HIPAA and Market Research: What You Can and Can’t Do
HIPAA market research - here's what you can and cant do.

A pharma brand manager asks if she needs a business associate agreement to test three taglines with people who have type 2 diabetes. A healthtech founder asks if he needs patient authorization to survey users about his new app. The answer to both, most of the time, is no.
HIPAA market research questions come up because “patient” and “health” in the same sentence make people assume HIPAA is automatically involved. It isn’t. HIPAA regulates covered entities (health plans, health care providers, and clearinghouses) and their business associates. Most market research firms are neither. This piece covers when HIPAA actually applies to research, when it doesn’t, and where the two get confused: recruiting through a provider, buying a patient list, and using AI-generated respondents instead of real patient records.
Does market research need to comply with HIPAA?
Only if a covered entity or its business associate is involved, and only if protected health information (PHI) changes hands. Put another way: market research is HIPAA compliant by default in the sense that most of it was never subject to HIPAA in the first place, because no covered entity ever disclosed PHI into the project. The HIPAA Privacy Rule applies to covered entities, defined as health plans, health care clearinghouses, and providers who transmit health information electronically for standard transactions, and to business associates who perform work for those entities involving PHI, according to HHS. If an entity is neither, HIPAA doesn’t apply to it at all.
A market research firm that recruits self-identified patients through an opt-in panel, asks them to describe their own condition in their own words, and never touches a covered entity’s records is outside HIPAA’s reach. A firm that receives a patient list from a hospital to run a satisfaction survey on the hospital’s behalf is a different story, and usually becomes a business associate.
What counts as PHI in market research?
PHI is individually identifiable health information created, received, or maintained by a covered entity or business associate: a name, a diagnosis, a treatment date, tied to a specific person. It only becomes PHI when it passes through a covered entity’s hands. The same diagnosis, volunteered directly by a person who found your survey on Instagram, is just data you collected, not PHI.
HIPAA sets 18 specific identifiers that make health data individually identifiable under the Safe Harbor method: things like name, geographic subdivisions smaller than a state, dates tied to an individual, phone numbers, and medical record numbers. Strip all 18, and the data is generally no longer PHI, per HHS’s de-identification guidance (the covered entity also has to have no actual knowledge that what’s left could still identify someone). This is the standard most market researchers reach for when a project starts with a covered entity’s data and needs to leave the building.
Can you do patient research without PHI?
Yes, and most commercial healthcare market research already does. Three approaches keep PHI out of the picture entirely, which is also how most teams protect patient research privacy without a legal team on standby:
- Direct, opt-in recruitment. Panels and communities where people self-report their condition to join a study. No covered entity discloses anything; the person is the source.
- De-identified or limited data sets. Data that started as PHI inside a covered entity, then had identifiers stripped under Safe Harbor or Expert Determination before it reached the researcher.
- Synthetic respondents. Personas generated from aggregate behavioral and market patterns rather than any single real patient’s chart, often run through a concept testing platform built for exactly this kind of early-stage validation, so there’s no individually identifiable health information to begin with.
Each avoids the compliance overhead of a business associate agreement, because none of them involves a covered entity disclosing a real patient’s PHI to a market researcher.
What are the HIPAA rules for research?
Here’s where “research” gets confusing: HIPAA’s research provisions exist, but they’re built for clinical and academic research under IRB oversight and informed consent, not commercial market research. Under 45 CFR 164.512(i), a covered entity can disclose PHI for research without individual authorization only through specific, documented paths: an IRB or Privacy Board waiver, or a review that’s strictly preparatory to research where the PHI never leaves the covered entity, or research limited to decedents’ records. A separate provision, 164.514(e), allows a limited data set under a signed data use agreement.
A commercial market research project pitching a new drug’s messaging generally doesn’t qualify for any of those paths, because it isn’t the kind of “research” the Privacy Rule’s research exception was written for. That’s part of why most agencies steer commercial projects toward authorization, de-identification, or self-reported data instead of trying to invoke the research exception, and why healthcare research compliance for a commercial study looks different from compliance for a clinical trial.
When does a market research firm become a business associate?
The moment a covered entity hands over PHI so the firm can perform a function on the entity’s behalf, like running a patient satisfaction survey, segmenting a physician list, or analyzing claims data. At that point the firm is a business associate under 45 CFR 160.103, and needs a signed business associate agreement before it touches the data. Market research vendors that work with healthcare clients regularly find themselves here even when they didn’t set out to enter a regulated market, which is a known trap in the industry.
Researchers are a specific carve-out. A researcher hired to perform research on a covered entity’s own behalf isn’t automatically a business associate, per HHS guidance, because research isn’t one of the functions the business associate definition covers. But that carve-out is narrow and depends on the activity genuinely being research under HIPAA’s definition, not commercial market testing dressed up as a study. When in doubt, a signed business associate agreement is the safer default, not the workaround.
What HIPAA-safe research methods actually work?
| Method | Involves real PHI? | Typical trigger | Compliance need |
|---|---|---|---|
| Recruit through a provider’s patient list | Yes | Hospital or health plan shares records to help recruit | BAA, or authorization, or IRB waiver |
| Buy or rent a patient list from a data broker | Depends | Broker may or may not be a covered entity or BA | Authorization almost always required; high risk |
| Opt-in panel, self-reported condition | No | Person volunteers their own information | None, if truly self-sourced |
| De-identified or limited data set | No (post-processing) | Covered entity strips identifiers before sharing | Data use agreement for limited data sets |
| Synthetic respondents built from aggregate patterns | No | No real patient record is the source | None, but verify the vendor’s data provenance |
The riskiest row on that table is the second one. Purchased patient lists sit in a gray zone: if the seller is a covered entity or business associate, HIPAA’s rules on selling PHI and on marketing apply, and HHS is explicit that a health plan or provider can’t sell a patient list to a third party for that party’s own use without patient authorization. Skipping this check is how a legitimate-looking research project turns into a HIPAA violation nobody saw coming.
What’s the cheapest way to do HIPAA-safe market research?
Self-reported, opt-in surveys are usually the cheapest option, close to free if you’re recruiting from an audience you already have (your email list, your app’s users, a subreddit) rather than paying a panel for incentivized reach. The next cheapest tier is synthetic respondents, which run on a flat subscription instead of per-participant incentive costs that scale with sample size; Articos, for example, starts at $79 a month for 10 studies. That compares with traditional research agencies, where individual studies commonly run $2,000 to $10,000 or more once recruitment, moderation, and incentives are added up.
The expensive part of traditional healthcare market research usually isn’t the PHI compliance itself; it’s the recruitment. Finding real patients with a specific diagnosis, verifying them, scheduling interviews, and paying no-show-adjusted incentives is what drives cost up, HIPAA aside. If your project doesn’t strictly require real patient records, cutting PHI out of the workflow tends to cut cost at the same time.
Should you combine synthetic and human research instead of choosing one?
For most projects, yes. Synthetic respondents are a fast, cheap way to pressure-test messaging, positioning, and early concepts before anything ships, precisely because there’s no PHI and no recruitment lag. But synthetic personas are a model of patterns in existing data, not a replacement for the regulatory-grade evidence a clinical trial, outcomes study, or FDA submission requires.
A workable split: use synthetic research to kill the weak ideas early and narrow down to two or three concepts worth testing further, then bring in IRB-governed patient research, a compliant panel, or a specialist firm for the claims that actually need real patient data behind them. That sequencing keeps the expensive, slow, PHI-sensitive research reserved for the questions that genuinely require it.
Is synthetic data HIPAA compliant?
Properly built synthetic data sits outside HIPAA entirely, because it was never individually identifiable health information about a real person in the first place. If a persona is generated from aggregate patterns in market and behavioral data rather than assembled from one real patient’s chart, there’s no de-identified patient data or PHI for HIPAA to regulate at all.
That structural position is different from “synthetic data” made by lightly perturbing real patient records, which can still carry re-identification risk and typically needs Expert Determination review before anyone treats it as safe. The distinction matters more than the label. Vendors should be able to explain, specifically, whether their synthetic personas are built from real, individually identifiable records or from aggregate patterns with no single real patient behind any one persona.
Articos builds synthetic personas from aggregate behavioral and market data rather than real patient charts, which is why running concept or message testing through Articos doesn’t require a BAA in the way pulling PHI from an EHR would. To be direct about the limit: Articos does not currently offer a signed business associate agreement, so it isn’t the right tool for a project that requires disclosing or processing real, identifiable PHI from a covered entity’s systems. F
or messaging, positioning, or concept validation where the goal is understanding how a target audience reacts rather than analyzing a specific patient’s chart, synthetic respondents deliver a read in under 30 minutes without any PHI ever entering the workflow. Teams specifically focused on message and tagline testing, like the pharma brand manager from the top of this piece, sometimes compare this approach against panel-based tools like Wynter, which tests copy with a verified human B2B panel and turns results around in 12 to 48 hours; the tradeoff is real human judgment against speed and cost.
What we found when we tested this message in Articos
We ran the exact question behind this piece through Articos: 12 synthetic interviews across pharma brand managers, healthtech founders, market research leads, and a healthcare data privacy officer, testing whether leading with “HIPAA-safe synthetic AI respondents” and an open “no BAA yet” admission would land the way we hoped.

The verdict: leading with “HIPAA-safe” reads as overreach. One participant said a phrase like that makes them “immediately want the boundary behind that phrase,” and another flagged it as language that’s “almost always doing too much work.” What held up instead was narrower and more specific: no PHI ingestion, no patient-level outputs, concept and messaging work only, backed by something concrete like a data-flow diagram or a no-PHI attestation rather than reassurance on its own. Being upfront about not having a signed BAA helped, but only when it was tied to a specific, scoped explanation of what that limits, not offered as a blanket reassurance.

That’s the posture this piece has tried to take throughout: no unqualified “HIPAA-safe” claim, and the earlier note about the missing BAA attached to exactly what it limits rather than dressed up as a trust badge.
How to choose the right HIPAA market research approach
Start with where the data comes from. That matters more than what the project is called. If real patient records from a covered entity are involved at any point, work backward from a business associate agreement, an authorization, or a properly executed data use agreement, and get compliance or counsel involved early. If the people in the study are volunteering their own information, or the respondents are synthetic and built from aggregate patterns rather than real records, most of HIPAA’s requirements simply don’t apply.
Traditional, IRB-governed patient research still matters, and synthetic respondent research isn’t a substitute for it when a study specifically requires identifiable clinical or claims data, longitudinal outcomes tracking, or regulatory submission-grade evidence. For earlier-stage questions, like the messaging, positioning, and concept reactions covered by a market research consulting engagement, the underlying data was never PHI to start with, so that overhead doesn’t need to exist.