---
title: "HIPAA-Compliant Marketing for Behavioral Health: The 2026 Rules, Explained"
date: 2026-08-11
author: "Matthew Travers"
featured_image: "https://leadtorecovery.com/wp-content/uploads/HIPAA-compliance-consulting.webp"
categories:
  - name: "Blog"
    url: "/blog/category/blog.md"
---

# HIPAA-Compliant Marketing for Behavioral Health: The 2026 Rules, Explained

*Updated August 11, 2026. Lead to Recovery, Pompano Beach, FL. 855-876-7238.*

## Direct Answer

*![Illustration representing HIPAA-compliant marketing for behavioral health centers](https://leadtorecovery.com/wp-content/uploads/HIPAA-compliance-consulting.webp "1")*

HIPAA-compliant marketing means promoting healthcare services without using protected health information in ways the Privacy Rule regulates. It governs how audiences are built, which vendors receive data, and what agreements are in place. For substance use disorder programs, a second federal rule, 42 CFR Part 2, adds stricter consent requirements on top.

*This article is general information, not legal advice. Consult qualified healthcare counsel about your specific situation.*

## TL;DR

- HIPAA regulates a narrowly defined activity called marketing, and a large share of what treatment centers do every day sits outside that definition
- Part 2 is stricter, has no carve-out for describing your own services, and OCR began accepting complaints under it on February 16, 2026
- A federal court vacated part of OCR’s online tracking guidance in June 2024, but only the portion covering metadata on public pages, and private lawsuits were never affected
- Google treats health as a sensitive interest category and restricts advertiser-curated audiences for it, which blocks most retargeting by contract before any privacy question arises
- How you pay for leads is a separate criminal-law question under EKRA, and the first federal appellate ruling on it landed in July 2025 and reached marketers directly
- The largest financial exposures in this area have come from private class actions rather than from OCR

One liner: Audit where your data goes before you audit what your ads say.

## Key Numbers



FigureWhat it isSource and dateFebruary 16, 2026Part 2 compliance date and start of OCR civil enforcementHHS Office for Civil Rights, 2026June 20, 2024Date a federal court vacated the contested portion of OCR’s tracking bulletinN.D. Tex., 2024January 28, 2026Effective date of the current HIPAA civil monetary penalty scheduleFederal Register, 2026$73,011Maximum penalty per violation, all four tiers, current scheduleFederal Register, 2026$12,225,000Advocate Aurora pixel class action settlement, final approval July 2024Court record, 2024$30,000OCR settlement with a psychiatric practice over PHI in review repliesOCR, 2023July 11, 2025First federal appellate decision interpreting EKRA9th Cir., 202518Identifiers that must be removed under Safe Harbor de-identification45 CFR 164.514July 2027Current target for final action on the proposed Security Rule overhaulHHS Unified Agenda, 2026

## What HIPAA Actually Says About Marketing

*In short: HIPAA does not ban marketing. It defines the word narrowly, then requires written authorization before protected health information gets used for it. Most of what a treatment center does every day sits outside that definition.*

Under the Privacy Rule, marketing means a communication about a product or service that encourages the recipient to purchase or use it \[1\]. That definition does the work people expect the statute to do, and it does less of it than they think. The rule bites when protected health information is used to make the communication. A billboard on I-95 uses no PHI. An email to everyone who completed detox last quarter does.

### The definition at 45 CFR 164.501

Two questions decide whether a communication is regulated marketing.

**Did PHI select the audience?** Broadcast advertising, organic search content, a Google Ads campaign targeting a keyword, a community education night: none of these use patient information to pick who sees the message. The Privacy Rule has nothing to say about them. Ad platform policy and truth-in-advertising law still apply, which is a separate matter covered further down.

**Is a third party paying for the message?** This is the hinge that catches people. The rule defines financial remuneration as direct or indirect payment from or on behalf of a third party whose product or service is being described, and excludes payment for treatment of an individual \[1\]. Accept money from a lab, a medication manufacturer, or a partner program to send a message to your patients, and a communication that would otherwise be permitted becomes regulated marketing.

### What the rule carves out

Three categories are excluded from the definition, and both members of the second group collapse the moment third-party money appears \[1\].



ExclusionCoversConditionsRefill remindersCommunications about a drug or biologic currently prescribed to the individualAny payment received must be reasonably related to the cost of making the communicationTreatment and care coordinationTreating the individual, case management, directing or recommending alternative treatments, therapies, providers, or settings of careNo financial remuneration from a third partyYour own servicesDescribing a health-related product or service provided by the covered entity making the communicationNo financial remuneration from a third party

That third row is the one treatment centers most often get wrong, in the cautious direction. A center describing its own new outpatient track to its own patients is describing a health-related service it provides. Absent third-party payment, that falls outside the marketing definition entirely. The blanket rule many programs operate under, that you can never contact a former patient about a program, is stricter than the Privacy Rule requires.

It is not stricter than the rule that governs substance use disorder records. That comes next.

### Authorization is not consent

When a communication does land inside the definition, the Privacy Rule requires a written authorization before PHI is used or disclosed for it, with narrow exceptions for face-to-face communications and promotional gifts of nominal value \[2\]. If third-party remuneration is involved, the authorization has to say so \[2\].

Authorization is a specific document with required elements. It is not the general consent buried in an intake packet, and it is not a checkbox on a web form. Programs that treat the two as interchangeable have an intake packet that will not survive a records request.

## Why Behavioral Health Plays by a Second Rulebook

*In short: If your program diagnoses, treats, or refers for substance use disorder, a second federal rule sits on top of HIPAA. It is stricter on marketing than HIPAA is, and OCR began accepting complaints under it on February 16, 2026.*

The previous section ended on a permissive note. A covered entity describing its own services to its own patients, with no third-party money involved, sits outside HIPAA’s marketing definition. For a mental health practice, that is where the analysis ends. For an SUD program, it is where the analysis starts, because 42 CFR Part 2 does not have that carve-out.

### What makes a program a Part 2 program

Two conditions have to be met. The program has to hold itself out as providing, and actually provide, SUD diagnosis, treatment, or referral for treatment, and it has to be federally assisted \[3\]\[4\]. Operators consistently underestimate the second condition. Federal assistance reaches well past grant funding \[3\]:

- Participating provider status in the Medicare program
- Authorization to conduct maintenance treatment or withdrawal management
- DEA registration to dispense a controlled substance used in SUD treatment, which captures most [medication-assisted treatment programs](/mat-clinic-marketing/)
- Receipt of federal financial assistance in any form, including assistance that does not pay for SUD services
- Tax-exempt status granted by the IRS, or the deductibility of contributions to the program

Under that list, a private-pay residential program with a DEA registration and a nonprofit designation is federally assisted. A general medical facility is not a Part 2 program, but an identified unit inside one can be \[4\].

### Where Part 2 is stricter than HIPAA

Part 2 works from the opposite default. Records may be used or disclosed only as the rule permits, and marketing is not among the permitted uses \[5\]. There is no equivalent to HIPAA’s exclusion for describing your own services.



Marketing activityUnder HIPAAUnder Part 2Emailing your own patients about your own new programOutside the marketing definition, absent third-party payment \[1\]Requires written consent meeting the rule’s elements \[7\]Confirming a named person is a patientGenerally requires authorizationCannot be acknowledged at a facility publicly identified as SUD-only without written consent or a court order \[5\]Fundraising to your patient listPermitted with an opt-outPermitted only after a clear and conspicuous opt-out opportunity, disclosed in the patient notice \[8\]Building an audience from your record systemAuthorization required if PHI selects the audienceConsent required, with specified elements and an expiration \[7\]

That second row is why alumni testimonials, review responses, and tagged social content carry more risk in this vertical than in any other corner of healthcare marketing.

### What changed on February 16, 2026

Four dates matter, and none of them appear on the pages currently ranking for this topic.



DateEventFebruary 16, 2024Final rule published, aligning Part 2 with HIPAA under CARES Act section 3221 \[6\]April 16, 2024Rule takes effect, opening a two-year implementation window \[6\]August 25, 2025HHS delegates Part 2 administration and enforcement to the Director of OCR \[6\]February 16, 2026Compliance required. OCR begins accepting complaints alleging Part 2 violations and Part 2 breach notification failures \[6\]\[9\]

Worth stating plainly: the 2024 rule loosened several things. A single patient consent can now cover future treatment, payment, and health care operations, and records no longer have to be segregated \[6\]. Marketing was not part of that loosening. The consent requirement for marketing uses survived the alignment intact.

One practical consequence for mixed programs. A center running a mental health track and an SUD track holds two record populations under two different rules, often inside one CRM and one email platform. When the tighter rule applies to part of a list, plan the campaign to the tighter rule.

## What Counts as PHI Inside a Marketing Stack

*In short: PHI is not a type of data. It is an identifier joined to health information about an identifiable person. On a treatment center website, the page itself often supplies the health half, which is why identifiers that look harmless on other sites carry weight here.*

Most stack audits go wrong at the first question. Teams look at a field and ask whether it is sensitive. The rule asks something different: does this information identify a person, and does it relate to that person’s health, care, or payment for care. Both halves have to be present. Neither half is interesting alone.

### The 18 identifiers under Safe Harbor

The Privacy Rule’s Safe Harbor method lists the identifiers that have to be stripped, for the individual and for their relatives, employers, and household members, before data stops being PHI. It also requires that the covered entity have no actual knowledge that what remains could still identify someone \[10\].



IdentifierWhere it turns up in a marketing stackNamesForm fields, CRM records, call transcripts, review responsesGeographic units smaller than a stateForm addresses, geo-targeting exports, location-based bid adjustmentsAll date elements except year, and ages above 89Admission and discharge dates in a CRM, appointment timestampsTelephone numbersCall tracking logs, SMS platforms, lead notificationsFax numbersReferral intake, legacy admissions workflowsEmail addressesESP lists, custom audience uploads, form submissionsSocial security numbersInsurance verification forms, rarely needed pre-admissionMedical record numbersEHR-to-CRM syncsHealth plan beneficiary numbersInsurance verification forms and their notification emailsAccount numbersBilling portals, payment plan communicationsCertificate and license numbersUncommon in marketing, common in referral partner dataVehicle identifiers, including plate numbersFacility intake logsDevice identifiers and serial numbersMobile advertising IDs, device fingerprintsWeb URLsReferrer strings, UTM parameters, page paths in analyticsIP addressesEvery analytics tool, every ad pixel, every chat widget, by defaultBiometric identifiersVoice prints in recorded callsFull face photographic imagesAlumni photos, testimonial video, social contentAny other unique identifying number, characteristic, or codeCookie IDs, click identifiers, hashed audience keys

Note the ZIP code exception. The first three digits can be retained when the area they cover holds more than 20,000 people, and are otherwise changed to 000 \[10\]. Note also the last row. The catch-all is where most modern advertising identifiers land, and it is the reason “we only send anonymous IDs” is rarely the end of the conversation.

Safe Harbor is one of two routes. The other, Expert Determination, has a qualified person apply statistical and scientific principles, conclude that the risk of identification is small enough to satisfy the regulatory standard, and document how that conclusion was reached \[10\]. Safe Harbor is a checklist. Expert Determination is an opinion someone signs.

### Why context does the work in behavioral health

An IP address recorded on a hospital’s parking directions page carries almost no health inference. The same IP address recorded on a page titled “opioid detox program” carries a strong one. The identifier is identical. The page supplies the health context.

Whether that pairing on a public page actually constitutes PHI is the exact question a federal court took up in 2024, and the answer is more favorable to providers than most compliance guides suggest.

Part 2 runs a parallel track. Its term is patient identifying information, defined as name, address, Social Security number, fingerprints, photograph, or similar information by which a patient’s identity can be determined with reasonable accuracy, directly or by reference to other information \[4\]. The rule’s de-identification standard then points back to the HIPAA method \[5\].

### De-identified, aggregated, hashed

Marketers use these three words as synonyms. They describe three different states.

**De-identified** means one of the two regulatory methods was applied and documented. The result is outside the Privacy Rule.

**Aggregated** means individual rows were rolled into totals. A report showing 412 sessions on a page is aggregated. That is a summary of data, not a treatment of the underlying data, and the event-level records usually still exist somewhere upstream.

**Hashed** means transformed into a fixed string. Hashing an email address is a security measure, not de-identification. Hashes are deterministic, which is precisely why ad platforms accept them for audience matching. A value that reliably matches to one person still identifies that person.

One field deserves a specific mention. The open text box labeled something like “tell us how we can help” collects clinical detail nobody scoped, in the reader’s own words, and then routes it wherever the form platform sends submissions.

## Website Analytics and Tracking Pixels After the 2024 Ruling

*In short: A federal court struck down one specific piece of OCR’s tracking guidance in June 2024, covering metadata on public webpages. The rest of the guidance stands, the vendor contract problem is untouched, and private lawsuits run on a separate track that the ruling did not narrow.*

This is where published guidance splits into two wrong answers. One set of pages still describes the vacated rule as binding. Another set read the headline and concluded that tracking on healthcare sites is fine again. The accurate position sits between them and is more useful than either.

### What the court vacated, and what it did not

OCR published guidance in December 2022 taking the position that an IP address combined with a visit to an unauthenticated page about a health condition or provider could constitute PHI and trigger HIPAA obligations. OCR revised the guidance in March 2024. Hospital plaintiffs challenged the revised version, and on June 20, 2024 the U.S. District Court for the Northern District of Texas held that this rule, which the litigation called the Proscribed Combination, was unlawful because it exceeded the agency’s authority under HIPAA, and vacated that portion \[11\]. The rest of the revised bulletin was left intact \[11\]. HHS filed an appeal in August 2024 and withdrew it days later \[12\].

Three consequences follow, and the third is the one guides miss.

**On public marketing pages,** the specific proposition that metadata alone creates PHI no longer stands as an agency rule. A blog post about recognizing alcohol use disorder, a location page, a careers page: these are the pages the ruling addressed.

**On authenticated pages,** nothing changed. Portals, booking flows behind a login, and anything where a person has identified themselves to you were never covered by the vacated portion.

**On private litigation,** nothing changed either. HIPAA has no private right of action, so the pixel cases were never HIPAA claims. They are state wiretap, privacy, and consumer protection claims, and a federal court’s reading of HHS’s rulemaking authority does not touch them. Advocate Aurora Health settled consolidated pixel claims for $12,225,000, with final approval granted in July 2024 \[14\]. Novant Health settled a comparable consolidated case for $6.6 million \[15\]. Neither was an OCR enforcement action.

### The vendor question is separate from the court question

Even where a page is unquestionably outside HIPAA’s reach, the tool sending data off your site has to be contractually permitted to receive whatever it receives.

Google signs a business associate agreement covering a defined list of Workspace and Cloud services. Google Analytics, Tag Manager, and Google Ads sit outside that list, along with most additional Google services and third-party Marketplace add-ons installed through a Workspace account \[13\]. That is a product decision, not a configuration setting. Turning on IP anonymization, shortening retention, or moving to server-side tagging does not create a BAA where the vendor does not offer one.

The practical read: these tools are available for pages where no PHI is involved, and a BAA-covered alternative is the path for pages where it is. Which pages are which is the next question.

### Classifying your pages

Every page on a treatment center site falls into one of three buckets. Deciding which bucket each page belongs to is the whole exercise, and it is worth doing alongside a [website build or rebuild](/rehab/website-design/) rather than after.



BucketExamplesWhat the visitor has revealedTypical posturePublic contentBlog posts, condition pages, about, careers, location pagesInterest, not identityStandard analytics generally used hereTransitionalBooking, insurance verification, chat widgets, contact and intake forms, thank-you pagesIdentity plus health context, often in the same requestBAA-covered tools only, and no third-party tagsAuthenticatedPatient portal, alumni portal, anything behind a loginBoth, confirmedBAA-covered tools only

The transitional bucket is where nearly every real problem lives. A thank-you page fires a conversion event that carries the referring URL, and the referring URL is a detox program page. The form platform emails a lead notification containing a free-text field. A chat widget loads a third-party script on the same page where a person is typing about their drinking. None of these are exotic. All of them are configuration decisions, which means they are fixable, and getting them right is part of building [conversion tracking that stands up](/rehab/cro/).

There is a fast way to see your own exposure. Open a booking or intake page in a browser, open developer tools, watch the network tab, and note every third-party domain that receives a request. Fifteen minutes gives you a list. The list is the audit. Tag governance tools exist as a category and automate this at scale, which is worth considering for a large site. For most treatment center sites the manual pass is enough to find the problem.

## Forms, Chat, and Intake: Where the Leaks Actually Happen

*In short: The form itself is rarely the compliance problem. The eight places a submission travels afterward are the problem, and most programs have never mapped that path end to end.*

The previous section dealt with data that leaves your site without anyone deciding to send it. This section deals with the opposite: information a person hands over on purpose, in response to a question you wrote, which then moves through a chain of systems nobody has inventoried.

### Lead forms and intake forms are different objects

A lead form asks whether a conversation should start. Name, phone, maybe a preferred callback time. An intake form collects clinical history, insurance details, and often a description of current use.

Programs run both through the same platform, under the same settings, with the same notification rules. When that happens, the whole path defaults to whatever protection the lighter form was set up with, which is generally none.

The distinction is worth drawing before the audit starts, because the two form types deserve different tools, different retention windows, and different destinations.

### Where the submission goes next

Trace a single submission. A form on a page about medication-assisted treatment, collecting a name and a phone number.



StopWhat arrivesUsual BAA status1. BrowserField values, page URL, referrer, any hidden fieldsNot applicable2. Form platformFull submission, storedSometimes covered3. Webhook or integrationFull submission, in transit to the CRMRarely reviewed4. CRMFull submission, stored and searchableSometimes covered5. Notification email to admissionsName, phone, page context, free-text fieldOften uncovered6. Forwarded copySame, now on a personal deviceAlmost never covered7. Autoresponder to the inquirerConfirms the inquiry in writing, to an address you have not verifiedSometimes covered8. Conversion event to analytics and ad platformsEvent name, page URL, sometimes hashed identifiersNot covered

Eight stops. In a typical setup, a business associate agreement exists at one or two of them. The vendor management section below covers which of these vendors needs one and how to tell.

Stop 5 deserves particular attention. The lead notification email is the least examined artifact in behavioral health marketing. It contains everything the form collected, it lands in whatever inbox was configured during setup, and it gets forwarded to phones so admissions can respond quickly. Speed matters in this vertical, which is exactly why this path was built without a review.

Worth retiring a common defense here. A form that asks only for a name and a phone number, sitting on a page about opioid treatment, has still recorded that this named person inquired about opioid treatment. The health context comes from the page, not from a field.

### Chat widgets and session replay

A chat widget is a third-party script loaded on the page where a person types their situation in their own words. The transcript is a record. It is stored somewhere, retained for some period, and possibly reviewed for training.

Session replay tools go further. They reconstruct the visit, including keystrokes in fields the visitor typed into and then abandoned. Someone who starts filling in a form, thinks better of it, and closes the tab may have generated a stored record anyway.

Neither category is off limits. Both need the same three answers as any other vendor: what does it receive, where does it store it, and will the provider sign a business associate agreement.

### A five-question field inventory

Run this against every form on the site.

1. What page does this form sit on, and what does that page reveal about the person filling it in?
2. Which fields are visible, and which are hidden, prefilled, or passed through from the URL?
3. Where does the submission go, in order, until it stops moving?
4. Which of those destinations has a signed business associate agreement?
5. How long does each destination keep it, and who can search it?

Most programs cannot answer question three without opening the form builder. That is the finding.

## Call Tracking and Text Messaging

*In short: A call tracking record pairs a phone number with the page and often the search term that produced the call. Recording adds state law, and texting adds the TCPA. HIPAA is one of three regimes operating here, and it is not always the strictest.*

Calls drive admissions in this vertical. That makes the admissions line the highest-value data stream a treatment center owns, and the least audited.

### What a call tracking record actually contains

Dynamic number insertion swaps the displayed phone number based on how the visitor arrived, which is what makes channel attribution possible. The byproduct is a record that looks like this.



ElementIdentifier under Safe Harbor?Supplies health context?Caller’s phone numberYesNoTimestamp and durationYes, dates related to an individualNoLanding page URLYesFrequentlyReferring keyword or search termCatch-all, when uniqueFrequentlyCampaign and ad groupNoSometimes, by nameCall recordingVoice print is biometricYesTranscriptDepends on contentsYesRep’s notes fieldWhatever was typedUsually

The keyword row deserves its own moment. Call tracking platforms commonly capture the search term that produced the call, which is the entire point of [keyword-level PPC attribution](/rehab/ppc/). In this vertical that term is regularly a substance, a condition, or a phrase like “detox near me.” A phone number paired with that query is the identifier-plus-context combination described above, sitting in a vendor database, sorted for reporting.

Campaign naming conventions compound it. An ad group labeled for a specific substance and level of care travels into every downstream system that receives conversion data.

### Recording, transcription, and state consent law

Call recording is governed by state wiretap statutes, which have nothing to do with HIPAA and vary in what they require. Some states are satisfied when one party to the call consents. Others require all parties to consent. A national campaign routes calls from every state into one recording configuration, which means the configuration has to satisfy the strictest state it reaches, not the state the facility sits in.

Transcription changes the character of the record again. A recording is an audio file somebody has to listen to. A transcript is a searchable text document of a clinical conversation, held by a vendor, retained on whatever schedule the account defaulted to at setup, and increasingly passed through automated summarization. Ask where transcripts live, how long they persist, and who else processes them.

### Text messaging

Two questions, and they are independent.

**Was the list built permissibly?** If patient information selected who receives the message, the rules above govern. For a Part 2 program, written consent is required, and there is no equivalent to HIPAA’s own-services carve-out.

**Does the message satisfy the TCPA?** Marketing calls and texts require prior express written consent under the TCPA regardless of anything HIPAA says. This is a separate statute with a private right of action, which is more than HIPAA offers a plaintiff.

One point of currency here, because a great deal of published guidance is out of date. The FCC adopted a rule in 2023 that would have required consent to be given to one identified seller at a time and limited to topics logically and topically associated with the interaction that prompted it. The Eleventh Circuit vacated that rule on January 24, 2025, holding that the FCC exceeded its statutory authority under the TCPA, and remanded \[16\]. The FCC subsequently removed the vacated language and formally eliminated the requirement \[17\]. The rule never took effect. Guidance that tells treatment centers to rebuild their lead consent flows around one-to-one consent is describing a requirement that does not exist.

The underlying TCPA consent standard still applies. Honoring a STOP reply satisfies the opt-out obligation and says nothing about whether the list was assembled permissibly in the first place.

## Email Marketing and CRM

*In short: Building a segment is a use of patient information, not a step you take before using it. For a Part 2 program, that use needs written consent even when HIPAA alone would permit it. The reliable fix is architectural: keep the system that holds records separate from the system that runs campaigns.*

### Segmenting a list is a use, not a preparation

A covered entity describing a health-related service it provides, to its own patients, with no third-party payment involved, falls outside HIPAA’s marketing definition \[1\]. On HIPAA alone, an alumni newsletter or a note about a new outpatient track is permitted. The blanket prohibition many programs impose on themselves is stricter than the Privacy Rule requires.

Now the correction, and it is not a footnote. If the program is a Part 2 program, the analysis does not end there. Part 2 permits uses and disclosures of records only as the rule allows, marketing is not among them, and there is no own-services exclusion \[5\]. Using records to decide who receives the email requires written consent meeting the rule’s elements \[7\]. A [mental health practice](/mental-health/) that is not a Part 2 program and a co-located SUD program can send the same email under two different standards.

Either way, the decision point is earlier than most teams think. It is not the send. It is the query that produced the audience.

### Two systems, one boundary

Almost every problem in the preceding three sections dissolves under one architectural choice.



Marketing systemClinical systemHoldsInquirers, prospects, referral contactsPatients and their recordsNever holdsDiagnoses, treatment status, admission dates, clinical notesCampaign data it does not needVendorsChosen for capabilityChosen for BAA availability and controlsIntegrationReceives consent status onlyPushes nothing outbound by default

The boundary is crossed by one thing: whether a person has given the consent that permits contact. Not their diagnosis, not their admission date, not their program.

This is harder than it sounds, because reporting pressure pushes the other way. Someone wants cost per admission by campaign, which requires knowing which inquirers became patients, which pulls admission status back into the marketing system. That reporting is achievable with aggregate counts rather than record-level syncs. Decide which one you built.

The minimum necessary standard points the same direction. Nobody on a marketing team needs a diagnosis field. The question is not whether a CRM could hold one securely. It is whether it should hold one at all.

### The suppression list paradox

Worth naming because the instinct behind it is a good one.

A program decides former patients should not see its ads. Ad platforms support this through exclusion audiences. To exclude a group of people, you upload the list of who they are. Hashing the email addresses does not resolve it, for the reason given above: the hash is deterministic, which is why matching works.

The privacy-protective impulse produces the disclosure.

### What the platform question actually is

Teams ask whether a given email platform is HIPAA compliant. The question does not resolve at the platform level.

Ask instead: what am I about to send this vendor, does that constitute PHI or a Part 2 record, and if it does, will the vendor sign a business associate agreement covering it. A platform with no BAA is available for a list that contains no PHI. The same platform is unavailable the moment the list is built from records.

One more regime applies to email specifically. Commercial messages carry CAN-SPAM obligations that run independent of both HIPAA and the TCPA: accurate header and sender identification, a valid physical postal address, and a working unsubscribe mechanism honored promptly. Those obligations attach to the message regardless of how the list was built.

## Paid Advertising, Retargeting, and Platform Policy

*In short: Two separate rulebooks operate in paid media. Federal law governs whether patient information built your audience. Platform contracts govern whether you may advertise at all and what you may target on. In this vertical the platform rules bite first, and they are stricter than HIPAA on retargeting.*

A treatment center can be flawless on HIPAA and Part 2 and still be unable to run a single ad. Understanding which rulebook is blocking you determines whether the fix is a lawyer, a certification application, or a campaign rebuild.



What it governsSourceWhat happens when you violate itHIPAA and Part 2Whether patient information was used to build the audience or the conversion dataFederal regulationOCR complaint, investigation, civil monetary penaltyPlatform policyWhether you may advertise, what you may target on, what you may send backContract terms you acceptedAd disapproval, account suspension, loss of the channel

### LegitScript is the gate, and it is not federal law

Since 2018, the major platforms have outsourced advertiser vetting for this category to one certification program.

Google’s healthcare and medicines policy requires certification as an addiction services provider through LegitScript before recovery-oriented drug and alcohol addiction services can be advertised in the US. Meta requires both: certification with LegitScript and written permission obtained by applying to Meta directly \[20\]. Microsoft Advertising and Nextdoor recognize the same certification \[21\].

None of that is a statute. It is a set of contract terms, and satisfying every one of them tells you nothing about your position under the Privacy Rule or Part 2.

Two exclusions in the certification standards matter more than the rest, and they point at a business model rather than a paperwork gap \[21\]:

- Lead generators, call centers, and marketers who refer patients to other providers in exchange for compensation are not eligible.
- Sober living homes and recovery residences without licensed clinical services do not meet the standards.

Hold that first exclusion. A federal criminal statute covered further down reaches the same arrangement from a different direction. When a certification program and a criminal statute both single out per-referral compensation, the arrangement is worth examining regardless of which one you were worried about.

### What the platforms restrict on their own terms

This is where the paid channel gets genuinely narrower than the law requires, and where most agency guidance is wrong by omission.

Google treats health as a sensitive interest category. The category expressly covers physical and mental health conditions, including chronic conditions requiring long-term care or management, and products or services to treat or manage them \[18\]. Advertisers promoting products and services falling within sensitive interest categories cannot use advertiser-curated audiences \[19\]. Custom segments built on sensitive creative or pointing to sensitive landing pages face further serving limits \[19\].

Read that plainly. Remarketing lists and customer-match uploads, the two tactics the retargeting question is usually about, are restricted by platform policy for this category before any privacy analysis begins. The HIPAA question about whether you may build a retargeting audience is frequently moot, because the platform will not let you use it. Policies verified as published in July 2026, and this is the fastest-changing material in this guide.

What remains available is contextual and intent-based reach: search terms, placements, and content adjacency rather than accumulated audience data. That is a real constraint on media planning and it is better to design around it from the start than to discover it at launch. The same logic shapes what is workable on [paid social](/mental-health/social-media-advertising/).

One constructive note. A large share of inquiries in this vertical come from a spouse, parent, or adult child rather than the person entering treatment. Broad intent-based reach to a searching family member raises none of the questions that retargeting a former site visitor does, and it is frequently the better-performing audience anyway.

### Conversions API and server-side tagging

These are sold as the compliance answer. They are not.

Moving a transmission from the browser to your server changes who sends the data. It does not change what the recipient receives, and it does not create a business associate agreement where the vendor does not offer one. If the payload identifies a person and the page supplied the health context, relocating the sending mechanism relocates nothing that matters.

Server-side implementations do offer real control, because you decide field by field what leaves. That control is the value. Use it to send less, not to send the same thing from a different origin.

Offline conversion import belongs in the same conversation. Rather than firing a browser event when someone converts, you upload conversion outcomes from your own records to train the platform’s bidding. It genuinely reduces what leaves the browser, which is a real improvement over pixel-based measurement. It does not change the underlying question. You are still deciding what to send and to whom, and the identifiers used to match those uploads are still identifiers.

## Testimonials, Reviews, and Social Proof

*In short: A person can tell their own recovery story publicly whenever they choose. The program cannot confirm it. That asymmetry governs testimonials, review replies, alumni features, and tagged photos, and Part 2 makes it stricter than it is anywhere else in healthcare.*

This is the highest-emotion, lowest-scrutiny activity in the vertical. It is also where a single well-meaning sentence, published under the program’s own account, becomes a permanent public disclosure.

### The asymmetry that governs everything here

Patients hold their own information and may share it freely. A covered entity may not, absent authorization \[2\].

Part 2 tightens this considerably. Where a facility is publicly identified as a place providing only SUD diagnosis, treatment, or referral, the presence of an identified patient may be acknowledged only with written consent or a court order \[5\]. The rule goes further still: a response to a request that cannot be fulfilled must be framed so that it does not affirmatively reveal that an identified individual has been or is being treated for a substance use disorder \[5\].

Read that against a marketing calendar and the implications cascade. It is not only that you cannot publish a name. It is that a warm, non-specific, entirely well-intentioned public reply can itself be the acknowledgment.

### Replying to a review is a disclosure

OCR has enforced on this repeatedly, including against a behavioral health provider. In June 2023, OCR announced a settlement with Manasa Health Center, a New Jersey psychiatric practice, resolving allegations that it impermissibly disclosed protected health information in public responses to negative online reviews, affecting four patients. The practice paid $30,000 and entered a two-year corrective action plan \[22\].

The trigger is confirmation, not detail. Consider a constructed example, written for illustration and not drawn from any real review.

A review reads: “The staff here saved my life. Ninety days and counting.”

A reply that discloses: “Thank you so much for trusting us with your recovery. We are proud of your ninety days and we loved having you in the program.”

That reply confirms, publicly and permanently, that a named account holder was a patient at a named facility. Every warm specific in it makes the confirmation firmer.

A reply that does not: “Thank you for the kind words. We are not able to discuss anyone’s care publicly, but our team is always glad to hear feedback. If you would like to reach us directly, our main line is on our contact page.”

Nothing is confirmed. Nothing is denied. The tone is still human.

The hardest case is a negative review that is unfair or factually wrong. That is exactly when the instinct to correct the record is strongest, and correcting the record almost always requires disclosing something about the person. The recommended posture is to move the conversation off the platform without acknowledging the relationship, and to treat any internal decision to respond further as a legal question rather than a marketing one.

### Testimonials, revocation, and photographs

A published testimonial requires authorization from the individual, with the required elements, before it runs \[2\]. For a Part 2 program, written consent meeting the rule’s elements is the equivalent requirement \[7\].

Two practical points follow.

**Authorization is revocable.** Someone at ninety days signs enthusiastically. Three years later they are applying for a professional license, or a custody arrangement is contested, and they want the video gone. Content on properties you own can be pulled. Content distributed to third-party platforms, syndicated, or scraped is a different problem. Time-bound the consent, keep testimonial assets on owned properties where practical, and maintain a record of who consented to what and when.

**Photographs are identifiers.** Full face photographic images and comparable images sit on the Safe Harbor list \[10\]. That reaches the group photo at an alumni barbecue, the facility tour video with residents visible in the background, and the graduation post. Consent covers the people who gave it and nobody else in the frame.

One category sits outside all of this. A staff member sharing their own recovery story is speaking for themselves, which is often the most credible content a program can publish. The line is whether the program’s content presents them as a patient of the program.

Separately, testimonials that imply typical outcomes carry FTC exposure on advertising substantiation grounds, which runs independently of anything in this section.

## Vendor Management: BAAs and the Questions to Ask

*In short: A vendor that creates, receives, maintains, or transmits PHI while performing a service for you is a business associate, and an agreement with specified terms has to be in place before the data moves. For Part 2 records, a second agreement type applies that a standard form may not cover.*

Nine sections of channel analysis reduce to one determination you can run against any tool, including tools that do not exist yet. That durability is the point of this section.

### What makes a vendor a business associate

Two conditions, both required. The vendor performs a function or service for you, and in doing so it creates, receives, maintains, or transmits protected health information on your behalf.

Notice what is absent from that test. Not whether the vendor is a healthcare company. Not whether the tool was bought by the marketing team. Not whether anyone intended it to receive patient information. A form platform that stores submissions from an intake page qualifies. A call tracking vendor holding recordings qualifies. An agency that manages any of it qualifies, which includes the kind of agency whose website you are reading.

When the test is met, the agreement has to contain specified terms. Among them: the permitted and required uses and disclosures, a commitment not to use or disclose the information otherwise, appropriate safeguards including Security Rule compliance for electronic PHI, reporting of impermissible uses and breaches back to you, flow-down requiring subcontractors to agree to the same restrictions, return or destruction of PHI at termination, and your right to terminate for a material breach \[23\].

That flow-down clause deserves attention it rarely gets. Marketing platforms are assemblies of subprocessors, and the AI features bolted onto most of them since 2024 introduced processors that predate anybody’s diligence file. A signed agreement from 2022 does not describe the vendor’s 2026 subprocessor list.

One misconception to retire. The narrow allowance for entities that merely transmit data without accessing it gets stretched to cover platforms that plainly store, index, and process. Storage is not transmission.

### The vendor screen

Run these ten questions before a tool touches anything.

1. What data does this tool receive, field by field, including hidden fields and URL parameters?
2. Does it store that data, or only pass it through?
3. Where is it stored, and under whose control?
4. How long is it retained by default, and can that be changed?
5. Who inside the vendor can access it, and is that access logged?
6. Will the vendor sign a business associate agreement covering this use?
7. Which subprocessors touch the data, and do they have flow-down agreements?
8. Have AI or analytics features been added that introduced new processors since the agreement was signed?
9. What happens to the data when the contract ends?
10. What is the vendor’s breach notification commitment, and how fast?

Most programs can answer one through three after some digging. Question seven is where the exercise usually stops, and that is the finding rather than a failure.

### Part 2 adds a second agreement

Part 2 does not use the business associate framework by default. It uses qualified service organizations, defined as persons providing services to a Part 2 program under a written agreement in which the organization acknowledges it is fully bound by Part 2 and will resist judicial efforts to obtain patient identifying information except as the rule permits \[4\].

The 2024 rule brought the two frameworks closer. A person meeting the business associate definition for a Part 2 program that is also a covered entity is included in the qualified service organization definition, with respect to information that is both PHI and a Part 2 record \[4\].

The practical read: a vendor’s standard form BAA, drafted for hospitals and never amended, may not address Part 2 at all. If your program is a Part 2 program, that is worth checking rather than assuming, and it is a question for counsel rather than for a procurement checklist.

### Nobody certifies HIPAA compliance

No federal agency certifies HIPAA compliance. There is no registry, no credential, and no expiration date to check.

A vendor badge reading “HIPAA certified” describes a purchased third-party audit or a self-attestation. Those can be informative. They are not a government status, and they do not substitute for a signed agreement or for your own assessment of what you are about to send. Ask for the agreement, not the badge.

## Paying for Leads: EKRA, Patient Brokering, and Compensation Structure

*In short: How you pay for marketing is a separate legal question from how you handle data. A federal criminal statute enacted in 2018 reaches payments made to induce referrals to recovery homes and treatment facilities, the first federal appellate ruling on it landed in 2025 and reached marketers directly, and several states criminalize the same conduct independently.*

Everything to this point has been about information. This section is about contracts, and it is the only exposure in this guide that is criminal rather than civil.

### What EKRA covers

The Eliminating Kickbacks in Recovery Act, enacted in 2018 as part of the SUPPORT Act and codified at 18 U.S.C. 220, makes it an offense to knowingly and willfully pay or offer remuneration, directly or indirectly, to induce a referral of an individual to a recovery home, clinical treatment facility, or laboratory \[24\].

It is often described as the Anti-Kickback Statute’s cousin. The differences are what matter here.



Anti-Kickback StatuteEKRAReachesFederal health care programsAny health care benefit program, including private insurance and cash-pay \[24\]Safe harborsNumerous and well developedFew \[24\]Volume-based pay to employeesProtected under the bona fide employment safe harborNot similarly protected \[24\]EnforcementCivil and criminalCriminal

The cash-pay reach is the part that surprises people. A private-pay residential program with no federal payer relationship at all is inside EKRA’s scope.

### What the Ninth Circuit decided in 2025

Until recently the statute had almost no appellate interpretation. That changed with United States v. Schena, decided July 11, 2025, the first federal appellate review of EKRA \[25\].

Two holdings matter for anyone buying or selling marketing in this vertical, and both need stating.

**EKRA reaches marketing intermediaries.** The defendant argued the statute did not apply because he paid marketers rather than physicians or patients directly. The court disagreed, holding that EKRA covers marketing intermediaries who interface with those who make referrals, and that payment need not go directly to a referral source \[25\].

**Percentage-based pay is not automatically a violation.** The court also held that paying percentage-based compensation to marketers is not by itself wrongful inducement. It became so in that case when combined with efforts to improperly influence referrals through false or fraudulent means \[25\].

Reporting only the first holding is alarmist. Reporting only the second is reassuring past the point of accuracy. The honest summary is that the compensation structure alone rarely decides the question, and that the surrounding conduct does.

### State patient brokering statutes

Federal law is not the only exposure, and in this vertical the state statutes have been more actively used.

Florida’s is the most frequently invoked, which matters given how much of the industry operates there. It makes it unlawful to offer or pay any commission, bonus, rebate, kickback, or bribe, directly or indirectly, in cash or in kind, or to engage in any split-fee arrangement in any form, to induce the referral of patients or patronage to or from a health care provider or facility, and it reaches those who aid or abet the conduct \[26\]. Violations are a third-degree felony, rising to a first-degree felony with a $500,000 fine where the conduct involves twenty or more patients \[26\].

The statute’s exception for information services is instructive on structure. It contemplates services that do not steer consumers toward a particular provider and that charge fees set in advance, consistent with fair market value for the information services provided, and not based on the potential value of a patient to the provider \[26\].

Fees set in advance. Fair market value. Not indexed to the value of a patient. That is a legislature describing what an arm’s-length marketing arrangement looks like.

### Where this touches ordinary marketing arrangements

Marketing in this vertical is commonly bought on a spectrum: flat monthly fee, fee plus a bonus tied to non-patient metrics, percentage of ad spend, payment per qualified lead, payment per admission. Those sit at different distances from the conduct these statutes describe.

Two clarifications, because this is where readers over-correct.

**Measuring cost per admission is not the same as paying on it.** Every program should know its cost per admission by channel. That is analytics. Tying a vendor’s compensation to that number is a contractual choice, and a different question.

**This is where the certification point closes the loop.** LegitScript’s certification standards exclude lead generators, call centers, and marketers who refer patients to other providers in exchange for compensation \[21\]. A certification program and a criminal statute pointing at the same arrangement from two directions is a signal worth reading.

What this section does not do is tell you whether a given arrangement is lawful. That determination turns on the specific facts, the specific contract, and the surrounding conduct, and it belongs to healthcare counsel rather than to a marketing guide.

## What Noncompliance Costs in 2026

*In short: The regulatory penalty is usually the smallest of three numbers. Private class actions have produced far larger settlements in this area, and state consumer health data laws add a private right of action that HIPAA has never had.*

Figures below reflect the schedule in effect as of July 2026 and are adjusted annually.

### HIPAA and Part 2 civil monetary penalties

HHS applied an inflation adjustment effective January 28, 2026, using the 2025 cost-of-living multiplier. The amounts apply to penalties assessed on or after that date for violations occurring on or after November 2, 2015 \[27\].



TierCulpabilityPer violationStatutory annual cap1Did not know$145 to $73,011$2,190,2942Reasonable cause$1,461 to $73,011$2,190,2943Willful neglect, corrected$14,602 to $73,011$2,190,2944Willful neglect, not corrected$73,011$2,190,294

One qualification that most published tables omit. Since April 2019, OCR has operated under a notice of enforcement discretion applying lower annual caps to the first three tiers than the statutory figures above \[27\]. Those reduced caps are agency policy rather than statute, and OCR can revisit them.

Civil penalties are not the only federal exposure. Criminal penalties under 42 U.S.C. 1320d-6, enforced by the Department of Justice rather than OCR, escalate from knowingly obtaining or disclosing PHI, to offenses under false pretenses, to offenses committed with intent to sell or use PHI for commercial advantage or personal gain. The preceding section covers a second criminal statute reaching compensation arrangements.

Part 2 penalties run through the same machinery. The rule applies the penalties under Social Security Act sections 1176 and 1177, and HIPAA’s enforcement provisions apply to Part 2 noncompliance in the same manner they apply to covered entities and business associates \[28\]. Combined with the February 16, 2026 enforcement start, a Part 2 marketing violation now has a complaint pathway and a penalty schedule behind it.

Worth knowing how these cases start. Enforcement in this area is overwhelmingly complaint-driven rather than audit-driven. One former patient, one review reply, one form. Worth noting alongside this: OCR’s most consistent enforcement theme across all HIPAA cases is the risk analysis requirement under the Security Rule. A marketing stack that holds electronic PHI sits inside that scope, and it is frequently absent from the analysis a program has on file.

### Private litigation is the bigger number

Put two figures from earlier in this guide side by side.



What it wasAmountManasa Health Center, 2023OCR settlement over PHI disclosed in responses to online reviews \[22\]$30,000In re Advocate Aurora Health Pixel Litigation, 2024Private class action settlement over tracking technologies \[14\]$12,225,000

The regulator was not the expensive party. HIPAA has no private right of action, so the pixel cases proceeded on state wiretap, privacy, and consumer protection theories instead, and those carry statutory damages that scale with class size. The 2024 ruling on OCR’s tracking guidance did nothing to narrow that track.

### State consumer health data laws

This is the layer most likely to change what your exposure looks like over the next two years.

Washington’s My Health My Data Act regulates consumer health data generated outside HIPAA and made violations enforceable through the state consumer protection statute, including by individuals \[29\]. Its definition of consumer health data reaches information identifying a consumer’s past, present, or future physical or mental health status \[29\]. Connecticut and Nevada enacted comparable laws without a private right of action \[29\]. The first private suit under the Washington statute was filed in February 2025 \[29\].

New York has been trying. A health information privacy bill passed both chambers in January 2025 and was vetoed in December 2025. A revised version passed the Senate and Assembly in June 2026 and was awaiting the governor’s action as of publication \[30\]. Notably, the revised bill exempts Part 2 programs and substance use disorder records alongside its existing HIPAA exemption \[30\].

Separately, Part 2 does not occupy the field. Where state law prohibits a disclosure that Part 2 would otherwise permit, the state law governs. Several states impose confidentiality requirements on SUD records that exceed the federal baseline.

### One regime that probably does not reach you

The FTC’s Health Breach Notification Rule comes up constantly in marketing compliance content. It applies to entities handling health information that are not covered by HIPAA, which is why it has been used against health apps and consumer platforms. A treatment center operating as a covered entity generally sits outside it.

It is listed here because naming what does not apply is part of an honest risk inventory. Padding the list makes everything on it easier to ignore.

## The HIPAA Marketing Checklist

*In short: Twelve sections reduce to one ordered audit. Three items are free and take under an hour combined. The rest are ordered by exposure rather than by ease.*

### Run these three this week

**1. Open a booking or intake page with developer tools running.** Watch the network tab and write down every third-party domain that receives a request. Fifteen minutes gives you a list of who is receiving data from the page where people identify themselves.

**2. Trace one form submission until it stops moving.** Browser, form platform, integration, CRM, notification email, forwarded copy, autoresponder, conversion event. Note which stop is the last one covered by a signed agreement.

**3. Read your last twenty review replies.** Look for any response that confirms, warmly or otherwise, that the reviewer received care.

Each of these reliably surfaces something. None requires a budget or a vendor. The first two are the dev-tools check and the vendor screen described above, run as a pair.

### The full audit

Ordered by exposure. Items touching Part 2 records, paid-lead compensation, and public acknowledgment of patients sit above analytics configuration, because the first three carry criminal or per-patient exposure and the last is a settings change.



\#What to examine1Whether your program meets the federally-assisted test and is a Part 2 program2How marketing vendors and agencies are compensated, and whether any element is indexed to leads, admissions, or patient value3Every public reply, testimonial, photo, and tagged post that could confirm a named person received care4Written consent and authorization records behind any list built from patient information5Which system holds records and which system runs campaigns, and what crosses between them6Every form on the site, its fields, its destinations, and its retention settings7Signed agreements for every vendor that receives data, plus their subprocessor lists8Call tracking configuration, including keyword capture, recording, transcripts, and retention9Chat widgets, session replay, and any AI intake tool on the site10Lead notification email routing, including forwarded copies on personal devices11Page-by-page classification into public, transitional, and authenticated, and which tools fire on each12Certification status and platform policy posture for every paid channel in use13Campaign, ad group, and URL naming conventions that carry condition names into downstream systems14Whether any state consumer health data law reaches the audiences you target

Most programs find their largest gap somewhere in items 5 through 7. Most programs expect to find it in item 11.

### What this does not replace

A checklist is a way to find questions. It is not a risk analysis under the Security Rule, it is not a legal opinion, and it is not a substitute for counsel who has read your actual contracts and looked at your actual configuration.

Two of the items above touch a criminal statute. Those are not marketing decisions.

### Where to go from here

Most of what this guide covers is fixable, and a fair amount of it is fixable this quarter. The pattern across programs we work with is consistent: the gaps are rarely deliberate, they accumulate through ordinary decisions made quickly by people trying to reach families in crisis, and they stay invisible until somebody traces a form submission end to end.

If you want a second set of eyes on any of it, [book a strategy call](/quote/) or call **855-876-7238**. We build and run marketing programs for behavioral health organizations, which means these questions come up on every engagement. We will tell you what we see. Your compliance obligations remain yours, and decisions about legal risk belong with your counsel.

*This article is general information about federal and state regulations affecting behavioral health marketing. It is not legal advice, and it does not create an attorney-client or advisory relationship. Consult qualified healthcare counsel about your specific circumstances.*



## Frequently Asked Questions



#### [Does HIPAA apply to my treatment center's marketing?](#432fe4d27875bfdf4)



It applies to how you use patient information, not to marketing generally. Advertising that reaches people without using patient information to select who sees it falls outside the Privacy Rule’s marketing provisions. The rules engage when protected health information builds the audience, or when a third party pays you to send a message.





#### [Is Google Analytics HIPAA compliant?](#7a72a2f2fda851f1e)



Google does not sign a business associate agreement for Google Analytics, Tag Manager, or Google Ads. Those products sit outside the defined service list Google’s BAA covers. No configuration setting changes that, which means the question is which pages the tool runs on rather than how it is configured.





#### [Can I still run retargeting ads for a treatment center?](#61a42cc74bfa4c7d0)



Platform policy is usually the binding constraint before privacy law is. Google treats health as a sensitive interest category and restricts advertiser-curated audiences for products and services in sensitive categories, which limits remarketing lists and customer match uploads for this vertical regardless of your privacy posture.





#### [Do I need a BAA with my marketing agency?](#c2bd5db6ff67bb0fe)



If the agency creates, receives, maintains, or transmits protected health information while performing services for you, it is a business associate and an agreement is required before the data moves. Most agencies handling forms, call data, or CRM records for a treatment center meet that test.





#### [How do I find out whether a platform will sign a BAA?](#2a99b26097c9664e2)



Check the provider’s published compliance documentation first, since most vendors that offer one say so and list which products it covers. Then ask sales for the agreement in writing before contracting. Confirm the specific products in scope, because coverage is frequently product-by-product rather than account-wide.





#### [Can I publish patient testimonials?](#df1ac067deb57d726)



Not without authorization containing the required elements, obtained before publication. A general consent signed at intake typically does not cover marketing use. For a Part 2 program, written consent meeting that rule’s elements is the equivalent requirement, and authorization can be revoked later.





#### [Can I respond to a Google review?](#06fefe187ceb80409)



You can respond without confirming that the reviewer received care. A reply that thanks someone for trusting you with their treatment has confirmed the treatment relationship publicly. OCR has brought enforcement actions on exactly this, including against a psychiatric practice in 2023.





#### [Can I email or text former patients?](#35e340543c7fc106b)



Under HIPAA alone, a covered entity describing a health-related service it provides, to its own patients, with no third-party payment involved, falls outside the marketing definition. For a Part 2 program the answer changes, because Part 2 has no equivalent carve-out and requires written consent. Text messages carry TCPA obligations on top.





#### [What is a Part 2 program, and am I one?](#b4adc3f4c4ffcc012)



A Part 2 program holds itself out as providing, and provides, substance use disorder diagnosis, treatment, or referral, and is federally assisted. Federal assistance is broader than grant funding and includes Medicare participation, DEA registration to dispense a controlled substance used in SUD treatment, federal financial assistance in any form, and IRS tax-exempt status.





#### [What changed for SUD programs in February 2026?](#254a942e120f023dc)



February 16, 2026 was the compliance date for the 2024 Part 2 final rule, and OCR began accepting complaints alleging Part 2 violations and Part 2 breach notification failures on that date. Enforcement authority was delegated to OCR in August 2025.





#### [Can I pay a marketing agency per admission?](#0a0cb42434007b110)



That question sits under a federal criminal statute rather than a privacy rule. EKRA prohibits remuneration to induce referrals to recovery homes and treatment facilities, reaches private insurance and cash-pay, and a federal appellate court held in 2025 that it covers payments to marketing intermediaries. Several states criminalize patient brokering independently. This is a question for healthcare counsel.





#### [Is call recording allowed on marketing calls?](#3cd2701c23d833128)



Recording is governed by state wiretap law, which is separate from HIPAA and varies by state. A national campaign routes calls from many states into one recording configuration, so the configuration has to satisfy the strictest state it reaches. Transcripts create a searchable record held by a vendor, with its own retention question.





#### [What are the HIPAA penalties for marketing violations?](#fd2eaefb519544dd7)



Under the schedule effective January 28, 2026, penalties range from $145 to $73,011 per violation across four tiers, with a statutory annual cap of $2,190,294. OCR has applied lower annual caps to the first three tiers since 2019 under an enforcement discretion notice. Criminal penalties under a separate provision are enforced by the Department of Justice.





#### [What should I do if we're already non-compliant?](#dbe6c5521f4b4e545)



Stop the transmission or practice first, then document what happened, when it started, and what information was involved. Run a breach risk assessment before deciding whether notification obligations are triggered, and involve counsel in that determination rather than after it. Remediate the configuration, then build the review step that would have caught it.









## Definition Bank

**Part 2 program.** A federally assisted program that holds itself out as providing, and provides, substance use disorder diagnosis, treatment, or referral for treatment. Defined at 42 CFR 2.11.

**Federally assisted.** Broader than grant funding. Includes Medicare participation, authorization to conduct maintenance treatment or withdrawal management, DEA registration to dispense a controlled substance used in SUD treatment, federal financial assistance in any form, and IRS tax-exempt status. Defined at 42 CFR 2.12(b).

**Protected health information.** Individually identifiable health information held or transmitted by a covered entity or business associate. Requires both an identifier and a link to a person’s health, care, or payment for care.

**Patient identifying information.** Part 2’s parallel term: name, address, Social Security number, fingerprints, photograph, or similar information by which a patient’s identity can be determined with reasonable accuracy. Defined at 42 CFR 2.11.

**Marketing.** Under the Privacy Rule, a communication about a product or service that encourages the recipient to purchase or use it, subject to three exclusions. Defined at 45 CFR 164.501.

**Financial remuneration.** Direct or indirect payment from or on behalf of a third party whose product or service is being described. Excludes payment for treatment of an individual. Its presence removes two of the three marketing exclusions. Defined at 45 CFR 164.501.

**Authorization.** A signed document with required elements permitting a specific use or disclosure of PHI. Required before PHI is used for marketing, with narrow exceptions. Not the same as a general consent. See 45 CFR 164.508.

**Written consent (Part 2).** Part 2’s equivalent instrument, with its own required elements including a description of the information, the recipients, the purpose, revocation rights, and an expiration. See 42 CFR 2.31.

**Business associate.** A person or entity that creates, receives, maintains, or transmits PHI while performing a function or service for a covered entity. Marketing agencies, form platforms, and call tracking vendors routinely qualify.

**Business associate agreement.** The contract required before a business associate handles PHI, containing specified terms including safeguards, breach reporting, subcontractor flow-down, and return or destruction at termination. See 45 CFR 164.504(e).

**Qualified service organization.** Part 2’s counterpart to the business associate, defined as a service provider that has signed a written agreement acknowledging it is fully bound by Part 2. Defined at 42 CFR 2.11.

**Safe Harbor de-identification.** One of two methods for removing information from the Privacy Rule’s scope, requiring removal of 18 listed identifiers and no actual knowledge that what remains could identify someone. See 45 CFR 164.514(b)(2).

**Unauthenticated public webpage.** A page requiring no login or user verification. The distinction matters because the 2024 court ruling addressed metadata collected on these pages specifically.

**EKRA.** The Eliminating Kickbacks in Recovery Act, 18 U.S.C. 220, a federal criminal statute prohibiting remuneration to induce referrals to recovery homes, clinical treatment facilities, and laboratories. Reaches private insurance and cash-pay, unlike the Anti-Kickback Statute.

## Entity Cards

### 42 CFR Part 2



PropertyValueWhat it isFederal confidentiality rule for substance use disorder patient recordsWho it coversFederally assisted programs providing SUD diagnosis, treatment, or referralEnforcing agencyHHS Office for Civil Rights, delegated August 25, 2025Key datesFinal rule February 16, 2024; effective April 16, 2024; compliance and enforcement February 16, 2026How it differs from HIPAANo exclusion for describing your own services; marketing use requires written consent; acknowledgment of patient presence restricted at SUD-only facilities

### EKRA (18 U.S.C. 220)



PropertyValueWhat it prohibitsKnowingly and willfully paying or offering remuneration to induce referrals to recovery homes, clinical treatment facilities, or laboratoriesEnacted2018, as part of the SUPPORT ActScopeAny health care benefit program, including private insurance and cash-paySafe harborsFew, and no protection equivalent to the Anti-Kickback Statute’s bona fide employment provisionKey caseUnited States v. Schena, 9th Cir., July 11, 2025Exposure typeCriminal

### LegitScript Addiction Treatment Certification



PropertyValueWhat it isThird-party certification and monitoring program for addiction treatment advertisersWho requires itGoogle, Meta, Microsoft Advertising, NextdoorWhat it is notFederal law, a HIPAA credential, or evidence of privacy complianceKey exclusionsLead generators, call centers, and marketers referring patients for compensation; sober living without licensed clinical servicesMeta’s added stepCertification plus written permission obtained from Meta directly

### My Health My Data Act (Washington)



PropertyValueJurisdictionWashington residents and individuals whose consumer health data is collected in WashingtonWhat it coversConsumer health data outside HIPAA, expressly including mental health statusEnforcementState attorney general, plus a private right of action through the state consumer protection statuteFirst private suitFebruary 2025Comparable lawsConnecticut and Nevada, without a private right of action

## Sources

1. **45 CFR 164.501, Definitions** — <https://www.ecfr.gov/current/title-45/part-164/section-164.501>
2. **45 CFR 164.508, Authorizations** — <https://www.ecfr.gov/current/title-45/part-164/section-164.508>
3. **42 CFR 2.12, Applicability** — <https://www.ecfr.gov/current/title-42/part-2/section-2.12>
4. **42 CFR 2.11, Definitions** — <https://www.ecfr.gov/current/title-42/part-2/section-2.11>
5. **42 CFR 2.13, Confidentiality restrictions** — <https://www.ecfr.gov/current/title-42/part-2/section-2.13>
6. **HHS, Understanding Confidentiality of SUD Patient Records (Part 2)** — <https://www.hhs.gov/hipaa/part-2/index.html>
7. **42 CFR 2.31, Consent requirements** — <https://www.ecfr.gov/current/title-42/part-2/section-2.31>
8. **42 CFR 2.22, Notice to patients** — <https://www.ecfr.gov/current/title-42/part-2/section-2.22>
9. **HHS OCR, Part 2 civil enforcement program announcement (Feb 13, 2026)** — <https://www.hhs.gov/press-room/hhs-announce-civil-enforcement-program-sud-patient-records.html>
10. **45 CFR 164.514, De-identification etc.** — <https://www.ecfr.gov/current/title-45/part-164/section-164.514>
11. **Holland &amp; Knight, AHA v. Becerra analysis** — <https://www.hklaw.com/en/insights/publications/2024/06/american-hospital-assn-v-becerra-are-tracking-tools-ok-again>
12. **AHA, HHS withdraws appeal (Aug 29, 2024)** — <https://www.aha.org/news/headline/2024-08-29-hhs-will-not-appeal-aha-court-victory-online-tracking-case>
13. **Google HIPAA compliance docs** — [Cloud](https://cloud.google.com/security/compliance/hipaa) and [Workspace](https://support.google.com/a/answer/3407054)
14. **In re Advocate Aurora Health Pixel Litigation settlement** — <https://www.advocateaurorasettlement.com/>
15. **Novant Health pixel settlement** — [Class Action Settlement](https://topclassactions.com/lawsuit-settlements/closed-settlements/novant-health-pixel-tracking-6-66m-class-action-settlement/) (Court approval order: [PDF](https://www.ncmd.uscourts.gov/sites/ncmd/files/22cv697sa.pdf))
16. **Insurance Marketing Coalition v. FCC, 127 F.4th 303 (11th Cir. 2025)** — <https://law.justia.com/cases/federal/appellate-courts/ca11/24-10277/24-10277-2025-01-24.html>
17. **FCC final rule eliminating one-to-one consent (Fed. Reg., Aug 29, 2025)** — <https://www.federalregister.gov/documents/2025/08/29/2025-16641/delete-delete-delete-targeting-and-eliminating-unlawful-text-messages-rules-and-regulations>
18. **Google Ads, Health in personalized advertising** — <https://support.google.com/adspolicy/answer/16701855>
19. **Google Ads, Restricted targeting in Personalized advertising** — <https://support.google.com/adspolicy/answer/143465>
20. **Meta Transparency Center, Drug and Alcohol Addiction Treatment** — <https://transparency.meta.com/policies/ad-standards/restricted-goods-services/drug-alcohol-addiction-treatment/>
21. **LegitScript, Addiction Treatment Certification standards** — <https://www.legitscript.com/certification/addiction-treatment-certification/>
22. **HHS OCR, Manasa Health Center resolution agreement** — <https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/manasa/index.html>
23. **45 CFR 164.502(e) / 164.504(e), business associate contracts** — [164.502](https://www.ecfr.gov/current/title-45/part-164/section-164.502) and [164.504](https://www.ecfr.gov/current/title-45/part-164/section-164.504)
24. **18 U.S.C. 220 (EKRA)** — <https://www.law.cornell.edu/uscode/text/18/220>
25. **United States v. Schena, No. 23-2989 (9th Cir. July 11, 2025)** — <https://cdn.ca9.uscourts.gov/datastore/opinions/2025/07/11/23-2989.pdf>
26. **Fla. Stat. 817.505, Patient brokering** — [http://www.leg.state.fl.us/statutes/index.cfm?App\_mode=Display\_Statute&amp;URL=0800-0899/0817/Sections/0817.505.html](http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0800-0899/0817/Sections/0817.505.html)
27. **HHS CMP inflation adjustment (Fed. Reg., Jan 28, 2026)** — <https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment>
28. **42 CFR 2.3, Civil and criminal penalties** — <https://www.ecfr.gov/current/title-42/part-2/section-2.3>
29. **Washington My Health My Data Act, RCW 19.373** — <https://app.leg.wa.gov/rcw/default.aspx?cite=19.373>
30. **NY Health Information Privacy Act, S9269 / A10357** — [S9269](https://www.nysenate.gov/legislation/bills/2025/S9269) and [A10357](https://www.nysenate.gov/legislation/bills/2025/A10357)