What can you say
What are the email marketing rules for clinics?
One promotional email can answer to two federal regimes at once.
Two laws land on one message. CAN-SPAM governs the email as email: a commercial message needs a working opt-out, a postal address, honest headers, and clear identification. HIPAA governs it as a health message: marketing under the Privacy Rule usually needs a prior written authorization from each recipient. Clearing one does nothing for the other.
CAN-SPAM, at 15 U.S.C. 7704, sorts email by primary purpose: commercial messages versus transactional or relationship messages, with the FTC's primary-purpose test deciding mixed ones. Commercial messages carry the full duty set: honest headers and subject lines, a working opt-out honored within ten business days, a valid physical postal address, and identification as an advertisement. For a clinic, a patient relationship does not make a promotional email transactional; it does not exempt a newsletter that pushes a paid service.
A commercial email message must include a clear notice of the right to decline further messages and a functioning mechanism to opt out, honored within ten business days, plus a valid physical postal address.
HIPAA works differently. If an email is marketing as the Privacy Rule defines it, a covered entity generally needs a prior written authorization from the recipient, with narrow exceptions only for face-to-face communication and a promotional gift of nominal value. A message about the recipient's own treatment or the entity's own health-related products or services is usually not marketing; it becomes marketing, needing an authorization, when it encourages a purchase and a third party pays the entity to send it.
A covered entity must obtain an authorization for any use or disclosure of protected health information for marketing, except for a face-to-face communication or a promotional gift of nominal value.
- CAN-SPAM, the email as emailApplies when the primary purpose is commercial. Demands honest headers, an opt-out honored within ten business days, a postal address, and ad identification. 15 U.S.C. 7704.
- HIPAA, the email as a health messageApplies when the content is marketing under the Privacy Rule. Demands a prior written authorization from each recipient, narrow exceptions aside. 45 CFR 164.508(a)(3).
CAN-SPAM largely preempts state email statutes, so there is less variation here. The carve-out to remember: states may still reach false or deceptive email through their consumer-protection laws, and California is the example, where a materially misleading commercial email stays actionable despite preemption. HIPAA, by contrast, is a floor that state medical-privacy laws build on, so an email that clears HIPAA can still owe duties under a stricter state health-privacy statute. The safe email survives the strictest applicable rule.
| State | How it differs | Citation |
|---|---|---|
| California | CAN-SPAM preemption leaves state authority over false or deceptive commercial email intact, and California enforces it. | Cal. Bus. & Prof. Code 17529.5; 15 U.S.C. 7707(b) |
| Washington | Consumer health data law can reach email that uses or shares health data beyond HIPAA's limits. | RCW 19.373 (My Health My Data Act) |
| Most states | CAN-SPAM preempts general anti-spam statutes; HIPAA and the FTC standard set the operative floor. | 15 U.S.C. 7707(b); 45 CFR 164.508 |
A defensible clinic email answers both regimes. For CAN-SPAM: honest sender identification, a one-click opt-out you process, and a valid postal address. For HIPAA: either stay outside the marketing definition, own care or own services with no third-party payment, or hold a signed marketing authorization from every recipient. When a campaign promotes a paid program to a broad patient list, assume both apply and build for the stricter one. An outcome claim adds a substantiation duty, covered on our success-rate claims page.
The scanner cannot read your authorization files, it reads the email for the pieces CAN-SPAM makes visible and the promotional framing that pulls HIPAA in.
A clinic emails its full patient list promoting a new paid weight-management program with a we-thought-you-would-want-this line, no unsubscribe link, no postal address, and no marketing authorization on file.
As a commercial message it misses CAN-SPAM's opt-out and physical-address duties, and because it promotes a service to drive purchase it may also be HIPAA marketing that needed a prior authorization, so one send can breach both regimes.
A treatment-promoting email with no opt-out and no HIPAA authorization can violate CAN-SPAM and the Privacy Rule at once. · 15 U.S.C. 7704; 16 CFR Part 316; 45 CFR 164.508(a)(3), 164.501
The same email carries a working one-click unsubscribe, the clinic's postal address, and honest sender identification, and it either fits a HIPAA exception or goes only to patients who signed a marketing authorization.
It meets CAN-SPAM's commercial-email duties, and it either falls outside the HIPAA marketing definition or rests on a valid authorization, so each regime is answered on its own terms.
Sources
Pre-Trip is a rigorous screen, not legal advice. Counsel decides; we help you arrive prepared.