HIPAA dental marketing is the set of rules that decides when a practice's promotional messages can touch patient information, and the short version is that HIPAA regulates the patient data inside your marketing, not the marketing itself.
The dental advertising regulations guide covers the FTC, ADA, and state-board layers that apply to every ad a practice runs, and this page stays on the privacy layer, where mistakes tend to be permanent.
What HIPAA means by marketing
Under HIPAA, marketing is a message about a product or service that encourages the person receiving it to buy or use it, and the definition in 45 CFR 164.501 carves out most of what practices already send.
Messages about your own health-related services are excluded, and so are treatment communications, including recommending alternative treatments or providers, and case management or care coordination messages.
That is why a recall email or a new-service announcement from your practice to its own patients is generally not marketing under HIPAA at all.
Every exclusion carries one condition: it disappears if the practice receives financial remuneration from the third party whose product or service the message describes, so a sponsored campaign is measured by the marketing rules even when the content sounds routine.
Generally not HIPAA marketing
-
A recall message from your practice to its own patients
-
An announcement about a service your own practice offers
-
Treatment and care-coordination messages, including recommending alternatives
Marketing under HIPAA
-
A message encouraging someone to buy or use a product or service
-
A message about a product or service that its provider paid the practice to send
-
A patient photo or story used to promote the practice
One caution belongs next to every exclusion in that table: clearing HIPAA does not clear the message, because TCPA and CAN-SPAM run on separate tracks covered below.
When marketing needs written authorization
When a communication is marketing under HIPAA and uses protected health information, 45 CFR 164.508(a)(3) requires the patient's written authorization before the use or disclosure.
The two exceptions are narrow: face-to-face communication, and a promotional gift of nominal value.
If a third party pays for the marketing, the authorization has to say so.
The application most practices actually meet is photos and testimonials: putting an identifiable patient's photo or story into a public ad uses protected health information to promote the practice, so the standard practice is a signed HIPAA-compliant authorization before anything publishes.
That reading follows from the marketing provision rather than from an HHS quotation, and it stacks on state rules that separately require written consent for patient photos and testimonials, such as Texas and New York.
HIPAA for dental social media
Social media is where HIPAA and marketing collide most often, because the channel makes it effortless to turn a patient moment into content.
The rule is the same as elsewhere: a post about an identifiable patient, even one who praised your practice in the comments, uses protected health information to promote the practice, and it needs written authorization before it goes up.
Staff features, office updates, and education can be published freely, because none discloses a patient's information.
Review replies deserve their own warning, because HHS's Office for Civil Rights has settled with dental practices that disclosed patient information in review replies: $10,000 in 2019 and $23,000 in 2022, both with corrective action plans.
OCR has called the disclosure of patient information in review responses illegal under HIPAA, and the safe pattern is to reply generically without confirming the person is a patient.
The full reply process, including templates and when to report instead of reply, is in the guide to responding to negative dental reviews.
The laws that ride along with HIPAA
Under FCC rules, calls or texts that carry advertising and use an autodialer or a prerecorded voice need the recipient's prior express written consent, and the practical move is to collect that written consent for any promotional message rather than argue about whether your texting platform counts as an autodialer.
Appointment and exam reminders can qualify for a healthcare exemption, but only if every condition holds: the message is free to the patient and not counted against their plan limits, goes only to the number the patient provided, names the provider, contains no marketing or billing content, stays within 160 characters, runs no more than one message a day and three a week, and offers an immediate STOP opt-out.
Attaching a promotion to a reminder takes the message out of the exemption, so a whitening offer bolted onto a recall text needs its own consent.
Email runs on CAN-SPAM, which requires accurate headers, non-deceptive subject lines, identifying the message as an ad, a valid physical postal address, and a working opt-out honored within 10 business days, and each violating email can cost up to $53,088 as of September 2026, according to the FTC's compliance guide.
Website tracking is the last ride-along: HHS's bulletin says HIPAA applies when a pixel or analytics tool collects protected health information, such as an email address typed into an appointment form, and a June 2024 court order vacated only the IP-address-plus-public-page slice of that guidance, with the rest still standing and HHS still evaluating its next steps as of September 2026.
That question has its own guide: HIPAA dental website tracking.
What HIPAA-compliant dental marketing looks like
None of this forbids growing the practice, and a compliant setup mostly means sequencing the paperwork before the promotion.
-
Sort every campaign before it ships: is it a message from your practice about your own services, or does it use patient information or carry third-party money?
-
Get a signed HIPAA-compliant authorization before any patient photo, story, or testimonial appears in an ad, post, or email.
-
Reply to every review with a generic template that never confirms the reviewer is a patient.
-
Keep promotions out of appointment reminders, or collect prior express written consent before sending them anyway.
-
List every tracking script on your site and confirm what it collects from form pages before judging the marketing on top of it.
-
Confirm each campaign against your state board's advertising rule too, because HIPAA clearance is not board clearance.
-
Take anything that touches PHI in a public channel to a healthcare attorney first.
This page describes rules as they appear in the regulations, guidance, and settlements cited, it is not legal advice, and your healthcare attorney should confirm how they apply to your practice.
The payoff is practical: once the data handling is clean, the testing and optimization work covered in dental website conversion can proceed without a compliance asterisk on every result.
Frequently asked questions
Does HIPAA allow marketing?
Yes, and its definition of the word is narrow: a message from your practice about your own health-related services, and treatment messages, are generally not marketing under HIPAA at all unless the third party whose product or service the message describes paid you to send them. Marketing that does use protected health information needs the patient's written authorization.
Does HIPAA apply to dental practices?
Yes. HHS's Office for Civil Rights has enforced HIPAA directly against dental practices, including settlements over patient details disclosed in review replies, so a practice is measured by the same privacy rules as any covered entity.
Is a recall email to my own patients marketing under HIPAA?
Generally no: a message from a practice about its own health-related services falls outside HIPAA's definition of marketing unless the third party whose product or service the message describes paid for it. TCPA and CAN-SPAM still apply to the same message, so the HIPAA exclusion is not a blank check.
Can my office attach a whitening promotion to appointment reminder texts?
Not under the federal healthcare exemption for reminder messages, which applies only when the message contains no marketing content. Under FCC rules, promotional texts sent with an autodialer need prior express written consent, and the practical move is to collect that consent for any promotional text.
What are the new HIPAA rules for dental offices in 2026?
The rules this page covers carried the wording described here in the sources cited: the marketing definition in 45 CFR 164.501 and the written-authorization rule in 164.508 read as described on this page in the eCFR text current as of September 2026, and on tracking, the HHS bulletin was revised in March 2024, a June 2024 court order vacated one part of it, and as of September 2026 the bulletin still noted that HHS was evaluating its next steps. For anything beyond the provisions this page cites, ask a healthcare attorney what has changed.