Email marketing · Guide
The real rules for HIPAA compliant email marketing
A clinic newsletter and a targeted treatment promo aren’t the same risk. One pulls names off a sign-up sheet, the other pulls a segment straight from the patient record, and HIPAA treats that difference seriously. This guide covers when patient authorization is required, what a BAA with your email vendor needs to cover, and the CAN-SPAM and CASL rules that apply on top of it.
The short answer
HIPAA compliant email marketing means using PHI to build or personalize a campaign only with the patient authorization the Privacy Rule requires, backed by a signed Business Associate Agreement with the email platform and lists built to the minimum necessary standard. In the US, CAN-SPAM sets baseline rules for every commercial email; in Canada, CASL adds its own consent requirements on top.
01 · PHI in email
When a clinic email carries PHI
A marketing email becomes protected health information the moment it ties a patient’s identity to something about their care: a treatment name, a before-and-after photo, an outstanding balance, a next appointment date. A general newsletter pulled from a sign-up form isn’t touching PHI. The same newsletter built from a segment of who booked what treatment and when already is.
The distinction matters because HIPAA doesn’t regulate email marketing as a category. It regulates protected health information, wherever it travels, including inside a campaign platform most clinics think of as a marketing tool rather than part of the patient record. For a deeper look at how that plays out across a whole patient database, see our guide to a HIPAA compliant CRM.
02 · Authorization
When marketing needs authorization
The HIPAA Privacy Rule requires a patient’s written authorization before PHI is used or disclosed for marketing, with narrow exceptions the rule carves out itself: face-to-face conversations between a provider and a patient, and promotional items of nominal value (U.S. Department of Health and Human Services). A refill reminder about a patient’s own prescription isn’t treated as marketing under the rule, even when a third party helps pay for sending it (U.S. Department of Health and Human Services).
A clinic emailing its own patients about its own services, an appointment reminder, a seasonal offer, a loyalty perk, generally sits outside that authorization requirement, since HHS excludes a provider’s communications about its own treatments and services from the definition of marketing, unless a third party pays the clinic to send them. Where a campaign involves a third party’s product, a paid list, or anything close to that line, confirm the specific case with compliance counsel before it goes out. This page describes what HHS guidance says; it isn’t legal advice.
03 · Vendor agreement
The BAA your email platform needs
If the platform sending the campaign stores or processes PHI, patient names tied to treatment history, appointment status, or membership data, to build a list or personalize a send, it’s acting as a business associate. HIPAA requires a signed agreement before PHI passes through it, one that spells out the permitted uses, requires safeguards, and obligates the vendor to report any use outside what the contract allows (U.S. Department of Health and Human Services).
That same agreement should require the vendor to return or destroy PHI at the end of the relationship and hold its own subcontractors, the infrastructure underneath the platform, to the same restrictions. A platform that only ever touches a generic email address grabbed from a public contact form may sit outside this requirement, but that’s a determination worth confirming rather than assuming. Our own approach as a vendor is on our HIPAA and PHI practices page.
04 · Segmenting
Build a list without exposing the chart
The minimum necessary standard applies here as much as anywhere else in a clinic: limit what a marketing send touches to the minimum necessary to build the list and personalize the message, and keep the rest of the chart out of it (U.S. Department of Health and Human Services).
In practice that means segmenting by operational fields rather than clinical ones, and keeping the segment names themselves generic enough that someone glancing at a campaign dashboard can’t read a condition or treatment off the list title.
- ✓Safe to segment by: last visit date, membership status, lead source, general service category.
- ✓Risky without extra controls: a segment or campaign named after a specific diagnosis or a sensitive treatment.
- ✓Either way, access to build and view segments should be limited to the staff who need it, not open to the whole front desk.
05 · CAN-SPAM
What CAN-SPAM requires either way
Every commercial email a US clinic sends has to clear the FTC’s CAN-SPAM Act, regardless of whether PHI is involved: accurate sender and routing information, a subject line that reflects the message, a clear disclosure when the email is an advertisement, a valid physical postal address, and a clear way to opt out (Federal Trade Commission).
Opt-out requests have to be honoured within 10 business days, and the opt-out mechanism itself has to keep working for at least 30 days after a send. A clinic stays responsible for CAN-SPAM compliance even when a vendor or agency sends the campaign on its behalf, and violations carry penalties up to $53,088 per email (Federal Trade Commission).
06 · Canada
CASL rules for Canadian patients
A clinic emailing anyone in Canada, regardless of where the clinic itself is based, has to clear Canada’s Anti-Spam Legislation on top of any provincial health-privacy rule. CASL requires consent before a commercial message goes out, either express (the patient agreed) or implied through an existing relationship, and implied consent is time-limited in a way express consent isn’t (Government of Canada).
A compliant message identifies who’s sending it, includes a current mailing address and a way to reach the sender, and gives the recipient an unsubscribe link the clinic has to action within 10 business days at no cost to the patient (Government of Canada). A patient list built from old intake forms is worth revisiting periodically, since implied consent expires even when nobody updates the list.
07 · In practice
Where med spas trip on this
Aesthetic and wellness clinics send more visual, treatment-specific email than most practices: a before-and-after grid, a promo aimed at people who’ve had a specific injectable, a nudge that someone is due for their next session. Each one pulls from the patient record even when the email itself reads like ordinary marketing copy.
- ✓A monthly newsletter to the full list, not filtered by condition or treatment: low risk on its own.
- ✓A promo aimed at a segment like ’filler patients’: needs the authorization and BAA thinking above before it ships.
- ✓A patient’s own photo in a campaign: only with that patient’s written authorization for that specific use, the same as anywhere else it might appear.
08 · One platform
Compliant by default, not by memory
Health Hue Hub’s Campaigns builds a segment from the patient data already inside the Hub, treatment history, last visit, membership status, rather than an export nobody on the compliance side ever reviewed, and the Email Builder sends from inside that same platform instead of a separate tool with its own login and its own data trail.
None of that replaces reading the Business Associate Agreement, confirming your own consent records, or checking a specific campaign with counsel. It does mean the list, the send, and the patient record live in one place instead of three, each carrying its own gap.
FAQ
Questions
Do we need a patient’s written authorization for every clinic email?
Do we need a Business Associate Agreement with our email marketing platform?
Can we send a campaign about a specific treatment?
Does CAN-SPAM apply if we already follow HIPAA?
Do we need to think about CASL if our clinic is in the US?
What’s the risk in naming a segment after a treatment or condition?
Can we include before-and-after photos in a marketing email?
Sources
- U.S. Department of Health and Human Services · Marketing (HIPAA Privacy Rule FAQ)
- U.S. Department of Health and Human Services · Minimum Necessary Requirement
- U.S. Department of Health and Human Services · Business Associate Contracts, Sample Provisions
- Federal Trade Commission · CAN-SPAM Act: A Compliance Guide for Business
- Government of Canada · Getting Consent to Send Email (Canada’s Anti-Spam Legislation)
