Most telehealth clinics find out whether their marketing stack needed a business associate agreement at the worst moment: during a security review, a payer conversation, or after something has already gone wrong. It is a cheaper question to answer at vendor-selection time, and the answer is more nuanced than either “marketing is exempt” or “everything needs a BAA.”
What follows is how to think about the problem. It is not legal advice, and the specifics turn on your entity, your state, and your architecture, so this is a conversation to have with counsel armed with better questions.
The Test Is Architecture, Not Job Title
HIPAA generally requires a business associate agreement when a vendor creates, receives, maintains, or transmits protected health information on behalf of a covered entity. The vendor’s category is absent from that test. There is no marketing exemption and no automatic marketing inclusion.
So the question is not “is this an agency,” it is “does patient information flow through this system.” An agency that builds creative and manages campaigns, and never has access to patient records, is in a materially different position from one administering the CRM where patient names, phone numbers, and treatment interest are stored. Same industry, same job title, very different answer.
Run the question vendor by vendor rather than deciding once for the whole stack.
How Little It Takes to Become PHI
The consistent misunderstanding is that health information requires a diagnosis, a chart, or a medical record number. It does not. What makes information protected is the combination of something identifying a person with something indicating their health status or care.
An email address on its own is not health information. An email address paired with the fact that this person completed a weight loss intake form is. An IP address on its own is not. An IP address recorded against a visit to an HRT treatment page starts to be. No name and no date of birth is required for the pairing to be sensitive, which is why tracking on clinical pages is a different question from tracking on a homepage.
Where the Pixel Belongs and Where It Does Not
Tracking pixels are not inherently a problem, and a clinic that removes all measurement is just advertising blind. The workable line is between pre-clinical marketing surfaces and anything that reveals a condition or a course of treatment.
Tracking on a homepage, a service overview, or a general landing page is ordinary marketing measurement. Tracking on intake forms, quiz result pages, treatment selection steps, patient portals, and confirmation pages that name a medication is where the exposure lives. Custom events deserve particular attention, because an event named for a condition or a drug carries the health signal in the event name itself, and it will sit in an ad platform’s systems indefinitely.
The same logic rules out building advertising audiences from patient lists. Uploading a patient file as a custom audience, or generating a lookalike from it, transmits the fact of the relationship to the platform. It is also, separately, usually the worst-performing thing a clinic can do with that list compared to owned email and SMS.
“The BAA is the cheap part of this. The expensive part is discovering your CRM only offers one on a plan tier three steps above the one you are on, after you have already migrated two thousand patients into it,” says Simon Molay, founder of ScaleClinics.
The CRM Is Usually the Real Decision
Of everything in a typical clinic marketing stack, the CRM is the vendor most likely to hold protected health information, because it is where the patient record ends up. It is also where the unpleasant surprise usually lives: several widely used platforms will only sign a business associate agreement on a specific higher-priced tier, and that cost is not obvious during evaluation.
Ask three questions before you migrate anyone. Will the vendor sign a BAA. On which plan. What does that plan cost compared to the one you were about to buy. Repeat for anything else that touches patient data, including your scheduling tool, your SMS and email sender, your call recording or AI phone system, and your analytics.
The FTC Changed the Shape of This in July 2026
On July 29, 2026, the FTC, joined by the State of Utah and Los Angeles County, filed suit against Hims & Hers in the Northern District of California. The complaint alleges the company shared users’ sensitive health information with advertising platforms through tracking pixels and SDKs while promising discretion, along with separate allegations about billing and cancellation practices. The company has called the claims baseless and says it will defend itself.
The case is unresolved and it would be wrong to treat the allegations as findings. What is already relevant is the posture. The FTC is pursuing tracking-technology practices under its own consumer protection authority, which operates independently of HIPAA. A telehealth business that concluded it sits outside HIPAA, or that its vendors do, has not thereby escaped the exposure. Promises made in a privacy policy are enforceable on their own terms.
For a clinic, the practical step is making sure your privacy policy matches what your pixel does. That is a one-afternoon audit and it is the single highest-value thing most clinics could do about this.
A Starting Checklist
Inventory every vendor that touches patient information and decide, per vendor, whether a BAA is needed. Confirm which of them will sign one and on what plan. Audit which pages carry tracking and remove it from anything clinical. Review every custom event name and parameter for health signals. Confirm no patient list has been uploaded as an advertising audience. Then read your own privacy policy against what you just found.
This is general information, not legal advice. HIPAA, state privacy law, and FTC enforcement all apply differently depending on your entity and arrangements. Have counsel review your specific stack.