Compliance

How we handle compliance.

Most agencies say they are HIPAA compliant. Very few will tell you what that means in practice. This page does.

What a Business Associate Agreement actually is

A Business Associate Agreement, usually called a BAA, is a contract required by federal law. Under HIPAA, a healthcare provider is a covered entity. Any vendor that creates, receives, maintains, or transmits protected health information on that provider's behalf is a business associate, and the two parties must have a signed BAA in place before the vendor touches that information.

Protected health information, or PHI, is broader than most practice owners expect. It is not only diagnoses and chart notes. A name paired with an appointment request is PHI. An email address submitted through a contact form asking about a procedure is PHI. A phone number captured by call tracking on a page about a specific condition is PHI. This is why marketing is a compliance question and not just a growth question.

A marketing agency that runs your website forms, your call tracking, or your analytics is handling PHI whether it intends to or not. If that agency has not signed a BAA with you, the arrangement does not meet the requirement.

When we sign, and what we sign

We sign a Business Associate Agreement with every healthcare client before we are given access to any system that could carry patient information. Not after the first invoice, and not when someone remembers to ask. Before access.

We work from a standard agreement, and we are equally willing to sign the agreement your own counsel prefers. Practices with an existing compliance program usually have a template they use with every vendor, and using theirs is often simpler for everyone.

What the agreement covers in our work

The systems below are the ones where marketing work can touch patient information. Each is covered by the agreement and configured with that in mind.

  • Website forms. Contact forms, appointment requests, and consultation requests. Submissions route to systems covered by the agreement.
  • Call tracking. Where used, call tracking is configured so that call data is handled under the agreement rather than passed to platforms that will not sign one.
  • Analytics. Configured so that identifiers and page paths that could reveal a health condition are not sent to platforms that will not sign a BAA. This includes stripping personal identifiers from URLs before they reach any analytics system.
  • Advertising platforms. No health condition targeting, no patient lists uploaded as audiences, and conversion tracking configured server side rather than through client side pixels that carry more than they should.
  • Access to practice systems. Where we are given access to a practice management system, a CRM, or a patient communication tool, that access is covered by the agreement and limited to what the work requires.

Who is responsible

Ben Mansouri, our founder, is the agency's designated HIPAA Officer. That is a named role with an owner, not a shared responsibility that belongs to nobody. He personally reviews the compliance setup on every client engagement: how forms are routed, how analytics are configured, what the advertising platforms are allowed to receive, and who has access to what.

If something in your setup is not compliant, the person who has to fix it is the person who signed off on it. That is deliberate.

Subcontractors

Work on client systems is done by our own team. Where a subcontractor would need access to any system covered by your agreement, they sign a business associate agreement with us before that access is granted, and you are told who they are.

What we do not do

Some of the clearest compliance commitments are the negative ones.

  • We do not upload patient lists to advertising platforms.
  • We do not use health conditions as ad targeting criteria.
  • We do not publish patient photographs, reviews, or stories without written authorization from that patient.
  • We do not send patient information through email or messaging tools that are not covered by an agreement.
  • We do not respond to online reviews in a way that confirms a person is a patient of the practice, which is itself a disclosure.

What to ask any agency before you sign

Whether or not you work with us, these are the questions worth asking. An agency that handles healthcare marketing properly will have quick answers. An agency that does not will change the subject.

  1. Will you sign a Business Associate Agreement, and at what point in the engagement?
  2. Which of my systems will you have access to, and what patient information passes through each one?
  3. Who at your agency is responsible for compliance, by name and role?
  4. How is my analytics configured so that page paths and identifiers do not expose a patient's condition?
  5. How is conversion tracking set up on my ads, and what does the ad platform receive?
  6. Do any subcontractors touch my systems, and have they signed agreements with you?
  7. What happens to my data, accounts, and access if we stop working together?

That last one matters more than practices expect. With us, you own your website, your ad accounts, your analytics, and your Google Business Profile. If you leave, you keep all of it.

This is not legal advice

We are a marketing agency, not a law firm. This page describes how we work and what our agreements cover. It is not a legal opinion about your practice's obligations, and your compliance program should be reviewed by counsel who knows your specific situation. California practices have additional obligations under the Confidentiality of Medical Information Act that go beyond federal HIPAA requirements.

Questions about how this would work for your practice?

Start With a Free Practice Growth Audit