Every tool evaluation at a healthcare marketing team hits the same checkpoint: will the vendor sign a business associate agreement? The BAA becomes the proxy for compliance, and once it’s signed, the conversation moves on.
That’s the problem. A BAA is a contractual document. It doesn’t change how data actually flows through tracking tools, EHR feeds, and ad platforms. The risky data flows still exist whether a vendor has signed or not.
The Question That Actually Matters
For covered entities, the real test is whether the data in question qualifies as protected health information. PHI is defined as identifiable information tied to someone’s health, their care, or their payment for that care.
That definition is broader than most martech stacks are built to handle. A user ID passed to an ad platform, a session cookie tied to a condition-specific landing page, a form submission that includes an appointment request: any of these can cross into PHI territory depending on context.
Where the Exposure Lives
The article from MarTech flags three specific areas worth auditing:
- Tracking tools: client-side pixels and analytics tags that may capture identifiable health signals
- EHR feeds: data integrations between electronic health records and marketing or CRM systems
- Ad platforms: audience uploads, conversion tracking, and retargeting pools that touch patient data
The Operator Takeaway
If you run marketing for a healthcare brand or work with covered entities as an agency, the BAA is table stakes, not a finish line. The audit question isn’t “did they sign?” It’s “what data is actually moving, where is it going, and does any of it meet the PHI definition?” Those are different questions with more uncomfortable answers.
