Field note · Published 2026-07-07 · Updated 2026-07-10

HIPAA rules for MedSpa marketing: when an agency needs a BAA

By VitalSignal. Researched and maintained for licensed MedSpa operators and their marketing teams.

This is general marketing guidance, not legal or medical advice. It was researched against the linked primary sources and has not been reviewed by legal or medical counsel. Rules vary by state, treatment, platform, and practice structure. Confirm decisions with qualified counsel.

A MedSpa should not decide its HIPAA obligations from a slogan such as “cash pay” or “medical practice.” The legal test starts with the entity, the transactions it conducts, the information involved, and what a vendor is hired to do. This guide explains the federal framework in operational terms. It is not legal advice.

Step 1: determine whether the practice is a covered entity

HHS says a healthcare provider is a HIPAA covered entity only if it transmits health information electronically in connection with a transaction for which HHS has adopted a standard. The agency’s covered entities and business associates guide includes the definition and a decision tool.

Cash payment alone does not answer the question. A practice might still conduct a covered electronic transaction through billing, eligibility, or another workflow. Conversely, a healthcare business that does not meet the federal definition is not made a HIPAA covered entity simply because it handles sensitive information. Document the actual transactions and have counsel confirm ambiguous structures.

Step 2: map which marketing data is PHI

For a covered entity, protected health information is individually identifiable health information maintained or transmitted by the covered entity or its business associate, subject to the rule’s exclusions. HHS summarizes the scope in its Privacy Rule overview.

Marketing systems can receive PHI when they use patient records, appointment details, treatment interests, identifiable photographs, or communications that connect a person to care. Context matters. An email address collected from a general newsletter form is not automatically PHI, while the same address exported from a patient list may be part of a protected record.

Create a data-flow inventory before selecting tools. For each form, booking page, CRM field, email list, call recording, analytics tag, and ad event, record what is collected, where it goes, why it goes there, and whether an identifier travels with it.

Step 3: decide whether the marketing vendor is a business associate

HHS defines a business associate as a person or entity that performs specified functions or services for a covered entity involving the use or disclosure of PHI. When that relationship exists, the assurances must be in writing. HHS provides both business associate guidance and sample BAA provisions.

The agency label is not decisive. A vendor limited to public website copy, non-patient photography, and public business listings may never receive PHI. A vendor that operates a patient CRM, sends messages from a patient list, or stores identifiable appointment data may be performing a business associate function. Define the scope first, then sign any required BAA before access begins.

A BAA is not permission for the vendor to use PHI for its own targeting, portfolio, or product-development purposes. It defines permitted uses and safeguards for work on behalf of the covered entity.

Step 4: separate treatment communications from HIPAA marketing

HIPAA uses a specific definition of marketing and includes exceptions. HHS states that, except for the identified exceptions, a communication meeting the definition of marketing requires the individual’s authorization. Its marketing guidance explains the definition, exceptions, and special rule for remuneration.

Do not assume that a general photo release, verbal approval, or a checkbox drafted for another purpose satisfies the HIPAA authorization requirements. Before publishing an identifiable patient story, photograph, testimonial, or treatment detail from the record, have qualified counsel approve the exact authorization and workflow.

Step 5: audit pixels and other tracking technologies page by page

HHS’s current online tracking technology guidance is more precise than the claim that every public-page visit is PHI. It says the analysis depends on the information transmitted and the visitor’s relationship to the regulated entity. A privacy-policy notice alone does not authorize an otherwise impermissible disclosure.

Authenticated pages, patient portals, and flows that reveal an appointment, treatment, or condition deserve the highest scrutiny. Public pages still require a field-level inspection because form values, URLs, event names, and identifiers can reveal health information. For every tag, inspect the actual network payload rather than relying on the vendor’s product description.

HIPAA is not the end of the privacy analysis

If the business is not covered by HIPAA, do not conclude that health data is unregulated. The FTC’s Health Breach Notification Rule covers specified vendors of personal health records, related entities, and service providers. The FTC’s 2024 amendments clarified the rule’s application to many health apps and similar technologies, as explained in its compliance guide.

State law can reach further. Washington’s My Health My Data Act regulates defined consumer health data and includes collection, sharing, privacy-policy, security, and consent duties. Applicability and exemptions must be checked against the statute, not assumed from the business category.

A practical control list

  1. Record the transactions used to determine HIPAA covered status.
  2. Inventory every marketing data flow and its fields.
  3. Keep PHI out of marketing tools when the work can be done without it.
  4. Sign a BAA before a business associate receives PHI.
  5. Use counsel-approved authorizations for identifiable patient marketing.
  6. Inspect tracking payloads on public, booking, and authenticated pages.
  7. Check FTC and state health-data rules even when HIPAA does not apply.

Primary sources

The free MedSpa marketing audit reviews the public-facing site and conversion path. It does not inspect patient systems, determine covered status, or replace a privacy and security assessment.

See where your MedSpa loses demand.

Send the website and get three specific findings on local visibility, conversion, or follow-up. No call required.

Get the free audit or book a 20-minute consult