HIPAA-compliant blog content is content that contains no protected health information unless the patient has signed a written authorization for that use. General health education ("what to expect after a root canal") is not regulated by HIPAA at all. HIPAA applies the moment a post, photo, video or case study includes information that could identify a patient of your practice, together with anything about their health, care or payment.
So the practical rules are short: write about conditions and treatments, never about identifiable patients; get a signed authorization before featuring a real patient; de-identify properly when you use real cases; and keep patient information out of the tools you write with, including AI tools. This guide explains each rule and where it comes from. It is not legal advice; your privacy officer or counsel should approve your process, and HHS's HIPAA for professionals pages are the primary source.
What HIPAA covers in marketing content
HIPAA's Privacy Rule applies to covered entities (health care providers who bill electronically, health plans and clearinghouses) and their business associates (vendors that handle PHI for them, which can include a marketing agency).
Information is PHI when two things are true: it relates to someone's past, present or future health, care, or payment for care, and it identifies the person or could reasonably be used to. "Mrs. Lopez's crown" is PHI. "A crown on a lower molar" is not. A blog post on "5 signs you need a root canal" contains no PHI and HIPAA has nothing to say about it.
The traps are details that seem harmless but identify someone in context:
- A first name plus a rare condition in a small town
- A photo of the waiting room with patients in it
- A screenshot of a schedule, an x-ray with a label, or a whiteboard in the background of a staff video
- A "patient of the month" post
- A thank-you reply to a review that mentions the procedure
The marketing definition and when you need an authorization
HIPAA defines marketing as a communication about a product or service that encourages recipients to purchase or use it. Some communications are carved out, for example communications about a patient's own treatment, or describing your own health-related services, as long as no third party pays you to make them.
For content, the important rule is in 45 CFR 164.508(a)(3): a covered entity must obtain an authorization for any use or disclosure of PHI for marketing, with two exceptions (face-to-face communication and promotional gifts of nominal value). If a third party pays you for the communication, the authorization must say so.
A valid authorization is written in plain language and includes:
| Element | Example wording |
|---|---|
| What information | "My name, photographs, and a description of my hip replacement and recovery" |
| Who discloses it | The practice, by its legal name |
| Who receives it | "The public, through the practice's website, social media, email and print materials" |
| Purpose | "Marketing and advertising" |
| Expiration | "Three years from the date signed" |
| Signature and date | Patient, or a personal representative with their authority described |
| Right to revoke in writing | And how to do it |
| Treatment not conditioned on signing | Required statement |
| Redisclosure warning | Once published, the information may be shared further and no longer protected by HIPAA |
HHS's marketing guidance covers the carve-outs in more detail. Our guide to patient testimonials walks through collecting stories with an authorization and the FTC rules that apply on top.
Case studies and patient stories
Real stories are the most persuasive content a practice has. You have three ways to use them.
Option 1: authorization
The patient signs an authorization covering the specific story, photos and channels. They review the final version. This is the only option for stories that name or show the patient.
Option 2: de-identification
HIPAA does not apply to properly de-identified information. 45 CFR 164.514 recognizes two methods, explained in HHS's de-identification guidance:
- Safe Harbor: remove all 18 listed identifiers (names, geographic units smaller than a state with limited exceptions, all elements of dates except year, phone numbers, email addresses, record numbers, full-face photos and others), and have no actual knowledge that what remains could identify the person.
- Expert Determination: a qualified expert applies statistical or scientific methods and documents that the risk of re-identification is very small.
The "actual knowledge" condition is where marketing content fails. A case study about "a 34-year-old triathlete who tore her ACL during the city's spring race" has no names, but in a small community everyone knows who it is.
Option 3: composite or illustrative cases
Write a scenario that combines common features of many patients, and say so: "This example is a composite and does not describe a specific patient." Do not present a composite as a real person, which creates an FTC deception problem.
Photos and video
Photos are where most accidental disclosures happen, because the identifying detail is in the background.
| Content | Risk | What to do |
|---|---|---|
| Patient before and after photos | Full-face images are an identifier; tattoos and jewelry can identify too | Authorization naming photos and channels |
| Office and team photos | Patients in the background, screens, schedules | Shoot before opening hours; check every frame |
| Staff day-in-the-life videos | Monitors, whiteboards, voices in hallways | Script locations; review before posting |
| X-rays and scans | Labels with names, dates or record numbers | Crop or remove all labels, or use stock imagery |
| Event and community photos | Patients recognizable at a health fair | Get a photo release; do not caption anyone as a patient |
AI writing tools and PHI
AI tools are useful for drafting general education content. The risk is what you paste into them.
If staff paste a patient's chart note into a consumer chatbot to "turn this into a case study," the practice has disclosed PHI to a vendor. HHS's guidance on cloud computing explains that a service provider that creates, receives, maintains or transmits PHI on your behalf is a business associate, which requires a business associate agreement (BAA). Before anyone uses a tool with PHI, check whether its provider signs a BAA for the plan you are on.
A workable policy for content teams:
- No PHI in AI prompts unless the tool is approved by your privacy officer and covered by a BAA.
- De-identify before drafting. Remove all identifiers yourself before any tool sees a case.
- Clinical review of every AI draft. AI tools state errors confidently; a clinician signs off on medical accuracy.
- No invented patients. Do not let a tool generate testimonials or patient quotes. The FTC's 2024 rule on fake reviews and testimonials bans AI-generated testimonials presented as real.
- Log which tool produced what. It makes later corrections easier.
Our guide to AI and medical SEO covers how AI-assisted content performs in search. Rank.ai's content product researches and writes articles for your site, with review first or publishing on a schedule; general education topics like these need no patient information at all.
Social media and review replies
The same rules apply to every post and reply. The HHS Office for Civil Rights has settled with practices that disclosed patient details while replying to online reviews, including Manasa Health Center ($30,000 in 2023). Never confirm someone is a patient in a public reply. Our healthcare reputation management guide has compliant reply templates.
Website tracking is a separate issue: pixels and analytics on your pages can send information to vendors. See patient privacy in marketing.
Training and ongoing education
HIPAA's Privacy Rule requires covered entities to train all workforce members on their PHI policies as needed for their jobs: at the start, for each new hire within a reasonable time, and again when policies change materially (45 CFR 164.530(b)). The Security Rule adds security awareness training. Marketing staff, front-desk staff who post on social media, and outside agencies all handle content that can expose PHI, so include them.
Short, recurring training works better than a single onboarding session. Walk through real examples of what not to post, the reply templates, the authorization form and the AI policy, and repeat it when something changes.
Pre-publish checklist
| Check | Yes |
|---|---|
| No names, initials, dates, locations or other identifiers of a real patient (or a signed authorization covers them) | |
| Composite or illustrative cases are labeled | |
| Every photo and video frame checked for patients, screens, labels and documents | |
| No PHI was entered into an unapproved tool while drafting | |
| Clinical accuracy reviewed by a licensed clinician | |
| Outcome claims are typical and supported by evidence | |
| Authorization on file and not expired or revoked, where used | |
| Social captions and replies follow the same rules |
FAQ
Does HIPAA apply to a healthcare blog?
Only when the blog contains protected health information. Educational posts about conditions, treatments and prevention that do not identify any patient are outside HIPAA. A post that names, shows or could reasonably identify a patient needs that patient's written authorization.
Can I write about a patient case without their permission?
Only if the case is properly de-identified under HIPAA's Safe Harbor or Expert Determination method, so that no one could reasonably identify the patient. Removing the name is not enough when other details (age, town, occupation, a rare condition) point to one person. When in doubt, get an authorization or write a labeled composite.
Is it a HIPAA violation to post a patient photo on social media?
Posting an identifiable patient photo to promote your practice without a signed authorization is a use of PHI for marketing, which HIPAA prohibits. Full-face photos are one of HIPAA's 18 identifiers. Check backgrounds too, since patients in a waiting room shot count.
Can we use ChatGPT or other AI tools to write medical content?
Yes, for general content that contains no patient information. Do not enter PHI into an AI tool unless your privacy officer has approved it and a business associate agreement covers it. Have a clinician review every draft for accuracy.
Does our marketing agency need to sign a business associate agreement?
If the agency creates, receives, maintains or transmits PHI on your behalf (for example, it handles patient lists for email campaigns or manages review replies with access to patient data), it is a business associate and needs a BAA. An agency that only writes general content and never touches PHI does not.
How often should staff get HIPAA training?
The Privacy Rule requires training for every workforce member when they join, and again when policies or procedures change materially. Many practices also run annual refresher training, and include marketing and social media staff in it.



