Most agencies say they are HIPAA compliant. Very few will tell you what that means in practice. This page does.
A Business Associate Agreement, usually called a BAA, is a contract required by federal law. Under HIPAA, a healthcare provider is a covered entity. Any vendor that creates, receives, maintains, or transmits protected health information on that provider's behalf is a business associate, and the two parties must have a signed BAA in place before the vendor touches that information.
Protected health information, or PHI, is broader than most practice owners expect. It is not only diagnoses and chart notes. A name paired with an appointment request is PHI. An email address submitted through a contact form asking about a procedure is PHI. A phone number captured by call tracking on a page about a specific condition is PHI. This is why marketing is a compliance question and not just a growth question.
A marketing agency that runs your website forms, your call tracking, or your analytics is handling PHI whether it intends to or not. If that agency has not signed a BAA with you, the arrangement does not meet the requirement.
We sign a Business Associate Agreement with every healthcare client before we are given access to any system that could carry patient information. Not after the first invoice, and not when someone remembers to ask. Before access.
We work from a standard agreement, and we are equally willing to sign the agreement your own counsel prefers. Practices with an existing compliance program usually have a template they use with every vendor, and using theirs is often simpler for everyone.
The systems below are the ones where marketing work can touch patient information. Each is covered by the agreement and configured with that in mind.
Ben Mansouri, our founder, is the agency's designated HIPAA Officer. That is a named role with an owner, not a shared responsibility that belongs to nobody. He personally reviews the compliance setup on every client engagement: how forms are routed, how analytics are configured, what the advertising platforms are allowed to receive, and who has access to what.
If something in your setup is not compliant, the person who has to fix it is the person who signed off on it. That is deliberate.
Work on client systems is done by our own team. Where a subcontractor would need access to any system covered by your agreement, they sign a business associate agreement with us before that access is granted, and you are told who they are.
Some of the clearest compliance commitments are the negative ones.
Whether or not you work with us, these are the questions worth asking. An agency that handles healthcare marketing properly will have quick answers. An agency that does not will change the subject.
That last one matters more than practices expect. With us, you own your website, your ad accounts, your analytics, and your Google Business Profile. If you leave, you keep all of it.
We are a marketing agency, not a law firm. This page describes how we work and what our agreements cover. It is not a legal opinion about your practice's obligations, and your compliance program should be reviewed by counsel who knows your specific situation. California practices have additional obligations under the Confidentiality of Medical Information Act that go beyond federal HIPAA requirements.
Questions about how this would work for your practice?
Start With a Free Practice Growth AuditWritten and audited by Ben Mansouri, Founder of Zevi Digital and designated HIPAA Officer. Reviewed August 2026.