
Rules
A Practice Owner's Guide to HIPAA-Compliant Dental Marketing in the United States
HIPAA compliant dental marketing rests on written patient authorization, vendor agreements and six years of records that hold up in an OCR review.
What to take away
- HIPAA sets a federal floor for using patient information in advertising, enforced by the HHS Office for Civil Rights.
- Promotional content that names a patient usually needs written authorization, apart from the treatment consent form.
- Website tracking, ad pixels and email platforms each handle patient data and need a policy and a business associate agreement.
- State law can add duties, and state attorneys general can bring privacy cases.
- Keep authorizations and marketing files for six years, the federal retention standard.
Few practices set out to break privacy law. They break it by posting a patient photo, adding a tracking pixel to a booking page, or letting a hygienist answer a review.
Who has jurisdiction over dental marketing
The HHS Office for Civil Rights enforces the HIPAA Privacy Rule against covered entities and their business associates. A dental practice is a covered entity. So is the billing service, the answering service and the marketing vendor that touches a patient list.
The Federal Trade Commission polices advertising claims under the FTC Act. Its guidance on health product claims covers testimonial ads, directory listings and promises about outcomes.
State attorneys general can bring HIPAA actions under the HITECH Act. State dental boards add advertising rules of their own, often covering specialty and sedation claims.
What a compliant disclosure contains
An authorization is the document that lets a practice use patient information for marketing. It must carry specific elements and clear wording. A dental website marketing plan should also list which pages collect data and where that data goes.
| Element | What it must contain |
|---|---|
| Description of the information | Photos from the March visit, first name, city |
| Who may disclose and receive | The practice and the named agency |
| Purpose of each use | Instagram post, website testimonial |
| Expiration | Twelve months from the date of signature |
| Revocation | How to withdraw consent in writing |
| Treatment condition | Care is not conditioned on signing |
| Signature and date | Copy returned to the patient |
A Notice of Privacy Practices does not replace the form. It must state that marketing uses need authorization and that patient information will not be sold without one.
A staff member who texts a before-and-after photo to an agency without a signed form has made a disclosure HIPAA does not allow.
Tracking carries the same duty. A remarketing tag on a page about implants builds an audience from people seeking care. HHS safeguards for electronic protected health information call for an assessment of the vendor before any tag goes live.
Records a dental practice should keep
HIPAA requires documentation be kept six years from creation or the date last in effect under 45 CFR 164.530(j). For lists, a practice running dental email marketing should show where each address came from.
| Record | Retention | Reason it matters |
|---|---|---|
| Authorizations and revocations | 6 years | proves consent existed |
| Business associate agreements | 6 years after the contract ends | proves vendor oversight |
| Breach risk assessments | 6 years | shows how a call was made |
| Marketing copy and approvals | 6 years | defends the claim that ran |
| Training logs and sanctions | 6 years | first request from OCR |
State rules can run longer. Many states require adult treatment records be held five to ten years, and longer for minors. Where the periods differ, keep the longer one.
What happens after a breach or complaint
A complaint or a self-reported breach starts a review. OCR asks for the authorization, the policies, the risk analysis and the vendor agreement. Missing documents usually mean a finding of failure to safeguard.
The result can be a resolution agreement with a corrective action plan and annual reporting. Civil money penalties are tiered by culpability, from lack of awareness to willful neglect. State attorneys general can file separately.
Some damage never appears in a settlement. A breach listing stays on the OCR portal, referral sources notice, and dental reputation management turns into damage control.
Where state law adds to HIPAA
California's CCPA and CPRA exempt protected health information that HIPAA already governs, but not everything else. Website visitors who never became patients, newsletter lists and ad audiences can fall inside those statutes, with notice and deletion rights.
Washington's My Health My Data Act reaches health-related businesses beyond covered entities, including some marketing vendors. Texas, Nevada and Connecticut have similar consumer health data laws.
Advertising to minors and to people seeking reproductive care draws added scrutiny in some states. Dental board rules and retention periods differ too, so a campaign built for one state does not travel.
Common questions
Do we need patient authorization to reply to a public review?
Yes, if the reply confirms the person is a patient or describes treatment. A reply that avoids confirming any relationship is safer.
Is a marketing platform compliant on its own?
No. Compliance sits with the practice, not the tool. The vendor signs a business associate agreement and the practice controls the list.
Can we run Google Analytics or a Meta pixel on our site?
Only after a vendor assessment and a decision about which pages carry the tag.
Who owns the data when we change agencies?
The practice does. Before signing, work through dental marketing strategy questions on data return, deletion and tag removal, and put the answer in the contract.


