The trigger is data, not the word marketing: map whether the agency creates, receives, maintains or transmits PHI for the clinic, then document the relationship before access begins.
The correct acronym is BAA: Business Associate Agreement. Under HIPAA, a covered dental practice generally needs a written BAA with a vendor that creates, receives, maintains or transmits protected health information while performing work for the practice. An agency is not automatically a business associate simply because it buys ads; the analysis changes when it can access patient names, appointment requests, call recordings, intake forms, photos or other identifiable health information.
HHS says the contract must define permitted uses and disclosures, require safeguards, address reporting of improper use or breaches, flow obligations down to subcontractors, support the covered entity’s HIPAA duties, and require return or destruction of protected information when the relationship ends where feasible.
For marketing operations, the safest first step is a data map. Separate anonymous campaign metrics from patient-level leads, restrict access by role, avoid sending PHI into ordinary advertising platforms, document where forms and calls are stored, and identify every subcontractor that touches the information. A nondisclosure agreement alone does not replace the HIPAA provisions of a BAA.
This article is general information, not legal advice. HIPAA status depends on the parties and workflow, and state privacy, call-recording and consumer-health laws may impose additional duties. A clinic should have qualified counsel approve its agreement and data flow before an agency or technology provider receives patient information.
A practical decision tree for clinics and agencies
First ask whether the clinic is a HIPAA covered entity for the activity. Then map whether the agency creates, receives, maintains or transmits individually identifiable health information on the clinic’s behalf. Finally, determine whether the agency is acting as a service provider rather than merely receiving information as an ordinary member of the public.
The label placed on a form is not decisive. A lead can become PHI when it connects an identifiable person with a request for a dental service or appointment and the agency receives it for the clinic. Conversely, aggregate ad impressions and anonymous campaign totals may remain outside that patient-level flow. Counsel should evaluate the actual data path, not the name of the software.
- No patient-level data reaches the agency: document that boundary and enforce it technically.
- Agency receives appointment forms, recordings or identifiable requests: evaluate business-associate status before access.
- Agency uses subcontractors that touch PHI: the required restrictions must flow downstream.
- Agency sends data to ad platforms: stop and review whether that disclosure is permitted before launch.
What the BAA should cover in operational language
HHS sample provisions are a starting point, not a substitute for fitting the agreement to the workflow. The contract should identify permitted uses, safeguards, incident reporting, access to records, subcontractor obligations, support for the clinic’s HIPAA duties and return or destruction of PHI at termination. The security addendum should match the tools actually used.
The agreement also needs owners and deadlines. It should say where the agency reports a suspected incident, who at the clinic receives it, what evidence must be preserved, how subcontractors are involved and how access is removed at offboarding. A clause that no one can execute during an incident offers little protection.
- Permitted and prohibited uses of PHI.
- Administrative, physical and technical safeguards.
- Incident and breach-reporting route and timing.
- Subcontractor flow-down requirements.
- Access, amendment and accounting support where applicable.
- Return, destruction and access removal at termination.
A safer data architecture for dental marketing
Separate public marketing from patient operations. The advertising layer should use campaign, creative and aggregate performance data. Patient-level appointment requests should move into an approved intake or practice system with limited access. Staff and agency dashboards should expose only what each role needs.
This separation also improves measurement. The agency can receive privacy-safe conversion events or approved aggregate reports without downloading patient lists. If a campaign requires a spreadsheet of names to prove performance, the architecture is already creating unnecessary risk.
Questions to ask now
- Can the agency see any identifiable patient or appointment information?
- Where is that information stored and which subcontractors can touch it?
- Does the contract cover safeguards, incidents, subcontractors and data return or destruction?
This analysis adds original business context to reporting from U.S. Department of Health and Human Services. We link to the original publication and do not reproduce its article.
Read the original source ↗