HIPAA rarely comes up in marketing conversations until something goes wrong, and by then it’s expensive. Most dental practices assume HIPAA is only about clinical records and billing, but marketing touches patient information more often than owners realize — appointment request forms, chat widgets, email lists, even a testimonial. Getting the basics right isn’t complicated, but skipping them creates real risk.
Website forms are the most common blind spot
An appointment request or contact form that asks for a name, reason for visit, and contact details is collecting information that can fall under HIPAA if it’s tied to a specific patient’s health situation. The form itself needs to transmit that data securely, and whatever receives it — an email inbox, a CRM, a scheduling tool — needs to handle it appropriately. A form that emails patient details in plain text to a personal Gmail account is a common and avoidable gap.
Testimonials and reviews need real, informed consent
A glowing review a patient posts on their own on Google is theirs to post. A testimonial the practice asks a patient to write, records on video, or features on the website with specific treatment details is different — it should come with clear, documented consent about exactly what’s being shared and where. This protects the patient and the practice, and it’s a five-minute conversation that’s easy to skip under time pressure.
Marketing to your own patient list is generally fine, done carefully
Sending appointment reminders or recall emails to your existing patients is standard practice and not inherently a HIPAA problem — but the platform sending them should have appropriate safeguards, and the content shouldn’t reveal specific health details to anyone but the patient themselves. A subject line or preview text that references someone’s specific treatment, visible to anyone glancing at their phone, is worth avoiding regardless of the platform’s compliance status.
Chat widgets and third-party tools deserve a second look
A website chat widget, a scheduling plugin, or a review-request tool is a piece of software with access to whatever patients type into it. Before installing anything that touches patient contact, it’s worth a quick check of whether that vendor is willing to sign a Business Associate Agreement — if they won’t, that’s meaningful information about how seriously they treat this.
This is a conversation with a professional, not a marketing decision
The specifics of HIPAA compliance — what counts as protected information in a marketing context, what a Business Associate Agreement needs to cover, how a specific tool should be configured — are worth confirming with a healthcare attorney or compliance consultant rather than assuming. A marketing agency can flag where the risk typically sits, but the sign-off on ‘is this specific setup compliant’ belongs with someone qualified to say so.
What this means in practice
The highest-risk spots are website forms, testimonials, and third-party tools that touch patient contact information. None of these require abandoning marketing — they require setting them up with basic care and, where genuine questions come up, an actual conversation with a professional rather than a guess.
Related services
Frequently Asked Questions
Does a dental website contact form need to be HIPAA compliant?
If it collects information tied to a specific patient’s health situation, it should transmit and store that data securely, and whatever receives it should handle it appropriately. A form that emails details in plain text to a personal inbox is a common gap worth fixing.
Can I use patient testimonials in my dental marketing?
Yes, with clear, documented consent about exactly what’s being shared and where, especially if it includes specific treatment details. A patient’s own unprompted Google review is different from content the practice actively requests and features.
What makes dental marketing HIPAA compliant versus non-compliant?
Compliance largely comes down to never disclosing protected health information — a patient’s identity tied to their treatment, condition, or visit — in any public or third-party marketing context without explicit, documented authorization.
Can before-and-after photos violate HIPAA?
They can, if a patient is identifiable and hasn’t given specific, informed consent for that exact use. A signed release specific to marketing use, not just general treatment consent, protects the practice.
Is it a HIPAA violation to thank patients by name on social media?
It can be, since publicly associating a named individual with being a patient discloses protected information without authorization, even without describing their treatment. Using only a first name and initial, with consent, is safer.
Do email marketing platforms need to be HIPAA compliant?
If any protected health information is included in the email content or list segmentation logic, yes, the platform and process need to meet HIPAA requirements. General appointment reminders and newsletters with no PHI have lower risk but still warrant a cautious, documented approach.
Can dental practices use text message marketing without violating HIPAA?
Yes, as long as messages don’t include protected health information and patients have given clear consent to be texted, ideally documented at intake with an easy opt-out.
Does responding to a Google review risk a HIPAA violation?
Yes, if the response confirms the person was a patient or references any specific treatment detail, even to correct the reviewer’s account. Responses should stay general and never confirm patient status.
Who is responsible for HIPAA compliance in a practice’s marketing?
Ultimately the practice, even when marketing is handled by an outside agency. A signed Business Associate Agreement with any vendor handling patient data, and clear internal guidelines for what marketing content is and isn’t allowed to include, protect the practice.
What’s the safest approach to using patient stories in marketing?
Get explicit written consent specific to the intended use, keep identifying details general unless the patient specifically agrees to be named, and when in doubt, err toward less identifying detail rather than more.



