Home/Insights/HIPAA-compliant email marketing for clinics: consent, lists, and what you cannot send
Operator playbooks

HIPAA-compliant email marketing for clinics: consent, lists, and what you cannot send

Published 2 September 2026

What does HIPAA require for clinic email marketing?

Consent that records four things: who opted in, when, how, and for which topics, and it must be producible on request. Marketing consent has to be separate from consent to be contacted about care, and one checkbox covering both is not marketing consent. Where the marketing itself relies on protected health information, a HIPAA authorization is required rather than a simple opt-in, stored with a revocation path that propagates everywhere. Subject lines, preheader text, headers and image alt text must never carry patient information, because those fields are logged in more places and a subject line appears on a lock screen. A segment name is itself a disclosure: a list named after a treatment describes identifiable people and will eventually surface in an export or a screenshot. The practices that get stuck here have usually concluded HIPAA prevents email marketing, which is not what it says.

Almost everything published on HIPAA-compliant email marketing comes from two places: compliance organisations explaining the rule, and vendors explaining why their platform satisfies it. Very little comes from anyone who has had to build it inside a working practice, which is where the awkward parts live.

This is the operational version.

A tick in a box is not consent. The record needs to show who opted in, when, how, and for what topics, and it must be producible on request. What that record has to contain, and the fifth field almost nobody stores, is in consent management for clinic marketing. If your evidence is “they filled in the intake form in March” and the form no longer exists in that version, you cannot demonstrate anything.

Marketing consent must be separate from consent to be contacted about care. One checkbox covering both is not marketing consent, and this is the single most common gap. It appears on the intake form as a distinct opt-in with plain language, or as its own subscribe action.

Where the marketing itself relies on protected health information, a straightforward opt-in is not sufficient and a HIPAA authorization is required, stored with a working revocation path. Revocation has to propagate everywhere, not only to the system where the unsubscribe was clicked.

Two lists, two systems

The marketing list runs on documented consent. The clinical list runs on clinical necessity: appointment reminders, preparation instructions, aftercare, results notifications. These do not require marketing consent because they are not marketing.

Keep them in different systems with different access controls, not two segments in one platform. The wider requirements this sits inside are in HIPAA-compliant marketing automation. The failure this prevents is specific and common: a coordinator with access to everything sends a seasonal offer to the list built for clinical communication, and no segment naming convention stops that from happening on a busy afternoon.

The separation also removes an argument that otherwise recurs every quarter, about whether a particular message is a reminder or a promotion. If it goes out from the clinical system it is clinical, and if it needs the marketing system it needs consent.

The fields that must never carry patient information

Subject lines, preheader and preview text, headers, and image alt text.

These travel further and are logged in more places than message bodies, and a subject line appears on a phone’s lock screen where anybody nearby can read it. A subject naming a treatment discloses a condition to whoever happens to be holding the device.

The same logic applies to anything derived from the list. A segment name is a disclosure. A list called “GLP-1 enquiries, no show” describes identifiable people, and it will eventually appear in an export, a screenshot in a meeting, or a filename in an email.

What you can still do, which is more than most practices assume

The constraints are narrower than the caution they produce. Inside BAA-covered infrastructure, with consent recorded, a clinic can run genuinely personalised communication. Treatment-specific aftercare sequences, follow-up on a consultation that did not convert, reactivation of patients who have not been seen in eighteen months.

What changes is the plumbing rather than the ambition. The personalisation happens inside the boundary. Anything leaving for a system without a BAA leaves without identifiers.

The practices that get stuck here have usually concluded that HIPAA prevents email marketing, which is not what it says. It requires consent to be real, records to exist, and protected information to stay inside systems that are contractually responsible for it.

The grey areas, which is where the arguments happen

Four cases come up in every practice and none of them is obvious.

Appointment reminders are clinical. No marketing consent required. They stop being clinical the moment somebody appends “and ask us about our summer offer”, at which point the whole message needed consent.

Review requests are the genuinely contested one. A request to review a completed experience is not obviously marketing, and equally it is not clinically necessary. The defensible position is to treat it as marketing, send it from the marketing system, and require consent. It costs a little reach and removes an argument you would rather not have.

Newsletters are marketing, always, including the ones that are mostly educational. The educational framing does not change the basis on which they are sent.

Birthday and anniversary messages are marketing, and they are also the ones most likely to have been set up years ago by someone who has since left, running quietly against a list nobody has reviewed.

If you audit only one thing, audit the automations nobody remembers configuring.

If you are splitting a list of mixed provenance, you will need to re-permission part of it. That message is not itself marketing, so it can go from the clinical system, and it should be short and plain rather than promotional.

It needs to state what you will send, roughly how often, and how to stop. Do not bundle it with an offer, because an offer makes the message marketing and you are then sending marketing to people who have not consented, which is the thing you were fixing.

Expect a low response. That is not a failure of the message. A list where twenty per cent actively re-consent is a list of twenty per cent who want to hear from you, and it will outperform the whole of the previous one on every metric that matters.

Deliverability, which compliance makes harder

Healthcare senders face a compounding problem. Consent-based lists are smaller, sending frequency is lower because there is less to say, and low-frequency senders have weaker reputation with mailbox providers. Then a quarterly campaign to a cold list gets filtered, and the practice concludes email does not work for them.

Three things help. Send from a subdomain used only for marketing, so a filtering problem never touches appointment reminders. Keep a genuine cadence rather than saving everything for a quarterly push. And remove non-openers on a schedule, because a shrinking list that engages beats a large one that does not, and this is the rare case where the compliant approach and the effective one are the same approach.

Practical sequence

If you are starting from a working practice with an existing list of mixed provenance:

  1. Establish what consent you can actually evidence. Not what you believe was collected. What is recorded and producible.
  2. Split the list by that evidence. Anything you cannot evidence is clinical-only until re-consented.
  3. Move the marketing list to a platform with a signed BAA on the plan you are on, which for most major platforms is a tier feature rather than a product feature.
  4. Re-consent the unevidenced portion with a single clear opt-in message sent from the clinical system, since that message is not itself marketing.
  5. Audit the field discipline on every existing template: subject, preheader, alt text.
  6. Write the revocation path and test it by revoking a real record.

Step two is the uncomfortable one, because it usually shrinks the list. It also converts an unquantified liability into a smaller list you can actually use, which is the better position to argue from if anyone ever asks.

RelatedCRM automation: every enquiry followed up, every outcome recordedOpen →

Show us where the revenue stops.

Thirty minutes, your real numbers, an honest read on which layer is costing you most.

Book a call