Skip to main content
NewNMC’s advertising guidelines for doctors are in force from 6 Oct 2026. See what to change, and get a free compliance auditNew NMC advertising rules for doctors: what to change
🛡️ Checker · free

HIPAA Marketing Checker

12 yes/no questions across tracking, ads, forms, and storage. Flags exposure before it becomes liability.

What you get

Risk score · flagged exposure · BAA checklist

⏱ 4 minutes✓ Free · no card

Free · instant · no email

Use the tool right here.

It runs live in your browser — nothing is sent to us until you choose to share your results.

Enter your ad copy, website text, social media post, or email content to check for common HIPAA compliance issues.

0 characters

How it works

Three steps, no guesswork.

  1. Step 01

    Inputs

    12 multiple-choice questions

  2. Step 02

    Processing

    Live calculation in your browser. Nothing sent to us. No tracking on the inputs.

  3. Step 03

    Output

    Risk rating · checklist of fixes · BAA template request

Deeper context

Using the HIPAA Marketing Checker well.

When to use the HIPAA checker

Use this tool to check whether your marketing setup could be exposing patient information (what HIPAA calls protected health information, or PHI). It's especially worth running before you add any new tracking, retargeting, or analytics tool — that's where most clinics get caught out.

US regulators tightened the rules in December 2022, going after clinics that retarget people who visited pages about mental health, addiction, or other sensitive conditions. Several clinics have been penalised since for tracking code that once seemed harmless.

What HIPAA actually covers in marketing

Patient data on intake forms — name, email, phone, date of birth, condition, insurance — all count as protected patient information when they're tied to a clinic. Forms must use a secure (HTTPS) connection, store data only with vendors who've signed a data-handling agreement, and ask for clear consent.

Tracking code on sensitive pages — simply visiting a depression treatment page counts as protected information under the rules. Meta Pixel, Google Analytics, and similar trackers that send page-visit data to other companies without a signed agreement break the rules on those pages.

Email marketing — your patient email lists are protected information. To send marketing emails you need people to opt in and an email provider that has signed a data-handling agreement. Mailchimp's protected plan is fine; the standard plan is not for patient marketing.

CRM data — patient names, appointment details, and condition information sitting in your CRM are protected information. Salesforce Health Cloud is built to meet the rules; standard Salesforce needs a signed agreement plus careful setup.

Ad conversion tracking — sending Google or Meta data about which patients booked is protected information. Tracking done from your own server with scrambled identifiers is fine; ordinary cookie-based tracking on sensitive pages is not.

How the checker works

The tool runs through your current marketing setup and marks each item Pass, Flag, or Fail:

  • Pass: set up correctly under the current rules
  • Flag: unclear or borderline — check with whoever handles compliance
  • Fail: a clear breach; fix it straight away

Each flagged item comes with the exact rule it relates to and the steps to fix it. You can hand the result straight to your compliance officer or lawyer.

Common HIPAA marketing failures

Retargeting people who viewed mental health, addiction, or other sensitive pages. A clear breach under the December 2022 rules. Most clinics doing it have no idea — the ad platforms turn it on by default.

Mailchimp on the standard plan. The standard plan has no data-handling agreement, so clinics using it for patient marketing are exposed. Either move to the protected plan or switch to a provider that offers one.

Google Analytics on patient portals. Patient portal pages hold protected information even if the analytics never sees the form data — the web address alone can give it away. Clinics usually need privacy-first analytics (such as Plausible or Fathom) or server-based tracking.

Lead forms without a protected backend. Form entries land in a CRM or email tool. If that tool hasn't signed a data-handling agreement, the clinic is in breach the moment someone fills in the form.

Marketing abroad without the right local rules. Clinics marketing overseas need to follow India's DPDP law and the EU's GDPR on top of HIPAA. The rules overlap but aren't the same — DPDP needs its own consent step for patients in India.

What to do after the audit

  1. Fix the Fail items first — these are open breaches.
  2. Go over the Flag items with a compliance adviser — borderline cases that need a judgement call.
  3. Write down what you changed — keep a record showing exactly what was fixed.
  4. Re-check every quarter — the rules keep changing; what's fine this year may not be next year.
  5. Train your marketing team — most breaches happen because someone didn't know the rules.

FAQ

Things teams ask first.

Something else? Ask a strategist.

What's the HIPAA penalty for marketing violations?

Fines run from $100 to $50,000 per breach, up to $1.5M a year for each type of breach. There are criminal penalties too if a breach is deliberate. Most cases start with a patient complaint, though regulators also run their own audits.

Does HIPAA apply to my analytics platform?

Yes, if your site has any patient-facing pages or forms. Standard Google Analytics usually doesn't meet the rules for healthcare. You need privacy-first analytics (some GA4 setups done correctly), server-based tracking, or a healthcare-specific tool like Plausible or Fathom.

Can I retarget healthcare website visitors?

Sometimes. Retargeting people who viewed general pages (services, about, contact) is usually fine with the right consent. Retargeting people who viewed sensitive pages (mental health, addiction, fertility) breaks the rules under the December 2022 guidance.

What's a BAA and why does my marketing stack need it?

It's a data-handling agreement — a contract between your clinic and any vendor that touches patient information. HIPAA requires it. Any marketing tool that handles patient data (CRM, analytics, email, ad platforms) needs one, even if the data is scrambled.

How often should we re-audit HIPAA compliance?

At least every quarter while you're actively marketing. Also right away whenever you add new tracking, plug in a new tool, the rules change, or an incident is reported. For larger clinics, an outside audit once a year is a good idea.

Beyond the calculator

What the engagement actually delivers.

Full portfolio →

Items marked “mockup” are AI-staged presentations of real artwork.

Want the human version?

30 minutes with a strategist.

Tools are great for benchmarking. For your situation, the conversation is faster. No pitch.

  • A 30-minute call with a healthcare specialist
  • Your top three growth opportunities, in writing
  • Honest advice — even if that means not hiring us
  • No obligation and no hard sell
You’ll speak with a senior strategist
Consultations are hosted by Arush Thapar’s team.
Step 1 of 3Takes 30 seconds

What do you want to improve first?

Details stay privateNo obligationReply within 1 working day