Professional Documents
Culture Documents
Understanding the
Marketing Restrictions
of HIPAA
Leigh-Ann M. Patterson
Nixon Peabody LLP
101 Federal Street
Boston, MA 02110
(617) 345-1258
Lpatterson@nixonpeabody.com
HIPAAs Restrictions
on Marketing Activities:
THE AUTHORIZATION
REQUIREMENT: The general rule
is that covered entities must
obtain an individuals
authorization before using or
disclosing protected health
information (PHI) for marketing
purposes. 45 CFR 164.514(e)
2
HIPAAs Definition of
Marketing
First Exception
Communications made by a
covered entity for the purpose
of describing its network, the
scope of services it provides,
and the services for which it
pays.
Second Exception
Third Exception
More Exceptions . . .
SECOND SITUATION:
Communications involving products
or services of nominal value (note:
nominal value not defined in the
rule)
e.g. coupon, rebate, toothbrush, etc.
10
11
13
14
NO!
How to minimize
exposure for marketing
activities
Develop a policy on the use of
How to minimize
exposure for marketing
activities
Monitor the (cont.)
implementation of
the policy
Consider using only permissionbased marketing programs
topic-based permission (e.g.
heart disease)
points-based permission (e.g.
membership program)
19
TBA
20