Open 15-Minute Strategy Calls: Limited Weekly Slots Book yours →
Compliance

HIPAA-compliant marketing that protects your admissions, and your license

Treatment marketing lives inside a stack of overlapping rules, HIPAA, 42 CFR Part 2, the TCPA, and A2P 10DLC, that most agencies treat as someone else's problem. Here's what each one actually requires of your marketing, and why the only safe answer is to design them in from the first form, not bolt them on after a breach.

Why "HIPAA-compliant marketing" is more than HIPAA

Ask a generic agency about HIPAA-compliant marketing for treatment centers and you'll usually get a nod about keeping forms on a secure server. The reality is that four separate frameworks touch every inquiry your site generates, and getting any one of them wrong can cost a facility its advertising eligibility, its carrier texting, or its license. HIPAA governs the privacy and security of protected health information. 42 CFR Part 2 adds a stricter layer for substance use disorder records. The TCPA governs consent to call and text. A2P 10DLC governs whether the carriers will deliver your messages at all. They don't overlap cleanly, they stack, and the highest standard wins.

Because treatment is a Your Money or Your Life category in every sense, the cost of getting this wrong is not a slap on the wrist. A PHI breach is a reportable event with notification duties and fines. A TCPA violation is a private-action statute with statutory damages per message. A Part 2 disclosure without consent can void a program's ability to share records at all. None of this is theoretical for operators in our home market, see how it layers onto Florida law in our Florida treatment marketing guide.

The four layers, in plain terms

  • Layer 1

    HIPAA and the BAA

    PHI stays protected end to end. Every vendor in the data path signs a Business Associate Agreement.

  • Layer 2

    42 CFR Part 2

    Stricter than HIPAA for SUD records. Specific written consent before disclosure, designed in first.

  • Layer 3

    TCPA consent

    Prior express written consent to call or text. Captured at the form, stored, and provable.

  • Layer 4

    A2P 10DLC

    Carrier registration that lets treatment messaging actually deliver, brand and use-case vetted.

Four layers, one stack, each protects a different thing, and the highest standard always wins.

HIPAA: PHI and the Business Associate Agreement

The Health Insurance Portability and Accountability Act sets the floor for protecting protected health information, individually identifiable health information held or transmitted by a covered entity or its business associates. Its Privacy Rule limits how PHI is used and disclosed, its Security Rule sets administrative, physical, and technical safeguards for electronic PHI, and its Breach Notification Rule requires reporting when PHI is compromised.

For marketing, the part that fails most often is not the clinical system, it's the perimeter. A treatment center's marketing partner becomes a business associate the moment it creates, receives, maintains, or transmits PHI on the provider's behalf. That triggers a hard requirement: a signed Business Associate Agreement binding the agency to safeguard PHI, use it only for the permitted purpose, report breaches, and flow the same obligations down to its own subcontractors. The inquiry form that captures a name, a substance, and a callback number is PHI the instant it's submitted. Routing it into a generic CRM whose vendor will not sign a BAA is a compliance failure before the first follow-up call is ever made.

This is why we run the admissions engine on a proprietary GoHighLevel build with BAAs in place across the data path rather than stitching together consumer tools. The point is not a feature; it's that the standard marketing stack is structurally non-compliant for this niche, and rebuilding it correctly is the work.

42 CFR Part 2: the stricter rule for SUD records

Most general-purpose marketing advice stops at HIPAA and quietly assumes treatment is just another healthcare vertical. It is not. 42 CFR Part 2 is the federal confidentiality rule that applies to substance use disorder treatment records from federally assisted programs, and in most respects it is stricter than HIPAA. Where HIPAA permits use and disclosure for treatment, payment, and operations without separate authorization, Part 2 generally requires a specific, written patient consent before disclosure, including for communications that marketing-adjacent systems often treat as routine.

The practical effect is that consent capture, data segregation, and disclosure logic all have to be designed for Part 2 first, then relaxed only where the law actually allows. A "contact us" form that funnels SUD inquiries into a shared sales pipeline with no consent segmentation is a Part 2 problem waiting to surface. We build the consent and data-handling model to the higher standard so a program subject to Part 2 is covered by default, and describe the full set of compliance guardrails in our addiction treatment marketing playbook.

The TCPA: consent to call and text

HIPAA controls what data you may use; the Telephone Consumer Protection Act controls when and how you may contact someone. For treatment marketing, the load-bearing requirement is prior express written consent before making certain calls or sending marketing text messages, and the consent has to be captured clearly, stored provably, and honored on request. A workflow that texts an inquirer who checked a vague box three forms ago is exposed under the TCPA's private-action provisions, which carry statutory damages that scale with volume.

The consent architecture is not a checkbox; it's a record. Who consented, to what, when, and through which surface, captured and retrievable. That record is what makes follow-up defensible, and it's why consent lives inside the same HIPAA-aware system as the inquiry data rather than in a separate marketing tool. Our SMS and A2P compliance work treats consent capture and the messaging pipeline as one design problem.

A2P 10DLC: whether the carriers let you through

Even with HIPAA, Part 2, and TCPA all satisfied, your messages still have to physically deliver. A2P 10DLC, Application-to-Person 10-digit long code, is the registration and vetting regime the US wireless carriers require for commercial messaging, and treatment is a high-scrutiny use case within it. Unregistered or poorly vetted traffic gets filtered, throttled, or blocked outright, and a sudden delivery failure across your nurture sequence is an admissions problem disguised as a deliverability one. Proper registration ties a branded sender to a vetted use case, gives the carriers a reason to let your messages through, and is part of the same compliance posture as everything above. It's not glamorous, but in a category where a texted follow-up can be the difference between an admit and a no-show, it is load-bearing infrastructure.

Why the answering layer is a compliance decision

The most underappreciated compliance surface in treatment marketing is the one that picks up the phone. A 2am inquiry that reaches voicemail is a lost admission; one that reaches an automated system that records the caller, transcribes the conversation, and stores the transcript without a BAA in place is a breach. The answering layer sits at the exact intersection of PHI intake, TCPA consent verification, and Part 2 consent segmentation, which is why AI admissions automation built on a HIPAA-aware stack is a compliance choice, not just a conversion one. It answers, qualifies, and books around-the-clock inside the same protected environment the rest of the marketing lives in, so the first touch a patient has with your brand is also the safest one.

None of this is decoration. In a category gated by LegitScript certification on the ad side and regulated by 42 CFR Part 2 on the clinical side, a single mishandled inquiry can jeopardize the advertising eligibility it took months to earn. The compliance stack is not the thing you do after growth, it's the thing growth is built on.

Frequently asked questions

Do marketing agencies need to be HIPAA compliant?

Yes, whenever an agency creates, receives, maintains, or transmits PHI on a treatment provider's behalf, it's a business associate under HIPAA. The provider needs a signed BAA, and the agency must safeguard PHI to the Security Rule standard. Routing inquiry data through ordinary marketing tools that won't sign a BAA is itself the failure.

What is a Business Associate Agreement, and do we need one?

A BAA is the HIPAA-required contract binding any vendor that handles PHI to protect it, use it only for the permitted purpose, report breaches, and flow obligations to subcontractors. Treatment centers need BAAs with every vendor in the data path, CRM, email, call recording, forms, analytics, not just clinical systems.

Does HIPAA cover texts and calls to prospective patients?

HIPAA governs the privacy of PHI; the TCPA governs consent to call and text; A2P 10DLC governs whether carriers deliver the message. The three stack, HIPAA controls what data you may use, TCPA controls when and how you contact someone, A2P controls whether the message arrives. Compliant marketing honors all three.

How is 42 CFR Part 2 different from HIPAA?

Part 2 is the federal confidentiality rule for SUD treatment records from federally assisted programs, and it's stricter than HIPAA, generally requiring specific written consent before disclosure, where HIPAA permits many uses without it. A program subject to Part 2 must meet the higher standard wherever it applies, on top of HIPAA.

Related guides

Compliance

SMS and A2P compliance

Consent, TCPA, and 10DLC, the messaging layer done right.

Service

GoHighLevel for addiction treatment

The HIPAA-aware CRM build that holds the data path.

Flagship

Rehab admissions automation

The answering layer that's also a compliance decision.

Compliance

LegitScript certification

The ad-platform gate compliance work feeds into.

Is your marketing stack actually compliant, or just compliant-looking?

We'll audit your forms, CRM, call handling, and consent capture against HIPAA, 42 CFR Part 2, the TCPA, and A2P 10DLC, and tell you honestly where the exposure is before it becomes a reportable event.

Get a compliance review
Call Book a strategy call