Skip to main content

folkfox

Skip to main content
Skip to content
HEALTHCARE MARKETING

HIPAA compliant marketing just earned its proof of concept

A privacy-first growth platform for hospitals and health systems raised $15 million this week. That is a small number by venture standards and a large one for anyone still treating HIPAA compliant marketing as a cost centre rather than a category.

Quick answerHIPAA compliant marketing means using patient data only under a signed authorisation or a business associate agreement. Ours Privacy's $15 million raise shows investors now price that discipline as a growth advantage.
Section 01

A $15 million bet that HIPAA compliant marketing is a real category#

A fox does not forage in the open field when the hedgerow offers cover, and a healthcare marketer should not either. For years that has meant one of two postures: prowl the thicket of patient data cautiously and grow slowly, or graze the open field for clicks and hope no regulator is watching from the tree line. This week, a company betting there is a third path picked up serious backing to prove it.

Ours Privacy announced a $15 million Series A on 19 August 2026, led by Lightbank and Health Velocity Capital, with Rock Health, Lakehouse, TMV, Switch Ventures, Serena Ventures and GreyMatter joining the round. The company, which builds HIPAA compliant marketing infrastructure for hospitals and health systems, says more than 200 healthcare organisations already use its platform, though it has not disclosed revenue or a valuation. As Fierce Healthcare reported the same week, the round lands squarely inside a category that, eighteen months ago, most growth teams treated as a legal department's problem rather than a product one.

"The future of healthcare marketing is privacy-first," said co-founder and CRO Adam Putterman in the announcement. "Putting privacy first makes marketing not only safer, but better." Co-founder and CEO Jessica Holton framed the round as infrastructure, not just funding: "We've built the infrastructure that makes prioritizing patient privacy and driving meaningful growth possible, bringing together the data, performance, and compliance healthcare marketers need in a rapidly changing world." Eric Ong of Lightbank put it more bluntly on the investor side: the product and customer feedback sold the firm, because Ours Privacy had, in his account, built a full growth stack around compliance rather than a thin layer bolted on top of one.

Why one funding round is a market signal, not just a company milestone#

Single rounds rarely settle an argument, but this one lands against a useful backdrop. Rock Health's own H1 2026 funding report, published 13 July 2026, counted $7.4 billion invested across 244 digital health deals in the first half of the year, up from $6.4 billion across roughly the same deal volume a year earlier, with median deal size climbing to $14 million, the highest since 2022. Rock Health is also a named participant in the Ours Privacy round, which makes its own published numbers a legitimate yardstick rather than a borrowed one: the firm that tracks the category chose to fund a company inside it.

The round, in three numbers

Series A raised

15M

Led by Lightbank and Health Velocity Capital, six more investors joining.

Healthcare customers

200+

Hospitals and health systems already running the platform, per Ours Privacy.

H1 2026 digital health funding

7B

Rock Health's own count across 244 deals, up from $6.4B a year earlier.

None of that proves HIPAA compliant marketing is easy. It proves it is now fundable, which is a different and arguably more useful thing: fundable categories get built out, staffed, and iterated on, rather than patched together in-house by whichever analyst drew the short straw. The rest of this piece is about why the category needed solving in the first place, and what a marketing team should actually be doing about it, with or without a vendor's help.

Section 02

What HIPAA marketing rules actually require#

Most marketers who say "HIPAA compliant" are gesturing at a vibe. HIPAA itself is far more specific, and the specificity is the whole game. Under 45 CFR 164.501, "marketing" is a defined legal term: a communication about a product or service that encourages the recipient to purchase or use it. That definition catches far more than a Facebook ad. A newsletter that quietly promotes a paid wellness programme, a retargeting email nudging a lapsed patient toward a new service line, a chatbot script that upsells a screening package, all of these can legally be "marketing" whether or not anyone on the team would call it that.

The carve-outs matter as much as the rule. A clinician recommending an alternative treatment, a health plan describing its own network, a refill reminder that costs the sender roughly what it costs to send, none of that counts as marketing under the statute, so none of it needs a signature first. The line HIPAA actually draws is between helping a patient use care they already have and encouraging them to buy something new. Growth teams that ignore that line end up asking legal for authorisation on messages that never needed it, and skipping authorisation on the one campaign that did.

When you actually need a HIPAA marketing authorization form#

Once a communication crosses into marketing, 164.508(a)(3) is unambiguous: a covered entity must obtain a valid, patient-signed HIPAA marketing authorization form before using or disclosing protected health information to make it, with two narrow exceptions, a face-to-face conversation and a promotional gift of nominal value. If a third party pays the covered entity to make the communication, the authorisation must say so plainly, so the patient knows their data is generating revenue for someone other than their own care team.

This is the piece of the regulation smaller marketing teams tend to skip entirely, because it reads like legal paperwork rather than a growth blocker, right up until an audit asks for the signed forms and none exist. HIPAA compliant marketing lives or dies on that one folder of signatures.

That single requirement is why platforms built specifically for healthcare marketing rules exist at all. A generic marketing automation tool has no concept of a marketing authorisation, no field for it, no workflow that blocks a send until one is on file. A HIPAA compliant marketing stack does, and that gap, small on a feature list, large in an audit, is a fair chunk of what a $15 million round is actually buying.

Section 03

Where healthcare marketing regulations collided with the pixel#

The statute is old. The problem that made it urgent again is not. On 1 December 2022, the HHS Office for Civil Rights issued a bulletin on the use of online tracking technologies by HIPAA covered entities and business associates, updated on 18 March 2024. Its central claim was simple and, for most marketing stacks, alarming: sending protected health information to a tracking vendor such as Meta's pixel or a standard analytics tool, without a signed business associate agreement covering that vendor, can itself be a HIPAA violation. A scheduling page that fires a pixel on submission, a symptom checker that logs a query to an ad platform, either could quietly turn a routine marketing tool into an unauthorised disclosure.

hipaa compliant marketing, a fox listening carefully through a stethoscope pressed to a small locked box
Before anyone else hears what the data is saying, someone has to actually listen to it.

Hospitals pushed back, and the pushback worked, partially. The American Hospital Association, joined by the Texas Hospital Association and two health systems, sued HHS in November 2023, arguing the bulletin amounted to rulemaking without the notice-and-comment process the law requires.

On 20 June 2024, a federal district judge ruled in the AHA's favour, but only on the bulletin's most aggressive claim: that pairing an IP address with a visit to an unauthenticated public webpage about specific conditions or providers automatically counts as protected health information. The court struck that specific provision as exceeding HHS's authority. Everything else in the bulletin, including how it treats authenticated patient portals, appointment schedulers and logged-in tools, was left standing. OCR's position on public marketing pages is now narrower than it was in March 2024. Its position on anything behind a login is unchanged.

That nuance gets lost constantly in trade coverage, and it is the difference between a marketing team that can relax and one that cannot. Regulators did not go quiet after the ruling. The FTC and HHS jointly warned roughly 130 hospital systems in July 2023 about tracking technology risks. "When consumers visit a hospital's website or seek telehealth services, they should not have to worry that their most private and sensitive health information may be disclosed to advertisers and other unnamed, hidden third parties," said Samuel Levine, then director of the FTC's Bureau of Consumer Protection.

What the FTC actually charged, in dollars
Bar chart comparing two FTC health-privacy enforcement penalties: BetterHelp at $7.8 million and GoodRx at $1.5 millionBetterHelp, 2023: 7.8GoodRx, 2023: 1.58M6M4M2M0M7.8MBetterHelp, 20231.5MGoodRx, 2023
BetterHelp's penalty ran more than five times GoodRx's, reflecting the direct sale of therapy-questionnaire answers against GoodRx's ad-platform data sharing. Both remain the FTC's own named precedents for this warning.

The FTC's joint letter named its own precedents directly: BetterHelp's $7.8 million settlement, finalised in July 2023, over sharing email addresses, IP addresses and health-questionnaire answers with Facebook, Snapchat, Criteo and Pinterest after promising not to. GoodRx paid $1.5 million the previous February, the first-ever enforcement of the FTC's Health Breach Notification Rule, for failing to tell users it had shared their health data with Facebook and Google.

Premom rounds out the trio the FTC cites every time this topic comes up. None of these three needed a HIPAA violation to get fined; the FTC Act and the Health Breach Notification Rule reach plenty of health data HIPAA itself never touches, which is exactly why folkfox covered the FTC's newer suit against Hims and Hers as its own story rather than a footnote to this one.

Section 04

Choosing tools that keep HIPAA compliant marketing honest#

Vendors selling into this category are not solving a hypothetical. They are solving the fact that most marketing stacks were built for retail, not regulated care, and it shows. Good hipaa compliant email marketing platforms need three things a generic email service does not ship by default: a signed business associate agreement covering every vendor that touches patient data, segmentation logic that can hold protected health information without leaking it into a send list a compliance officer never approved, and a pixel and tag layer that defaults to off rather than defaults to firing.

Ours Privacy's pitch, and the pitch of the handful of competitors building similar infrastructure, is essentially that third point: stop shipping tools where privacy is a setting a marketer has to remember to switch on. That is what HIPAA compliant marketing looks like once it is built into the product rather than bolted on afterward.

How common the risk still is
How common the risk still isWaffle chart showing 33 percent of analysed healthcare websites still running Meta Pixel tracking code33% of healthcare websites analysed stillrun Meta Pixel tracking code
A third of healthcare sites in Lokker's March 2026 privacy scan still ran Meta Pixel outright, the exact tracker named in the FTC's BetterHelp and GoodRx actions and the pattern hipaa compliant marketing tools exist to catch.

That 33 percent, drawn from Lokker's Online Data Privacy Report, is not a fringe finding, and it is not a new problem either, it is the problem the OCR bulletin, the FTC warnings and now the venture money are all responding to in sequence. A pixel that fires on a scheduling confirmation is not a hypothetical risk, it is the median finding across thousands of sites checked, sitting quietly on public pages until a journalist, a regulator or a plaintiff's lawyer goes looking.

Four obligations under the marketing-specific rule, with the exact provision that creates each one.
RequirementTriggerWhere it lives
Signed authorisation before usePHI used or disclosed for marketing45 CFR 164.508(a)(3)
Disclose paid remunerationA third party pays for the marketing message45 CFR 164.508(a)(3)(ii)
Business associate agreementA tracking or ad vendor processes PHI on your behalfHHS OCR online tracking guidance
Breach notificationUnauthorised disclosure by a non-HIPAA health app16 CFR Part 318 (Health Breach Notification Rule)

None of this argues for retreating from marketing altogether, and folkfox would be a strange messenger for that argument. It argues for treating consent, authorisation and vendor agreements as product requirements rather than legal afterthoughts, the same way a checkout flow treats payment security. A growth team that builds that discipline in from the start spends less time later untangling which sends need a signature and which patients never gave one.

Section 05

Measuring HIPAA compliant marketing as a growth lever, not a tax#

The most useful reframe in this entire story is the one Ours Privacy's investors are pricing in: compliance work that used to sit on a checklist is starting to sit on a roadmap, budgeted, staffed and measured like any other growth investment. That is a genuinely different posture from "don't get sued," and it changes what a marketing team reports to its board. Two hundred healthcare organisations paying for compliant infrastructure, and $7.4 billion moving through the wider digital health category in a single half-year, are both signals that the market has stopped treating patient-data discipline as dead weight.

We've built the infrastructure that makes prioritizing patient privacy and driving meaningful growth possible, bringing together the data, performance, and compliance healthcare marketers need in a rapidly changing world.
Jessica Holton, co-founder and CEO, Ours Privacy

Practically, that means a short, unglamorous list a marketing lead can actually track: every vendor touching patient data has a signed business associate agreement on file; every campaign that fits the legal definition of marketing has a matching authorisation on record, not just an assumption that one exists; every public-facing page has had its tags and pixels audited against the OCR guidance that still stands, since the June 2024 ruling narrowed one clause and left the rest intact; and every quarter, someone re-runs that audit, because tag managers accumulate new scripts quietly and nobody remembers adding half of them.

One number worth reporting upward#

Pick a single metric and defend it: the share of active campaigns with a current, signed authorisation on file where HIPAA actually requires one. It is boring, it survives a change in ad platform or agency, and it turns a vague anxiety about healthcare marketing regulations into a line a board can watch move in the right direction. That is what a fundable compliance category looks like from the inside, less a cost centre, more a metric with a target.

folkfox builds that discipline into healthcare marketing programmes from the first brief, pairing SEO and GEO work with the same consent and authorisation logic this piece has walked through, and the same discipline runs through our content marketing and brand strategy work for regulated clients generally. A fox that survives the open field does not do it by avoiding the field. It does it by knowing exactly which scent trails are safe to follow and which ones lead straight back to the warden's gate.

Questions

Frequently asked questions#

What does HIPAA compliant marketing actually mean?

It means using protected health information in marketing only with a signed patient authorisation or under a business associate agreement with the vendor handling it. HIPAA defines marketing narrowly, as a communication encouraging someone to buy or use a product or service, and treats it differently from routine treatment communications.

Are HIPAA compliant email marketing platforms different from normal ESPs?

Yes. Compliant platforms ship with a signed business associate agreement, segmentation that can hold protected health information without leaking it into an unapproved list, and consent tracking built into the send workflow rather than bolted on afterward. A standard consumer ESP typically offers none of these by default.

When do I need a HIPAA marketing authorization form?

Whenever protected health information is used or disclosed to make a communication that legally counts as marketing, under 45 CFR 164.508(a)(3). The two exceptions are a face-to-face conversation and a low-value promotional gift. If a third party pays for the message, the form must say so.

Did the courts strike down HIPAA's rules on tracking pixels?

Only partly. A federal judge ruled for the American Hospital Association in June 2024, but the ruling vacated one narrow clause, treating an IP address plus a visit to an unauthenticated public health page as protected data. Everything else in OCR's guidance, including rules for authenticated patient portals, still stands.

What are the main healthcare marketing regulations beyond HIPAA?

The FTC Act and the Health Breach Notification Rule both apply, and both reach health apps and websites HIPAA itself may not cover. GoodRx's $1.5 million penalty and BetterHelp's $7.8 million settlement were both FTC actions, not HIPAA enforcement, which is why compliance teams need to watch both regulators.

Why did investors just put $15 million into a HIPAA compliant marketing platform?

Ours Privacy's Series A, led by Lightbank and Health Velocity Capital, treats compliant growth infrastructure as a fundable category rather than a legal cost. With 200-plus healthcare organisations already paying customers and digital health funding running at $7.4 billion for H1 2026, investors are pricing patient-data discipline as a genuine growth advantage.

Keep reading

Read more on this topic#

Ready to make compliance a growth lever, not a bottleneck?

folkfox builds HIPAA compliant marketing programmes for regulated healthcare brands: quotable, consented, audit-ready content that still grows.