MH-9078MarTech & AI
HIPAA Compliance in Martech Goes Beyond Signed BAAs
Signing a BAA doesn't make a martech platform HIPAA-compliant, and a 2024 federal ruling has narrowed but not eliminated exposure on IP-address tracking, MarTech argues.
Wire notes
- A 2024 federal court ruling vacated part of federal tracking guidance that covered IP addresses on public pages about conditions or providers.
- HIPAA allows two methods of de-identification: removing 18 specified identifiers or a formal expert determination; hashing an email does not qualify.
- Class actions under state wiretap and medical confidentiality laws have been underway since 2022, with class periods reaching back to when tracking started.
- The FTC treats unauthorized sharing of health data with advertisers as a breach under its Health Breach Notification Rule, and several states have their own consumer health data laws.
- Vendors often limit BAAs to specific products, configurations, or fields, leaving ad integrations and AI features outside the contract's scope.
A 2024 federal court ruling vacated part of federal tracking guidance on IP addresses, but marketers serving health systems still face HIPAA exposure on patient portals, apps, and pages where people book care or enter symptoms, according to analysis published by MarTech. The piece argues that signing a business associate agreement is the wrong first question in any tool evaluation.
Here are the key gaps the article identifies.
What does HIPAA actually cover?
HIPAA regulates entities, not data. Covered entities include health plans, clearinghouses, and providers that bill electronically, plus the business associates who handle protected health information (PHI) for them. A hospital system falls under HIPAA. An agency that runs campaigns using a client's patient data likely qualifies as a business associate. A direct-to-consumer supplement brand does not.
That doesn't make non-covered brands safe. The FTC treats unauthorized sharing of health data with advertisers as a breach under its Health Breach Notification Rule. Several states have their own consumer health data laws. Different rules, not zero rules, apply.
What's the practical identifier in martech?
In martech, the identifier is rarely a name. It is an IP address or a hashed email appearing next to a URL, form field, or appointment date. Compliance risk depends on where that data goes, who receives it, and how it is used.
Which misconceptions put marketers at risk?
The MarTech analysis lists five claims marketers commonly rely on:
-
"We signed a BAA, so we're covered." A BAA covers the vendor who signed it. It does nothing for the ad platform an audience syncs to or the pixel another team added last quarter.
-
"De-identified data isn't PHI." True only if the data meets one of two HIPAA methods: removing 18 specified identifiers or a formal expert determination. The identifier list includes IP addresses, device IDs, and URLs. Hashing an email does not de-identify it; hashing exists so records can be matched. That is the opposite of de-identification.
-
"IP addresses and device IDs aren't PHI." Alone, they often aren't. Next to health context, they can be. The 2024 ruling vacated the portion of federal tracking guidance that covered IP addresses on public pages about conditions or providers. Patient portals, apps, and appointment-booking or symptom-entry pages remain in scope.
"Server-side tagging solves it." Server-side changes where data is collected, not what is forwarded. Sending PHI to a vendor without a BAA is the same disclosure through a different pipe. Stripping PHI after receipt doesn't cure it; federal guidance says so directly. The value lies in the control point, where filtering happens before anything leaves.
"Our privacy policy covers this." Disclosing PHI to a third party for marketing requires a HIPAA authorization with specific required elements, including the right to revoke. A privacy policy isn't one. Neither is a cookie banner.
How do EHR feeds change the calculus?
Health systems increasingly pipe EHR data into CDPs, marketing automation, and journey-orchestration tools, including appointment history, service lines, discharge dates, and sometimes diagnosis codes. That data is PHI the moment it lands, and the platform vendor is a business associate. Its BAA has to cover the modules and features in actual use.
Communications about a covered entity's own services generally don't need patient authorization. Communications a third party pays for do, as does disclosing patient data for any other party's marketing.
Syncing an audience from a CDP to an ad platform hands a patient list to a company that typically won't sign a BAA. A journey triggered by a diagnosis can reveal that diagnosis in an email subject line or text preview. The minimum necessary standard applies: send each platform only the fields the use case requires.
What does a BAA actually do?
A BAA defines what the vendor may do with PHI and binds it to HIPAA's rules. It typically covers permitted uses and disclosures, Security Rule safeguards, breach and incident reporting, and flow-down to subcontractors.
A signed BAA still leaves four compliance gaps:
-
It doesn't fix structural problems. If a vendor won't sign, or its terms permit the vendor to use the data for its own ad products, a pixel on a condition-keyword URL remains an impermissible disclosure.
-
It doesn't expand what HIPAA allows. Retargeting and lookalike modeling usually require the ad platform itself to receive PHI, and few will under a BAA. No BAA can authorize a vendor to use identifiable PHI for its own commercial purposes.
It doesn't transfer your obligations. The risk analysis and the map of where PHI flows stay with the covered entity.
It doesn't cover every product or feature. Vendors often limit BAAs to specific configurations. Some exclude the exact fields marketers plan to use. Add-ons like ad integrations or AI features are sometimes carved out.
Why does enforcement matter now?
Class actions under state wiretap and medical confidentiality laws have been underway since 2022 and represent the larger financial exposure. Class periods reach back to when tracking started, so a tag installed years ago remains a liability. The federal regulator says its tracking investigations focus on whether organizations assessed and mitigated risk under the Security Rule. Not knowing a tag existed counts as evidence that the risk analysis missed something.
Where should health marketers start?
The article recommends mapping the stack in both directions. On the collection side, inventory every tag and SDK on every web and app property, including ones nobody remembers adding, and note what each sends from which pages. On the data side, trace every feed out of the EHR: which fields go into which platforms and where those platforms send data next.
Ad audiences, enrichment vendors, SMS gateways, and agency exports all count. Check each destination against a BAA, its actual scope, and whether the use itself is permitted. Gaps usually surface once the map exists.
Unresolved questions — whether a visit to a service-line page ties to the visitor's own care, or whether a hashed patient list uploaded only to suppress ads still counts as a disclosure — mean reasonable lawyers will keep giving different answers. That is why legal and compliance belong in the process early, not at final sign-off. Marketing knows what the tools do and where data moves. Legal knows how to read ambiguity and what the organization can defend. Health systems that wait for one universal "compliant" answer will keep waiting; the answer is organizational, and someone has to decide it on purpose.
via semrush.com (Original)
More from Elena Vasquez
Show full bio
Senior reporter covering media and advertising at Marketing Herald.
88 articles
More on the wire
- California Passes Compromise SB-690, Keeping CIPA Lawsuits Alive
- Apple Readies iOS Crackdown on Hundreds of Programmatic Data Firms
- Insurers Emerge as New Enforcers in Ad Tech's AI Compliance Push
- iOS 27 Is Blocking Ad Tech Vendors With No Warning
- Google Ads Customer Lifecycle Goals: The Good, The Bad, The Ugly