Email marketing · Guide

The real rules for HIPAA compliant email marketing

A clinic newsletter and a targeted treatment promo aren’t the same risk. One pulls names off a sign-up sheet, the other pulls a segment straight from the patient record, and HIPAA treats that difference seriously. This guide covers when patient authorization is required, what a BAA with your email vendor needs to cover, and the CAN-SPAM and CASL rules that apply on top of it.

The short answer

HIPAA compliant email marketing means using PHI to build or personalize a campaign only with the patient authorization the Privacy Rule requires, backed by a signed Business Associate Agreement with the email platform and lists built to the minimum necessary standard. In the US, CAN-SPAM sets baseline rules for every commercial email; in Canada, CASL adds its own consent requirements on top.

01 · PHI in email

When a clinic email carries PHI

A marketing email becomes protected health information the moment it ties a patient’s identity to something about their care: a treatment name, a before-and-after photo, an outstanding balance, a next appointment date. A general newsletter pulled from a sign-up form isn’t touching PHI. The same newsletter built from a segment of who booked what treatment and when already is.

The distinction matters because HIPAA doesn’t regulate email marketing as a category. It regulates protected health information, wherever it travels, including inside a campaign platform most clinics think of as a marketing tool rather than part of the patient record. For a deeper look at how that plays out across a whole patient database, see our guide to a HIPAA compliant CRM.

02 · Authorization

When marketing needs authorization

The HIPAA Privacy Rule requires a patient’s written authorization before PHI is used or disclosed for marketing, with narrow exceptions the rule carves out itself: face-to-face conversations between a provider and a patient, and promotional items of nominal value (U.S. Department of Health and Human Services). A refill reminder about a patient’s own prescription isn’t treated as marketing under the rule, even when a third party helps pay for sending it (U.S. Department of Health and Human Services).

A clinic emailing its own patients about its own services, an appointment reminder, a seasonal offer, a loyalty perk, generally sits outside that authorization requirement, since HHS excludes a provider’s communications about its own treatments and services from the definition of marketing, unless a third party pays the clinic to send them. Where a campaign involves a third party’s product, a paid list, or anything close to that line, confirm the specific case with compliance counsel before it goes out. This page describes what HHS guidance says; it isn’t legal advice.

03 · Vendor agreement

The BAA your email platform needs

If the platform sending the campaign stores or processes PHI, patient names tied to treatment history, appointment status, or membership data, to build a list or personalize a send, it’s acting as a business associate. HIPAA requires a signed agreement before PHI passes through it, one that spells out the permitted uses, requires safeguards, and obligates the vendor to report any use outside what the contract allows (U.S. Department of Health and Human Services).

That same agreement should require the vendor to return or destroy PHI at the end of the relationship and hold its own subcontractors, the infrastructure underneath the platform, to the same restrictions. A platform that only ever touches a generic email address grabbed from a public contact form may sit outside this requirement, but that’s a determination worth confirming rather than assuming. Our own approach as a vendor is on our HIPAA and PHI practices page.

04 · Segmenting

Build a list without exposing the chart

The minimum necessary standard applies here as much as anywhere else in a clinic: limit what a marketing send touches to the minimum necessary to build the list and personalize the message, and keep the rest of the chart out of it (U.S. Department of Health and Human Services).

In practice that means segmenting by operational fields rather than clinical ones, and keeping the segment names themselves generic enough that someone glancing at a campaign dashboard can’t read a condition or treatment off the list title.

  • ✓Safe to segment by: last visit date, membership status, lead source, general service category.
  • ✓Risky without extra controls: a segment or campaign named after a specific diagnosis or a sensitive treatment.
  • ✓Either way, access to build and view segments should be limited to the staff who need it, not open to the whole front desk.

05 · CAN-SPAM

What CAN-SPAM requires either way

Every commercial email a US clinic sends has to clear the FTC’s CAN-SPAM Act, regardless of whether PHI is involved: accurate sender and routing information, a subject line that reflects the message, a clear disclosure when the email is an advertisement, a valid physical postal address, and a clear way to opt out (Federal Trade Commission).

Opt-out requests have to be honoured within 10 business days, and the opt-out mechanism itself has to keep working for at least 30 days after a send. A clinic stays responsible for CAN-SPAM compliance even when a vendor or agency sends the campaign on its behalf, and violations carry penalties up to $53,088 per email (Federal Trade Commission).

06 · Canada

CASL rules for Canadian patients

A clinic emailing anyone in Canada, regardless of where the clinic itself is based, has to clear Canada’s Anti-Spam Legislation on top of any provincial health-privacy rule. CASL requires consent before a commercial message goes out, either express (the patient agreed) or implied through an existing relationship, and implied consent is time-limited in a way express consent isn’t (Government of Canada).

A compliant message identifies who’s sending it, includes a current mailing address and a way to reach the sender, and gives the recipient an unsubscribe link the clinic has to action within 10 business days at no cost to the patient (Government of Canada). A patient list built from old intake forms is worth revisiting periodically, since implied consent expires even when nobody updates the list.

07 · In practice

Where med spas trip on this

Aesthetic and wellness clinics send more visual, treatment-specific email than most practices: a before-and-after grid, a promo aimed at people who’ve had a specific injectable, a nudge that someone is due for their next session. Each one pulls from the patient record even when the email itself reads like ordinary marketing copy.

  • ✓A monthly newsletter to the full list, not filtered by condition or treatment: low risk on its own.
  • ✓A promo aimed at a segment like ’filler patients’: needs the authorization and BAA thinking above before it ships.
  • ✓A patient’s own photo in a campaign: only with that patient’s written authorization for that specific use, the same as anywhere else it might appear.

08 · One platform

Compliant by default, not by memory

Health Hue Hub’s Campaigns builds a segment from the patient data already inside the Hub, treatment history, last visit, membership status, rather than an export nobody on the compliance side ever reviewed, and the Email Builder sends from inside that same platform instead of a separate tool with its own login and its own data trail.

None of that replaces reading the Business Associate Agreement, confirming your own consent records, or checking a specific campaign with counsel. It does mean the list, the send, and the patient record live in one place instead of three, each carrying its own gap.

See the email builder

A look at how a campaign gets built, from segment to send, inside the same platform that holds the patient record.

FAQ

Questions

Do we need a patient’s written authorization for every clinic email?
Not every email. HHS requires authorization for marketing, but a provider’s communications about its own treatments and services fall outside that definition unless a third party pays for the message. A clinic’s own newsletter or appointment reminder typically sits outside that requirement, but a campaign involving a third party’s product is worth confirming with counsel first.
Do we need a Business Associate Agreement with our email marketing platform?
If the platform stores or uses PHI, patient names tied to treatment history, appointment status, or membership data, to build lists or personalize sends, yes. HIPAA requires that agreement before any PHI passes through the platform, and it should name the safeguards the vendor commits to and what happens to the data if you leave.
Can we send a campaign about a specific treatment?
You can, but building the list for it from the patient record turns it into a use of PHI, which brings in the authorization and minimum necessary questions above. Keep the segment fields operational rather than clinical, and limit who can build or view that segment to staff who need it.
Does CAN-SPAM apply if we already follow HIPAA?
Yes, they’re separate requirements and both apply. CAN-SPAM covers the mechanics of every commercial email, a truthful subject line, sender identification, a working opt-out honoured within 10 business days, regardless of whether the message touches PHI at all.
Do we need to think about CASL if our clinic is in the US?
Only if you have Canadian patients on the list. CASL applies to any commercial email reaching a recipient in Canada, no matter where the sender is based, so a US clinic with cross-border patients still needs consent and a working unsubscribe for that segment.
What’s the risk in naming a segment after a treatment or condition?
A segment name is metadata, and metadata is still PHI once it ties an identifiable list of patients to something about their care. A segment visible to staff who don’t need clinical detail is a disclosure risk on its own, separate from whatever the email itself says.
Can we include before-and-after photos in a marketing email?
Only with that patient’s own written authorization for that specific use. A photo used once with permission doesn’t carry blanket permission for every future campaign, so track the authorization the same way you’d track any other record, not as a one-time checkbox.

Sources

Keep reading

Related guides

HIPAA compliant CRM, explainedThe real rules for HIPAA compliant textingHIPAA compliant scheduling softwareChoosing a med spa CRM