HIPAA is not a data privacy law for everyone. It is a federal perimeter that binds health plans, clearinghouses, most hospitals, clinics and pharmacies—and the outside vendors that touch protected health information for them. For a performance marketer, that perimeter is the difference between a legal health audience and a breach headline.
What the law actually restricts
The Health Insurance Portability and Accountability Act was signed on August 21, 1996. The Privacy Rule became enforceable on April 14, 2003, and the Omnibus Final Rule has been binding since September 23, 2013.
Three categories are covered directly: health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically. A fourth group—business associates—was added later; cloud hosts, billing vendors and analytics providers qualify once regulated patient data passes through them.
Protected health information, or PHI, includes individually identifiable health data held or transmitted by a regulated entity. That is where ad tech collides with the rules. Written authorization is required before PHI can be used for marketing, defined as a communication about a product or service that “encourages the recipient to purchase or use” it. Treatment reminders and refill notices remain outside marketing.
The pixel collision that redrew the line
In June 2022, The Markup found the Meta Pixel on 33 of Newsweek’s top 100 U.S. hospital sites, including seven password-protected patient portals. HHS responded on December 1, 2022 with guidance saying an IP address plus a visit to a condition-specific page could be PHI. The American Hospital Association sued, and on June 20, 2024 a federal court in Texas vacated that IP-plus-page-visit theory nationwide.
Civil cases kept moving. Advocate Aurora Health settled for $12.25 million in July 2024, and Novant Health settled for about $6.6 million over pixels on its MyChart portal. The lesson: authenticated portals remain high risk even after the tracking guidance was partly struck down.
Where health ad tech is moving
The compliance gap created a product category. Healthcare-specific demand-side platforms exist because general platforms cannot sign business associate agreements at scale. Provider targeting has become the workaround: National Provider Identifier numbers describe clinicians, not patients, so campaigns aimed at doctors largely avoid PHI. Recent launches from DeepIntent and StackAdapt have pushed this model, though “HIPAA-compliant” remains a self-assessment, not an official certification.
Other regulators are also patrolling the gap. The FTC fined GoodRx $1.5 million in February 2023 and BetterHelp $7.8 million in March 2023. California settled with Healthline for $1.55 million in July 2025. HIPAA may not cover a fitness app or symptom site, but state and consumer-protection law often does.
What marketers should do now
- Map every health audience data flow: if PHI could pass through your pixel, log, or server, clarify whether a business associate agreement is required.
- Avoid unauthenticated condition-page signals when you do not have consent or a BAA; state and FTC enforcement can still apply.
- Use provider identity, NPI targeting, or contextual placements instead of patient-level health signals.
- Treat vendor claims of “HIPAA-compliant” with caution—ask which specific rule and which audit backs the claim.
- Monitor non-HIPAA laws such as the FTC Health Breach Notification Rule and Washington’s My Health My Data Act.
For health and pharma advertisers, the playbook is shifting from tracking patients to targeting providers and buying on privacy-safe infrastructure. That may feel slower than open programmatic, but the settlements show the alternative is not hypothetical.
Source: PPC Land



