HIPAA is the Health Insurance Portability and Accountability Act of 1996, a United States federal statute setting national rules for how a defined group of health organisations may use, disclose and safeguard patient information. Public Law 104-191 was signed on August 21, 1996, and its original purpose was administrative: keep insurance coverage portable between jobs, standardise electronic billing, attack fraud. Privacy arrived as a secondary instruction. Congress told the Department of Health and Human Services to write privacy rules if it failed to legislate within three years. It failed, and HHS wrote them.

For advertising, the law matters because of what it forecloses. A hospital, a health plan or a pharmacy sits inside its perimeter; a demand-side platform, a social network or an analytics vendor generally does not. Every mechanism moving an audience signal from the first group to the second has to survive a rule set written in 2000, before programmatic buying existed.

Covered entities, business associates and PHI

Three categories are bound directly: health plans, including insurers and employer-sponsored group plans; health care clearinghouses, which translate claims data between formats; and health care providers transmitting health information electronically in a covered transaction, meaning almost every hospital, clinic and pharmacy in the country.

A fourth came later. A business associate is any outside party that creates, receives, maintains or transmits protected health information for a covered entity. Cloud hosts, billing vendors and analytics providers qualify once patient data passes through them. Since 2013 they carry direct statutory liability, and each must sign an agreement flowing the same obligations downstream.

Protected health information, abbreviated PHI, is individually identifiable health information held or transmitted by a regulated entity in any form. The identifiability test is where advertising technology runs into trouble. Information stops being PHI once de-identified, and 45 CFR 164.514 offers two routes: expert determination, or safe harbour, which strips 18 enumerated categories including names, email addresses, IP addresses and device identifiers. The mechanics behind that standard have their own history.

Three rule sets sit on top: the Privacy Rule, governing use and disclosure; the Security Rule, setting safeguards for electronic PHI; and the Breach Notification Rule, requiring 60-day notice.

The marketing provision

The operative text for advertisers is short. Section 164.501 defines marketing as a communication about a product or service that encourages the recipient to purchase or use it. Section 164.508(a)(3) requires written authorisation before PHI may be used or disclosed for that purpose, with two narrow exceptions: face-to-face communication, and a promotional gift of nominal value. Where a third party pays the covered entity to carry the message, the authorisation must say so, and Section 164.508(a)(4) adds a separate requirement for any sale of PHI for remuneration.

Treatment and care coordination communications fall outside the definition, which is why appointment reminders and refill notices remain lawful. Once a manufacturer subsidises the message, the 2013 rules pull it back in.

Origin and evolution

The Privacy Rule was published on December 28, 2000, modified on August 14, 2002 and became enforceable on April 14, 2003. The Security Rule followed on February 20, 2003, with compliance due April 20, 2005, and an Enforcement Rule arrived in February 2006.

The HITECH Act, signed February 17, 2009 inside the stimulus package, rewrote the incentives: tiered civil monetary penalties, breach notification, and liability extended to business associates.

The Omnibus Final Rule, published January 25, 2013 at 78 Federal Register 5566 and binding from September 23, 2013, is the version still in force. It broadened the business associate definition to capture cloud and storage vendors, tightened the marketing and sale-of-PHI provisions, and made any impermissible disclosure presumptively a breach. Penalties published on January 28, 2026 run from $145 per violation to $2,190,294, though a 2019 notice of enforcement discretion applies lower annual caps to the first three tiers.

Where the statute met the pixel

The collision was documented rather than predicted. In June 2022, The Markup tested the websites of Newsweek's 100 top-ranked American hospitals and reported finding the Meta Pixel on 33 of them, transmitting a data packet to Facebook when a visitor clicked to book an appointment. Pixels also sat inside the password-protected patient portals of seven health systems, and the 33 hospitals had together reported more than 26 million admissions and outpatient visits in 2020.

HHS responded on December 1, 2022 with a bulletin on online tracking technologies. Its most contested passage held that combining a visitor's IP address with a visit to an unauthenticated public page about a specific condition or provider produced individually identifiable health information. In July 2023, the Office for Civil Rights (OCR) and the Federal Trade Commission jointly warned roughly 130 health organisations.

The American Hospital Association, the Texas Hospital Association and two Texas health systems sued in November 2023. OCR revised the bulletin on March 18, 2024. On June 20, 2024, the US District Court for the Northern District of Texas held in American Hospital Association v. Becerra that the agency had exceeded its statutory authority, vacating the IP-plus-page-visit theory nationwide. No replacement rulemaking has issued since.

Civil litigation was unaffected. Advocate Aurora Health settled a consolidated class action for $12.25 million in July 2024, covering roughly 3 million patients, and Novant Health settled for about $6.6 million over pixels on its MyChart portal. Portal pages were always authenticated, and the vacatur never touched them.

Why it matters for the marketing community

The compliance perimeter shaped an entire product category. Healthcare demand-side platforms exist because general-purpose platforms cannot sign business associate agreements at scale or defend their data flows to an OCR investigator. DeepIntent opened its infrastructure to third parties through Helix on March 19, 2026, covering what it says are more than 3.7 million providers and over 240 million patient lives.

Provider targeting is the workaround the statute permits. National Provider Identifier numbers describe clinicians in their professional capacity rather than patients, which is why StackAdapt launched self-serve NPI targeting on January 6, 2026 with reporting it calls HIPAA-compliant. The same logic runs through point-of-care media, where patient-facing campaigns using identifiable data trigger authorisation requirements while provider-only campaigns generally do not, and through the epocrates integration, built on deterministic clinician identity. Three supply deals closed in one week in late May 2026 reached six electronic health record systems and 158,000 doctors.

Platform policy tracks the same boundary from the other side, through a restricted drug term certification covering personalised targeting of clinicians, revised prescription drug rules split by market, and looser constraints for Authorized Buyers.

Limitations and disputes

The law's reach is narrower than its reputation, because HIPAA binds entities rather than data. A fitness app, a symptom search, a period tracker and a pharmacy discount site sit outside it even when the information is more revealing than anything in a chart. Facebook is not a covered entity. Neither is Google.

Enforcement of that gap has fallen to other regulators. The FTC brought its first Health Breach Notification Rule action against GoodRx on February 1, 2023, producing a $1.5 million penalty and a permanent ban on sharing health data for advertising; BetterHelp followed in March 2023 with $7.8 million in refunds. California secured a $1.55 million settlement with Healthline in July 2025 over article titles suggesting diagnoses, fined a data broker $45,000 for selling lists organised by medical condition, and saw a jury find Meta liable for collecting health data in August 2025.

The vacatur is disputed on both sides. Hospitals argued that a website visit reveals nothing about why the visitor came, since students, journalists and relatives browse the same pages. Privacy advocates counter that the ruling leaves unauthenticated pages, where most advertising happens, unregulated at federal level. Scope narrowed again in Purl v. HHS on June 18, 2025, when the same Texas court vacated nearly all of the April 2024 reproductive health privacy amendments nationwide.

Vendor claims deserve scepticism. HIPAA has no certification scheme, so the phrase HIPAA-compliant describes a self-assessment rather than an audit. A recent DeepIntent announcement, for its Cora planning tool, dropped the word in favour of privacy-safe framing without explaining the change.

Not the same as

HITECH is the 2009 statute that amended HIPAA, supplying the penalty tiers, breach notification and business associate liability usually attributed to the 1996 law.

The FTC Health Breach Notification Rule covers health apps and connected devices that HIPAA does not. Amendments effective July 29, 2024 confirmed that unauthorised sharing with advertising partners counts as a breach even without a hack.

Washington's My Health My Data Act, effective March 31, 2024, regulates consumer health data outside HIPAA, requires separate consent, bans geofencing within 2,000 feet of an in-person care facility, and carries a private right of action.

GDPR Article 9 treats health data as a special category regardless of who holds it, the opposite architecture. Grindr priced that exposure by agreeing to pay 26 million pounds to about 12,000 UK users over HIV-related data reaching ad partners.

Recent developments

Federal preemption would redraw the map again. The SECURE Data Act, unveiled in April 2026, excludes HIPAA-covered entities and HIPAA-protected data outright while extinguishing state regimes, a structure the ANA has backed on employment grounds. Colorado carved a similar exemption into SB 26-189, while California legislators moved the other way with a proposed ban on selling sensitive data.

OCR enforcement through 2026 has concentrated on ransomware and risk analysis rather than tracking, with four settlements announced on April 23, 2026 totalling $1,165,000. The Security Rule overhaul proposed on January 6, 2025 drew more than 4,700 comments and has slipped to a July 2027 target. Whether a replacement tracking bulletin lands first remains open.

Timeline

  • August 21, 1996: HIPAA signed into law as Public Law 104-191
  • December 28, 2000: Privacy Rule published
  • February 20, 2003: Security Rule published; compliance follows April 20, 2005
  • April 14, 2003: Privacy Rule compliance date
  • February 2006: Enforcement Rule issued
  • February 17, 2009: HITECH Act signed, creating tiered penalties and business associate liability
  • August 24, 2009: Interim final Breach Notification Rule issued
  • January 25, 2013: Omnibus Final Rule published; effective March 26, 2013; compliance September 23, 2013
  • April 2019: HHS notice of enforcement discretion lowers annual caps for three penalty tiers
  • June 16, 2022: The Markup reports the Meta Pixel on 33 of Newsweek's top 100 US hospital websites
  • December 1, 2022: OCR publishes its online tracking technologies bulletin
  • February 1, 2023: FTC brings its first Health Breach Notification Rule action, against GoodRx
  • July 20, 2023: OCR and FTC send a joint warning letter to roughly 130 health organisations
  • November 2023: American Hospital Association and co-plaintiffs sue HHS
  • March 18, 2024: OCR issues a revised tracking bulletin
  • June 20, 2024: Northern District of Texas vacates the IP-plus-page-visit theory in AHA v. Becerra
  • July 10, 2024: Advocate Aurora Health pixel settlement receives final approval
  • July 29, 2024: Amended FTC Health Breach Notification Rule takes effect
  • January 6, 2025: Security Rule overhaul proposed
  • June 18, 2025: Purl v. HHS vacates most of the 2024 reproductive health privacy rule
  • September 10, 2025: Fifth Circuit dismisses the Purl appeal
  • January 28, 2026: Inflation-adjusted civil monetary penalties published
  • July 2027: Current target date for final action on the Security Rule overhaul

Summary

Who: HHS and its Office for Civil Rights enforce the law against covered entities, meaning health plans, clearinghouses and most providers, plus the business associates that process protected health information for them. Advertising platforms, analytics vendors and consumer health apps sit outside unless a business associate agreement pulls them in.

What: A federal statute and its implementing Privacy, Security, Breach Notification and Enforcement Rules, which require written authorisation before protected health information is used for marketing or sold, mandate safeguards for electronic records, and impose breach notice within 60 days. Civil penalties published for 2026 range from $145 to $2,190,294 per violation.

When: Enacted August 21, 1996. The Privacy Rule became enforceable April 14, 2003, the Security Rule April 20, 2005, and the Omnibus Rule September 23, 2013. The online tracking bulletin issued December 1, 2022 and was partly vacated June 20, 2024.

Where: The United States, binding regulated entities regardless of where a website visitor is located. Other jurisdictions regulate health data through different instruments, notably Article 9 of the GDPR in Europe.

Why: Congress wanted electronic health transactions standardised without stripping patients of control over the records those transactions create. The advertising consequence was unintended: a rule set drafted in 2000 now determines which behavioural signals may lawfully leave a health organisation, and a court ruling in 2024 moved that line back toward the login screen.