The HIPAA violation almost never looks like a violation. It doesn't look like a hacker or a leaked database. It looks like a merge field.
A subject line that says "Following up on your dermatology visit." A list segment named "GLP-1 patients, active." A well meaning front desk staffer who exports a spreadsheet with appointment types in it and drops it into Mailchimp because that's the tool everyone already knows. None of that feels like a compliance event in the moment. All of it can be one.
Here's what actually matters if you're sending email or text to patients.
The HHS Privacy Rule defines protected health information as information that relates to a person's health, condition, or care, and that identifies them or could reasonably be used to identify them. The full definition covers "demographic data" tied to "past, present or future physical or mental health or condition" or "the provision of health care to the individual."
In marketing terms, that means a name and email address alone is usually fine. A name and email address next to an appointment type, a diagnosis, a treatment name, or a procedure code is PHI, whether it sits in a spreadsheet, a list segment, or a merge tag inside a template. It doesn't matter that the email itself reads as friendly and routine. The classification depends on what data touched the system, not on how the message sounds.
A business associate, under HHS guidance, is anyone who performs a function on behalf of a healthcare provider that involves "creating, receiving, maintaining, or transmitting PHI." An email or SMS platform that stores your patient list and sends campaigns on your behalf fits that definition the moment PHI is involved. HHS is direct about what's owed in that case: the provider needs "satisfactory assurances, in the form of a contract," before handing that data over.
That contract is the BAA. It's not a formality or an upsell. It's the vendor accepting legal responsibility for how it handles PHI, including breach notification if something goes wrong. If a platform won't sign one, it doesn't matter how good the rest of the product is. It doesn't belong in the stack.
Getting the data handling right doesn't automatically mean you're clear to contact someone. HIPAA governs what you can do with PHI once you have permission to use it. A separate law, the TCPA, governs whether you're allowed to text or call someone at all, and it has its own consent requirements that don't overlap cleanly with HIPAA's. We've written more on the two law problem for patient texting if that's the piece you're missing. For email, the short version is that satisfying HIPAA is necessary but not sufficient. Consent is its own checklist.
A few patterns show up repeatedly in practices that get this wrong, and none of them involve anyone acting carelessly on purpose.
Every one of those is a normal, well intentioned shortcut. That's what makes them common.
PatientCampaign signs a BAA on every plan, and email and SMS both run on the same compliant infrastructure, so a campaign can reference visit history or treatment type without anyone needing to route around the platform to make it work. We put together a fuller comparison against Mailchimp and a shorter answer on Mailchimp specifically if you're auditing what you're on today. If you want to see how the segmentation and consent handling actually works, we can walk through it.