries. On a booking page or patient portal, that can add up to patient information handed to a tech company with no BAA.
Regulators have noticed. In 2023, the FTC and HHS warned roughly 130 hospital systems and telehealth providers about tools such as the Meta pixel and Google Analytics. Later, a 2024 federal court ruling in Texas struck down part of the HHS guidance on public web pages. Even so, that ruling didn’t make it safe to track patients inside portals or on forms where they type health details.
A Simple Pixel Audit
- List every script. Check your tag manager, theme and plugins for pixels, analytics, chat widgets, heatmaps and session recorders.
- Map where each one fires. Flag any that load on appointment pages, thank-you pages, portal logins or condition pages.
- Remove or replace. Pull third-party tracking from those pages. Where you still need measurement, use tools whose vendors will sign a BAA.
- Rethink retargeting. Don’t build ad audiences from people who visited condition pages or booked visits. Google and Meta also restrict health-based targeting in their own ad policies.
- Repeat after every change. A new plugin or a redesign can quietly add tracking back.
Paid search still works without risky audiences. It simply needs ad campaigns built around privacy-safe measurement, such as counting calls and booked appointments inside your own systems.

Healthcare Web Forms That Pass a Compliance Check
Your contact form is often the first place a patient shares something private. Picture a dermatology office in Montclair whose form asks, “What brings you in?” One visitor types a detailed description of a worrying mole. That message may now sit in an unencrypted inbox, a form vendor’s database and a CRM, possibly with no BAA covering any of them.
A few design choices fix most of this:
- Ask for less. A general contact form needs a name, a phone number and a preferred time. Save clinical questions for intake inside your EHR or patient portal.
- Add a gentle warning. A note such as “Please don’t include medical details here” cuts down on oversharing.
- Secure the path. Use HTTPS, send submissions to a system covered by a BAA and stop forwarding full entries to personal email.
- Limit access. Only the staff who schedule patients should see submissions.
A well-planned practice website builds privacy in from the start, just like speed and accessibility, instead of patching it later.
Replying to Patient Reviews Without Breaking HIPAA
This is where good people get into trouble. A patient posts an unfair review, and someone at the front desk wants to set the record straight. But confirming that the reviewer is a patient, or mentioning their visit, can be an impermissible disclosure.
The risk is real. In 2023, a New Jersey psychiatry practice paid $30,000 to settle with federal regulators. The problem: its replies to negative Google reviews included details about patients’ diagnoses and mental health conditions. Investigators found disclosures involving four patients, plus missing privacy policies. The practice also agreed to a corrective action plan covering new policies, staff training and breach notices.
A Reply Template That Stays Safe
Keep public replies general, then move the conversation offline. For example: “Thank you for sharing this. We take every concern seriously and would like to talk with you directly. Please call our office manager at [phone].” Notice what’s missing. There’s no confirmation of a visit, no clinical detail and no argument. The same rule applies to praise, so skip “Glad your knee surgery went well!”
When you ask for reviews, ask every patient rather than only the happy ones. Also, never offer a reward for a good rating, since FTC guidance warns against both. If replies eat up your week, reputation management support can handle monitoring under a written, HIPAA-aware policy.
Patient Testimonials and Healthcare Marketing Rules in New Jersey
Patient stories are persuasive, but they come with rules. Under HIPAA, you need a signed authorization before you use a patient’s name, photo, story or before-and-after images in marketing. Spell out where and how you’ll use the material, and keep the signed form on file.
Physicians face a second layer. The state’s Board of Medical Examiners advertising rule sets specific terms for testimonials:
- Keep it true. A procedure testimonial must reflect the patient’s actual experience. It must also carry two statements the rule spells out: the procedure may not suit every patient, and no procedure is risk-free.
- Disclose payment. If the patient received anything of value, the ad must say that compensation has been provided for the testimonial.
- Paper it first. Get a signed, notarized release confirming the testimonial is truthful before it runs. Keep that file, and copies of your ads, for three years after last use.
- Skip what patients can’t judge. Patients can’t vouch for care that takes medical expertise to assess, like the quality of a surgery. The rule also bars promising results.
Dentists and physical therapists answer to their own boards and rules. The physical therapy board, for instance, bars testimonials that vouch for the quality of a therapist’s care. Whatever your license, skip outcome promises like “pain-free in two weeks,” which invite trouble with your board and the FTC. Instead, describe what you treat, who you help and what a first visit looks like.
Email, Texts and Telehealth Promotions
Your patient list is itself protected information, so the email or texting platform that stores it needs a BAA. Newsletters about your own services are usually fine under HIPAA, but CAN-SPAM still requires a working opt-out and your physical mailing address. Promotional texts need prior express written consent under the TCPA, so collect it through a clear, separate opt-in. For virtual care, our article on promoting telehealth visits covers the platform and data questions.
Healthcare Marketing Compliance FAQ
Can we use Google Analytics on a medical website?
Only with care. Google says it doesn’t offer BAAs for Google Analytics, so keep it off portals, forms, appointment flows and condition pages. If you need measurement there, use an analytics tool whose vendor will sign a BAA.
Does our marketing agency need to sign a BAA?
Yes, if it handles patient information for you, such as form entries, CRM records or your patient email list. Business associates have been directly liable for some HIPAA violations since 2013. Still, your practice stays responsible, so limit what each vendor can see.
Make Compliance Part of Your Marketing Routine
Healthcare marketing compliance isn’t a one-time project. It’s a habit: a quarterly pixel check, a form review after each site update, a written reply policy and a signed authorization for every testimonial.
Samaroo Solutions is based in northern New Jersey and works with practices across the state. If you’d like a second set of eyes on your tracking, forms and review process, get in touch with our team.