Marketing — HHS.gov HIPAA Guidance
Fetch status: Tier 1 (hhs.gov, direct) attempted and 403-blocked. Content below is reconstructed from search-result snippets of the live page and companion HHS pages (Privacy Rule summary, Security Rule summary), not a verified full-page fetch. Treat as directionally reliable but re-verify before raising confidence above 0.68.
Marketing Rule
The HIPAA Privacy Rule gives individuals control over whether and how their protected health information (PHI) is used and disclosed for marketing purposes. With limited exceptions, the Rule requires an individual's written authorization before PHI can be used or disclosed for marketing.
Companion Rules (same HHS "for professionals" hub)
- Privacy Rule — national standards protecting individually identifiable health information ("protected health information"); applies to health plans, healthcare clearinghouses, and healthcare providers conducting certain electronic transactions.
- Security Rule — administrative, physical, and technical safeguards for electronic PHI; complements the Privacy Rule and the Breach Notification Rule (HITECH Act).
KG Relevance
Primary-source grounding for constraint.hipaa-phi-cdp-healthcare, which currently cites secondary sources only (source.hipaajournal-com.hipaa-marketing-rules-2025, source.hipaajournal-com.hipaa-privacy-rule-2026, source.chesshealthsolutions-com.2026-hipaa-rule-updates-2025). This source corroborates the written-authorization requirement those secondary sources describe but does not yet raise the constraint's confidence — see pre-write self-check and bias_note above. A successful direct fetch or Wayback capture in a future run should supersede this node's fetch_status and raise confidence.