Healthcare marketing
HIPAA compliance
How we protect patient information when we market medical, dental and wellness practices, including California-specific medical privacy rules.
Effective September 28, 2026
Our role under HIPAA
RPM National is a marketing agency, not a healthcare provider or health plan. The Health Insurance Portability and Accountability Act (HIPAA) applies to "covered entities" (such as medical, dental, chiropractic and behavioral health practices) and to "business associates" that create, receive, maintain or transmit protected health information (PHI) on their behalf.
When a healthcare client needs us to handle PHI, for example patient reviews, appointment-request leads or campaign data tied to patients, we act as a business associate. We sign a Business Associate Agreement (BAA) before we access any PHI, and we follow the HIPAA Privacy, Security and Breach Notification Rules that apply to business associates.
Most of our marketing work does not require PHI at all. Whenever possible, we design campaigns so PHI never leaves your systems.
A note for website visitors
Please do not submit health, medical or insurance information through rpmnational.com, including our contact forms, free audit tool or website assistant. Our own website is not designed to receive PHI, and information you send here is handled under our Privacy Policy.
If you are a patient of one of our clients, contact that provider directly about your health information.
HIPAA-aware tracking and advertising
The U.S. Department of Health and Human Services (HHS) has warned that pixels, cookies and analytics tools on healthcare websites can disclose PHI to third parties. For healthcare clients, we:
- Audit existing sites for tracking technologies that could send PHI to ad or analytics platforms.
- Keep third-party pixels and session-recording tools off patient portals, appointment and intake forms, symptom checkers, and pages about specific conditions or treatments, unless a vendor signs a BAA.
- Use server-side or HIPAA-eligible analytics and conversion tracking that strip identifiers before data reaches ad platforms.
- Never upload patient lists or PHI to ad platforms for targeting or retargeting without a valid written authorization from each patient.
- Write ads and landing pages that do not imply a viewer has a specific health condition, in line with Google, Meta and Microsoft healthcare advertising policies.
How we safeguard PHI
When we handle PHI under a BAA, we apply administrative, physical and technical safeguards, including:
- Minimum necessary — we request and use only the PHI needed for the specific task.
- Access controls — role-based access, unique logins and multi-factor authentication for anyone who touches client data.
- Encryption — PHI is encrypted in transit and at rest.
- Vetted subcontractors — we only use vendors that sign a BAA with us before handling PHI.
- Workforce training — team members with access to PHI complete HIPAA privacy and security training when they join and every year after.
- Risk assessment — we review our security practices at least once a year and after significant changes.
- Return or destruction — when an engagement ends, we return or securely destroy PHI as the BAA requires.
Breach notification
If we discover a breach of unsecured PHI, we notify the affected covered entity without unreasonable delay and no later than 60 calendar days after discovery, or sooner if the BAA requires it. We provide the details the covered entity needs to meet its own notification duties to patients, HHS and, where required, the media.
California medical privacy (CMIA)
California's Confidentiality of Medical Information Act (Cal. Civ. Code § 56 et seq.) is in some ways stricter than HIPAA. For California healthcare clients, we also:
- Do not use or disclose medical information for marketing without a valid written authorization that meets CMIA requirements.
- Treat information from digital health tools and apps, including reproductive and sexual health services, as medical information protected by the CMIA.
- Follow California rules that restrict sharing information about reproductive health care, gender-affirming care and related services with out-of-state parties.
- Report unauthorized access to medical information to clients promptly, so they can meet California deadlines for notifying patients and the California Department of Public Health.
Medical information governed by HIPAA or the CMIA is generally exempt from the California Consumer Privacy Act. How we handle other personal information is described in our California privacy rights section.
Request a BAA
Healthcare practices can request our Business Associate Agreement, or send us their own for review, before an engagement starts. Questions about HIPAA or a possible privacy incident can go to:
RPM National — HIPAA Privacy & Security9988 Niblick Dr #6, Roseville, CA 95678info@rpmnational.com(877) 929-8331