GreyMatters

 

The Latest Hospital Digital Marketing Articles

GreyMatters is your hospital digital marketing guide, with articles on hospital digital marketing best practices, trends, updates and more.

 

Hospital Marketers: Get Some Free Legal Advice at #HCIC26

This article was written for Greystone.Net by Jessica Levco, a freelance healthcare writer and event strategist. 

photo of Richard Chapman

Nobody wants their hospital to wind up on Becker’s Hospital Review for a data breach, ransomware attack or cybersecurity lawsuit.

But one of the reasons why this could happen is that most hospital marketers think of their tech stack in terms of ad placement, conversion rates and campaign performance. Richard Chapman, CEO of Cyndelos Inc. and a former Chief Privacy Officer at University of Kentucky HealthCare, wants them to see it as one of the largest unmanaged legal exposure points in the entire health system.

At #HCIC26, he’s going to lead this discussion, “From Campaign Optimization to Litigation Exposure: How the Marketing Stack Became a Legal System,” specifically geared for healthcare marketers who are responsible for technology decisions that directly impact patient data without realizing the legal and regulatory implications. The same tools used to improve targeting, personalization and campaign performance can create significant privacy, compliance and litigation exposure if not properly governed.

Chapman believes marketers should have a seat at the governance table because they often own the technologies, vendor relationships and website experiences where privacy risk originates. Finding the right balance between understanding the patient journey and protecting patient privacy is not only good compliance practice, but also good business practice that builds trust with consumers.

For example, when a hospital buys a new EMR or financial platform, it goes through rigorous vendor due diligence for security evaluations, risk assessments and IT sign-off. Marketing tools rarely get the same treatment.

That's a problem because modern marketing platforms, analytics tools, session replay technologies, pixels, chatbots and tracking scripts often collect information from individuals who may already be patients. Unlike many traditional enterprise systems, these tools can be deployed quickly and sometimes without the same level of legal, privacy, security and governance review. As a result, organizations may not fully understand what data is being collected, where it's being shared or their potential liability.

“There are limited evaluations of the marketing tools that people are using today, but this is a problem because marketing platforms create a bidirectional conversation with website visitors,” Chapman says. “If a patient record gets out to anybody, all that data is exposed to hackers.”

Chapman says that the tools driving your campaign results are the same tools creating your legal exposure. Right now, very few marketers are auditing them the way they audit everything else. Here’s what you can do to help protect your hospital from legal woes:

Introduce yourself to your legal team. Marketing and legal often operate as if they’re part of different organizations entirely. Don’t wait until a crisis to establish a relationship, Chapman says. Establish the common language and understanding of each other before the problems arise.

Focus on your inventory. Most health systems underestimate how many websites, portals and third-party tools are running under their name. “We had one client who cleaned up their main website very well, but didn’t think about all the links they had out there for ‘Pay My Bill,’ the portal or other sites connected to a healthcare site,” Chapman says. “Health organizations are potentially liable for third-party trackers just as they are on the main healthcare website.”

Get your cookie banners and consent language right. California’s Invasion of Privacy Act requires websites to collect authorization before using visitor data for marketing or advertising. Technology enables visitors from anywhere in the world to find your hospital and the state privacy laws are focused on consumer rights. “Find out if your privacy policy is matching what you’re doing,” Chapman says.

Understand your multi-state liability. While many of the lawsuits receive attention in California, health systems should not assume they are insulated simply because they operate elsewhere. Patients routinely access healthcare websites across state lines, and state privacy laws continue to expand. Organizations frequently find themselves subject to multiple jurisdictions simultaneously. Twenty-three states now have relevant privacy laws, and health systems that span state borders — think a North Carolina hospital with facilities in Virginia or South Carolina — face overlapping and sometimes conflicting requirements. “You need to start to figure out where the liability is,” Chapman says. “If you’re running a centralized marketing program, you’ve got to figure out your governance structure and how to adapt.”

Ask questions. Here are a few questions Chapman wants you to take home with you:

  • Do we know every tool collecting information from visitors across our websites, patient portals, scheduling tools and bill-pay platforms?
  • Could we explain to a regulator exactly where visitor information is being transmitted?
  • Have our legal, privacy, security and marketing teams reviewed these technologies together?
  • Do our privacy notices accurately reflect what our technologies are doing today?

“Healthcare marketers don't need to become lawyers,” Chapman says. "But they do need to understand that the technologies driving growth, engagement and patient acquisition are also creating risk. The organizations that succeed will be the ones that bring marketing, privacy, security and legal teams together before a problem occurs rather than after."

We hope you’ll join us at #HCIC26, Oct. 25-28 in Orlando. Learn more.