Skip to main content
Healthcare marketing tools: a premium toolkit of a search lens, calculator without digits, checklist and cursor, arranged on stepped ivory plinths
Checker

HIPAA Marketing Checker

12 yes/no questions across tracking, ads, forms, and storage. Flags exposure before it becomes liability.

What you get
Risk score · flagged exposure · BAA checklist
4 minutes✓ FREE · NO CARD
Free · instant · no email

Use the tool right here.

It runs live in your browser — nothing is sent to us until you choose to share your results.

Jump to the tool ↓

Enter your ad copy, website text, social media post, or email content to check for common HIPAA compliance issues.

0 characters

How it works

STEP 01

Inputs

12 multiple-choice questions

STEP 02

Processing

Live calculation in your browser. Nothing sent to us. No tracking on the inputs.

STEP 03

Output

Risk rating · checklist of fixes · BAA template request

Deeper context

When to use the HIPAA checker

Use this tool to check whether your marketing setup could be exposing patient information (what HIPAA calls protected health information, or PHI). It's especially worth running before you add any new tracking, retargeting, or analytics tool — that's where most clinics get caught out.

US regulators tightened the rules in December 2022, going after clinics that retarget people who visited pages about mental health, addiction, or other sensitive conditions. Several clinics have been penalised since for tracking code that once seemed harmless.

What HIPAA actually covers in marketing

Patient data on intake forms — name, email, phone, date of birth, condition, insurance — all count as protected patient information when they're tied to a clinic. Forms must use a secure (HTTPS) connection, store data only with vendors who've signed a data-handling agreement, and ask for clear consent.

Tracking code on sensitive pages — simply visiting a depression treatment page counts as protected information under the rules. Meta Pixel, Google Analytics, and similar trackers that send page-visit data to other companies without a signed agreement break the rules on those pages.

Email marketing — your patient email lists are protected information. To send marketing emails you need people to opt in and an email provider that has signed a data-handling agreement. Mailchimp's protected plan is fine; the standard plan is not for patient marketing.

CRM data — patient names, appointment details, and condition information sitting in your CRM are protected information. Salesforce Health Cloud is built to meet the rules; standard Salesforce needs a signed agreement plus careful setup.

Ad conversion tracking — sending Google or Meta data about which patients booked is protected information. Tracking done from your own server with scrambled identifiers is fine; ordinary cookie-based tracking on sensitive pages is not.

How the checker works

The tool runs through your current marketing setup and marks each item Pass, Flag, or Fail:

  • Pass: set up correctly under the current rules
  • Flag: unclear or borderline — check with whoever handles compliance
  • Fail: a clear breach; fix it straight away

Each flagged item comes with the exact rule it relates to and the steps to fix it. You can hand the result straight to your compliance officer or lawyer.

Common HIPAA marketing failures

Retargeting people who viewed mental health, addiction, or other sensitive pages. A clear breach under the December 2022 rules. Most clinics doing it have no idea — the ad platforms turn it on by default.

Mailchimp on the standard plan. The standard plan has no data-handling agreement, so clinics using it for patient marketing are exposed. Either move to the protected plan or switch to a provider that offers one.

Google Analytics on patient portals. Patient portal pages hold protected information even if the analytics never sees the form data — the web address alone can give it away. Clinics usually need privacy-first analytics (such as Plausible or Fathom) or server-based tracking.

Lead forms without a protected backend. Form entries land in a CRM or email tool. If that tool hasn't signed a data-handling agreement, the clinic is in breach the moment someone fills in the form.

Marketing abroad without the right local rules. Clinics marketing overseas need to follow India's DPDP law and the EU's GDPR on top of HIPAA. The rules overlap but aren't the same — DPDP needs its own consent step for patients in India.

What to do after the audit

  1. Fix the Fail items first — these are open breaches.
  2. Go over the Flag items with a compliance adviser — borderline cases that need a judgement call.
  3. Write down what you changed — keep a record showing exactly what was fixed.
  4. Re-check every quarter — the rules keep changing; what's fine this year may not be next year.
  5. Train your marketing team — most breaches happen because someone didn't know the rules.
FAQ

Things teams ask first.

What's the HIPAA penalty for marketing violations?

Fines run from $100 to $50,000 per breach, up to $1.5M a year for each type of breach. There are criminal penalties too if a breach is deliberate. Most cases start with a patient complaint, though regulators also run their own audits.

Does HIPAA apply to my analytics platform?

Yes, if your site has any patient-facing pages or forms. Standard Google Analytics usually doesn't meet the rules for healthcare. You need privacy-first analytics (some GA4 setups done correctly), server-based tracking, or a healthcare-specific tool like Plausible or Fathom.

Can I retarget healthcare website visitors?

Sometimes. Retargeting people who viewed general pages (services, about, contact) is usually fine with the right consent. Retargeting people who viewed sensitive pages (mental health, addiction, fertility) breaks the rules under the December 2022 guidance.

What's a BAA and why does my marketing stack need it?

It's a data-handling agreement — a contract between your clinic and any vendor that touches patient information. HIPAA requires it. Any marketing tool that handles patient data (CRM, analytics, email, ad platforms) needs one, even if the data is scrambled.

How often should we re-audit HIPAA compliance?

At least every quarter while you're actively marketing. Also right away whenever you add new tracking, plug in a new tool, the rules change, or an incident is reported. For larger clinics, an outside audit once a year is a good idea.

More healthcare tools.

SEE ALL 14
Why choose us

Why healthcare brands choose us.

Six reasons hospitals, clinics, and doctors pick a healthcare-only firm over a generalist agency.

  • Healthcare-only

    It's all we do. No retail, no fintech — the whole team thinks in patient journeys, clinical trust, and the way people actually choose a doctor.

  • AI-first systems

    Receptionists, WhatsApp triage, and attribution built in-house — we answer patients in seconds and tie every click to a booked appointment.

  • Compliance built-in

    HIPAA-aware handling, ASCI-reviewed creative, and GDPR/DPDP sign-off on every campaign — our standard, not an upcharge or an afterthought.

  • Senior on every account

    The senior who pitched you stays on the engagement. No bait-and-switch to juniors learning on your budget.

  • Measured to the appointment

    Patient-level attribution across calls, forms, and walk-ins. Monthly reports show booked patients — not just clicks and impressions.

  • Receipts, not promises

    We name our clients and show the work. Quarterly reviews with the numbers attached, every cycle.

The Branding Pioneers healthcare-marketing team at work
Healthcare-only · since 2016
A team that does one thing well.
Adjacent files

When the tool runs out, this is what you call us about.

Services, problems, and case files in the same orbit as the diagnostic you just ran.

Want the human version?

30 min with a strategist.

Tools are great for benchmarking. For your situation, the conversation is faster. No pitch.

Beyond the calculator

What the engagement actually delivers.

Feddy — Feedback capture and patient-experience analytics
Product
Feddy
Meta Ads reach and delivery reporting
Meta Ads
Meta Ads — delivery and reach reporting
MAX@Home — homecare services homepage
Web · Homecare
MAX@Home — homecare services homepage
Clinic clients across specialties
Clients
Clinics across specialties
JASS AI — AI marketing co-pilot for healthcare marketers
Product
JASS AI