Yes. Plastic surgeons can run Meta and Google ads under HIPAA. HIPAA restricts how a practice discloses protected health information, not whether it buys advertising. The compliance line sits in three specific places: the tracking that fires behind the ad, the audience data a practice uploads to a platform, and whether every identifiable patient image carries a signed authorization.
This post is the plastic surgery version of that question, written for a practice that sells surgical consultations rather than a subscription. ClinicAds has covered the telehealth side separately, where the Cerebral and BetterHelp FTC actions set the public enforcement record. A surgical practice faces a different set of daily decisions: before-and-after galleries, named patient testimonials, procedure-specific retargeting, and a front desk that handles identified patients by phone. Here is what a plastic surgeon is allowed to run, what breaks the rule, and how a compliant account is built.
- Plastic surgeons can run Meta and Google ads under HIPAA. HIPAA governs how a practice discloses protected health information, not whether the practice advertises.
- Three things create almost all of the exposure in a plastic surgery ad account: pixels firing on consult request forms, patient lists uploaded as custom audiences, and identifiable patient images published without a signed authorization.
- Meta and Google do not sign HIPAA Business Associate Agreements, so a plastic surgery practice cannot send either platform data that ties a named person to a procedure.
- HIPAA and platform advertising policy are separate tests. A before-and-after photo can carry a valid HIPAA authorization and still be rejected under Meta's rules on body imagery.
- A compliant plastic surgery account still runs at $80 to $150 per booked consultation and 5-10x return on a $5,000 to $10,000 monthly budget. Those are agency averages, not guarantees.
Can plastic surgeons run Meta and Google ads under HIPAA?
Plastic surgeons can run Meta and Google ads under HIPAA, and thousands of practices do so lawfully. HIPAA is a disclosure rule, not an advertising ban. It restricts a covered entity from releasing protected health information without patient authorization, and an ad shown to a cold audience that has never contacted the practice involves no protected health information at all. The violation happens later in the funnel, when the practice sends the platform something that identifies a real person and connects that person to a procedure or an inquiry.
The practical test a plastic surgery practice can apply to any advertising decision is this: does this action tell Meta or Google that a specific, identifiable individual is a patient or a prospective patient of this practice? If the answer is no, HIPAA is not the obstacle. If the answer is yes, the action needs either a signed patient authorization or a redesign, because neither platform will sign a Business Associate Agreement that would allow it to receive that data.
What is a plastic surgeon allowed to advertise under HIPAA?
A plastic surgeon is allowed to advertise procedures, pricing, financing, surgeon credentials, and the practice itself to any audience the platform targeting tools support, because none of that involves a patient's protected health information. Authorization becomes necessary the moment the ad features an identifiable patient, and the setup becomes non-compliant when patient data flows to the platform. The table below sorts the decisions a plastic surgery practice actually faces into those three categories.
| Advertising action | Status under HIPAA | What it requires |
|---|---|---|
| Procedure ads to a cold, interest-based audience | Allowed | No patient information is involved; standard platform targeting only |
| Before-and-after photos of an identifiable patient | Allowed with authorization | A signed HIPAA authorization that names marketing use and is revocable in writing |
| A named or recognizable patient testimonial | Allowed with authorization | The same signed authorization; the patient controls the disclosure, not the practice |
| Retargeting visitors who viewed a homepage or procedure page | Generally allowed | No identifiers in the URL or event, and no consult-form or portal pages in the audience rule |
| A pixel firing on a consult request or intake form | Not allowed by default | Move the conversion server-side and remove identifiers before anything is sent |
| Uploading a patient list as a custom audience | Not allowed | The list itself is protected health information and no Business Associate Agreement exists with either platform |
Are before-and-after photos allowed in plastic surgery ads?
Before-and-after photos are allowed in plastic surgery advertising when the patient has signed a HIPAA authorization that specifically permits marketing use, and that authorization has to be obtained before publication rather than assumed from a surgical consent form. A standard consent to treat does not cover marketing. The authorization should name the media where the images may appear, state that the patient can revoke permission in writing, and be retained by the practice as a record. A plastic surgery practice that cannot produce the signed authorization for an image in its current ad rotation has a compliance gap, regardless of how long the photo has been running.
The second test is separate and catches practices that assume HIPAA clearance is the only hurdle. Meta and Google apply their own advertising policies, which restrict body-focused and before-and-after imagery independently of any patient permission. A photo can be fully authorized under HIPAA and still be disapproved, and repeated disapprovals put the ad account at risk. Plastic surgery practices generally get better delivery by keeping the gallery on the website, where the practice controls the rules, and running compliant creative that drives traffic to it.
| Question | HIPAA | Meta and Google ad policy |
|---|---|---|
| Who sets the rule | Federal privacy law, enforced by the HHS Office for Civil Rights | Private platforms, enforced by automated review |
| What it protects | A patient's control over their own health information | Platform advertising standards and user experience |
| Before-and-after imagery | Permitted with a signed patient authorization | Restricted; body-focused and before-and-after creative is frequently disapproved |
| Cost of getting it wrong | Civil penalties, regulatory action, patient complaints | Ad disapproval, account restriction, or permanent ban |
Can a plastic surgery practice retarget website visitors?
A plastic surgery practice can retarget website visitors under HIPAA as long as the audience does not identify individuals as patients or prospective patients to the platform. Retargeting everyone who visited the practice homepage is low risk, because a homepage visit says nothing about a person's health. Retargeting everyone who submitted a rhinoplasty consult request is a different matter, because that audience is a list of identified individuals seeking a specific procedure, and building it inside the platform hands the platform that fact.
The distinction that matters is between page-level traffic and conversion-level patient data. ClinicAds keeps procedure-page retargeting in place, since a page view is browsing behavior rather than a patient relationship, and moves everything downstream of the consult form into server-side measurement where identifiers are removed or hashed before transmission. That structure preserves the campaign optimization a practice needs while keeping the platform from ever holding a name attached to a procedure.
What breaks HIPAA in a plastic surgery ad account?
Five specific configurations account for nearly every HIPAA exposure ClinicAds finds when auditing an existing plastic surgery ad account, and four of the five are default settings someone enabled without reading what they transmit. None of them are the ads themselves. Each one is a data path that quietly sends the platform something about an identified individual, and each has a compliant replacement that preserves the measurement the practice is paying for.
- A Meta or Google pixel firing on the consult request confirmation page, transmitting the submitted email or phone number
- A patient or past-surgery list uploaded as a custom audience or a customer match file
- Procedure names or patient identifiers passed in URL query strings that the pixel then forwards
- Call tracking that records identified patient calls and syncs them to an ad platform for optimization
- A marketing vendor holding patient data with no signed Business Associate Agreement in place
How should a plastic surgery practice set up compliant ads?
A compliant plastic surgery ad setup keeps every identifier inside the practice's own infrastructure and sends the ad platforms conversion signals rather than patient records. The sequence below is the one ClinicAds runs before a new surgical account goes live, and it takes about two weeks. The economics do not suffer for it. A properly tracked plastic surgery account runs at $80 to $150 per booked consultation and returns 5-10x on a $5,000 to $10,000 monthly budget. Those figures are agency averages across active accounts, not guarantees.
Practices often expect compliance to cost them performance, and the opposite tends to happen. Server-side conversion tracking recovers bookings that browser-based pixels lose to ad blockers and privacy settings, so the account frequently reports a lower cost per booked consult after the rebuild than before it. Compliance and attribution quality are solved by the same piece of infrastructure, which is why ClinicAds treats the tracking build as step one rather than a legal formality bolted on at the end.
- Audit every pixel and tag currently firing on consult, contact, and procedure pages
- Move conversion measurement server-side through the Conversions API and hash or strip identifiers first
- Remove any patient-list custom audiences and rebuild targeting from page-level behavior
- Sign a Business Associate Agreement with the agency and any vendor touching patient data
- Collect and file a marketing-specific authorization for every identifiable patient image in rotation
- Document the setup in writing, because the record is what demonstrates the practice acted deliberately
Can plastic surgeons run Meta and Google ads under HIPAA?
Yes. HIPAA restricts the disclosure of protected health information, not advertising itself. A plastic surgery practice can advertise procedures, credentials, and pricing freely. The compliance line is crossed when the practice sends a platform data that identifies a specific person as a patient or prospective patient.
Do plastic surgeons need patient permission for before-and-after photos in ads?
Yes, when the patient is identifiable. A signed HIPAA authorization that specifically permits marketing use is required, and a surgical consent form does not cover it. The authorization should name where the images may appear and be revocable in writing.
Can a plastic surgery practice upload its patient list to Meta or Google?
No. A patient list is protected health information, and neither Meta nor Google signs a Business Associate Agreement for advertising. Uploading that list as a custom audience or customer match file is a disclosure of patient information to a party not permitted to receive it.
Is retargeting allowed for plastic surgery practices?
Page-level retargeting is generally allowed, because a visit to a homepage or procedure page is browsing behavior rather than a patient relationship. Audiences built from consult-form submissions or intake pages identify individuals as prospective patients and should be handled server-side instead.
Does HIPAA-compliant tracking hurt plastic surgery ad performance?
Generally not. Server-side conversion tracking recovers bookings that browser pixels lose to ad blockers and privacy settings, so cost per booked consult often improves after the rebuild. Compliant accounts still run at $80 to $150 per booked consultation and 5-10x on spend, which are agency averages rather than guarantees.