HIPAA and Pharma Advertising: Where It Applies and Where It Does Not
HIPAA and pharma advertising explained: why manufacturers are usually not covered entities, when HIPAA reaches marketing data, and what tracking guidance means.
The short answer
HIPAA applies to pharma advertising less often than people think. Drug manufacturers are usually not covered entities, so their own media is generally governed by FDA, the FTC, and state privacy laws rather than HIPAA. HIPAA does apply when data comes from a covered entity or business associate, such as a provider, pharmacy, health plan, or some hub and patient support partners, and when tracking tags run on a covered entity's website or portal.
"Is this HIPAA compliant?" is one of the most common questions in a pharma media meeting and one of the least precise. Sometimes it means "is this legal," sometimes "is this de-identified," sometimes "will privacy review approve it." This article sorts out where HIPAA actually reaches pharma advertising and where other rules take over. It is not legal advice; your privacy counsel decides the specific cases.
Who HIPAA covers, and why manufacturers usually are not on the list
HIPAA's Privacy Rule applies to covered entities and their business associates. Covered entities are health plans, health care clearinghouses, and health care providers that conduct certain standard electronic transactions. Business associates are companies that handle protected health information (PHI) on a covered entity's behalf, such as billing vendors or IT providers.
A pharmaceutical manufacturer selling and advertising its products is generally not a covered entity. Its consumer site, its savings program, and its branded social accounts are not HIPAA-regulated just because they discuss health. That surprises people, and it cuts both ways: the brand is not bound by HIPAA's rules in those settings, but it is bound by FTC rules, state consumer health laws, and its own privacy promises, which can be stricter in practice.
Where HIPAA does reach pharma marketing
HIPAA enters the picture through the data and the partners, not through the brand's status. The table is a simplification for orientation.
| Situation | Does HIPAA usually apply? | What to check |
|---|---|---|
| Brand runs DTC display using a third-party consumer audience segment | Generally no, unless the segment was built from PHI | Data provenance; state health data laws; platform policy |
| Pharmacy or provider sends a promotional message about a drug using patient records | Yes, the covered entity is using PHI for marketing | Patient authorization; disclosure of third-party payment; exceptions |
| Hub or patient support program collects patient information | Depends on the structure; data from providers and pharmacies often flows under a patient authorization | Scope of the authorization; whether it covers marketing use; contract terms |
| Measurement vendor matches ad exposure to claims data | The claims data source is often HIPAA-governed; outputs are usually de-identified | De-identification method; re-identification limits; who sees row-level data |
| Health system's website runs ad pixels | Yes, for the health system, when tags can access PHI | Authenticated pages; business associate agreements; consent |
| Brand runs a symptom tracker app | Generally no, but the FTC Health Breach Notification Rule may apply | App data flows to SDKs and ad platforms |
HIPAA marketing rules and authorizations
When a covered entity wants to use PHI to send a communication that encourages someone to buy or use a product, HIPAA generally treats it as marketing and requires the individual's written authorization under 45 CFR 164.508. If a third party, such as a manufacturer, pays the covered entity for the communication, the authorization has to say so.
The exceptions are narrow and get misapplied. Face-to-face communications and promotional gifts of nominal value do not need authorization. Refill reminders and communications about a drug the patient is currently prescribed are excluded from the marketing definition, as long as any payment to the covered entity is reasonably related to the cost of making the communication. HHS has published separate guidance on refill reminders, including what costs can be reimbursed. If a program design depends on one of these exceptions, it needs a lawyer's sign-off, not a planner's reading.
For media teams, the practical point is simple. If a partner offers to "activate" an audience based on its patients' prescriptions or diagnoses, ask what authorization covers that use. "It's HIPAA compliant" is not an answer. The distinction between consent, permission, and fitness for use is covered in consent, permission, and fitness for use.
De-identified data and the measurement exception people assume
Much of pharma media measurement depends on data that started as PHI, such as claims or pharmacy records, and was de-identified. HIPAA recognizes two methods: safe harbor (removing specified identifiers and having no actual knowledge that the rest could identify someone) and expert determination (a qualified expert concludes the risk of re-identification is very small).
De-identified data is not PHI. But de-identification is tied to a context. A dataset certified for one use can become identifiable when combined with an ad exposure file, a location feed, or a small rare-disease population. That is why measurement vendors typically keep the match inside their own environment and return only aggregated results, and why requests for row-level outputs get pushback. For rare conditions, see patient identification with diagnostic data.
Tracking technologies: what HHS guidance says now
HHS's Office for Civil Rights issued a bulletin on online tracking technologies in December 2022 and updated it in March 2024. It explains when pixels, SDKs, and similar tools on covered entity websites and apps can disclose PHI to vendors, which would require a business associate agreement or patient authorization.
In June 2024, a federal court in Texas (American Hospital Association v. Becerra) vacated the part of the guidance that treated an IP address combined with a visit to an unauthenticated public page about a health condition or provider as PHI. HHS updated its page to reflect the ruling. The rest of the guidance was not vacated, including tracking on authenticated pages such as patient portals and pages where people enter health information. Check HHS's page for current language, because this area has changed more than once.
For pharma, this matters most when the brand partners with health systems, telehealth providers, or pharmacies whose sites carry brand tags or conversion pixels. Their HIPAA exposure becomes your contract problem. Governance for the brand's own sites is in tracking pixel governance on pharma and health websites.
Where state laws pick up what HIPAA leaves
Because HIPAA's reach is limited, states have passed laws covering consumer health data held by companies that are not covered entities. Washington's My Health My Data Act is the best known; it exempts HIPAA-regulated PHI but covers a wide range of other health data, including inferences. For pharma brand media, these laws are often more relevant day to day than HIPAA. See state consumer health data laws and pharma media and the series overview in the pharma marketing compliance guide.
Practical takeaway
List every data source behind your current audiences and measurement, and next to each write who collected it, whether it began as PHI, and what authorization or de-identification covers the use. Any line you cannot fill in goes to privacy review before the next flight, not after.
Frequently asked questions
Does HIPAA apply to pharmaceutical companies?
Usually not directly. HIPAA applies to covered entities (health plans, health care clearinghouses, and most providers) and their business associates. A drug manufacturer running its own advertising is generally neither, though it can receive HIPAA-governed data through partners, and other privacy laws may apply to it.
Can a pharmacy or provider use patient data to send drug marketing?
Under HIPAA, a covered entity generally needs the patient's written authorization to use PHI for marketing, and the authorization must disclose if a third party is paying for the communication. There are narrow exceptions, including certain refill reminders and face-to-face communications.
Is de-identified data covered by HIPAA?
Data properly de-identified under HIPAA's safe harbor or expert determination methods is no longer PHI. It can still be subject to contracts, state laws, and re-identification restrictions, and de-identification done for one use may not hold once it is combined with other data.
Did a court strike down HHS's tracking technology guidance?
In June 2024 a federal court in Texas vacated the part of the guidance saying that an IP address combined with a visit to an unauthenticated public page about a health condition could be PHI. Other parts of the guidance, including tracking on authenticated pages such as patient portals, were not vacated. Check HHS's page for the current version.
Sources
- HHS OCR, Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
- eCFR, 45 CFR 164.508 Uses and disclosures for which an authorization is required
- HHS, Guidance Regarding Methods for De-identification of Protected Health Information
External guidance and platform documentation change. Links were current at publication; check them again before relying on them for a decision.
Editorial note. Analysis and frameworks are the author's own and do not represent Acxiom or any current or former employer, client, or named platform. Examples labeled hypothetical or illustrative are not results from real campaigns. Nothing here is legal, regulatory, or medical advice.
New pharma programmatic breakdowns, occasionally
One email when I publish something worth reading. Benchmarks, measurement teardowns, and case studies with the caveats attached. No cadence promises, no reselling your address.
Unsubscribe any time. See the privacy policy.
Working through this decision on a real plan?
I work on health and pharma data, identity, and activation, after five years running HCP and DTC programmatic agency-side. Happy to talk through how this applies to your situation.