Addiction Treatment Marketing Compliance Guide

Addiction Treatment Marketing Compliance Guide

If you run marketing for an addiction treatment center, you are operating in one of the most heavily regulated corners of advertising that exists. The same tactics that would be completely routine for a plumber, a dentist, or an e-commerce brand can trigger federal criminal liability, six-figure civil penalties, or the loss of your ability to advertise at all when you apply them to substance use disorder treatment. That is not an exaggeration, and it is not fearmongering. It is the practical reality of a field where the government has decided, with good reason, that vulnerable people seeking help deserve extra protection from bad actors.

The problem is that the rules are scattered across multiple agencies, several federal statutes, a patchwork of state laws, and private certification programs, and almost none of them were written to be read together. A marketing decision that satisfies HIPAA might still violate EKRA. An ad that passes Google’s policy review might still cross an FTC line. And a lead generation arrangement that looked fine three years ago might now be a felony in the state where your center operates.

This guide is written for the people who actually sign off on these decisions: owners, executive directors, compliance officers, and marketing directors who are personally accountable when something goes wrong. Compliance is one part of a broader addiction treatment marketing program, and the rules below shape every other part of it. The goal is not to scare you into doing nothing. It is to give you a clear, honest map of what governs your marketing, who enforces it, and how to build programs that generate patients without putting your license, your bank account, or your freedom at risk. One caveat before we start: this is an educational overview, not legal advice. These rules change, they apply differently depending on your state, your services, and your payer mix, and the only reliable way to know how they apply to your center is to work through them with qualified legal and compliance professionals.

Executive Summary

Addiction treatment marketing operates under a level of legal scrutiny that most industries never encounter. The same tactics that are routine for other businesses can trigger criminal liability, six-figure civil penalties, or the loss of your ability to advertise when applied to substance use disorder treatment. The rules are scattered across multiple federal agencies, several statutes, a patchwork of state laws, and private platform policies, and almost none of them were written to be read together. Satisfying one rule does not mean you have satisfied the others.

This guide maps the entire landscape for the people who actually sign off on marketing decisions: what governs your advertising, who enforces each set of rules, and where the real exposure lives. It covers HIPAA and 42 CFR Part 2 privacy obligations (including the February 2026 Part 2 compliance date), the hidden risk of tracking pixels on your own website, EKRA and state patient brokering laws that govern how you pay for leads, FTC rules on outcome claims and testimonials, and TCPA consent requirements for calls and texts.

The recurring theme is that no single certification or approval substitutes for the separate obligations that may apply to you. LegitScript clears you to advertise but does not immunize you from regulators. The safest path is to understand each obligation separately, build an intake and lead-handling process that holds up to scrutiny, and audit your own marketing regularly the way an investigator would, bringing in qualified healthcare counsel when criminal statutes or genuinely ambiguous questions are involved.

Table of Contents

  • Executive Summary
  • Why Addiction Treatment Marketing Carries More Legal Risk Than Any Other Vertical
  • The Rules That Actually Govern Your Marketing, and Who Enforces Them
  • LegitScript Certification: What It Covers and What It Does Not
  • 42 CFR Part 2 After the February 2026 Compliance Deadline
  • HIPAA, Tracking Pixels, and Your Website Analytics Stack
  • EKRA and State Patient Brokering Laws: How You Pay for Leads
  • FTC Rules on Outcome Claims, Testimonials, and Reviews
  • TCPA and Consent for Calls and Text Messages
  • Building an Intake and Lead-Handling Process That Holds Up
  • How to Audit Your Own Marketing for Compliance Risk
  • The Five Star Framework
  • Common Mistakes to Avoid
  • Quick Answers
  • Frequently Asked Questions
  • Conclusion

Why Addiction Treatment Marketing Carries More Legal Risk Than Any Other Vertical

Most industries face marketing risk in the form of unhappy customers, refund demands, or the occasional consumer complaint. Addiction treatment marketing carries a fundamentally different category of exposure because the underlying conduct can be criminal, not merely regulatory. The Eliminating Kickbacks in Recovery Act, passed in 2018, made certain referral and lead-payment arrangements federal crimes with penalties that include prison time. There is no equivalent statute hanging over a landscaping company that pays for leads. For the wider program these rules sit inside, see our guide on how to market an addiction treatment center.

The second reason the risk is elevated is that your patients are, by definition, protected in ways ordinary consumers are not. Their status as people seeking treatment for a substance use disorder is itself sensitive information under both HIPAA and 42 CFR Part 2. The moment a website visitor fills out a form, calls your number, or even browses certain pages, you may be handling protected health information, and the tools most marketers reach for by default (tracking pixels, call analytics, retargeting audiences) can quietly turn a routine campaign into a reportable breach.

There is also a history here that shapes how regulators behave. The treatment industry earned intense and still-growing scrutiny after well-documented abuses involving patient brokering, deceptive call centers, and centers buying and selling vulnerable people as if they were inventory. That history means enforcement agencies approach this vertical with suspicion already baked in. Google and other major platforms responded by restricting who can advertise at all, which is why certification became a gatekeeping requirement rather than a nice-to-have.

Finally, the stakes compound because multiple regulators can pursue the same conduct at the same time. A single deceptive testimonial could draw an FTC action, a state attorney general investigation, and a platform ban simultaneously. In most industries you worry about one referee. Here you are being watched by several, each with different rules and different appetites for punishment.

Key Takeaway: Addiction treatment marketing is uniquely dangerous because ordinary tactics can trigger federal criminal liability, protected-health-information breaches, and simultaneous enforcement from several agencies at once.

The Rules That Actually Govern Your Marketing, and Who Enforces Them

The compliance picture becomes far less overwhelming once you separate the distinct bodies of rules and understand that each has its own enforcer and its own logic. Broadly, your marketing is governed by federal privacy law (HIPAA and 42 CFR Part 2), federal anti-kickback and consumer protection law (EKRA and the FTC Act), federal communications law (the TCPA), a layer of state statutes covering patient brokering, telemarketing, and consumer protection, and finally the private policies of the advertising platforms themselves.

HIPAA is enforced by the Department of Health and Human Services Office for Civil Rights, which handles complaints, conducts investigations, and levies civil penalties for improper disclosure of protected health information. 42 CFR Part 2, the special confidentiality rule for substance use disorder records, is also overseen by HHS, with recent rulemaking bringing it closer to HIPAA’s framework. The FTC polices deceptive and unfair advertising, including outcome claims and fake or manipulated reviews, and it has been increasingly active on health privacy through its enforcement of the Health Breach Notification Rule.

EKRA is a criminal statute, which means the Department of Justice, through federal prosecutors, is the enforcer. That is a different animal entirely from a civil regulator. The TCPA is enforced both by the Federal Communications Commission and, powerfully, through private lawsuits, because it creates a private right of action with statutory damages per violation, which is why it fuels so much class-action litigation. On top of all of this, state attorneys general enforce their own patient brokering laws, mini-FTC acts, and telemarketing rules, and some states are far more aggressive than the federal baseline.

The platforms deserve their own mention because, in practical terms, they are often the first enforcer you encounter. Google, Microsoft, and Meta each maintain policies specific to addiction treatment advertising, and they can suspend your account long before any government agency ever looks at you. Losing platform access is frequently the most immediate and painful consequence a center faces, even though the platform is not a regulator in the legal sense.

Rule or lawPrimary enforcerWhat it coversNature of penalty
HIPAAHHS Office for Civil RightsDisclosure of protected health informationCivil penalties, corrective action
42 CFR Part 2HHSConfidentiality of substance use disorder recordsCivil penalties aligned with HIPAA
EKRADepartment of JusticeKickbacks and referral paymentsCriminal fines and prison
FTC ActFederal Trade CommissionDeceptive claims, testimonials, reviewsCivil penalties, injunctions
TCPAFCC and private lawsuitsUnwanted calls and textsStatutory damages per violation
State patient brokering lawsState attorneys generalPaying for patient referralsVaries, often criminal

Key Takeaway: Your marketing answers to at least six distinct authorities, ranging from civil privacy regulators to criminal prosecutors to the ad platforms themselves, and each enforces different rules with different consequences.

LegitScript Certification: What It Covers and What It Does Not

LegitScript certification exists because the major advertising platforms needed a way to filter out the bad actors that flooded treatment advertising during the worst years of the industry. Google will not let an addiction treatment provider run search ads without LegitScript certification, and Meta and Microsoft have adopted similar requirements. In that sense, certification functions as a platform requirement rather than a legal one: if paid search is part of your strategy, it is the ticket to entry.

What LegitScript actually does is vet your business. It reviews your licensing, your ownership, your business practices, and your compliance posture, and it monitors you on an ongoing basis rather than issuing a one-time stamp. If you are working through certification for the first time, our breakdown of what LegitScript is and who needs it covers the process in more detail. Passing tells the platforms that a third party has confirmed you are a legitimate, licensed provider operating in accordance with applicable laws and platform policies. That is genuinely valuable, and it does raise the floor for the whole industry.

What certification does not do is make you compliant with HIPAA, 42 CFR Part 2, EKRA, the TCPA, or the FTC Act. This is the single most common misunderstanding among operators. LegitScript is a gatekeeper for advertising eligibility, not a compliance program. Being certified does not resolve how EKRA applies to the way you pay for leads, and it does not settle whether your website’s tracking configuration meets privacy requirements. Regulators are not bound by LegitScript’s assessment, and centers should not assume a certification will carry weight as a defense if questions arise.

Think of it this way: certification is necessary but not sufficient. It clears you to advertise on the platforms that require it, and it signals baseline legitimacy, but every legal obligation discussed in the rest of this guide still applies to you in full after you are certified. Treating the certificate as the finish line is exactly how well-intentioned centers end up exposed.

Key Takeaway: LegitScript certification is the required entry ticket for advertising on major platforms, but it verifies legitimacy rather than legal compliance and should not be relied on as protection against HIPAA, EKRA, TCPA, or FTC enforcement.

42 CFR Part 2 After the February 2026 Compliance Deadline

42 CFR Part 2 is the federal rule that protects the confidentiality of records identifying someone as a patient of a substance use disorder program. It has historically been stricter than HIPAA, and it matters enormously for marketing because the fact that a specific individual sought treatment from you is exactly the kind of information Part 2 shields. The 2024 final rule reshaped Part 2 to align more closely with HIPAA, and the compliance date for those changes is February 16, 2026. If you have been putting off updating your practices, that deadline is the moment the updated expectations become fully operative.

The alignment with HIPAA is a mixed blessing for marketers. On one hand, it simplifies certain workflows because a single patient consent can now permit use and disclosure for treatment, payment, and health care operations under a framework that looks more like HIPAA. On the other hand, it does not loosen the core principle that identifiable substance use disorder information is highly protected. The rule continues to treat marketing use of that information as requiring clear, specific authorization, and the penalties for getting it wrong now track HIPAA’s civil penalty structure rather than the older criminal framing.

The practical implications for a marketing team are concrete. Any list of former patients, any retargeting audience built from people who inquired about treatment, any testimonial that identifies a real patient, and any communication that reveals someone’s connection to your program all sit squarely inside Part 2 territory. The fact that someone is no longer in your care does not, by itself, free that data for marketing use. In practice, that generally means documented authorization specifically covering the intended marketing use, described in plain terms the patient can actually understand. Whether a particular list, audience, or consent form clears that bar is exactly the kind of question to put to your compliance counsel rather than settle internally.

The February 2026 date is a good forcing function to review three things: how consent is captured and documented, how patient data flows between your intake, clinical, and marketing systems, and who has access to identifiable information along the way. Centers that treat Part 2 as an afterthought tend to discover that data has been leaking into their marketing stack for years, often through integrations nobody consciously approved.

Key Takeaway: After the February 16, 2026 compliance date, 42 CFR Part 2 aligns more closely with HIPAA but continues to restrict marketing use of identifiable substance use disorder information absent specific, documented patient authorization.

HIPAA, Tracking Pixels, and Your Website Analytics Stack

The most overlooked compliance risk in treatment marketing is not in the ads at all: it is in the code running on your own website. Standard analytics and advertising tools, including the Meta pixel, Google Analytics, conversion tracking tags, chat widgets, and call tracking scripts, work by collecting information about what visitors do and transmitting it to third parties. On an addiction treatment website, the mere fact that someone is browsing your pages, viewing a specific program, or starting an intake form can constitute protected health information, because it reveals a connection between an identifiable person and substance use disorder treatment.

HHS set out its position in sub-regulatory guidance on online tracking technologies, and the status of that guidance is worth being precise about: agency guidance reflects how a regulator reads the law rather than the law itself, and a federal court vacated portions of that particular guidance in 2024. The underlying HIPAA obligations did not change, and the FTC has separately pursued companies for sharing health-related browsing and inquiry data with advertising platforms. The practical picture is that a default tracking pixel on a treatment site can amount to an impermissible disclosure of protected health information to a vendor with no business associate agreement and no authorization to receive it. This is an active enforcement area rather than a theoretical one, though the precise boundaries remain contested and continue to move.

The approach most centers settle on is not abandoning measurement entirely, but being deliberate about what data leaves the site and where it goes. That means auditing every script on every page, understanding what each one actually sends, removing or restricting trackers on pages that reveal treatment intent, and using server-side or privacy-preserving configurations where possible so that identifiers and sensitive context are not shipped wholesale to advertising networks. It also commonly means executing business associate agreements where a vendor genuinely qualifies, while recognizing that many advertising platforms will simply refuse to sign one, which itself tells you they should not be receiving PHI.

The uncomfortable tradeoff is that stricter privacy configurations reduce the richness of your conversion data and can make campaign optimization harder. That is a real cost, and any marketer who tells you otherwise is not being honest. The right posture is to accept somewhat coarser measurement in exchange for staying out of an enforcement action, and to build reporting around events that do not require exporting identifiable, health-revealing information to third parties.

Key Takeaway: Standard tracking pixels and analytics tools can quietly transmit protected health information to advertising platforms, so every script on a treatment website needs to be audited and restricted rather than installed by default.

EKRA and State Patient Brokering Laws: How You Pay for Leads

EKRA reshaped how treatment centers can structure payment for patient acquisition, and it is the statute most likely to turn a marketing decision into a criminal matter. In plain terms, EKRA prohibits knowingly and willfully paying or receiving any remuneration in return for referring a patient to a recovery home, clinical treatment facility, or laboratory. It applies regardless of whether the patient is covered by a government program or private insurance, which is what makes it broader and more dangerous than the older Anti-Kickback Statute in this context.

The reason this matters so much for marketing is that many common lead generation arrangements look exactly like what EKRA prohibits. Paying a call center, a marketing agency, or an affiliate a bounty for each admitted patient, or compensating anyone based on the volume or value of patients they send you, can fall within the statute. Structures generally regarded as lower risk avoid tying compensation to referrals or admissions and instead pay for legitimate services at fair market value in ways that do not vary based on how many patients result. EKRA contains a limited employee compensation exception, but it is narrower than people assume and does not sweep in every arrangement you might wish it did.

State patient brokering laws layer on top of EKRA and, in several states, reach even further. Florida’s patient brokering statute is the best-known example, and it has been used aggressively; a number of states have their own versions with their own definitions and their own penalties, some criminal. The critical point is that satisfying EKRA does not mean you satisfy state law, and vice versa. Both can apply at once, which is why this analysis is typically done state by state for every market you operate in and every partner you pay.

Because these are criminal statutes with genuinely fact-specific application, this is the area where generic advice is least reliable and where qualified healthcare counsel matters most. Any per-lead, per-admission, or percentage-of-revenue arrangement with a marketing partner deserves a legal review before you sign, and existing arrangements that predate your awareness of EKRA deserve a fresh look. The way you pay for leads is not a marketing detail. It is potentially the difference between a legitimate expense and a felony.

Key Takeaway: EKRA and state patient brokering laws can make per-lead and per-admission payment arrangements criminal, so compensation for marketing and referrals should be reviewed by healthcare counsel and structured to avoid rewarding referral volume.

FTC Rules on Outcome Claims, Testimonials, and Reviews

The FTC governs the truthfulness of your advertising, and treatment marketing is full of claims that draw its attention. Success rate figures, recovery statistics, and outcome promises are the most obvious risk. The FTC’s stated expectation is that a specific success rate claim rests on competent and reliable scientific evidence, and in a field where outcomes are notoriously difficult to measure and define, most centers simply cannot substantiate the numbers they would like to use. An unsupported outcome claim is the kind of representation the FTC treats as deceptive, and it is one of the easier problems for a regulator to spot.

Testimonials and reviews carry their own set of rules that tightened considerably under the FTC’s updated guidance on endorsements and its rule targeting fake and manipulated reviews. Those rules target fabricated testimonials, bought reviews, selectively suppressing negative reviews while promoting positive ones, and presenting an atypical result as if it were what most patients experience. If a testimonial describes an unusually good outcome, the general expectation is that it not misrepresent what a typical patient should anticipate. Material connections between you and anyone endorsing you are expected to be disclosed clearly.

There is also the intersection with privacy: a genuine patient testimonial identifies that person as someone who received substance use disorder treatment, which means the privacy rules apply on top of the FTC’s. A testimonial can be entirely truthful and non-deceptive and still create exposure if valid authorization was never obtained. Both dimensions need attention, and whether a given authorization is sufficient is a question for compliance counsel rather than a marketing team.

The practical guidance here is conservative by necessity. Describe your programs, credentials, philosophy, and services accurately, avoid quantified outcome claims you cannot prove, present reviews honestly without cherry-picking or incentivizing them, and keep documentation of the authorization and substantiation behind anything you publish. Honest, specific, verifiable marketing is not only safer, it also tends to build more durable trust with families making an agonizing decision.

Key Takeaway: Outcome claims are expected to rest on real scientific substantiation most centers do not have, the FTC’s rules target fabricated, incentivized, and cherry-picked reviews, and a genuine patient testimonial raises privacy authorization questions on top of the advertising ones.

TCPA and Consent for Calls and Text Messages

The TCPA governs how you can call and text prospective patients, and it is one of the most litigated statutes in the country because it lets individuals sue for statutory damages on a per-message basis. Those damages stack quickly, which is why plaintiffs’ attorneys watch for violations and why a sloppy texting program can turn into a class action that dwarfs whatever revenue it generated. For treatment centers, which often rely on rapid follow-up to connect with someone in a moment of readiness, the tension between speed and consent is real.

The core requirement is consent, and the level of consent required depends on what you are doing. Calls and texts made with an autodialer or containing prerecorded or artificial voice messages, and marketing texts generally, call for prior express written consent that is clear, unambiguous, and not buried in fine print or bundled as a condition of receiving other services. Consent is generally expected to be tied to the specific number and the specific type of contact, and the burden of proving it falls on the party that placed the call or sent the text, which means documentation is everything. If you cannot produce a record of exactly how and when someone agreed to be texted, you are in a weak position if it is ever challenged.

The rules around purchased leads shifted recently, and it is worth being precise about where they actually landed, because a great deal of published compliance advice is now out of date. The FCC’s one-to-one consent rule, which would have required separate consent for each individual seller, was vacated by the Eleventh Circuit in January 2025 and formally repealed by the FCC in September 2025. The standard reverted to prior express written consent without that constraint, so a single written consent can cover multiple sellers as long as the disclosure clearly identifies who may contact the consumer. That is a lower legal bar than many articles still describe, but it does not make purchased leads safe. The burden of proving consent still falls on you, which means a vendor’s assurance is only ever as good as the underlying record, and the major wireless carriers continue to enforce their own one-to-one opt-in requirements for SMS traffic regardless of what the FCC requires. If you buy leads, insist on seeing exactly how consent was captured, confirm the disclosure named your organization, and keep your own copy of that documentation.

On the operational side, the practices centers commonly adopt are straightforward even if they require discipline. Capture consent through a clear checkbox or affirmative action that states who will contact the person and how, retain those records indefinitely, honor opt-out requests immediately and maintain an internal do-not-contact list, respect calling time restrictions, and train your intake staff so that no one is manually dialing or blasting texts to numbers that never agreed to hear from you. The convenience of aggressive outreach is never worth the exposure of a consent you cannot prove.

Key Takeaway: Autodialed calls and marketing texts generally call for documented, specific prior express written consent, the burden of proving that consent sits with you rather than your lead vendor, and every violation carries per-message statutory damages that fuel class actions.

Building an Intake and Lead-Handling Process That Holds Up

Compliance does not stop when a lead comes in; in many ways the intake and lead-handling process is where the most serious risks actually materialize. This is the stage where consent is relied upon, where sensitive information is collected, where referral relationships get paid, and where staff under pressure to fill beds can improvise their way into a violation. A marketing program can be perfectly clean at the ad level and still expose the center through what happens after the phone rings.

Start with data handling. From the first contact, you are collecting information that is protected the moment it is associated with treatment intent. In practice that means treating your CRM, your call recording system, your intake forms, and any spreadsheet a coordinator keeps as systems holding protected information, with access limited to people who need it, with vendors covered by business associate agreements where required, and with a clear understanding of what is retained, for how long, and why. Ad hoc storage of intake data in personal inboxes or unsecured tools is a breach waiting to be discovered.

Next, document consent at the moment it is given and in a way you can retrieve later. Every prospective patient record should carry a clear trail of what they agreed to: consent to be contacted, and where applicable, authorization to use their information for any purpose beyond treatment. If you cannot reconstruct, months later, exactly how a given person entered your system and what they permitted, you have a hole in your process that will not survive scrutiny.

Finally, scrutinize the humans and partners in the loop. Call centers, whether in-house or outsourced, should be trained not to make deceptive claims, not to promise outcomes, and not to steer callers based on insurance in ways that cross ethical or legal lines. Any partner you compensate should have an arrangement that has been reviewed against EKRA and applicable state law. And your staff needs a clear escalation path so that when something unusual happens, someone raises a hand rather than quietly making a judgment call that becomes the center’s liability. A defensible intake process is written down, trained, monitored, and auditable, not held in the heads of a few experienced coordinators.

Key Takeaway: Most enforcement risk lives in what happens after the lead arrives, so intake data handling, retrievable consent records, trained call handling, and legally sound partner compensation all need documented, auditable processes.

How to Audit Your Own Marketing for Compliance Risk

A self-audit is the single most useful thing an operator can do, and it does not require waiting for a regulator or spending a fortune. The point is to look at your own marketing the way an investigator or a plaintiff’s attorney would, systematically, before someone else does it for you. Approach it as a recurring exercise rather than a one-time cleanup, because your website, your vendors, and the rules themselves all keep changing.

Begin with your website’s technology. Inventory every tracking script, pixel, tag, chat tool, and call-tracking snippet running on the site, identify what data each one collects and where it sends that data, and flag anything transmitting information from pages that reveal treatment intent to a third party without a business associate agreement and proper authorization. This is usually where the fastest, highest-value fixes are found, because privacy exposure through tracking is both common and directly enforceable.

Next, review your claims and content. Read every outcome statement, success rate, statistic, testimonial, and review presentation on your site and in your ads, and ask whether you could actually substantiate each one and whether you hold valid authorization for any patient identified in your materials. Then examine your consent mechanisms for calls and texts: how consent is captured, what it actually says, how it is stored, and whether it genuinely covers the contact you are making, including any leads you purchase. After that, map how you pay every marketing and referral partner and test each arrangement against EKRA and the patient brokering laws of every state you operate in.

Document what you find, prioritize by severity, and fix the criminal and privacy exposures first because those carry the harshest consequences. Keep a written record of the audit itself, because demonstrating that you have an ongoing, good-faith compliance process is meaningful if you ever do face questions. The honest truth is that a thorough audit almost always surfaces something, even at well-run centers, and finding it yourself is vastly cheaper than having a regulator find it for you. When an issue touches criminal statutes or genuinely ambiguous legal questions, bring in qualified healthcare counsel rather than guessing. On the marketing side, working with an agency that already operates inside these constraints, the way our treatment center marketing practice does, removes a whole category of avoidable risk.

Key Takeaway: Regularly audit your own marketing the way an investigator would, starting with website tracking, then claims and authorizations, then consent records, then partner payments, and fix criminal and privacy exposures first.

The Five Star Framework

Here is a practical sequence that pulls the guide’s recommendations into a process you can actually work through, starting with the highest-stakes exposures. Treat it as a way to structure the conversation with your own legal and compliance advisors, not as a replacement for it.

1. Map Your Rules: Identify which bodies of law apply to your marketing (HIPAA, 42 CFR Part 2, EKRA, the FTC Act, the TCPA, state patient brokering laws, and platform policies) and remember that clearing one does not clear the others.

2. Audit Your Website Tech: Inventory every pixel, tag, chat widget, and call-tracking script, learn what data each one sends and where, and stop any tool from shipping treatment-intent data to third parties without a business associate agreement and authorization.

3. Fix How You Pay for Leads: Review every marketing and referral arrangement against EKRA and each state’s patient brokering law, avoiding per-lead, per-admission, or percentage-of-revenue structures, and get qualified healthcare counsel to review anything ambiguous before you sign.

4. Clean Up Claims and Consent: Remove outcome claims you cannot substantiate, present testimonials and reviews honestly with proper authorization, and capture and store TCPA consent so you can prove exactly how and when each person agreed to be contacted.

5. Document and Repeat: Harden your intake and lead-handling process so consent and data flows are written down, trained, and auditable, then treat the whole audit as a recurring exercise because your site, vendors, and the rules keep changing.

Common Mistakes to Avoid

Mistake: Treating LegitScript certification as proof of full compliance. Fix: Recognize that certification only clears you to advertise on the platforms that require it. Certification does not displace the HIPAA, Part 2, EKRA, TCPA, and FTC obligations that may apply to you.

Mistake: Running default tracking pixels and analytics on pages that reveal treatment intent. Fix: Audit every script, restrict or remove trackers on sensitive pages, use server-side or privacy-preserving configurations, and never ship identifiable health-revealing data to advertising platforms that will not sign a business associate agreement.

Mistake: Paying marketing partners a bounty per admitted patient or a percentage of revenue. Fix: Restructure compensation so it does not vary with the volume or value of patients referred, pay fair market value for legitimate services, and have qualified healthcare counsel review any arrangement against EKRA and state law before signing.

Mistake: Repurposing former patient data or intake lists for retargeting and marketing. Fix: Treat any information identifying someone as a treatment patient as protected under Part 2 and HIPAA, and obtain documented, specific authorization that plainly describes the marketing use before touching that data.

Mistake: Relying on a lead vendor’s claim that a consumer consented to contact. Fix: Remember that the burden of proving consent sits with you, not the vendor. Confirm exactly how consent was captured, verify that the disclosure named your organization, keep your own retrievable copy of the record, and check the wireless carriers’ separate one-to-one opt-in requirements before running any SMS campaign.

Mistake: Advertising success rates and outcome statistics you cannot prove. Fix: Drop quantified outcome claims unless you hold competent and reliable scientific evidence, and instead describe your programs, credentials, and services accurately.

Quick Answers

Q: Does LegitScript certification make my center compliant? No. LegitScript certification is a gatekeeper that lets you advertise on platforms like Google, Meta, and Microsoft, but it does not make you compliant with HIPAA, 42 CFR Part 2, EKRA, the TCPA, or the FTC Act. Every one of those obligations still applies in full after you are certified.

Q: Can tracking pixels on a treatment website violate HIPAA? Yes. On an addiction treatment site, the fact that someone browses a program page or starts an intake form can be protected health information. A default pixel that sends that data to an advertising platform with no business associate agreement can be an impermissible disclosure, and this is an active enforcement area.

Q: Why is EKRA such a big deal for treatment marketing? EKRA is a criminal statute enforced by the Department of Justice that prohibits knowingly paying or receiving remuneration in exchange for referring patients. It applies to both private and government-covered patients, which is why common per-lead or per-admission marketing arrangements can fall within its reach.

Q: When is the 42 CFR Part 2 compliance deadline? The compliance date for the 2024 final rule changes to 42 CFR Part 2 is February 16, 2026. The rule aligns Part 2 more closely with HIPAA, but identifiable substance use disorder information remains highly protected and marketing use still requires specific authorization.

Q: What consent do I need to text prospective patients? Marketing texts and autodialed or prerecorded calls generally require prior express written consent that is clear, specific to the number and type of contact, and not buried in fine print. The burden of proving consent is on you. A lead vendor’s consent can be valid if the disclosure clearly named your organization, but you need your own copy of that record, and wireless carriers impose their own one-to-one opt-in rules for SMS on top of the FCC standard.

Frequently Asked Questions

If I am LegitScript certified, why do I still need to worry about the other rules? Because certification and legal compliance are two different things. LegitScript vets your licensing, ownership, and business practices so platforms will let you advertise, but regulators do not defer to it. A certified center can still face a criminal EKRA prosecution over how it pays for leads, an FTC action over deceptive claims, or a HIPAA penalty over its tracking pixels. Certification clears you to advertise; it is not a substitute for the underlying obligations if questions arise.

How do I know if my website analytics are creating a compliance problem? Start by inventorying every tracking script, pixel, tag, chat tool, and call-tracking snippet on your site, then identify what data each one collects and where it sends that data. The problem exists when a tool transmits information from pages that reveal treatment intent to a third party without a business associate agreement and proper authorization. If an advertising platform refuses to sign a business associate agreement, that itself is a signal it should not be receiving protected health information.

What lead payment structures are safest under EKRA and state law? Structures generally regarded as lower risk avoid tying compensation to referrals or admissions and instead pay for legitimate services at fair market value in ways that do not vary based on how many patients result. Per-lead, per-admission, and percentage-of-revenue arrangements are the riskiest. Because EKRA is criminal and state patient brokering laws add a separate layer, every arrangement deserves review by qualified healthcare counsel in each state where you operate before you sign.

Can I use real patient testimonials in my marketing? Only if you clear two separate hurdles. First, the testimonial must be truthful and non-deceptive under FTC rules, which means no fabricated or bought reviews, no cherry-picking, and no presenting an atypical result as typical. Second, because a genuine testimonial identifies someone as having received substance use disorder treatment, using it raises authorization questions under Part 2 and HIPAA. A perfectly honest testimonial can still create exposure if proper authorization was never obtained.

Does the February 2026 Part 2 deadline make marketing easier or harder? It is a mixed picture. The alignment with HIPAA can simplify some workflows because a single patient consent can now cover treatment, payment, and health care operations. But it does not loosen the core protection: identifiable substance use disorder information still requires clear, specific authorization for marketing use, and penalties now track HIPAA’s civil structure. Use the deadline as a forcing function to review how consent is captured, how patient data flows between systems, and who can access identifiable information.

Can I rely on the consent a lead vendor says it collected? Only with verification, and the legal picture here changed recently. The FCC’s one-to-one consent rule was vacated by the Eleventh Circuit in January 2025 and formally repealed in September 2025, so a single written consent can lawfully cover multiple sellers when the disclosure clearly identifies them. That is a lower bar than much of the published compliance advice still describes. What did not change is that the burden of proving consent falls on you. Before you buy or act on any lead, confirm precisely how consent was captured, check that the disclosure named your organization, and keep your own copy of the record. The major wireless carriers also enforce their own one-to-one opt-in requirements for SMS traffic independently of the FCC.

What happens in intake that creates compliance risk? Intake is where the most serious risks actually materialize, because it is where consent is relied upon, sensitive information is collected, referral relationships get paid, and staff under pressure to fill beds can improvise into a violation. The safeguards are to treat every system holding intake data as protected, document consent at the moment it is given and in a retrievable way, train call center staff to avoid deceptive or outcome claims, ensure every paid partner survives EKRA and state law review, and give staff a clear escalation path instead of leaving judgment calls in a few coordinators’ heads.

How often should I audit my marketing for compliance? Treat it as a recurring exercise, not a one-time cleanup, because your website, vendors, and the rules themselves keep changing. Work through your website technology, your claims and testimonials, your call and text consent mechanisms, and how you pay every partner, then document what you find, fix the criminal and privacy exposures first, and keep a written record of the audit itself. Demonstrating an ongoing, good-faith compliance process is meaningful if you ever face questions.

Conclusion

The through line of this guide is that addiction treatment marketing is not governed by one rulebook but by several, each with its own enforcer and its own logic, and clearing any single one does not clear the rest. LegitScript gets you onto the platforms. HIPAA and Part 2 protect the fact that someone sought treatment from you. EKRA and state patient brokering laws shape how you can pay for patients. The FTC governs what you can claim. The TCPA controls how you reach out. Miss any one of these and a clean-looking campaign can still expose your license, your bank account, or your freedom.

The good news is that the picture becomes manageable once you work it in order: map which rules apply, audit the technology on your own website, fix how you pay for leads, clean up your claims and consent, and then document everything and repeat the exercise on a schedule. Prioritize the criminal and privacy exposures first, because those carry the harshest consequences, and accept that stricter privacy configurations may cost you some measurement richness. That tradeoff is real, and it is worth it.

A thorough self-audit almost always surfaces something, even at well-run centers, and finding it yourself is far cheaper than having a regulator or a plaintiff’s attorney find it for you. Where an issue touches a criminal statute or a genuinely ambiguous legal question, that is the moment to bring in qualified healthcare counsel rather than guessing. It is also worth saying plainly that clearing every rule in this guide is the floor rather than the ceiling, because compliance alone is not the same as ethical marketing. Honest, specific, verifiable marketing is not only the safer path; it also tends to build more durable trust with the families making one of the hardest decisions of their lives.

Disclaimer: This guide is provided for educational purposes only and should not be considered legal or regulatory advice. Laws, regulations, and platform policies change over time. Treatment centers should consult qualified legal and compliance professionals regarding their specific circumstances.

If you want a second set of eyes on whether your current marketing would hold up under a compliance review, Five Star SEO is happy to take a look. No pressure, no sales pitch. Reach out anytime at https://fivestarseo.com.

more insights

Rehab SEO Best Practices

Rehab SEO Best Practices

Rehab SEO best practices for treatment centers: E-E-A-T, level-of-care keywords, site architecture, local SEO, technical fixes, and measuring admissions.

Read more >