A behavioral health practice can run paid ads, but compliance depends less on the ads than on the data that flows from the website and CRM back to ad platforms. Keyword-targeted search ads are generally workable. Remarketing to past visitors, uploading client lists, and sending identifiable health information to ad platforms are where risk concentrates.
Where does HIPAA risk show up in paid advertising for behavioral health?
HIPAA risk in paid advertising shows up mainly in tracking technology, meaning the pixels, tags, and scripts on a practice’s website that send information about visitors back to ad platforms and analytics vendors. The ad itself is rarely the problem.
The U.S. Department of Health and Human Services addresses this in its guidance on online tracking technologies. HHS states that individually identifiable health information collected on a regulated entity’s website generally counts as protected health information, even when the person has no existing relationship with the practice.
On June 20, 2024, a federal court vacated part of that guidance, specifically the portion treating an IP address combined with a visit to certain unauthenticated public web pages as enough to trigger HIPAA. The rest of the guidance remains posted, and the ruling left open exactly when tracking on public pages triggers HIPAA obligations. Pages where someone schedules an appointment or describes their situation remain the areas of greatest concern.
What do Google’s policies restrict for mental health advertising?
Google’s policies restrict how mental health advertisers can target people, independent of HIPAA. Its health in personalized advertising policy lists counseling services for mental health issues, including depression, anxiety, and addiction, among the health categories it covers.
For those ads, Google does not allow advertiser-curated audiences, including Customer Match, the advertiser’s own data segments, audience expansion, and lookalike segments, because those lists may contain sensitive signals. Predefined Google audiences, such as in-market and affinity segments, remain available because Google excludes sensitive signals from them.
Addiction treatment has an added requirement. LegitScript states that its addiction treatment certification is required to run addiction treatment ads on platforms including Google, Meta, Microsoft Advertising, and Nextdoor, in the United States and Canada. A treatment center without that certification generally cannot run those ads at all, regardless of how its tracking is configured.
What does a compliant paid advertising setup include?
A compliant paid advertising setup sends ad platforms only the minimum information needed for measurement, keeps protected health information inside systems approved to hold it, and is reviewed by the practice’s compliance or legal team before launch.
In practice, that usually means auditing every tag and script on the website, removing tracking from pages where people schedule or describe their needs, and using generic conversion event names. Vendors that receive protected health information need a business associate agreement, covered in Beacon’s page on what a business associate agreement is and when a practice needs one.
Hashing contact details before upload does not resolve the question on its own. [STEPHANIE LAST NAME, TITLE] at Beacon Media + Marketing explains the reason in one line: “The fact that something is hashed doesn’t erase the context around it.” Her article on how to send lead quality back to your ad platforms covers what can and cannot leave a practice’s CRM.
What this page does not cover
This page is not legal advice and does not determine whether any specific practice, website, or advertising setup complies with HIPAA. That determination depends on the practice’s systems, vendors, and agreements, and belongs to its compliance or legal counsel.
It does not cover state privacy and consumer health data laws in detail. Several states regulate health-related data more broadly than HIPAA, and some of those laws apply to organizations HIPAA does not reach. It also does not cover the Federal Trade Commission’s rules for health apps and companies outside HIPAA.
It does not review specific platforms, tag managers, or deidentification vendors, and it does not address Meta, Microsoft Advertising, or other ad platforms’ policies in detail. Each platform maintains its own health advertising rules, and those rules change often enough that the platform’s current policy pages should be checked directly before any campaign launches.
Frequently asked questions
Can a therapy practice use Google remarketing? Google’s health in personalized advertising policy does not allow advertiser-curated audiences, such as remarketing lists built from site visitors or Customer Match uploads, for ads about mental health counseling. Therapy practices can still run keyword-targeted search ads and can use Google’s predefined audiences, which exclude sensitive signals.
Is hashing client data enough to make ad uploads HIPAA compliant? Hashing alone does not make an upload compliant. Hashing changes how an email address or phone number looks, but the context it is paired with, such as an event showing someone sought behavioral health care, can still make it protected health information. Google’s customer data policies also restrict health-related conversions in enhanced conversions.
Can addiction treatment centers advertise on Google? Addiction treatment centers can advertise on Google once they hold LegitScript addiction treatment certification, which LegitScript states is required for addiction treatment ads on Google, Meta, Microsoft Advertising, and Nextdoor in the United States and Canada. Without certification, those ads are generally not permitted to run.
This page is general information about advertising and privacy practices and is not legal or compliance advice. Practices should consult qualified legal counsel about their specific obligations.