HIPAA-compliant email marketing is legal for psychiatry practices, and a large share of it never requires patient authorization at all. Two questions decide everything: does the email contain protected health information, and does the message meet HIPAA’s definition of marketing. A newsletter sent to a public subscriber list that anyone can join carries no PHI and sits outside HIPAA. An email sent to a list of your Spravato patients is a different animal, because membership in that list reveals a diagnosis before anyone opens the message. This guide covers where the line falls, what a valid authorization has to contain, how to pick a platform that will sign a business associate agreement, how to segment and personalize without exposing PHI, and which metrics you can safely track.
One note before we start: this is marketing guidance built on federal rules and published HHS guidance, not legal advice. State law is often stricter than HIPAA on mental health information, and your final policy should be reviewed by a healthcare compliance attorney who knows your state.
The distinction that decides everything
Most confusion about HIPAA and email marketing comes from treating “your email list” as one thing. It isn’t. You have at least two, and they carry completely different obligations.
The first is a prospect list. Someone found your site, read a page about treatment-resistant depression, and subscribed to a newsletter. They are not your patient. You hold no clinical information about them. HIPAA does not apply to that relationship, because HIPAA governs protected health information held by a covered entity, and a self-selected subscriber has given you none. CAN-SPAM applies. HIPAA does not.
The second is a patient list, pulled from your practice management system or EHR. Every address on it is protected health information, because you obtained it in connection with care. Everything you do with that list is a use of PHI.
Then there is the case that trips up psychiatry specifically: a segment. The moment you build a list called “Spravato patients” or “TMS completers” or “ketamine consults,” the list membership is itself clinical information. You could send those people a blank email and still have made a disclosure if it went to the wrong address, because being on the list says something about their health.
Get this split right and most of the rest becomes mechanical.
What HIPAA actually says about marketing
HIPAA defines marketing at 45 CFR 164.501 as a communication about a product or service that encourages the recipient to buy or use it. Where a covered entity wants to use PHI for marketing, 45 CFR 164.508(a)(3) requires written authorization from the individual first. Two narrow exceptions let you skip authorization: face-to-face communication, and a promotional gift of nominal value. Email is neither.
That sounds restrictive until you read the exclusions. Several categories of communication are carved out of the definition of marketing entirely, which means they need no authorization:
- Communications for the individual’s treatment.
- Communications for case management or care coordination, or that recommend alternative treatments, therapies, providers, or settings of care.
- Refill reminders and communications about a drug currently prescribed to the individual, including adherence messages and prescriptions that lapsed within the last 90 days, per HHS guidance on the refill reminder exception.
There is a catch attached to those exclusions. If a third party pays you to send the communication, the exclusion generally falls away and authorization is required again. For the refill reminder exception, payment is only acceptable where it reasonably covers your cost of sending. For an interventional psychiatry clinic, that matters if a device manufacturer or pharmaceutical partner ever offers to subsidize a patient education campaign. Take the money and you have changed the compliance category of the email.
Here is how that plays out in practice.
| Marketing under HIPAA? | Authorization needed? | |
|---|---|---|
| Reminder that a patient’s next TMS session is Thursday | No, it’s treatment | No |
| Message to a depression patient about your new Spravato service line | Generally no, it recommends an alternative treatment | No |
| Newsletter to a public subscriber list about what TMS involves | Not PHI at all | No |
| Promotional email to former patients about a discounted wellness package | Yes | Yes |
| Patient education campaign paid for by a device manufacturer | Yes | Yes |
That second row is the one most clinics never use. Telling an existing patient with treatment-resistant depression that you now offer an alternative treatment is a care-coordination communication, not an advertisement, provided nobody outside the practice is paying you to say it. A great deal of what interventional psychiatry clinics want to send falls into that space.
Why psychiatry is harder than the rest of medicine
Generic healthcare email advice underestimates this specialty. Three things are different.
Membership in a list is a diagnosis. A cardiology practice emailing its patient list reveals that someone has a heart. A psychiatry practice emailing a list segmented by treatment reveals that a specific person is receiving mental health care, which is exactly the fact most patients want controlled. This is the same problem that makes review generation harder in psychiatry, and it has the same solution: keep the identifying signal out of anything that could be seen by someone else.
Subject lines are visible on lock screens, and they cannot be encrypted. Even with a fully encrypted platform, the subject line travels in the clear and appears as a notification on a phone that a partner, parent, or colleague may be looking at. “Your Spravato session” on a lock screen is a disclosure to whoever is standing there. Treat the subject line as public.
Some practices carry a second rulebook. If any part of your operation is a federally assisted program that diagnoses or treats substance use disorder, 42 CFR Part 2 applies alongside HIPAA and has historically been stricter. The 2024 final rule aligned much of Part 2 with HIPAA on penalties and breach notification, with compliance required from February 16, 2026. Not every psychiatry practice is a Part 2 program and the definition is specific, so check rather than assume, particularly if you run a ketamine or medication-assisted treatment service line.
Choosing a platform: the BAA is necessary but not sufficient
If your email touches PHI, the vendor sending it is a business associate and must sign a business associate agreement. Mailchimp does not sign one on any plan, and its acceptable use terms restrict health data, which is why it keeps appearing on lists of platforms to avoid for patient email. Other mainstream tools vary: some will sign, some won’t, and some have changed position. Verify in writing rather than trusting a blog post, including this one.
The advice usually stops there, and it stops too early. A signed BAA tells you the vendor accepts liability. It does not tell you what the BAA covers. Some platforms will sign an agreement that covers data at rest in their cloud but says nothing about the transmission of the emails themselves, which is the part you actually care about.
Ask these before you sign anything:
| Question | What a good answer sounds like |
|---|---|
| Does the BAA cover message transmission, not just stored data? | Yes, in writing, naming outbound delivery |
| How is the message encrypted in transit and at rest? | TLS enforced on delivery, with a fallback path when the recipient server refuses TLS |
| Does the recipient need to log into a portal to read it? | Ideally no, portal friction destroys open rates on patient email |
| Who at the vendor can see list contents and message bodies? | Role-based access with logging |
| What happens to our data if we leave? | Documented export and deletion, with a timeline |
| Do sub-processors handle our data, and are they under the same terms? | A named list, flowed-down obligations |
| Is open and click tracking on by default, and can it be turned off per campaign? | Yes to the second half |
That last one gets skipped constantly. Click tracking on a patient list generates a record that a specific person opened a message about a specific treatment. That record is PHI sitting inside your marketing tool.
On encryption itself, the current Security Rule treats encryption as an addressable specification at 45 CFR 164.312, which means you either implement it or document a defensible reason why an equivalent safeguard is reasonable. In practice, for email carrying mental health information, “we decided not to encrypt” is not a position worth defending. HHS published a proposed Security Rule overhaul in the Federal Register on January 6, 2025 that would remove the addressable category and make encryption mandatory. As of July 2026 it remains a proposal. The comment period closed in March 2025, OCR has not issued a final rule, and the Unified Agenda target has slipped to 2027. The current rule still governs. Build as though encryption is mandatory anyway, because it removes the argument.
Consent, authorization, and the difference between them
These are two separate things and clinics regularly collect the wrong one.
Consent to be contacted by email is an operational permission. You capture it at intake, you note the patient’s preferred contact method, and you honor requests for confidential communications by alternative means, which patients have a right to request under the Privacy Rule.
Authorization is the formal document HIPAA requires before PHI is used for marketing. To be valid, it has to describe the information being used, identify who is making and receiving the disclosure, state the purpose, carry an expiration date or event, explain the right to revoke and how, and be signed and dated by the patient. If any third-party payment is involved, the authorization has to say so. Keep signed authorizations for six years, which is the retention period HIPAA sets for required documentation.
A practical detail that saves arguments later: a checkbox on an intake form saying “I agree to receive emails” is consent, not authorization. If you plan to run genuine promotional campaigns to your patient list, build a separate, signed marketing authorization rather than burying a clause in the intake packet.
Two more layers sit on top of HIPAA. CAN-SPAM applies to your commercial email regardless of HIPAA and requires honest headers and subject lines, a valid physical postal address, clear identification of the message as an advertisement where applicable, and an opt-out that you honor within ten business days. And HHS has been explicit that patients may receive unencrypted email if they have been warned of the risk and still prefer it, so a patient’s stated preference is a legitimate path, provided you document the warning and the preference.
Segmentation and personalization without exposing PHI
This is where the practical work happens. The goal is relevance without ever putting clinical detail into a message body or a list name.
Segment by behavior, not by diagnosis. “Downloaded the TMS insurance guide” is a marketing signal. “Diagnosed with MDD” is a clinical one. Both let you send the same email; only one of them creates a PHI list inside your marketing tool.
Keep the clinical segment in the EHR and send a neutral trigger. If a patient finishes a TMS course, the EHR knows. Your marketing platform does not need to. Push a flag that means nothing on its own, like a campaign ID, and let the platform send against that. If you are wiring this through intake automations, audit what the integration actually passes rather than what the mapping screen says it passes.
Use first names and nothing else. Personalization tokens are where PHI leaks. First name is fine. Treatment name, appointment date, provider specialty, and medication are not, because merge fields fail in public and a mis-merge in psychiatry is a disclosure.
Write subject lines that would be unremarkable on a stranger’s phone. “A question about your next visit” works. “Your esketamine appointment” does not.
Send to individuals, never to a group. If you are sending anything manually from a regular mailbox, blind copy is the minimum, because visible recipients on a psychiatry list disclose every one of them to every other one.
Four sequences that earn their keep
None of these need patient authorization when built as described, because the first two never touch PHI and the second two are treatment or care-coordination communications.
1. Prospect nurture, for people who inquired but never booked
The most valuable sequence a clinic can run, and the least common. Interventional psychiatry has a long consideration window. Someone reads about TMS in March and calls in July. Email is what keeps you in the room during those four months.
Five emails over three weeks: what the treatment involves and what a session actually feels like, how insurance coverage typically works, what the evidence says about who responds, common concerns about side effects, and a plain invitation to book a consultation. No PHI, because these people are not patients. This runs on ordinary marketing software, and it is the single highest-return piece of mental health marketing most clinics have never switched on.
If your inquiries are going cold before anyone calls them, the sequencing problem usually starts earlier than email, and TMS consult follow-up is worth reading alongside this.
2. Referring clinician updates
Therapists and primary care physicians send more interventional psychiatry patients than any ad campaign, and almost nobody emails them properly. A quarterly note covering what you treat, your current wait time, referral criteria, and one short piece of clinical education keeps you present without asking for anything.
This list contains no patient data at all, so it needs no BAA and no authorization. It pairs with the offline work described in building a therapist referral network.
3. Treatment education during a course
A TMS course runs roughly six weeks and patients drop out in week two, usually because early sessions are uncomfortable and nobody told them the response curve is slow. A short sequence timed to the course, sent through a platform under a BAA, is a treatment communication. It also does more for no-show rates at a Spravato or TMS clinic than another reminder text.
Keep the content general enough that it would make sense to anyone. Session-count language like “you’re halfway through” is fine in a portal, risky in an inbox.
4. Reactivation for patients who stopped
Depression relapses, and patients who completed a course two years ago are the warmest audience a clinic has. A message telling a former patient that maintenance sessions exist, or that you now offer something you didn’t before, is a care-coordination communication rather than an advertisement, as long as no third party is paying you to send it. For a Spravato clinic this is often the cheapest source of filled slots available.
The wording is what keeps it on the right side of the line. “We wanted to let you know about a treatment option that may be relevant” reads as clinical. “Book now and save 20%” reads as an advertisement and needs an authorization.
What you can and cannot measure
Analytics is the quietest compliance risk in healthcare marketing, and the rules moved recently.
OCR issued a bulletin in December 2022 saying that tracking technologies on healthcare websites could turn ordinary web analytics into PHI, and revised it in March 2024. The American Hospital Association sued. On June 20, 2024 the US District Court for the Northern District of Texas vacated the part of the bulletin that treated an IP address plus a visit to an unauthenticated public webpage about a health condition as protected health information, holding that OCR had exceeded its authority. HHS filed an appeal in August 2024 and withdrew it ten days later.
What that means for a clinic today: standard analytics on your public marketing pages is on considerably firmer ground than it was in 2023. The rest of the bulletin was not vacated, so authenticated pages, patient portals, and anything behind a login still carry the original obligations. The safe reading is that the public front of your website is marketing and the logged-in part is clinical, and the two should not share a tracking configuration.
Email metrics follow the same logic.
| Metric | Prospect list | Patient list |
|---|---|---|
| Open and click rates | Fine | Creates a record tying a person to a treatment topic |
| Aggregate campaign performance | Fine | Fine |
| Individual-level engagement history | Fine | Treat as PHI |
| Conversion tracking to a booking page | Fine | Only inside a BAA-covered stack |
| Passing data to an ad platform | Fine for prospects | No |
The practical answer for patient campaigns is to measure at the aggregate level and resist the urge to build engagement scores on individuals. You lose some optimization. You avoid building a database of who is interested in what treatment.
The mistakes that actually happen
Sending to a diagnosis-named segment through a platform with no BAA. The most common failure and the easiest to make, because the list name is the giveaway even if the email body is clean.
Merging clinical fields into subject lines. Someone tests a template with a friendly merge field, it works, and it ships. Audit what your system sends, not what the preview shows.
Uploading a patient CSV into a marketing tool “just to test.” The upload is the disclosure. There is no test mode in HIPAA.
Treating an intake checkbox as a marketing authorization. It isn’t, and the difference only becomes visible during an investigation.
Leaving click tracking on for a patient campaign because nobody knew it was a setting.
Forgetting that the platform stores an archive. Every campaign you send sits in the vendor’s system indefinitely, which is fine under a BAA and a problem without one.
Using a shared inbox with visible recipients. Blind copy is not a strategy, but it is a floor, and plenty of clinics still don’t clear it.
A pre-send checklist
Run this before any campaign that touches a patient list:
- The platform has a signed BAA that names message transmission, not only stored data.
- The list name contains no clinical term.
- The subject line would be unremarkable on someone else’s phone.
- No merge field beyond first name.
- The message body contains no diagnosis, medication, treatment name, provider specialty, or appointment detail.
- The message is classified: treatment, care coordination, or marketing. If marketing, signed authorizations exist for everyone on the list.
- No third party is paying for this send. If one is, an authorization is required regardless of category.
- CAN-SPAM elements are present: physical address, working unsubscribe, honest subject.
- Individual-level tracking is off, or the analytics stack is inside the BAA.
- Someone other than the sender has read the whole thing.
Frequently asked questions
Is Mailchimp HIPAA compliant?
Not for patient email. Mailchimp does not sign business associate agreements for its standard marketing product, so it cannot be used for any list that constitutes PHI. It is perfectly usable for a public prospect newsletter, because no PHI is involved.
Do patients have to opt in before we email them marketing?
Where the email uses PHI and meets HIPAA’s definition of marketing, you need a signed authorization, not just an opt-in. Where the communication is for treatment or care coordination, no authorization is required. CAN-SPAM separately requires a working opt-out on commercial email regardless of which category applies.
Can we send appointment reminders by email?
Yes. Appointment reminders are treatment communications and fall outside the definition of marketing. Keep clinical detail out of the message and the subject line, since the reminder still travels through an inbox someone else may see.
Are email addresses protected health information?
An email address becomes PHI when a covered entity holds it in connection with an individual’s care. A subscriber who signed up on your website has not created PHI. A patient whose address sits in your EHR has.
Does a HIPAA-compliant platform mean we can put diagnoses in emails?
Technically some encrypted platforms allow it. In psychiatry it is still a poor idea, because the recipient’s device is outside your control and the subject line is never encrypted. Compliance and discretion are separate questions.
What about email marketing to referring therapists?
No patient data, no HIPAA obligation. Referral communication to other clinicians runs on ordinary marketing software, which makes it one of the easiest channels for an interventional psychiatry clinic to start with.
How long do we keep authorizations?
Six years, which matches HIPAA’s documentation retention requirement. Store them where an auditor could find them without asking you.
Where to start
If you are running nothing today, start with the two lists that carry no HIPAA obligation: a public prospect nurture sequence and a quarterly referring-clinician update. They cover the majority of the revenue opportunity, they need no BAA, and you can have both live in a fortnight.
Patient email is worth doing next, and it is worth doing properly, with a platform that has signed a real agreement and a written policy that tells your team what may never appear in a subject line. Most of the risk in this channel comes from a segment name and a merge field, not from anything clever.
If you’d like a second pair of eyes on how your clinic’s follow-up is set up before you turn any of it on, book a call and we’ll go through it together.