Updated August 11, 2026. Lead to Recovery, Pompano Beach, FL. 855-876-7238.
Direct Answer
HIPAA-compliant marketing means promoting healthcare services without using protected health information in ways the Privacy Rule regulates. It governs how audiences are built, which vendors receive data, and what agreements are in place. For substance use disorder programs, a second federal rule, 42 CFR Part 2, adds stricter consent requirements on top.
This article is general information, not legal advice. Consult qualified healthcare counsel about your specific situation.
TL;DR
- HIPAA regulates a narrowly defined activity called marketing, and a large share of what treatment centers do every day sits outside that definition
- Part 2 is stricter, has no carve-out for describing your own services, and OCR began accepting complaints under it on February 16, 2026
- A federal court vacated part of OCR’s online tracking guidance in June 2024, but only the portion covering metadata on public pages, and private lawsuits were never affected
- Google treats health as a sensitive interest category and restricts advertiser-curated audiences for it, which blocks most retargeting by contract before any privacy question arises
- How you pay for leads is a separate criminal-law question under EKRA, and the first federal appellate ruling on it landed in July 2025 and reached marketers directly
- The largest financial exposures in this area have come from private class actions rather than from OCR
One liner: Audit where your data goes before you audit what your ads say.
Key Numbers
| Figure | What it is | Source and date |
|---|---|---|
| February 16, 2026 | Part 2 compliance date and start of OCR civil enforcement | HHS Office for Civil Rights, 2026 |
| June 20, 2024 | Date a federal court vacated the contested portion of OCR’s tracking bulletin | N.D. Tex., 2024 |
| January 28, 2026 | Effective date of the current HIPAA civil monetary penalty schedule | Federal Register, 2026 |
| $73,011 | Maximum penalty per violation, all four tiers, current schedule | Federal Register, 2026 |
| $12,225,000 | Advocate Aurora pixel class action settlement, final approval July 2024 | Court record, 2024 |
| $30,000 | OCR settlement with a psychiatric practice over PHI in review replies | OCR, 2023 |
| July 11, 2025 | First federal appellate decision interpreting EKRA | 9th Cir., 2025 |
| 18 | Identifiers that must be removed under Safe Harbor de-identification | 45 CFR 164.514 |
| July 2027 | Current target for final action on the proposed Security Rule overhaul | HHS Unified Agenda, 2026 |
What HIPAA Actually Says About Marketing
In short: HIPAA does not ban marketing. It defines the word narrowly, then requires written authorization before protected health information gets used for it. Most of what a treatment center does every day sits outside that definition.
Under the Privacy Rule, marketing means a communication about a product or service that encourages the recipient to purchase or use it [1]. That definition does the work people expect the statute to do, and it does less of it than they think. The rule bites when protected health information is used to make the communication. A billboard on I-95 uses no PHI. An email to everyone who completed detox last quarter does.
The definition at 45 CFR 164.501
Two questions decide whether a communication is regulated marketing.
Did PHI select the audience? Broadcast advertising, organic search content, a Google Ads campaign targeting a keyword, a community education night: none of these use patient information to pick who sees the message. The Privacy Rule has nothing to say about them. Ad platform policy and truth-in-advertising law still apply, which is a separate matter covered further down.
Is a third party paying for the message? This is the hinge that catches people. The rule defines financial remuneration as direct or indirect payment from or on behalf of a third party whose product or service is being described, and excludes payment for treatment of an individual [1]. Accept money from a lab, a medication manufacturer, or a partner program to send a message to your patients, and a communication that would otherwise be permitted becomes regulated marketing.
What the rule carves out
Three categories are excluded from the definition, and both members of the second group collapse the moment third-party money appears [1].
| Exclusion | Covers | Conditions |
|---|---|---|
| Refill reminders | Communications about a drug or biologic currently prescribed to the individual | Any payment received must be reasonably related to the cost of making the communication |
| Treatment and care coordination | Treating the individual, case management, directing or recommending alternative treatments, therapies, providers, or settings of care | No financial remuneration from a third party |
| Your own services | Describing a health-related product or service provided by the covered entity making the communication | No financial remuneration from a third party |
That third row is the one treatment centers most often get wrong, in the cautious direction. A center describing its own new outpatient track to its own patients is describing a health-related service it provides. Absent third-party payment, that falls outside the marketing definition entirely. The blanket rule many programs operate under, that you can never contact a former patient about a program, is stricter than the Privacy Rule requires.
It is not stricter than the rule that governs substance use disorder records. That comes next.
Authorization is not consent
When a communication does land inside the definition, the Privacy Rule requires a written authorization before PHI is used or disclosed for it, with narrow exceptions for face-to-face communications and promotional gifts of nominal value [2]. If third-party remuneration is involved, the authorization has to say so [2].
Authorization is a specific document with required elements. It is not the general consent buried in an intake packet, and it is not a checkbox on a web form. Programs that treat the two as interchangeable have an intake packet that will not survive a records request.
Why Behavioral Health Plays by a Second Rulebook
In short: If your program diagnoses, treats, or refers for substance use disorder, a second federal rule sits on top of HIPAA. It is stricter on marketing than HIPAA is, and OCR began accepting complaints under it on February 16, 2026.
The previous section ended on a permissive note. A covered entity describing its own services to its own patients, with no third-party money involved, sits outside HIPAA’s marketing definition. For a mental health practice, that is where the analysis ends. For an SUD program, it is where the analysis starts, because 42 CFR Part 2 does not have that carve-out.
What makes a program a Part 2 program
Two conditions have to be met. The program has to hold itself out as providing, and actually provide, SUD diagnosis, treatment, or referral for treatment, and it has to be federally assisted [3][4]. Operators consistently underestimate the second condition. Federal assistance reaches well past grant funding [3]:
- Participating provider status in the Medicare program
- Authorization to conduct maintenance treatment or withdrawal management
- DEA registration to dispense a controlled substance used in SUD treatment, which captures most medication-assisted treatment programs
- Receipt of federal financial assistance in any form, including assistance that does not pay for SUD services
- Tax-exempt status granted by the IRS, or the deductibility of contributions to the program
Under that list, a private-pay residential program with a DEA registration and a nonprofit designation is federally assisted. A general medical facility is not a Part 2 program, but an identified unit inside one can be [4].
Where Part 2 is stricter than HIPAA
Part 2 works from the opposite default. Records may be used or disclosed only as the rule permits, and marketing is not among the permitted uses [5]. There is no equivalent to HIPAA’s exclusion for describing your own services.
| Marketing activity | Under HIPAA | Under Part 2 |
|---|---|---|
| Emailing your own patients about your own new program | Outside the marketing definition, absent third-party payment [1] | Requires written consent meeting the rule’s elements [7] |
| Confirming a named person is a patient | Generally requires authorization | Cannot be acknowledged at a facility publicly identified as SUD-only without written consent or a court order [5] |
| Fundraising to your patient list | Permitted with an opt-out | Permitted only after a clear and conspicuous opt-out opportunity, disclosed in the patient notice [8] |
| Building an audience from your record system | Authorization required if PHI selects the audience | Consent required, with specified elements and an expiration [7] |
That second row is why alumni testimonials, review responses, and tagged social content carry more risk in this vertical than in any other corner of healthcare marketing.
What changed on February 16, 2026
Four dates matter, and none of them appear on the pages currently ranking for this topic.
| Date | Event |
|---|---|
| February 16, 2024 | Final rule published, aligning Part 2 with HIPAA under CARES Act section 3221 [6] |
| April 16, 2024 | Rule takes effect, opening a two-year implementation window [6] |
| August 25, 2025 | HHS delegates Part 2 administration and enforcement to the Director of OCR [6] |
| February 16, 2026 | Compliance required. OCR begins accepting complaints alleging Part 2 violations and Part 2 breach notification failures [6][9] |
Worth stating plainly: the 2024 rule loosened several things. A single patient consent can now cover future treatment, payment, and health care operations, and records no longer have to be segregated [6]. Marketing was not part of that loosening. The consent requirement for marketing uses survived the alignment intact.
One practical consequence for mixed programs. A center running a mental health track and an SUD track holds two record populations under two different rules, often inside one CRM and one email platform. When the tighter rule applies to part of a list, plan the campaign to the tighter rule.
What Counts as PHI Inside a Marketing Stack
In short: PHI is not a type of data. It is an identifier joined to health information about an identifiable person. On a treatment center website, the page itself often supplies the health half, which is why identifiers that look harmless on other sites carry weight here.
Most stack audits go wrong at the first question. Teams look at a field and ask whether it is sensitive. The rule asks something different: does this information identify a person, and does it relate to that person’s health, care, or payment for care. Both halves have to be present. Neither half is interesting alone.
The 18 identifiers under Safe Harbor
The Privacy Rule’s Safe Harbor method lists the identifiers that have to be stripped, for the individual and for their relatives, employers, and household members, before data stops being PHI. It also requires that the covered entity have no actual knowledge that what remains could still identify someone [10].
| Identifier | Where it turns up in a marketing stack |
|---|---|
| Names | Form fields, CRM records, call transcripts, review responses |
| Geographic units smaller than a state | Form addresses, geo-targeting exports, location-based bid adjustments |
| All date elements except year, and ages above 89 | Admission and discharge dates in a CRM, appointment timestamps |
| Telephone numbers | Call tracking logs, SMS platforms, lead notifications |
| Fax numbers | Referral intake, legacy admissions workflows |
| Email addresses | ESP lists, custom audience uploads, form submissions |
| Social security numbers | Insurance verification forms, rarely needed pre-admission |
| Medical record numbers | EHR-to-CRM syncs |
| Health plan beneficiary numbers | Insurance verification forms and their notification emails |
| Account numbers | Billing portals, payment plan communications |
| Certificate and license numbers | Uncommon in marketing, common in referral partner data |
| Vehicle identifiers, including plate numbers | Facility intake logs |
| Device identifiers and serial numbers | Mobile advertising IDs, device fingerprints |
| Web URLs | Referrer strings, UTM parameters, page paths in analytics |
| IP addresses | Every analytics tool, every ad pixel, every chat widget, by default |
| Biometric identifiers | Voice prints in recorded calls |
| Full face photographic images | Alumni photos, testimonial video, social content |
| Any other unique identifying number, characteristic, or code | Cookie IDs, click identifiers, hashed audience keys |
Note the ZIP code exception. The first three digits can be retained when the area they cover holds more than 20,000 people, and are otherwise changed to 000 [10]. Note also the last row. The catch-all is where most modern advertising identifiers land, and it is the reason “we only send anonymous IDs” is rarely the end of the conversation.
Safe Harbor is one of two routes. The other, Expert Determination, has a qualified person apply statistical and scientific principles, conclude that the risk of identification is small enough to satisfy the regulatory standard, and document how that conclusion was reached [10]. Safe Harbor is a checklist. Expert Determination is an opinion someone signs.
Why context does the work in behavioral health
An IP address recorded on a hospital’s parking directions page carries almost no health inference. The same IP address recorded on a page titled “opioid detox program” carries a strong one. The identifier is identical. The page supplies the health context.
Whether that pairing on a public page actually constitutes PHI is the exact question a federal court took up in 2024, and the answer is more favorable to providers than most compliance guides suggest.
Part 2 runs a parallel track. Its term is patient identifying information, defined as name, address, Social Security number, fingerprints, photograph, or similar information by which a patient’s identity can be determined with reasonable accuracy, directly or by reference to other information [4]. The rule’s de-identification standard then points back to the HIPAA method [5].
De-identified, aggregated, hashed
Marketers use these three words as synonyms. They describe three different states.
De-identified means one of the two regulatory methods was applied and documented. The result is outside the Privacy Rule.
Aggregated means individual rows were rolled into totals. A report showing 412 sessions on a page is aggregated. That is a summary of data, not a treatment of the underlying data, and the event-level records usually still exist somewhere upstream.
Hashed means transformed into a fixed string. Hashing an email address is a security measure, not de-identification. Hashes are deterministic, which is precisely why ad platforms accept them for audience matching. A value that reliably matches to one person still identifies that person.
One field deserves a specific mention. The open text box labeled something like “tell us how we can help” collects clinical detail nobody scoped, in the reader’s own words, and then routes it wherever the form platform sends submissions.
Website Analytics and Tracking Pixels After the 2024 Ruling
In short: A federal court struck down one specific piece of OCR’s tracking guidance in June 2024, covering metadata on public webpages. The rest of the guidance stands, the vendor contract problem is untouched, and private lawsuits run on a separate track that the ruling did not narrow.
This is where published guidance splits into two wrong answers. One set of pages still describes the vacated rule as binding. Another set read the headline and concluded that tracking on healthcare sites is fine again. The accurate position sits between them and is more useful than either.
What the court vacated, and what it did not
OCR published guidance in December 2022 taking the position that an IP address combined with a visit to an unauthenticated page about a health condition or provider could constitute PHI and trigger HIPAA obligations. OCR revised the guidance in March 2024. Hospital plaintiffs challenged the revised version, and on June 20, 2024 the U.S. District Court for the Northern District of Texas held that this rule, which the litigation called the Proscribed Combination, was unlawful because it exceeded the agency’s authority under HIPAA, and vacated that portion [11]. The rest of the revised bulletin was left intact [11]. HHS filed an appeal in August 2024 and withdrew it days later [12].
Three consequences follow, and the third is the one guides miss.
On public marketing pages, the specific proposition that metadata alone creates PHI no longer stands as an agency rule. A blog post about recognizing alcohol use disorder, a location page, a careers page: these are the pages the ruling addressed.
On authenticated pages, nothing changed. Portals, booking flows behind a login, and anything where a person has identified themselves to you were never covered by the vacated portion.
On private litigation, nothing changed either. HIPAA has no private right of action, so the pixel cases were never HIPAA claims. They are state wiretap, privacy, and consumer protection claims, and a federal court’s reading of HHS’s rulemaking authority does not touch them. Advocate Aurora Health settled consolidated pixel claims for $12,225,000, with final approval granted in July 2024 [14]. Novant Health settled a comparable consolidated case for $6.6 million [15]. Neither was an OCR enforcement action.
The vendor question is separate from the court question
Even where a page is unquestionably outside HIPAA’s reach, the tool sending data off your site has to be contractually permitted to receive whatever it receives.
Google signs a business associate agreement covering a defined list of Workspace and Cloud services. Google Analytics, Tag Manager, and Google Ads sit outside that list, along with most additional Google services and third-party Marketplace add-ons installed through a Workspace account [13]. That is a product decision, not a configuration setting. Turning on IP anonymization, shortening retention, or moving to server-side tagging does not create a BAA where the vendor does not offer one.
The practical read: these tools are available for pages where no PHI is involved, and a BAA-covered alternative is the path for pages where it is. Which pages are which is the next question.
Classifying your pages
Every page on a treatment center site falls into one of three buckets. Deciding which bucket each page belongs to is the whole exercise, and it is worth doing alongside a website build or rebuild rather than after.
| Bucket | Examples | What the visitor has revealed | Typical posture |
|---|---|---|---|
| Public content | Blog posts, condition pages, about, careers, location pages | Interest, not identity | Standard analytics generally used here |
| Transitional | Booking, insurance verification, chat widgets, contact and intake forms, thank-you pages | Identity plus health context, often in the same request | BAA-covered tools only, and no third-party tags |
| Authenticated | Patient portal, alumni portal, anything behind a login | Both, confirmed | BAA-covered tools only |
The transitional bucket is where nearly every real problem lives. A thank-you page fires a conversion event that carries the referring URL, and the referring URL is a detox program page. The form platform emails a lead notification containing a free-text field. A chat widget loads a third-party script on the same page where a person is typing about their drinking. None of these are exotic. All of them are configuration decisions, which means they are fixable, and getting them right is part of building conversion tracking that stands up.
There is a fast way to see your own exposure. Open a booking or intake page in a browser, open developer tools, watch the network tab, and note every third-party domain that receives a request. Fifteen minutes gives you a list. The list is the audit. Tag governance tools exist as a category and automate this at scale, which is worth considering for a large site. For most treatment center sites the manual pass is enough to find the problem.
Forms, Chat, and Intake: Where the Leaks Actually Happen
In short: The form itself is rarely the compliance problem. The eight places a submission travels afterward are the problem, and most programs have never mapped that path end to end.
The previous section dealt with data that leaves your site without anyone deciding to send it. This section deals with the opposite: information a person hands over on purpose, in response to a question you wrote, which then moves through a chain of systems nobody has inventoried.
Lead forms and intake forms are different objects
A lead form asks whether a conversation should start. Name, phone, maybe a preferred callback time. An intake form collects clinical history, insurance details, and often a description of current use.
Programs run both through the same platform, under the same settings, with the same notification rules. When that happens, the whole path defaults to whatever protection the lighter form was set up with, which is generally none.
The distinction is worth drawing before the audit starts, because the two form types deserve different tools, different retention windows, and different destinations.
Where the submission goes next
Trace a single submission. A form on a page about medication-assisted treatment, collecting a name and a phone number.
| Stop | What arrives | Usual BAA status |
|---|---|---|
| 1. Browser | Field values, page URL, referrer, any hidden fields | Not applicable |
| 2. Form platform | Full submission, stored | Sometimes covered |
| 3. Webhook or integration | Full submission, in transit to the CRM | Rarely reviewed |
| 4. CRM | Full submission, stored and searchable | Sometimes covered |
| 5. Notification email to admissions | Name, phone, page context, free-text field | Often uncovered |
| 6. Forwarded copy | Same, now on a personal device | Almost never covered |
| 7. Autoresponder to the inquirer | Confirms the inquiry in writing, to an address you have not verified | Sometimes covered |
| 8. Conversion event to analytics and ad platforms | Event name, page URL, sometimes hashed identifiers | Not covered |
Eight stops. In a typical setup, a business associate agreement exists at one or two of them. The vendor management section below covers which of these vendors needs one and how to tell.
Stop 5 deserves particular attention. The lead notification email is the least examined artifact in behavioral health marketing. It contains everything the form collected, it lands in whatever inbox was configured during setup, and it gets forwarded to phones so admissions can respond quickly. Speed matters in this vertical, which is exactly why this path was built without a review.
Worth retiring a common defense here. A form that asks only for a name and a phone number, sitting on a page about opioid treatment, has still recorded that this named person inquired about opioid treatment. The health context comes from the page, not from a field.
Chat widgets and session replay
A chat widget is a third-party script loaded on the page where a person types their situation in their own words. The transcript is a record. It is stored somewhere, retained for some period, and possibly reviewed for training.
Session replay tools go further. They reconstruct the visit, including keystrokes in fields the visitor typed into and then abandoned. Someone who starts filling in a form, thinks better of it, and closes the tab may have generated a stored record anyway.
Neither category is off limits. Both need the same three answers as any other vendor: what does it receive, where does it store it, and will the provider sign a business associate agreement.
A five-question field inventory
Run this against every form on the site.
- What page does this form sit on, and what does that page reveal about the person filling it in?
- Which fields are visible, and which are hidden, prefilled, or passed through from the URL?
- Where does the submission go, in order, until it stops moving?
- Which of those destinations has a signed business associate agreement?
- How long does each destination keep it, and who can search it?
Most programs cannot answer question three without opening the form builder. That is the finding.
Call Tracking and Text Messaging
In short: A call tracking record pairs a phone number with the page and often the search term that produced the call. Recording adds state law, and texting adds the TCPA. HIPAA is one of three regimes operating here, and it is not always the strictest.
Calls drive admissions in this vertical. That makes the admissions line the highest-value data stream a treatment center owns, and the least audited.
What a call tracking record actually contains
Dynamic number insertion swaps the displayed phone number based on how the visitor arrived, which is what makes channel attribution possible. The byproduct is a record that looks like this.
| Element | Identifier under Safe Harbor? | Supplies health context? |
|---|---|---|
| Caller’s phone number | Yes | No |
| Timestamp and duration | Yes, dates related to an individual | No |
| Landing page URL | Yes | Frequently |
| Referring keyword or search term | Catch-all, when unique | Frequently |
| Campaign and ad group | No | Sometimes, by name |
| Call recording | Voice print is biometric | Yes |
| Transcript | Depends on contents | Yes |
| Rep’s notes field | Whatever was typed | Usually |
The keyword row deserves its own moment. Call tracking platforms commonly capture the search term that produced the call, which is the entire point of keyword-level PPC attribution. In this vertical that term is regularly a substance, a condition, or a phrase like “detox near me.” A phone number paired with that query is the identifier-plus-context combination described above, sitting in a vendor database, sorted for reporting.
Campaign naming conventions compound it. An ad group labeled for a specific substance and level of care travels into every downstream system that receives conversion data.
Recording, transcription, and state consent law
Call recording is governed by state wiretap statutes, which have nothing to do with HIPAA and vary in what they require. Some states are satisfied when one party to the call consents. Others require all parties to consent. A national campaign routes calls from every state into one recording configuration, which means the configuration has to satisfy the strictest state it reaches, not the state the facility sits in.
Transcription changes the character of the record again. A recording is an audio file somebody has to listen to. A transcript is a searchable text document of a clinical conversation, held by a vendor, retained on whatever schedule the account defaulted to at setup, and increasingly passed through automated summarization. Ask where transcripts live, how long they persist, and who else processes them.
Text messaging
Two questions, and they are independent.
Was the list built permissibly? If patient information selected who receives the message, the rules above govern. For a Part 2 program, written consent is required, and there is no equivalent to HIPAA’s own-services carve-out.
Does the message satisfy the TCPA? Marketing calls and texts require prior express written consent under the TCPA regardless of anything HIPAA says. This is a separate statute with a private right of action, which is more than HIPAA offers a plaintiff.
One point of currency here, because a great deal of published guidance is out of date. The FCC adopted a rule in 2023 that would have required consent to be given to one identified seller at a time and limited to topics logically and topically associated with the interaction that prompted it. The Eleventh Circuit vacated that rule on January 24, 2025, holding that the FCC exceeded its statutory authority under the TCPA, and remanded [16]. The FCC subsequently removed the vacated language and formally eliminated the requirement [17]. The rule never took effect. Guidance that tells treatment centers to rebuild their lead consent flows around one-to-one consent is describing a requirement that does not exist.
The underlying TCPA consent standard still applies. Honoring a STOP reply satisfies the opt-out obligation and says nothing about whether the list was assembled permissibly in the first place.
Email Marketing and CRM
In short: Building a segment is a use of patient information, not a step you take before using it. For a Part 2 program, that use needs written consent even when HIPAA alone would permit it. The reliable fix is architectural: keep the system that holds records separate from the system that runs campaigns.
Segmenting a list is a use, not a preparation
A covered entity describing a health-related service it provides, to its own patients, with no third-party payment involved, falls outside HIPAA’s marketing definition [1]. On HIPAA alone, an alumni newsletter or a note about a new outpatient track is permitted. The blanket prohibition many programs impose on themselves is stricter than the Privacy Rule requires.
Now the correction, and it is not a footnote. If the program is a Part 2 program, the analysis does not end there. Part 2 permits uses and disclosures of records only as the rule allows, marketing is not among them, and there is no own-services exclusion [5]. Using records to decide who receives the email requires written consent meeting the rule’s elements [7]. A mental health practice that is not a Part 2 program and a co-located SUD program can send the same email under two different standards.
Either way, the decision point is earlier than most teams think. It is not the send. It is the query that produced the audience.
Two systems, one boundary
Almost every problem in the preceding three sections dissolves under one architectural choice.
| Marketing system | Clinical system | |
|---|---|---|
| Holds | Inquirers, prospects, referral contacts | Patients and their records |
| Never holds | Diagnoses, treatment status, admission dates, clinical notes | Campaign data it does not need |
| Vendors | Chosen for capability | Chosen for BAA availability and controls |
| Integration | Receives consent status only | Pushes nothing outbound by default |
The boundary is crossed by one thing: whether a person has given the consent that permits contact. Not their diagnosis, not their admission date, not their program.
This is harder than it sounds, because reporting pressure pushes the other way. Someone wants cost per admission by campaign, which requires knowing which inquirers became patients, which pulls admission status back into the marketing system. That reporting is achievable with aggregate counts rather than record-level syncs. Decide which one you built.
The minimum necessary standard points the same direction. Nobody on a marketing team needs a diagnosis field. The question is not whether a CRM could hold one securely. It is whether it should hold one at all.
The suppression list paradox
Worth naming because the instinct behind it is a good one.
A program decides former patients should not see its ads. Ad platforms support this through exclusion audiences. To exclude a group of people, you upload the list of who they are. Hashing the email addresses does not resolve it, for the reason given above: the hash is deterministic, which is why matching works.
The privacy-protective impulse produces the disclosure.
What the platform question actually is
Teams ask whether a given email platform is HIPAA compliant. The question does not resolve at the platform level.
Ask instead: what am I about to send this vendor, does that constitute PHI or a Part 2 record, and if it does, will the vendor sign a business associate agreement covering it. A platform with no BAA is available for a list that contains no PHI. The same platform is unavailable the moment the list is built from records.
One more regime applies to email specifically. Commercial messages carry CAN-SPAM obligations that run independent of both HIPAA and the TCPA: accurate header and sender identification, a valid physical postal address, and a working unsubscribe mechanism honored promptly. Those obligations attach to the message regardless of how the list was built.
Paid Advertising, Retargeting, and Platform Policy
In short: Two separate rulebooks operate in paid media. Federal law governs whether patient information built your audience. Platform contracts govern whether you may advertise at all and what you may target on. In this vertical the platform rules bite first, and they are stricter than HIPAA on retargeting.
A treatment center can be flawless on HIPAA and Part 2 and still be unable to run a single ad. Understanding which rulebook is blocking you determines whether the fix is a lawyer, a certification application, or a campaign rebuild.
| What it governs | Source | What happens when you violate it | |
|---|---|---|---|
| HIPAA and Part 2 | Whether patient information was used to build the audience or the conversion data | Federal regulation | OCR complaint, investigation, civil monetary penalty |
| Platform policy | Whether you may advertise, what you may target on, what you may send back | Contract terms you accepted | Ad disapproval, account suspension, loss of the channel |
LegitScript is the gate, and it is not federal law
Since 2018, the major platforms have outsourced advertiser vetting for this category to one certification program.
Google’s healthcare and medicines policy requires certification as an addiction services provider through LegitScript before recovery-oriented drug and alcohol addiction services can be advertised in the US. Meta requires both: certification with LegitScript and written permission obtained by applying to Meta directly [20]. Microsoft Advertising and Nextdoor recognize the same certification [21].
None of that is a statute. It is a set of contract terms, and satisfying every one of them tells you nothing about your position under the Privacy Rule or Part 2.
Two exclusions in the certification standards matter more than the rest, and they point at a business model rather than a paperwork gap [21]:
- Lead generators, call centers, and marketers who refer patients to other providers in exchange for compensation are not eligible.
- Sober living homes and recovery residences without licensed clinical services do not meet the standards.
Hold that first exclusion. A federal criminal statute covered further down reaches the same arrangement from a different direction. When a certification program and a criminal statute both single out per-referral compensation, the arrangement is worth examining regardless of which one you were worried about.
What the platforms restrict on their own terms
This is where the paid channel gets genuinely narrower than the law requires, and where most agency guidance is wrong by omission.
Google treats health as a sensitive interest category. The category expressly covers physical and mental health conditions, including chronic conditions requiring long-term care or management, and products or services to treat or manage them [18]. Advertisers promoting products and services falling within sensitive interest categories cannot use advertiser-curated audiences [19]. Custom segments built on sensitive creative or pointing to sensitive landing pages face further serving limits [19].
Read that plainly. Remarketing lists and customer-match uploads, the two tactics the retargeting question is usually about, are restricted by platform policy for this category before any privacy analysis begins. The HIPAA question about whether you may build a retargeting audience is frequently moot, because the platform will not let you use it. Policies verified as published in July 2026, and this is the fastest-changing material in this guide.
What remains available is contextual and intent-based reach: search terms, placements, and content adjacency rather than accumulated audience data. That is a real constraint on media planning and it is better to design around it from the start than to discover it at launch. The same logic shapes what is workable on paid social.
One constructive note. A large share of inquiries in this vertical come from a spouse, parent, or adult child rather than the person entering treatment. Broad intent-based reach to a searching family member raises none of the questions that retargeting a former site visitor does, and it is frequently the better-performing audience anyway.
Conversions API and server-side tagging
These are sold as the compliance answer. They are not.
Moving a transmission from the browser to your server changes who sends the data. It does not change what the recipient receives, and it does not create a business associate agreement where the vendor does not offer one. If the payload identifies a person and the page supplied the health context, relocating the sending mechanism relocates nothing that matters.
Server-side implementations do offer real control, because you decide field by field what leaves. That control is the value. Use it to send less, not to send the same thing from a different origin.
Offline conversion import belongs in the same conversation. Rather than firing a browser event when someone converts, you upload conversion outcomes from your own records to train the platform’s bidding. It genuinely reduces what leaves the browser, which is a real improvement over pixel-based measurement. It does not change the underlying question. You are still deciding what to send and to whom, and the identifiers used to match those uploads are still identifiers.
Testimonials, Reviews, and Social Proof
In short: A person can tell their own recovery story publicly whenever they choose. The program cannot confirm it. That asymmetry governs testimonials, review replies, alumni features, and tagged photos, and Part 2 makes it stricter than it is anywhere else in healthcare.
This is the highest-emotion, lowest-scrutiny activity in the vertical. It is also where a single well-meaning sentence, published under the program’s own account, becomes a permanent public disclosure.
The asymmetry that governs everything here
Patients hold their own information and may share it freely. A covered entity may not, absent authorization [2].
Part 2 tightens this considerably. Where a facility is publicly identified as a place providing only SUD diagnosis, treatment, or referral, the presence of an identified patient may be acknowledged only with written consent or a court order [5]. The rule goes further still: a response to a request that cannot be fulfilled must be framed so that it does not affirmatively reveal that an identified individual has been or is being treated for a substance use disorder [5].
Read that against a marketing calendar and the implications cascade. It is not only that you cannot publish a name. It is that a warm, non-specific, entirely well-intentioned public reply can itself be the acknowledgment.
Replying to a review is a disclosure
OCR has enforced on this repeatedly, including against a behavioral health provider. In June 2023, OCR announced a settlement with Manasa Health Center, a New Jersey psychiatric practice, resolving allegations that it impermissibly disclosed protected health information in public responses to negative online reviews, affecting four patients. The practice paid $30,000 and entered a two-year corrective action plan [22].
The trigger is confirmation, not detail. Consider a constructed example, written for illustration and not drawn from any real review.
A review reads: “The staff here saved my life. Ninety days and counting.”
A reply that discloses: “Thank you so much for trusting us with your recovery. We are proud of your ninety days and we loved having you in the program.”
That reply confirms, publicly and permanently, that a named account holder was a patient at a named facility. Every warm specific in it makes the confirmation firmer.
A reply that does not: “Thank you for the kind words. We are not able to discuss anyone’s care publicly, but our team is always glad to hear feedback. If you would like to reach us directly, our main line is on our contact page.”
Nothing is confirmed. Nothing is denied. The tone is still human.
The hardest case is a negative review that is unfair or factually wrong. That is exactly when the instinct to correct the record is strongest, and correcting the record almost always requires disclosing something about the person. The recommended posture is to move the conversation off the platform without acknowledging the relationship, and to treat any internal decision to respond further as a legal question rather than a marketing one.
Testimonials, revocation, and photographs
A published testimonial requires authorization from the individual, with the required elements, before it runs [2]. For a Part 2 program, written consent meeting the rule’s elements is the equivalent requirement [7].
Two practical points follow.
Authorization is revocable. Someone at ninety days signs enthusiastically. Three years later they are applying for a professional license, or a custody arrangement is contested, and they want the video gone. Content on properties you own can be pulled. Content distributed to third-party platforms, syndicated, or scraped is a different problem. Time-bound the consent, keep testimonial assets on owned properties where practical, and maintain a record of who consented to what and when.
Photographs are identifiers. Full face photographic images and comparable images sit on the Safe Harbor list [10]. That reaches the group photo at an alumni barbecue, the facility tour video with residents visible in the background, and the graduation post. Consent covers the people who gave it and nobody else in the frame.
One category sits outside all of this. A staff member sharing their own recovery story is speaking for themselves, which is often the most credible content a program can publish. The line is whether the program’s content presents them as a patient of the program.
Separately, testimonials that imply typical outcomes carry FTC exposure on advertising substantiation grounds, which runs independently of anything in this section.
Vendor Management: BAAs and the Questions to Ask
In short: A vendor that creates, receives, maintains, or transmits PHI while performing a service for you is a business associate, and an agreement with specified terms has to be in place before the data moves. For Part 2 records, a second agreement type applies that a standard form may not cover.
Nine sections of channel analysis reduce to one determination you can run against any tool, including tools that do not exist yet. That durability is the point of this section.
What makes a vendor a business associate
Two conditions, both required. The vendor performs a function or service for you, and in doing so it creates, receives, maintains, or transmits protected health information on your behalf.
Notice what is absent from that test. Not whether the vendor is a healthcare company. Not whether the tool was bought by the marketing team. Not whether anyone intended it to receive patient information. A form platform that stores submissions from an intake page qualifies. A call tracking vendor holding recordings qualifies. An agency that manages any of it qualifies, which includes the kind of agency whose website you are reading.
When the test is met, the agreement has to contain specified terms. Among them: the permitted and required uses and disclosures, a commitment not to use or disclose the information otherwise, appropriate safeguards including Security Rule compliance for electronic PHI, reporting of impermissible uses and breaches back to you, flow-down requiring subcontractors to agree to the same restrictions, return or destruction of PHI at termination, and your right to terminate for a material breach [23].
That flow-down clause deserves attention it rarely gets. Marketing platforms are assemblies of subprocessors, and the AI features bolted onto most of them since 2024 introduced processors that predate anybody’s diligence file. A signed agreement from 2022 does not describe the vendor’s 2026 subprocessor list.
One misconception to retire. The narrow allowance for entities that merely transmit data without accessing it gets stretched to cover platforms that plainly store, index, and process. Storage is not transmission.
The vendor screen
Run these ten questions before a tool touches anything.
- What data does this tool receive, field by field, including hidden fields and URL parameters?
- Does it store that data, or only pass it through?
- Where is it stored, and under whose control?
- How long is it retained by default, and can that be changed?
- Who inside the vendor can access it, and is that access logged?
- Will the vendor sign a business associate agreement covering this use?
- Which subprocessors touch the data, and do they have flow-down agreements?
- Have AI or analytics features been added that introduced new processors since the agreement was signed?
- What happens to the data when the contract ends?
- What is the vendor’s breach notification commitment, and how fast?
Most programs can answer one through three after some digging. Question seven is where the exercise usually stops, and that is the finding rather than a failure.
Part 2 adds a second agreement
Part 2 does not use the business associate framework by default. It uses qualified service organizations, defined as persons providing services to a Part 2 program under a written agreement in which the organization acknowledges it is fully bound by Part 2 and will resist judicial efforts to obtain patient identifying information except as the rule permits [4].
The 2024 rule brought the two frameworks closer. A person meeting the business associate definition for a Part 2 program that is also a covered entity is included in the qualified service organization definition, with respect to information that is both PHI and a Part 2 record [4].
The practical read: a vendor’s standard form BAA, drafted for hospitals and never amended, may not address Part 2 at all. If your program is a Part 2 program, that is worth checking rather than assuming, and it is a question for counsel rather than for a procurement checklist.
Nobody certifies HIPAA compliance
No federal agency certifies HIPAA compliance. There is no registry, no credential, and no expiration date to check.
A vendor badge reading “HIPAA certified” describes a purchased third-party audit or a self-attestation. Those can be informative. They are not a government status, and they do not substitute for a signed agreement or for your own assessment of what you are about to send. Ask for the agreement, not the badge.
Paying for Leads: EKRA, Patient Brokering, and Compensation Structure
In short: How you pay for marketing is a separate legal question from how you handle data. A federal criminal statute enacted in 2018 reaches payments made to induce referrals to recovery homes and treatment facilities, the first federal appellate ruling on it landed in 2025 and reached marketers directly, and several states criminalize the same conduct independently.
Everything to this point has been about information. This section is about contracts, and it is the only exposure in this guide that is criminal rather than civil.
What EKRA covers
The Eliminating Kickbacks in Recovery Act, enacted in 2018 as part of the SUPPORT Act and codified at 18 U.S.C. 220, makes it an offense to knowingly and willfully pay or offer remuneration, directly or indirectly, to induce a referral of an individual to a recovery home, clinical treatment facility, or laboratory [24].
It is often described as the Anti-Kickback Statute’s cousin. The differences are what matter here.
| Anti-Kickback Statute | EKRA | |
|---|---|---|
| Reaches | Federal health care programs | Any health care benefit program, including private insurance and cash-pay [24] |
| Safe harbors | Numerous and well developed | Few [24] |
| Volume-based pay to employees | Protected under the bona fide employment safe harbor | Not similarly protected [24] |
| Enforcement | Civil and criminal | Criminal |
The cash-pay reach is the part that surprises people. A private-pay residential program with no federal payer relationship at all is inside EKRA’s scope.
What the Ninth Circuit decided in 2025
Until recently the statute had almost no appellate interpretation. That changed with United States v. Schena, decided July 11, 2025, the first federal appellate review of EKRA [25].
Two holdings matter for anyone buying or selling marketing in this vertical, and both need stating.
EKRA reaches marketing intermediaries. The defendant argued the statute did not apply because he paid marketers rather than physicians or patients directly. The court disagreed, holding that EKRA covers marketing intermediaries who interface with those who make referrals, and that payment need not go directly to a referral source [25].
Percentage-based pay is not automatically a violation. The court also held that paying percentage-based compensation to marketers is not by itself wrongful inducement. It became so in that case when combined with efforts to improperly influence referrals through false or fraudulent means [25].
Reporting only the first holding is alarmist. Reporting only the second is reassuring past the point of accuracy. The honest summary is that the compensation structure alone rarely decides the question, and that the surrounding conduct does.
State patient brokering statutes
Federal law is not the only exposure, and in this vertical the state statutes have been more actively used.
Florida’s is the most frequently invoked, which matters given how much of the industry operates there. It makes it unlawful to offer or pay any commission, bonus, rebate, kickback, or bribe, directly or indirectly, in cash or in kind, or to engage in any split-fee arrangement in any form, to induce the referral of patients or patronage to or from a health care provider or facility, and it reaches those who aid or abet the conduct [26]. Violations are a third-degree felony, rising to a first-degree felony with a $500,000 fine where the conduct involves twenty or more patients [26].
The statute’s exception for information services is instructive on structure. It contemplates services that do not steer consumers toward a particular provider and that charge fees set in advance, consistent with fair market value for the information services provided, and not based on the potential value of a patient to the provider [26].
Fees set in advance. Fair market value. Not indexed to the value of a patient. That is a legislature describing what an arm’s-length marketing arrangement looks like.
Where this touches ordinary marketing arrangements
Marketing in this vertical is commonly bought on a spectrum: flat monthly fee, fee plus a bonus tied to non-patient metrics, percentage of ad spend, payment per qualified lead, payment per admission. Those sit at different distances from the conduct these statutes describe.
Two clarifications, because this is where readers over-correct.
Measuring cost per admission is not the same as paying on it. Every program should know its cost per admission by channel. That is analytics. Tying a vendor’s compensation to that number is a contractual choice, and a different question.
This is where the certification point closes the loop. LegitScript’s certification standards exclude lead generators, call centers, and marketers who refer patients to other providers in exchange for compensation [21]. A certification program and a criminal statute pointing at the same arrangement from two directions is a signal worth reading.
What this section does not do is tell you whether a given arrangement is lawful. That determination turns on the specific facts, the specific contract, and the surrounding conduct, and it belongs to healthcare counsel rather than to a marketing guide.
What Noncompliance Costs in 2026
In short: The regulatory penalty is usually the smallest of three numbers. Private class actions have produced far larger settlements in this area, and state consumer health data laws add a private right of action that HIPAA has never had.
Figures below reflect the schedule in effect as of July 2026 and are adjusted annually.
HIPAA and Part 2 civil monetary penalties
HHS applied an inflation adjustment effective January 28, 2026, using the 2025 cost-of-living multiplier. The amounts apply to penalties assessed on or after that date for violations occurring on or after November 2, 2015 [27].
| Tier | Culpability | Per violation | Statutory annual cap |
|---|---|---|---|
| 1 | Did not know | $145 to $73,011 | $2,190,294 |
| 2 | Reasonable cause | $1,461 to $73,011 | $2,190,294 |
| 3 | Willful neglect, corrected | $14,602 to $73,011 | $2,190,294 |
| 4 | Willful neglect, not corrected | $73,011 | $2,190,294 |
One qualification that most published tables omit. Since April 2019, OCR has operated under a notice of enforcement discretion applying lower annual caps to the first three tiers than the statutory figures above [27]. Those reduced caps are agency policy rather than statute, and OCR can revisit them.
Civil penalties are not the only federal exposure. Criminal penalties under 42 U.S.C. 1320d-6, enforced by the Department of Justice rather than OCR, escalate from knowingly obtaining or disclosing PHI, to offenses under false pretenses, to offenses committed with intent to sell or use PHI for commercial advantage or personal gain. The preceding section covers a second criminal statute reaching compensation arrangements.
Part 2 penalties run through the same machinery. The rule applies the penalties under Social Security Act sections 1176 and 1177, and HIPAA’s enforcement provisions apply to Part 2 noncompliance in the same manner they apply to covered entities and business associates [28]. Combined with the February 16, 2026 enforcement start, a Part 2 marketing violation now has a complaint pathway and a penalty schedule behind it.
Worth knowing how these cases start. Enforcement in this area is overwhelmingly complaint-driven rather than audit-driven. One former patient, one review reply, one form. Worth noting alongside this: OCR’s most consistent enforcement theme across all HIPAA cases is the risk analysis requirement under the Security Rule. A marketing stack that holds electronic PHI sits inside that scope, and it is frequently absent from the analysis a program has on file.
Private litigation is the bigger number
Put two figures from earlier in this guide side by side.
| What it was | Amount | |
|---|---|---|
| Manasa Health Center, 2023 | OCR settlement over PHI disclosed in responses to online reviews [22] | $30,000 |
| In re Advocate Aurora Health Pixel Litigation, 2024 | Private class action settlement over tracking technologies [14] | $12,225,000 |
The regulator was not the expensive party. HIPAA has no private right of action, so the pixel cases proceeded on state wiretap, privacy, and consumer protection theories instead, and those carry statutory damages that scale with class size. The 2024 ruling on OCR’s tracking guidance did nothing to narrow that track.
State consumer health data laws
This is the layer most likely to change what your exposure looks like over the next two years.
Washington’s My Health My Data Act regulates consumer health data generated outside HIPAA and made violations enforceable through the state consumer protection statute, including by individuals [29]. Its definition of consumer health data reaches information identifying a consumer’s past, present, or future physical or mental health status [29]. Connecticut and Nevada enacted comparable laws without a private right of action [29]. The first private suit under the Washington statute was filed in February 2025 [29].
New York has been trying. A health information privacy bill passed both chambers in January 2025 and was vetoed in December 2025. A revised version passed the Senate and Assembly in June 2026 and was awaiting the governor’s action as of publication [30]. Notably, the revised bill exempts Part 2 programs and substance use disorder records alongside its existing HIPAA exemption [30].
Separately, Part 2 does not occupy the field. Where state law prohibits a disclosure that Part 2 would otherwise permit, the state law governs. Several states impose confidentiality requirements on SUD records that exceed the federal baseline.
One regime that probably does not reach you
The FTC’s Health Breach Notification Rule comes up constantly in marketing compliance content. It applies to entities handling health information that are not covered by HIPAA, which is why it has been used against health apps and consumer platforms. A treatment center operating as a covered entity generally sits outside it.
It is listed here because naming what does not apply is part of an honest risk inventory. Padding the list makes everything on it easier to ignore.
The HIPAA Marketing Checklist
In short: Twelve sections reduce to one ordered audit. Three items are free and take under an hour combined. The rest are ordered by exposure rather than by ease.
Run these three this week
1. Open a booking or intake page with developer tools running. Watch the network tab and write down every third-party domain that receives a request. Fifteen minutes gives you a list of who is receiving data from the page where people identify themselves.
2. Trace one form submission until it stops moving. Browser, form platform, integration, CRM, notification email, forwarded copy, autoresponder, conversion event. Note which stop is the last one covered by a signed agreement.
3. Read your last twenty review replies. Look for any response that confirms, warmly or otherwise, that the reviewer received care.
Each of these reliably surfaces something. None requires a budget or a vendor. The first two are the dev-tools check and the vendor screen described above, run as a pair.
The full audit
Ordered by exposure. Items touching Part 2 records, paid-lead compensation, and public acknowledgment of patients sit above analytics configuration, because the first three carry criminal or per-patient exposure and the last is a settings change.
| # | What to examine |
|---|---|
| 1 | Whether your program meets the federally-assisted test and is a Part 2 program |
| 2 | How marketing vendors and agencies are compensated, and whether any element is indexed to leads, admissions, or patient value |
| 3 | Every public reply, testimonial, photo, and tagged post that could confirm a named person received care |
| 4 | Written consent and authorization records behind any list built from patient information |
| 5 | Which system holds records and which system runs campaigns, and what crosses between them |
| 6 | Every form on the site, its fields, its destinations, and its retention settings |
| 7 | Signed agreements for every vendor that receives data, plus their subprocessor lists |
| 8 | Call tracking configuration, including keyword capture, recording, transcripts, and retention |
| 9 | Chat widgets, session replay, and any AI intake tool on the site |
| 10 | Lead notification email routing, including forwarded copies on personal devices |
| 11 | Page-by-page classification into public, transitional, and authenticated, and which tools fire on each |
| 12 | Certification status and platform policy posture for every paid channel in use |
| 13 | Campaign, ad group, and URL naming conventions that carry condition names into downstream systems |
| 14 | Whether any state consumer health data law reaches the audiences you target |
Most programs find their largest gap somewhere in items 5 through 7. Most programs expect to find it in item 11.
What this does not replace
A checklist is a way to find questions. It is not a risk analysis under the Security Rule, it is not a legal opinion, and it is not a substitute for counsel who has read your actual contracts and looked at your actual configuration.
Two of the items above touch a criminal statute. Those are not marketing decisions.
Where to go from here
Most of what this guide covers is fixable, and a fair amount of it is fixable this quarter. The pattern across programs we work with is consistent: the gaps are rarely deliberate, they accumulate through ordinary decisions made quickly by people trying to reach families in crisis, and they stay invisible until somebody traces a form submission end to end.
If you want a second set of eyes on any of it, book a strategy call or call 855-876-7238. We build and run marketing programs for behavioral health organizations, which means these questions come up on every engagement. We will tell you what we see. Your compliance obligations remain yours, and decisions about legal risk belong with your counsel.
This article is general information about federal and state regulations affecting behavioral health marketing. It is not legal advice, and it does not create an attorney-client or advisory relationship. Consult qualified healthcare counsel about your specific circumstances.
Frequently Asked Questions
Definition Bank
Part 2 program. A federally assisted program that holds itself out as providing, and provides, substance use disorder diagnosis, treatment, or referral for treatment. Defined at 42 CFR 2.11.
Federally assisted. Broader than grant funding. Includes Medicare participation, authorization to conduct maintenance treatment or withdrawal management, DEA registration to dispense a controlled substance used in SUD treatment, federal financial assistance in any form, and IRS tax-exempt status. Defined at 42 CFR 2.12(b).
Protected health information. Individually identifiable health information held or transmitted by a covered entity or business associate. Requires both an identifier and a link to a person’s health, care, or payment for care.
Patient identifying information. Part 2’s parallel term: name, address, Social Security number, fingerprints, photograph, or similar information by which a patient’s identity can be determined with reasonable accuracy. Defined at 42 CFR 2.11.
Marketing. Under the Privacy Rule, a communication about a product or service that encourages the recipient to purchase or use it, subject to three exclusions. Defined at 45 CFR 164.501.
Financial remuneration. Direct or indirect payment from or on behalf of a third party whose product or service is being described. Excludes payment for treatment of an individual. Its presence removes two of the three marketing exclusions. Defined at 45 CFR 164.501.
Authorization. A signed document with required elements permitting a specific use or disclosure of PHI. Required before PHI is used for marketing, with narrow exceptions. Not the same as a general consent. See 45 CFR 164.508.
Written consent (Part 2). Part 2’s equivalent instrument, with its own required elements including a description of the information, the recipients, the purpose, revocation rights, and an expiration. See 42 CFR 2.31.
Business associate. A person or entity that creates, receives, maintains, or transmits PHI while performing a function or service for a covered entity. Marketing agencies, form platforms, and call tracking vendors routinely qualify.
Business associate agreement. The contract required before a business associate handles PHI, containing specified terms including safeguards, breach reporting, subcontractor flow-down, and return or destruction at termination. See 45 CFR 164.504(e).
Qualified service organization. Part 2’s counterpart to the business associate, defined as a service provider that has signed a written agreement acknowledging it is fully bound by Part 2. Defined at 42 CFR 2.11.
Safe Harbor de-identification. One of two methods for removing information from the Privacy Rule’s scope, requiring removal of 18 listed identifiers and no actual knowledge that what remains could identify someone. See 45 CFR 164.514(b)(2).
Unauthenticated public webpage. A page requiring no login or user verification. The distinction matters because the 2024 court ruling addressed metadata collected on these pages specifically.
EKRA. The Eliminating Kickbacks in Recovery Act, 18 U.S.C. 220, a federal criminal statute prohibiting remuneration to induce referrals to recovery homes, clinical treatment facilities, and laboratories. Reaches private insurance and cash-pay, unlike the Anti-Kickback Statute.
Entity Cards
42 CFR Part 2
| Property | Value |
|---|---|
| What it is | Federal confidentiality rule for substance use disorder patient records |
| Who it covers | Federally assisted programs providing SUD diagnosis, treatment, or referral |
| Enforcing agency | HHS Office for Civil Rights, delegated August 25, 2025 |
| Key dates | Final rule February 16, 2024; effective April 16, 2024; compliance and enforcement February 16, 2026 |
| How it differs from HIPAA | No exclusion for describing your own services; marketing use requires written consent; acknowledgment of patient presence restricted at SUD-only facilities |
EKRA (18 U.S.C. 220)
| Property | Value |
|---|---|
| What it prohibits | Knowingly and willfully paying or offering remuneration to induce referrals to recovery homes, clinical treatment facilities, or laboratories |
| Enacted | 2018, as part of the SUPPORT Act |
| Scope | Any health care benefit program, including private insurance and cash-pay |
| Safe harbors | Few, and no protection equivalent to the Anti-Kickback Statute’s bona fide employment provision |
| Key case | United States v. Schena, 9th Cir., July 11, 2025 |
| Exposure type | Criminal |
LegitScript Addiction Treatment Certification
| Property | Value |
|---|---|
| What it is | Third-party certification and monitoring program for addiction treatment advertisers |
| Who requires it | Google, Meta, Microsoft Advertising, Nextdoor |
| What it is not | Federal law, a HIPAA credential, or evidence of privacy compliance |
| Key exclusions | Lead generators, call centers, and marketers referring patients for compensation; sober living without licensed clinical services |
| Meta’s added step | Certification plus written permission obtained from Meta directly |
My Health My Data Act (Washington)
| Property | Value |
|---|---|
| Jurisdiction | Washington residents and individuals whose consumer health data is collected in Washington |
| What it covers | Consumer health data outside HIPAA, expressly including mental health status |
| Enforcement | State attorney general, plus a private right of action through the state consumer protection statute |
| First private suit | February 2025 |
| Comparable laws | Connecticut and Nevada, without a private right of action |
Sources
- 45 CFR 164.501, Definitions — https://www.ecfr.gov/current/title-45/part-164/section-164.501
- 45 CFR 164.508, Authorizations — https://www.ecfr.gov/current/title-45/part-164/section-164.508
- 42 CFR 2.12, Applicability — https://www.ecfr.gov/current/title-42/part-2/section-2.12
- 42 CFR 2.11, Definitions — https://www.ecfr.gov/current/title-42/part-2/section-2.11
- 42 CFR 2.13, Confidentiality restrictions — https://www.ecfr.gov/current/title-42/part-2/section-2.13
- HHS, Understanding Confidentiality of SUD Patient Records (Part 2) — https://www.hhs.gov/hipaa/part-2/index.html
- 42 CFR 2.31, Consent requirements — https://www.ecfr.gov/current/title-42/part-2/section-2.31
- 42 CFR 2.22, Notice to patients — https://www.ecfr.gov/current/title-42/part-2/section-2.22
- HHS OCR, Part 2 civil enforcement program announcement (Feb 13, 2026) — https://www.hhs.gov/press-room/hhs-announce-civil-enforcement-program-sud-patient-records.html
- 45 CFR 164.514, De-identification etc. — https://www.ecfr.gov/current/title-45/part-164/section-164.514
- Holland & Knight, AHA v. Becerra analysis — https://www.hklaw.com/en/insights/publications/2024/06/american-hospital-assn-v-becerra-are-tracking-tools-ok-again
- AHA, HHS withdraws appeal (Aug 29, 2024) — https://www.aha.org/news/headline/2024-08-29-hhs-will-not-appeal-aha-court-victory-online-tracking-case
- Google HIPAA compliance docs — Cloud and Workspace
- In re Advocate Aurora Health Pixel Litigation settlement — https://www.advocateaurorasettlement.com/
- Novant Health pixel settlement — Class Action Settlement (Court approval order: PDF)
- Insurance Marketing Coalition v. FCC, 127 F.4th 303 (11th Cir. 2025) — https://law.justia.com/cases/federal/appellate-courts/ca11/24-10277/24-10277-2025-01-24.html
- FCC final rule eliminating one-to-one consent (Fed. Reg., Aug 29, 2025) — https://www.federalregister.gov/documents/2025/08/29/2025-16641/delete-delete-delete-targeting-and-eliminating-unlawful-text-messages-rules-and-regulations
- Google Ads, Health in personalized advertising — https://support.google.com/adspolicy/answer/16701855
- Google Ads, Restricted targeting in Personalized advertising — https://support.google.com/adspolicy/answer/143465
- Meta Transparency Center, Drug and Alcohol Addiction Treatment — https://transparency.meta.com/policies/ad-standards/restricted-goods-services/drug-alcohol-addiction-treatment/
- LegitScript, Addiction Treatment Certification standards — https://www.legitscript.com/certification/addiction-treatment-certification/
- HHS OCR, Manasa Health Center resolution agreement — https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/manasa/index.html
- 45 CFR 164.502(e) / 164.504(e), business associate contracts — 164.502 and 164.504
- 18 U.S.C. 220 (EKRA) — https://www.law.cornell.edu/uscode/text/18/220
- United States v. Schena, No. 23-2989 (9th Cir. July 11, 2025) — https://cdn.ca9.uscourts.gov/datastore/opinions/2025/07/11/23-2989.pdf
- Fla. Stat. 817.505, Patient brokering — http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0800-0899/0817/Sections/0817.505.html
- HHS CMP inflation adjustment (Fed. Reg., Jan 28, 2026) — https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
- 42 CFR 2.3, Civil and criminal penalties — https://www.ecfr.gov/current/title-42/part-2/section-2.3
- Washington My Health My Data Act, RCW 19.373 — https://app.leg.wa.gov/rcw/default.aspx?cite=19.373
- NY Health Information Privacy Act, S9269 / A10357 — S9269 and A10357