Coast Studio
Book a Consultation
  • Methodology
  • Growth LabsEcommerce & DTC Scale Regulated MarketsHealth, Fintech & Legal
  • Creative
  • Case Studies
  • Blog
  • About
  • Methodology
  • Growth Labs
  • Regulated Markets
  • Creative
  • Case Studies
  • Blog
  • About
  • Book Consultation →
Home / Blog / Patient Email & SMS Under HIPAA

HIPAA Tracking · Playbook

How to Do Email and SMS Marketing to Patients Under HIPAA

Last updated: August 10, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice — review your setup with healthcare counsel. Full legal landscape: The State of HIPAA Tracking.

You can email and text patients — on a platform that signs a BAA, with real authorization, and with message content that respects what a patient list is. A patient email list is PHI: the roster itself reveals who is your patient. That single fact governs the whole program.

The platform question comes first

Most popular email and SMS tools do not sign BAAs. Klaviyo does not, which is why telehealth and DTC health brands running on it face a real problem. Before content or strategy, answer: does the platform hold my patient list under a signed BAA? If not, no PHI — including the list — belongs in it. See which tools sign BAAs.

The split-stack pattern

The pattern that works separates two audiences:

  • Patients — managed in a BAA-covered platform (or your BAA-covered EHR/CRM), with authorization for marketing uses on file. Treatment and appointment content lives here.
  • Prospects and general subscribers — people who opted in before any care relationship. General brand and educational content can run on a standard marketing tool, because no one on that list is identified as a patient.

Keeping the two lists in the right systems is most of compliance. The failure mode is one blended list in a non-BAA tool.

Authorization and content

Marketing uses of PHI generally require the patient's authorization — distinct from consent to treat. And the message body itself must not expose more than necessary: avoid naming a diagnosis or treatment in a subject line or preview text a family member could see. "Your upcoming appointment" beats "Your therapy session reminder."

Tracking inside email and SMS

Open and click tracking can turn a newsletter into a health signal — a click on "managing your diabetes" tied to an identified patient is PHI. Keep engagement tracking inside the BAA-covered platform, and never pipe patient-level email engagement into an ad platform.

FAQ

Can we use Klaviyo or Mailchimp for patients? Not for PHI — they do not sign BAAs. Use a BAA-covered platform for the patient list; a standard tool is fine for pre-care prospects only.

Do appointment reminders need authorization? Treatment and operations messages like reminders sit differently from marketing. Marketing uses generally need authorization; confirm the boundary with counsel.

Can we retarget our email list on Meta? Uploading a patient list to Meta discloses PHI. Only a pre-care, ad-consented prospect list is eligible — never the patient roster.

Related

  • The State of HIPAA-Compliant Marketing Tracking
  • Is Klaviyo HIPAA Compliant?
  • Do I Need a BAA for My Analytics and Ad Tools?
  • Is HubSpot HIPAA Compliant?
JG

Jason Garrett

Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.

Connect on LinkedIn →

Compliant lifecycle marketing

Coast Studio designs HIPAA-compliant email and SMS programs for health brands — the split-stack, the BAA-covered platform, and content that respects what a patient list is.

Book a Consultation
Coast Studio

© 2026 Left Coast Agency, LLC.

AboutJason GarrettBlogPrivacyTermsContact
Google Partner