microscope, doctor, practice, examination, medicine, equipment, instrument, medical, doctor's office, disease, health, blood count, close up, microscope, microscope, microscope, microscope, microscope, doctor. HIPAA Compliant Google Ads Medical Practices: Rules and Limits
Photo by markusspiske on Pixabay

Rules

HIPAA Compliant Google Ads Medical Practices: Rules and Limits

HIPAA compliant Google Ads medical marketing is limited by signed authorizations, business associate agreements, and state licensing board rules.

What to take away

  • HIPAA binds the medical practice running the ads, not Google.
  • Marketing that names or describes a patient needs written authorization in most cases.
  • Google's healthcare policy and state medical board rules sit on top of HIPAA.
  • Authorizations, published ad copy and privacy notices are the first records an investigator asks for.

A practice that treats search advertising as a purely commercial exercise will misread what HIPAA compliant Google Ads medical advertising demands. The duties begin with a federal privacy statute and end at a state licensing board.

Who holds jurisdiction over a medical ad account

The HIPAA Privacy Rule is enforced by the Office for Civil Rights at the Department of Health and Human Services. It governs how a covered entity uses and discloses protected health information. Under the HIPAA Privacy Rule, treatment, payment and health care operations need no written permission. Advertising is not one of those categories.

Who Enforces What

HHS Office for Civil Rights

Privacy Rule
Enforces
Security Rule
Enforces
Healthcare and medicines policy
Not applicable
Advertising claims
Not applicable
Business associate agreement
Requires

Google

Privacy Rule
Not applicable
Security Rule
Not applicable
Healthcare and medicines policy
Enforces
Advertising claims
Not applicable
Business associate agreement
Not offered

State Medical Boards

Privacy Rule
Not applicable
Security Rule
Not applicable
Healthcare and medicines policy
Not applicable
Advertising claims
Enforces
Business associate agreement
Not applicable

Google is not a business associate when it serves an ad. Google Ads is not covered by Google's business associate agreement offering, so patient information cannot go into keywords, audiences or conversion files in any form. Google's healthcare and medicines policy is a contract term, not a federal rule. State boards license the practitioner and police advertising claims.

An outside firm changes the picture. The practice needs a business associate agreement in place before any work begins, and the parts of that relationship worth attention are set out in advertising agencies.

Who holds jurisdiction

Rule or policyWho enforces itWhat it covers
HIPAA Privacy RuleHHS Office for Civil RightsUse and disclosure of patient information, including marketing
HIPAA Security RuleHHS Office for Civil RightsSafeguards for electronic patient records
Healthcare and medicines policyGoogleWhich health services may be advertised, and in what form
State medical practice actsState licensing boardsAdvertising claims, testimonials and specialty titles

What a compliant disclosure contains

A HIPAA authorization is a defined document, not a consent line on an intake form. It must describe the information used, name who may disclose it and who may receive it, and state the purpose. It carries an expiration date.

What a HIPAA Authorization Must Contain

  • Describe the information used
  • Name who may disclose it
  • Name who may receive it
  • State the purpose
  • Carry an expiration date
  • Explain written revocation rights
  • State refusal will not affect treatment

It must tell the patient that they can revoke it in writing and that refusing to sign will not affect their treatment.

The notice of privacy practices is the second disclosure. If the practice intends to use patient information for marketing, the notice has to say so, and the practice has to follow it. HHS guidance on marketing draws the line between a treatment communication and an advertisement.

A message counts as marketing when a third party pays the practice to send it, or when it promotes a service the patient is not currently receiving.

Ad copy can disclose patient information on its own. A testimonial with a recognizable name, a before and after photograph, or a review quoted in full all reveal that a person received care. None of it belongs in a campaign without a signed authorization on file.

Records the practice has to keep

  • Signed authorizations with dates, scope and expiration
  • Final ad copy and landing pages as published
  • The current notice of privacy practices with revision dates
  • A log of impermissible disclosures and the response to each
  • Correspondence with Google about restricted or rejected ads

HIPAA requires covered entities to keep documentation for six years from the date of creation or the date it was last in effect, whichever is later (45 CFR 164.530(j)). The test is retrieval under pressure. A practice that cannot produce a signed authorization has no way to reconstruct one later.

Patient data can also leave through tracking. An email list uploaded for a conversion import, or a patient identifier passed in a URL parameter, is a disclosure the practice has not accounted for. How credit is assigned across those touchpoints is a separate problem, covered in paid media attribution.

What happens when the rules are broken

When the Office for Civil Rights finds that patient information went into a marketing campaign without a valid authorization, the resolution usually includes a corrective action plan. The plan runs for a fixed term and requires monitored retraining, revised policies and periodic reports to the agency. The practice name and the terms are published.

Google acts separately. An account that breaks the healthcare policy loses its ads, and repeat violations end the account. A state board can add a fine or a license restriction. An unauthorized disclosure also starts a breach assessment, in which the practice decides whether affected patients must be notified.

Where the rules differ by state

Washington's My Health My Data Act reaches health data held by organizations outside HIPAA and requires consent before most tracking. California treats health information as sensitive personal information under the CPRA, which limits how it may be used in advertising.

State medical boards differ on testimonials, on outcome claims, and on who may call themselves board certified. A practice licensed in several states answers to each board separately, and the strictest rule tends to set the standard for the group. Paid media strategy in healthcare starts from that point rather than from campaign settings.

Common questions

Can a medical practice advertise on Google at all?
Yes. Nothing in HIPAA prohibits paid search. The statute restricts how patient information moves, and an ad can be written to disclose none of it.
Does a patient testimonial need written authorization?
Yes, if the patient can be identified. HHS marketing guidance treats that as a use of protected health information, so the authorization has to be signed first.
Does Google sign a business associate agreement for Ads?
No. Google offers agreements for some cloud and workspace products, not for Google Ads, so patient data cannot sit in campaign settings or audiences.
What about a lead form that asks about symptoms?
Once the practice receives those answers and can link them to a person, they are protected health information. The form and its storage fall inside the covered system.

More in Rules

Latest from Records Desk