Refill reminders are not considered marketing under HIPAA if they concern a drug currently prescribed to the patient if the remuneration involved is reasonable enough to cover costs. However, any communication that extends beyond a current prescription or involves unreasonable remuneration requires explicit patient authorization.
Under HIPAA's Privacy Rule, marketing refers to communication that encourages the recipient to purchase or use a product or service. However, HIPAA does make an exception for refill reminders.
Marketing specifically excludes refill reminders or communications about a drug "currently being prescribed for the individual", as long as the covered entity’s financial remuneration is "reasonably related to the covered entity’s cost of making the communication" (45 CFR 164.501).
The HHS explains that providers should use the following criteria to determine whether a communication falls within the refill reminder exception to marketing:
1. If the communication is about “a currently prescribed drug or biologic.”
2. “Whether the financial remuneration is reasonably related to the covered entity’s cost of making the communication.”
Communications that meet the refill reminder exception include:
However, HIPAA does not permit the following types of communications about medications without patient authorization:
Using the HHS guidelines, remuneration can be accepted as long as it covers reasonable direct and indirect communication costs like "labor, materials, and supplies, as well as capital and overhead costs".
Financial consideration does not include non-financial or in-kind benefits, such as third-party supplies or equipment.
If a pharmacy uses HIPAA compliant emails for refill reminders to encourage patients to take their prescribed drugs, and the pharmacy is paid by the pharmaceutical manufacturers to cover their reasonable communication costs.
Another example is insulin pump manufacturers paying a pharmacy a reasonable fee to securely email information about the pumps to diabetic patients.
Learn more: HIPAA compliant email marketing
Yes, HIPAA allows providers to use compliant email marketing to send refill reminders for prescriptions that have lapsed within the last 90 days. These communications fall under the "refill reminder" exception and do not require patient authorization if payment received is limited to covering the cost of sending the reminder.
Yes, adherence reminders, which encourage patients to take their medications as prescribed, are allowed without authorization if they meet HIPAA’s refill reminder exception.
Yes, secure email solutions like Paubox are designed to be user-friendly and integrated into existing email workflows for healthcare providers. For patients, accessing encrypted emails is as simple as opening a regular email without additional login credentials or portals.