Hiring a Compliant Healthcare PPC Agency: Key Steps

Table of Contents
Ready to See Results?

From strategy to execution, we turn underperforming campaigns into measurable wins. Let’s put our expertise to work for your business.

Key Takeaways

  • Treat the PPC agency as a business associate inside the compliance perimeter, requiring a BAA that enumerates every data flow, subprocessor, and breach notification timeline 11.
  • Audit tracking and remarketing configurations against the OCR bulletin, routing identifiers through server-side endpoints and suppressing pixels on intake or verification pages 7.
  • Confirm the agency maps which workflows touch SUD patient-identifying information and ensures consent metadata travels with any disclosure under 42 CFR Part 2 5.
  • Require a per-claim substantiation file tying every clinical, outcome, or comparative assertion to controlled evidence, since FTC liability extends to the agency placing the ad 6.
  • Document call infrastructure end to end and reject aggregator leads that cannot produce consent records and BAA coverage, since recordings carry PHI and Part 2 protections 12.

The agency sits inside the compliance perimeter, not outside it

Treatment center operators tend to evaluate paid search partners on creative, reporting cadence, and cost per lead. That framing understates the actual risk. A healthcare PPC agency that runs call tracking, syncs admissions data to a CRM, uploads customer match lists, or fires server-side conversion events is, by function, handling protected health information on behalf of a covered entity. Under HHS guidance, that activity makes the agency a business associate, which means a Business Associate Agreement is required before campaigns touch any data flow connected to patient identity 11.

Onboarding the agency as a vendor is the wrong mental model. The agency belongs inside the compliance perimeter alongside the EHR, the answering service, and the admissions CRM. Its pixel configuration, consent flows, and ad copy are subject to the same federal scrutiny that applies to the facility itself, including HIPAA marketing rules 9, the OCR online tracking bulletin 7, 42 CFR Part 2 for SUD records 5, and FTC substantiation standards for clinical claims 1.

What follows reframes agency selection around five regulator-sourced checkpoints. Each maps a specific federal rule to the specific PPC artifact it governs, with the disqualifying answers an operator should listen for during diligence.

Five regulator-sourced checkpoints for evaluating a paid search partner

Checkpoint 1: BAA scope that actually covers the data the agency touches

HHS guidance defines a business associate as any entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity, including for data analysis or administration 11. A paid search agency rarely admits to handling PHI in pitch decks, yet the data flows it operates almost always qualify once they touch a treatment center’s identifiable patient context.

The artifacts that pull an agency inside the BAA requirement are concrete. Call tracking platforms that record inbound admissions calls capture voice content and caller phone numbers tied to a center advertising SUD treatment. Webhooks that sync form submissions from a landing page to the admissions CRM carry name, contact data, and the implicit fact that the individual is inquiring about clinical care. Customer match list uploads to Google Ads or Meta push hashed identifiers paired with the center’s audience context, which OCR has treated as PHI-equivalent in many configurations. Server-side conversion APIs forward event data tied to user identifiers from a healthcare property. Pixels firing on intake or insurance verification pages collect identifiers combined with health context 11.

A defensible BAA enumerates each of these data flows, names the subprocessors involved (call tracking vendor, tag manager, CRM, ad platform), and assigns breach notification timelines that align with the operator’s own obligations. An agency that offers a one-page template BAA referencing only “marketing services” has not done the work.

Checkpoint 2: Tracking and remarketing configuration after the OCR bulletin

Conversion tracking is where most agencies fail diligence. OCR’s bulletin on online tracking technologies states that HIPAA rules apply when these tools collect information that
“relates to an individual’s past, present, or future health, healthcare, or payment for healthcare,”
including when combined with an IP address or device identifier 7. The bulletin further warns that regulated entities
“are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors or any other violations of the HIPAA Rules”
7.

In June 2024, a federal district court vacated a portion of the guidance, but OCR has continued to emphasize Security Rule compliance and enforcement around tracking technologies 7. Operators should not read the partial vacatur as a signal that the analytics stack is now unregulated. The Security Rule obligations on confidentiality, integrity, and availability of electronic PHI did not move.

The practical implication is that standard ad-tech contracts from Google, Meta, and TikTok do not contain business associate terms covering PHI transmission, and OCR has noted that such contracts often fail to meet business associate requirements 7. A compliant configuration:

  • moves identifiable conversion data through a server-side endpoint the operator controls,
  • strips or hashes identifiers before any platform call,
  • suppresses pixel firing on URLs that imply diagnosis or service line, and
  • uses modeled conversions or aggregated reporting where direct identifiers would otherwise flow to the platform.

A compliant agency answer describes specifically how its Google Tag Manager containers, server-side GTM endpoints, Meta Conversions API setup, and call tracking integrations handle identifiers on pages tied to clinical context. It can name which URLs trigger which events, which fields are hashed, and where the data terminates.

A disqualifying answer treats the issue as solved by “using a HIPAA-compliant CRM” or by signing a BAA with the call tracking vendor while leaving client-side pixels firing freely on intake pages. The pixel does not become compliant because the downstream CRM is. The PHI exposure occurs at the moment the identifier and the health context leave the operator’s domain together 7.

Checkpoint 3: 42 CFR Part 2 consent handling for SUD intake data

For addiction treatment operators, Part 2 sits on top of HIPAA and tightens what is permissible. The statute and rule, codified at 42 U.S.C. 290dd-2 and 42 CFR Part 2, protect the confidentiality of patient records for people receiving services for substance use disorders, and Part 2 generally prohibits disclosing SUD patient-identifying information without written consent 10.

The 2024 final rule updating Part 2 aligns several provisions with HIPAA. It permits a single patient consent for future uses and disclosures for treatment, payment, and healthcare operations, strengthens breach notification, and exposes Part 2 violations to HIPAA-like civil and criminal penalties 5. The fact sheet also notes that
“each disclosure made with patient consent must include a copy of the consent or a clear explanation of the scope of the consent”
5.

For a PPC partner, the operational consequence is that any data flow carrying SUD patient-identifying information, including call recordings of intake conversations, transcripts, CRM records, and any audience list built from prior admissions, sits inside Part 2’s scope. A consent that authorizes operations communications under HIPAA does not automatically authorize what Part 2 treats as further disclosure, and any disclosure made with consent must travel with the consent document or its scope description 5.

A compliant agency answer identifies which of its workflows touch Part 2-protected information, confirms that call recording vendors and CRMs are configured to support Part 2 consent metadata, and demonstrates how remarketing audiences are built without using SUD treatment status as a targeting criterion or seed.

A disqualifying answer treats Part 2 as a clinical concern that does not apply to marketing. The rule is record-based, not department-based. If the agency’s systems hold information that identifies someone as a current or former SUD patient, Part 2 governs it 10.

Checkpoint 4: Substantiation behind every clinical and outcome claim

FTC’s 2022 Health Products Compliance Guidance, which updated and replaced the 1998 Dietary Supplements guide, sets the evidentiary bar advertisers must clear before disseminating health-related claims 6. The guidance is direct:
“As a general matter, substantiation of health-related benefits will need to be in the form of randomized, controlled human clinical testing”
6. Consumer testimonials and before-and-after photos are insufficient to substantiate health benefits on their own 6.

The broader substantiation framework, articulated in the FTC’s training document, requires advertisers to substantiate all claims, express and implied, that an ad conveys to reasonable consumers before dissemination, with health benefit and safety claims requiring competent and reliable scientific evidence 1.

Treatment center ad copy and landing pages routinely contain language that triggers this standard:

  • “95% completion rate.”
  • “Industry-leading outcomes.”
  • “Proven to reduce cravings.”
  • “More effective than traditional rehab.”

Each is a health benefit or comparative effectiveness claim, and each is the kind of statement the FTC expects to be backed by controlled human clinical testing or an equivalent body of evidence specific to the program being advertised 6.

A compliant agency maintains a substantiation file for every clinical, outcome, or comparative claim it places in headlines, descriptions, sitelinks, callouts, and landing page copy. The file ties each claim to the underlying study, internal outcomes data with stated methodology, or a clinician-reviewed source. Implied claims are reviewed under the same standard, because the FTC holds advertisers responsible for all reasonable consumer interpretations, not just literal wording 1.

A disqualifying answer is “the client gave us the copy.” Liability for substantiation extends to the agency that drafted and placed the ad. If the operator cannot produce the underlying evidence on request, the claim should not be in the ad 6.

Checkpoint 5: Call handling, recording, and lead-buying ethics

Inbound calls are where paid search converts in this category, and they are also where compliance frequently breaks. A recorded admissions call captures voice data, caller phone numbers, often insurance details, and statements that establish the caller as a current or prospective SUD patient. Under HHS guidance, the vendor recording, storing, or transcribing those calls is creating and maintaining PHI on behalf of the covered entity and therefore qualifies as a business associate requiring a BAA 11. Under Part 2, the recording is also protected SUD treatment information once it identifies the caller in connection with treatment 10.

Two operational risks deserve specific attention:

  1. The first is call recording configuration: recordings should not be retained in vendor systems that lack BAA coverage, transcripts should not be piped into third-party analytics that fall outside the BAA chain, and quality-assurance scoring tools must be evaluated under the same standard.
  2. The second is third-party lead buying. Agencies that supplement direct PPC with purchased calls or form fills from aggregators introduce a chain where the operator often cannot verify the consent disclosures the lead saw, the platforms the data passed through, or whether PHI was disclosed to third parties in exchange for remuneration so they could advertise their own services, which HIPAA marketing rules prohibit without authorization 12.

A compliant agency documents its call infrastructure end to end, refuses to bolt on lead sources that cannot produce consent records and BAA coverage, and treats every recording the same way clinical records are treated. A disqualifying answer minimizes the lead source question or claims the aggregator “handles compliance on their end.”

Visualize the five sequential diligence checkpoints described in this section, each mapped to its governing federal rule, giving readers a single reference frame for the subsections that follow

When marketing crosses into territory requiring written patient authorization

HIPAA’s marketing rule draws a hard line that paid search activity routinely brushes against. OCR’s guidance states that,
“with limited exceptions, the Rule requires an individual’s written authorization before a use or disclosure of his or her protected health information can be made for marketing”
9. The definition of marketing turns on whether a communication encourages purchase or use of a product or service, which is exactly what a PPC funnel does 4.

Three PPC activities sit closest to the line:

  • Building a remarketing audience from prior patients or inquirers uses PHI to deliver a communication that encourages further service use.
  • Uploading a customer match list of past admissions to a search or social platform discloses PHI to a third party.
  • Selling or sharing inquiry data with a referral partner in exchange for placement fees triggers the prohibition on disclosing PHI to third parties for remuneration so they can advertise their own services 12.
Visualize the operations-vs-marketing decision boundary described in this section, showing which PPC activities require written patient authorization under HIPAA and which do not

A diligence matrix: compliant answers versus disqualifying ones

The five checkpoints above resolve into a single diligence exercise: ask each question, score the answer against the regulator-sourced standard, and treat any disqualifying response as a hard stop rather than a coaching opportunity.

CheckpointCompliant answer sounds likeDisqualifying answer sounds like
BAA scope 11Enumerates each data flow (call recordings, CRM webhooks, match list uploads, server-side events, intake-page pixels), names subprocessors, and sets breach notification timelines that mirror the operator’s own.“We don’t need a BAA because we never see patient charts,” or a one-page template referencing only “marketing services.”
Tracking configuration 7Describes which URLs fire which events, where identifiers are hashed or stripped, and how server-side endpoints terminate data the operator controls.“We’re covered because the CRM is HIPAA-compliant,” while client-side pixels still fire on intake and verification pages.
Part 2 consent 5Maps which workflows touch SUD patient-identifying information and shows how consent metadata travels with any disclosure.Treats Part 2 as a clinical-records issue that does not reach marketing systems.
Claim substantiation 1Maintains a per-claim substantiation file tying each headline, sitelink, and landing page assertion to controlled evidence or clinician-reviewed sources.“The client gave us the copy,” with no file behind outcome percentages or comparative claims.
Call handling and lead sourcing 12Documents the call infrastructure end to end and rejects aggregator leads that cannot produce consent records and BAA coverage.“The aggregator handles compliance on their end.”

Operators should run this matrix in a single working session with the agency’s technical lead present, not the account manager. The answers that hold up under direct questioning are the ones written into the contract.

Key Criteria for Selecting a Compliant Healthcare PPC Partner

Leverage data-driven PPC strategies designed for regulatory compliance and measurable admissions growth in behavioral health marketing.

Evaluate Your PPC Approach

Edge cases: Medicare Advantage populations and non-HIPAA-covered service lines

Operators accepting Medicare Advantage (dual-diagnosis, older adult tracks)

This subsection applies to a narrow slice of treatment operators: facilities running dual-diagnosis or older-adult tracks that bill Medicare Advantage. For everyone else, the five core checkpoints already cover the field.

CMS Medicare Marketing Guidelines layer an additional rulebook onto any PPC activity that promotes plan-affiliated services, with specific definitions separating “marketing” from “communications,” required disclaimers, and constraints on how provider names, logos, and benefit information appear in advertising 2. Some materials require CMS submission for review; others do not, and the distinction shapes how landing pages and ad extensions must be structured 2. The 2024 revisions tightened rules around third-party marketing organizations and digital practices, which directly affects how agencies handle lead generation and call routing for Medicare-eligible inquiries 2.

A compliant agency working this segment uses CMS standardized outreach and educational materials as the language baseline for call scripts, landing page disclosures, and remarketing copy targeting Medicare populations 3. A disqualifying answer is silence on CMS submission workflow or reliance on generic insurance-acceptance copy that names plans without the required disclaimers.

Wellness-adjacent or non-covered service lines and state health-data laws

This subsection narrows again, this time to operators running wellness-adjacent service lines that may fall outside HIPAA coverage: cash-pay coaching, app-based recovery support, executive wellness retreats, or alumni programs structured outside the clinical entity. HIPAA is not the ceiling for these properties.

State and municipal legislatures are filling the gap. The District of Columbia bill introduced in 2024 would require regulated entities to obtain consumers’ informed consent before collecting and sharing personal health data, and would restrict using that data for targeted advertising, explicitly reaching entities that fall outside HIPAA 8. Washington’s My Health My Data Act and Nevada’s SB 370 follow similar logic, and more jurisdictions are moving in the same direction 8.

A PPC agency operating a non-covered wellness brand under the same parent organization should still apply consent-first collection, opt-out honoring, and audience-building constraints aligned with the strictest jurisdiction the operator serves.

If you manage multiple facilities: standardizing the compliance stack across sites

This section applies to operators running two or more licensed facilities, regional brands, or alumni programs under a single parent. Compliance configuration that gets negotiated facility by facility is how exposure compounds across a portfolio.

The BAA, the consent language, the tag manager containers, the call recording retention rules, and the substantiation files should exist once at the parent level and inherit down. When each facility’s local marketer cuts a side deal with a regional vendor, the result is a patchwork: one site fires client-side Meta pixels on intake pages while another routes everything server-side, one location’s call vendor holds recordings under a BAA while another’s does not, and one landing page cites a 90% completion figure with no underlying file 7.

Three artifacts should be standardized before any new facility comes online:

  1. a master BAA the agency signs at the parent level covering every subprocessor across sites 11,
  2. a single tracking specification document that defines which URLs fire which events with what identifier handling, and
  3. a centralized substantiation library that ad copy must draw from rather than improvise against 1.

Local creative variation is fine. Local compliance variation is the risk.

What to put in the contract before campaigns go live

The diligence answers only matter if they survive contract drafting. Five clauses convert verbal commitments into enforceable obligations.

  1. First, a master BAA executed at the parent entity level, naming every subprocessor the agency uses across call tracking, tag management, CRM sync, and ad platforms, with a flow-down requirement that no new subprocessor enters the stack without written approval 11.
  2. Second, a tracking specification appendix that lists which URLs fire which events, where identifiers are hashed or stripped, and which server-side endpoints terminate the data, updated whenever the configuration changes 7.
  3. Third, a Part 2 addendum acknowledging that any workflow touching SUD patient-identifying information is governed by 42 CFR Part 2 and that consent metadata must travel with any disclosure 5.
  4. Fourth, a substantiation protocol requiring the agency to maintain per-claim files for every clinical, outcome, or comparative assertion placed in ad copy or landing pages, with the operator retaining audit rights 1.
  5. Fifth, a lead-source clause prohibiting the agency from supplementing campaigns with aggregator leads that cannot produce consent records and BAA coverage 12.

Termination rights should attach to each clause. A breach of the tracking specification is not a service issue; it is a regulatory event.

Frequently Asked Questions

Does a healthcare PPC agency need to sign a Business Associate Agreement?

Yes, in nearly every operational configuration. HHS guidance treats any entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity as a business associate, and call tracking, CRM webhooks, and audience uploads tied to patient identity meet that threshold 11. The BAA should name each subprocessor in the stack, not reference “marketing services” generically.

Can a treatment center still run remarketing and conversion tracking after the OCR online tracking bulletin?

Running them is possible; running them as configured by default is not. OCR’s bulletin holds that identifiers combined with health context constitute PHI, and standard ad-tech contracts do not satisfy business associate requirements 7. Compliant setups route conversions through server-side endpoints the operator controls, strip identifiers before platform calls, and suppress pixel firing on intake or verification pages.

How does 42 CFR Part 2 change what a PPC agency can do with SUD intake data?

Part 2 tightens HIPAA for substance use disorder records, generally prohibiting disclosure of SUD patient-identifying information without written consent 10. The 2024 final rule permits a single consent for treatment, payment, and operations, but each disclosure must travel with the consent or a clear scope description 5. Call recordings, transcripts, and audience seeds built from prior admissions all sit inside Part 2.

When does PPC activity cross from healthcare operations into marketing that requires written patient authorization?

OCR requires written authorization before PHI is used or disclosed for marketing, defined as communications that encourage purchase or use of a service 9. Remarketing lists built from prior patients, customer match uploads of past admissions, and any disclosure of PHI to third parties for remuneration so they can advertise their own services all require authorization or cannot run 12.

What level of evidence does the FTC expect behind clinical or outcome claims in treatment center ads?

The FTC’s 2022 Health Products Compliance Guidance states that substantiation of health-related benefits generally requires randomized, controlled human clinical testing, and that testimonials and before-and-after photos are insufficient on their own 6. Advertisers must hold a reasonable basis for every express and implied claim before dissemination, with health claims requiring competent and reliable scientific evidence specific to the program advertised 1.

Do CMS Medicare Marketing Guidelines apply to a treatment center’s PPC campaigns?

Only for facilities marketing services tied to Medicare Advantage or Part D plans, which typically means dual-diagnosis or older-adult tracks. CMS rules separate “marketing” from “communications,” require specific disclaimers, and constrain how provider names, logos, and benefits appear in ads 2. Agencies operating this segment should anchor copy to CMS standardized outreach and educational materials rather than improvising plan-related language 3.

References

  1. Advertising Substantiation Principles. https://www.ftc.gov/sites/default/files/attachments/training-materials/substantiation.pdf
  2. Medicare Marketing Guidelines. https://www.cms.gov/medicare/health-drug-plans/managed-care-marketing/medicare-guidelines
  3. Marketing Models, Standard Documents, and Educational Material. https://www.cms.gov/medicare/health-drug-plans/managed-care-marketing/models-standard-documents-educational-materials
  4. What Healthcare Marketing Professionals Should Know About HIPAA. https://onlinedegrees.etsu.edu/programs/business/mba/healthcare-marketing/what-to-know-about-hipaa/
  5. Fact Sheet: 42 CFR Part 2 Final Rule. https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html
  6. Health Products Compliance Guidance. https://www.ftc.gov/business-guidance/resources/health-products-compliance-guidance
  7. Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html
  8. Attorney General Schwalb Introduces Legislation to Protect Personal Health Data of District Consumers and Strengthen Privacy Laws. https://oag.dc.gov/release/attorney-general-schwalb-introduces-privacy-legislation
  9. Marketing. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/marketing/index.html
  10. Substance Use Disorders: Statutes, Regulations, and Guidelines. https://www.samhsa.gov/substance-use/treatment/statutes-regulations-guidelines
  11. Business Associates. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
  12. What are the HIPAA Marketing Rules?. https://www.hipaajournal.com/hipaa-marketing-rules/