Share:

AI marketing & automation




Marketing your therapy practice touches client data at almost every step: a contact form, an appointment reminder, a Google Analytics report, a testimonial. Get any of those wrong and the exposure is real, not theoretical. Two mental health platforms have already paid multimillion-dollar FTC settlements for exactly this kind of mistake.
This article breaks down what HIPAA and FTC rules actually require for your practice’s marketing, channel by channel. You will learn what to do about analytics and ad pixels, how to build a compliant CRM, what you can safely say in a testimonial, and how directories and AI search fit into your growth plan in 2026.

HIPAA requires a written authorization before you use anything that could identify a client in your marketing, a signed business associate agreement with any vendor that touches protected health information, and safeguards that match the HIPAA Security Rule. A 2024 court ruling narrowed one piece of federal guidance on tracking technology, but it left every one of these core obligations in place.
Three HIPAA rules govern almost everything you do online.
Any vendor that creates, receives, or transmits PHI on your behalf, your CRM, your email platform, your scheduling tool, needs a signed business associate agreement. Without one, using that vendor for anything client-related is a violation regardless of how careful your wording is.
In June 2024, a federal court vacated large parts of the Office for Civil Rights’ December 2022 bulletin on tracking technologies. The American Hospital Association, which brought the case, had argued for over a year that the bulletin was unlawful and harmful to patients and communities, and OCR chose not to appeal. Some marketers treated the ruling as a green light. It is not. Legal analysis of the case shows it narrowed one specific piece of guidance. It did not touch the underlying duty to avoid impermissible PHI disclosure. OCR still defines a tracking technology as a script or code that gathers information about users or their actions on a site or app, and that definition still applies.
Compliance is also getting stricter, not looser. A proposed 2026 update to the HIPAA Security Rule would require mandatory encryption of electronic PHI, mandatory multi-factor authentication, and breach reporting to OCR within 60 days for larger incidents. Build your marketing stack for where the rule is heading, not for the loosest possible reading of one court case.

Two mental health platforms have already paid multimillion-dollar FTC settlements for the kind of data sharing many practices still do by accident, and HIPAA fines now reach well into six figures per violation. At the same time, millions of Americans live in a mental health shortage area, so treating all marketing as too risky is not the safe choice either.
FTC Director Samuel Levine put it plainly after fining GoodRx: digital health companies and mobile apps should not cash in on consumers’ extremely sensitive and personally identifiable health information. GoodRx paid a 1.5 million dollar civil penalty and was permanently banned from disclosing user health data to advertisers. A few months later, online therapy platform BetterHelp paid 7.8 million dollars to settle FTC charges that it shared customers’ mental health data with Facebook and Snapchat for advertising. Both cases involved standard marketing tools, not exotic hacking.
On the HIPAA side, penalties now run in four tiers. The current penalty structure puts per-violation fines as high as 71,162 dollars, with a calendar-year cap near 2.1 million dollars for repeated violations of the same rule. Most competing guides still quote the flat 100 to 50,000 dollar figure from years ago. That number is out of date.
Going quiet is not free either. As of December 2025, 137 million Americans, 40 percent of the country, live in a federally designated Mental Health Professional Shortage Area, according to HRSA’s own workforce data. HRSA projects that shortage to widen across nearly every behavioral health profession through 2038. A therapist who avoids marketing out of fear is not protecting anyone. They are one more provider a person in a shortage area cannot find.
Google Analytics and Meta Pixel are not automatically illegal on a therapy website. Both become a HIPAA problem when they send identifiable information, an IP address paired with a visit to a specific condition or service page, to a vendor with no business associate agreement in place. The fix is configuration and scope. You do not need to delete your analytics entirely.
A tracking technology becomes a compliance issue the moment it connects a real person to health information without authorization. That can happen through:
None of that requires bad intent. It is usually a default install nobody ever revisited.
“We treat this as a systems problem, not a legal one. Map every script that touches a client-facing page, then decide tool by tool whether it needs a BAA or needs to go.” Derick Do, Co-Founder and Chief Product Officer

This is the kind of work that separates a practice that survives an audit from one that gets a settlement letter.
A HIPAA-compliant CRM needs a signed business associate agreement, encryption at rest and in transit, access controls, and audit logs. It needs to replace any general-purpose tool anywhere near a lead’s contact information. Most therapist-specific platforms already clear this bar. Most general marketing tools do not.
Free personal email services, Gmail included, do not offer a business associate agreement, and any message revealing that someone is a therapy client counts as PHI the moment it touches a health-related channel. That covers appointment reminders, intake follow-ups, and the quick reply sent from a phone between sessions. If your lead nurture sequence runs through a personal inbox, it is not compliant no matter how careful the wording is.
Several platforms are built specifically for this:
| Tool | What it handles | Why it fits |
|---|---|---|
| SimplePractice | EHR, scheduling, billing | Used by over 225,000 clinicians, signs a BAA |
| TherapyNotes | Clinical documentation, scheduling | Compliance-first design for behavioral health |
| Hushmail | Encrypted email, secure forms | Built for small practices, one BAA covers email and forms |
| Doxy.me, Zoom for Healthcare | Telehealth video | Signed BAA available, unlike consumer video tools |
| GoHighLevel (configured) | CRM, automation | Some agencies build a BAA-covered instance for lead tracking |
“The mistake we see most is one platform trying to do everything. A scheduling tool, a CRM, and an email sender each need their own BAA check, not a single blanket assumption.” Derick Do, Co-Founder and Chief Product Officer
Pick the tool that matches the step in your funnel, not one platform trying to do everything, and confirm the BAA covers the specific feature you plan to use, not just the account in general.
A client testimonial can only be used after getting written authorization that is separate from general consent paperwork, and even then, any detail specific enough to identify the person still carries risk. For most practices, a fully anonymized composite case is the safer path, and it still works as marketing.
HIPAA treats any use of a client’s information in marketing as something that needs its own signed, detailed authorization, not a line buried in an intake form. Vivian Chung Easton, LMFT and Clinical Product Lead at Blueprint, frames it well. She says the foundation of HIPAA-compliant marketing rests on three main principles: trust, compliance, and transparency. A testimonial that skips written authorization fails all three, even if the client offered it verbally and even if the name was changed.
Real client language is not the only way to show your work.
None of these require choosing between marketing and privacy. They just move the proof from a person’s story to your practice’s own expertise.
Psychology Today still drives real referrals and is worth a listing for most practices, but leaning on it alone is getting riskier. Individual profile performance has dropped sharply for some therapists as the directory gets more crowded, which means directories now work best as one channel inside a bigger owned marketing strategy.
Tyler Jensen, a licensed psychotherapist, still calls Psychology Today the powerhouse of our industry, and with roughly 80,000 listed therapists, it remains the largest directory by far. Scale cuts both ways, though. One California LMFT’s own profile analytics, shared publicly in therapist forums, showed contacts falling from 357 in 2021 to 40 in 2025, even as the directory itself grew larger. More listings competing for the same search volume means a smaller share for any single profile.
A directory listing should sit alongside a website that ranks on its own, an email list your practice actually owns, and a Google Business Profile under your control. A practice with only a directory listing would lose its entire pipeline if that platform changed overnight. A practice with real owned channels would barely notice.
“A directory listing is a rented audience. The practices that grow fastest treat their own website and email list as the asset, and the directory as one more channel pointing back to it.” Tanner Medina, Co-Founder and Chief Growth Officer

AI tools like ChatGPT now answer “find me a therapist” questions directly, citing a small number of sources instead of listing ten blue links, so your visibility increasingly depends on structured, specific content an AI system can quote. This is generative engine optimization, and almost none of the current HIPAA marketing guides address it.
Scale is the reason this cannot wait. OpenAI announced that ChatGPT passed 900 million weekly active users in February 2026, more than double the figure from a year earlier. A meaningful share of those users ask health-related questions, and a growing number ask for a provider recommendation directly. A practice that only optimizes for old-style blue link results is invisible to that entire layer of discovery.
GEO rewards specificity, not keyword density.
“GEO and SEO are not separate strategies anymore. The same page that ranks on Google needs to answer a specific question clearly enough for ChatGPT to quote it. That is the bar now.” Tanner Medina, Co-Founder and Chief Growth Officer
This is why launchcodex treats AI visibility as a core layer of every SEO engagement, not an afterthought. The same content that earns a page one ranking rarely earns an AI citation without this extra structure.

Every channel covered in this article behaves differently under HIPAA and FTC rules, so a single table is more useful than another wall of caveats. Use it as a starting checklist before touching your next campaign.
| Channel | Status | What it needs |
|---|---|---|
| Google Analytics | Conditional | Strip identifying URLs and condition-specific titles, review regularly |
| Meta Pixel | Conditional | No signed BAA available, avoid on booking and intake pages |
| Email marketing | Conditional | Requires a BAA-covered platform, never a personal inbox |
| CRM and lead tracking | Conditional | Requires a signed BAA and encryption, not a general-purpose tool |
| Client testimonials | Conditional | Requires separate written authorization or full anonymization |
| Directory listings | Generally safe | No PHI involved, but should not be the only channel |
| AI search and GEO | Generally safe | No PHI risk, requires structured, specific, current content |
None of these channels are off limits. Almost every one just needs a specific fix rather than a blanket avoidance. A practice that treats compliance as a design constraint, not a reason to stay quiet, ends up with a marketing system that holds up under an audit and still brings in the clients who need care. That is the same approach launchcodex takes when building marketing systems for regulated industries: treat the rule as a spec to build around, not a wall to avoid.
Not by default. It becomes compliant only when identifying details, like condition-specific URLs, are removed from what gets sent to Google.
Meta does not sign a business associate agreement for its standard Pixel, so avoid it on any page tied to booking, intake, or a specific condition.
Yes. Any vendor that stores or processes a lead’s contact information alongside health-related context needs a signed BAA before use.
Only with a separate written authorization specific to marketing use. A fully anonymized composite example is safer and needs no authorization at all.
It helps, but referral volume has dropped for many individual profiles as the directory has grown. Pair it with a website and email list you own outright.
Penalties now reach into six figures per violation, with a calendar year cap near 2.1 million dollars for repeated violations of the same rule, on top of any separate FTC exposure.



Real stories from the people we’ve partnered with to modernize and grow their marketing.