What can you say

What are the email marketing rules for clinics?

One promotional email can answer to two federal regimes at once.

Two laws land on one message. CAN-SPAM governs the email as email: a commercial message needs a working opt-out, a postal address, honest headers, and clear identification. HIPAA governs it as a health message: marketing under the Privacy Rule usually needs a prior written authorization from each recipient. Clearing one does nothing for the other.

Stop 1CAN-SPAM starts with a sorting question

CAN-SPAM, at 15 U.S.C. 7704, sorts email by primary purpose: commercial messages versus transactional or relationship messages, with the FTC's primary-purpose test deciding mixed ones. Commercial messages carry the full duty set: honest headers and subject lines, a working opt-out honored within ten business days, a valid physical postal address, and identification as an advertisement. For a clinic, a patient relationship does not make a promotional email transactional; it does not exempt a newsletter that pushes a paid service.

A commercial email message must include a clear notice of the right to decline further messages and a functioning mechanism to opt out, honored within ten business days, plus a valid physical postal address.
CAN-SPAM Act, 15 U.S.C. 7704; FTC CAN-SPAM Rule, 16 CFR Part 316Effective currentLast verified true
Stop 2HIPAA enters when the message is marketing

HIPAA works differently. If an email is marketing as the Privacy Rule defines it, a covered entity generally needs a prior written authorization from the recipient, with narrow exceptions only for face-to-face communication and a promotional gift of nominal value. A message about the recipient's own treatment or the entity's own health-related products or services is usually not marketing; it becomes marketing, needing an authorization, when it encourages a purchase and a third party pays the entity to send it.

A covered entity must obtain an authorization for any use or disclosure of protected health information for marketing, except for a face-to-face communication or a promotional gift of nominal value.
45 CFR 164.508(a)(3); definition of marketing at 45 CFR 164.501Effective currentLast verified true
Stop 3Where states change the picture

CAN-SPAM largely preempts state email statutes, so there is less variation here. The carve-out to remember: states may still reach false or deceptive email through their consumer-protection laws, and California is the example, where a materially misleading commercial email stays actionable despite preemption. HIPAA, by contrast, is a floor that state medical-privacy laws build on, so an email that clears HIPAA can still owe duties under a stricter state health-privacy statute. The safe email survives the strictest applicable rule.

StateHow it differsCitation
CaliforniaCAN-SPAM preemption leaves state authority over false or deceptive commercial email intact, and California enforces it.Cal. Bus. & Prof. Code 17529.5; 15 U.S.C. 7707(b)
WashingtonConsumer health data law can reach email that uses or shares health data beyond HIPAA's limits.RCW 19.373 (My Health My Data Act)
Most statesCAN-SPAM preempts general anti-spam statutes; HIPAA and the FTC standard set the operative floor.15 U.S.C. 7707(b); 45 CFR 164.508
Stop 4Building an email that clears both

A defensible clinic email answers both regimes. For CAN-SPAM: honest sender identification, a one-click opt-out you process, and a valid postal address. For HIPAA: either stay outside the marketing definition, own care or own services with no third-party payment, or hold a signed marketing authorization from every recipient. When a campaign promotes a paid program to a broad patient list, assume both apply and build for the stricter one. An outcome claim adds a substantiation duty, covered on our success-rate claims page.

Stop 5A line that flags, a line that passes

The scanner cannot read your authorization files, it reads the email for the pieces CAN-SPAM makes visible and the promotional framing that pulls HIPAA in.

FlagWould flag
A clinic emails its full patient list promoting a new paid weight-management program with a we-thought-you-would-want-this line, no unsubscribe link, no postal address, and no marketing authorization on file.

As a commercial message it misses CAN-SPAM's opt-out and physical-address duties, and because it promotes a service to drive purchase it may also be HIPAA marketing that needed a prior authorization, so one send can breach both regimes.

A treatment-promoting email with no opt-out and no HIPAA authorization can violate CAN-SPAM and the Privacy Rule at once. · 15 U.S.C. 7704; 16 CFR Part 316; 45 CFR 164.508(a)(3), 164.501

PassWould clear
The same email carries a working one-click unsubscribe, the clinic's postal address, and honest sender identification, and it either fits a HIPAA exception or goes only to patients who signed a marketing authorization.

It meets CAN-SPAM's commercial-email duties, and it either falls outside the HIPAA marketing definition or rests on a valid authorization, so each regime is answered on its own terms.