Enterprise & Groups

Marketing Due Diligence Checklist for Healthcare Acquirers (2026)

When you acquire a practice, you acquire its pixels. URMC settled tracker claims for $2.85 million; Froedtert paid $2 million; Cerebral's marketing data practices drew an FTC order. Enforcement lands on whoever owns the website when the letter arrives — and after close, that's you. Yet most healthcare deal teams diligence the payer mix, the chart counts, and the lease, and never once crawl the target's website. Marketing diligence is the cheapest workstream in the deal and the only one that can surface a seven-figure federal liability with a browser.

Here is the full checklist — no form, no gate. Run it in a week per target with one marketing-literate person and read access.

How to use it

For each item: Request (what to ask the seller for), Verify (what you check yourself — never accept the answer without the check), Red flag, and Deal impact (price, indemnity, or integration cost). Score each row green/yellow/red; the reds go in the memo.

Section 1: Tracking and PHI exposure (the liability section)

1. Full tracker crawl of every domain.
Request: list of all analytics/marketing tags. Verify: crawl every page yourself — sellers don't know what's on their own sites; agencies installed things in 2019 and left. Flag anything firing on contact, appointment, patient-portal, or condition pages: Meta Pixel, TikTok, Google Ads remarketing, session recorders (Hotjar/Clarity-class), chat widgets. Red flag: any third-party tag on an intake path. Deal impact: this is inherited breach-notification and enforcement exposure — quantify it, escrow against it, and kill the tags day one post-close. (A fast self-serve pass: our free scanner at the PHI leak self-audit, and the method in Does Your Practice Website Leak PHI?.)

2. Form destinations.
Request: where every website form submission goes. Verify: submit a test on each form; trace it. Red flags: submissions stored in the website database; emailed to personal accounts; landing in tools with no BAA. Deal impact: possible historical breach requiring notification analysis — not just a cleanup task.

3. Analytics configuration.
Request: GA4 (or other) property access. Verify: whether URLs, form data, or user identifiers with health context flow to Google. Red flag: raw GA4 on condition/appointment pages with no scrubbing layer. Deal impact: remediation cost is modest; the historical exposure isn't.

4. Email/SMS marketing data.
Request: every list, its tool, and its consent provenance. Verify: BAA status of the tool; how the list was built; opt-out handling; whether messages reference conditions or treatment. Red flags: patient lists exported into a consumer email tool; texting from staff cell phones; no A2P 10DLC registration for business SMS. Deal impact: TCPA exposure is per-message; carrier deregistration kills the channel post-close.

Section 2: Vendor paper

5. BAA inventory.
Request: signed BAAs for every vendor touching patient data — CRM, forms, scheduler, call tracking, chat, email, agency. Verify: match the BAA list against the vendor list from items 1–4; the gaps are the finding. Red flag: the marketing agency itself has no BAA but receives lead data. Deal impact: every gap is an ongoing disclosure to price in.

6. Vendor security posture.
Request: SOC 2 or equivalent for material marketing vendors; subprocessor lists. Verify: does the vendor publish a live trust center, or produce a stale PDF? (What good looks like: SOC 2 + HIPAA with a continuously maintained, Drata-backed trust center like trust.pilotpractice.com, BAA standard, subprocessors published.) Red flag: nobody can produce anything. Deal impact: vendor consolidation goes in the 100-day plan; the screen to run is in MSO & PE Roll-Up Marketing Infrastructure.

7. Owned vs. resold tooling — count the BAAs.
Request: for each marketing function (tracking, forms, scheduling, call tracking, email/SMS), whether the agency runs its own platform or resells a third-party product. Verify: match invoices to vendors — a common pattern is an agency reselling Freshpaint for HIPAA tracking, so the target pays the agency fee plus a Freshpaint subscription and holds two BAAs (and two subprocessor lists) for one function. Red flags: pass-through subscriptions the seller didn't know they were paying; a resold tool whose contract terminates with the agency relationship. Deal impact: each resold layer is a vendor you inherit, a BAA to re-paper at close, and a cost line an owned single-BAA platform eliminates.

8. Agency and tool contracts.
Request: every marketing contract, term, and termination clause. Verify: who owns the work product — site, content, creative, data. Red flags: auto-renewing multi-year agency lock-in; agency owns the website; "proprietary" landing pages hosted on agency infrastructure that vanish at termination. Deal impact: real dollars and real traffic, on a timeline you don't control.

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

Section 3: Asset ownership (the "can we even take the keys" section)

9. Domains and DNS.
Request: registrar access. Verify: registrant identity, expiry dates, who controls DNS. Red flags: domain registered to the seller personally, a former employee, or the agency; expiring within 90 days. Deal impact: a domain you don't control is a website you don't own.

10. Website, hosting, CMS.
Request: admin and hosting credentials. Verify: log in; enumerate admin accounts; check backup existence and restorability; note CMS/plugin patch level. Red flags: agency-held sole admin; no backups; years-unpatched WordPress. Deal impact: hardening cost — and a soft site is a breach vector, not just tech debt (the target state: How We Build HIPAA-Compliant WordPress Sites).

11. Google Business Profiles.
Request: manager access to every location's profile. Verify: which Google account owns each listing; suspension history; duplicate listings per location; review count and rating trend. Red flags: owned by the seller's personal Gmail or a departed office manager; unresolved duplicates splitting reviews. Deal impact: GBP is often the target's single largest patient-acquisition asset; an ownership gap here is a revenue interruption at close.

12. Ad accounts.
Request: admin access to Google Ads, Meta, and any others. Verify: account ownership (seller vs. agency), policy strikes and disapproval history, whether conversion history lives in an account you're getting. Red flags: everything runs in the agency's account (history leaves with them); prior policy suspensions in a sensitive category. Deal impact: rebuilt-from-zero ad accounts perform worse for months — price the ramp.

13. Review platforms and social.
Request: credentials for every profile. Verify: admin access transfers; check review responses for HIPAA violations (confirming patient status, discussing care) — those are inherited published disclosures. Red flag: responses that acknowledge treatment details. Deal impact: cleanup plus the pattern it reveals about compliance culture.

Section 4: Performance reality (the "is the growth real" section)

14. Traffic and rankings provenance.
Request: 12 months of Search Console and analytics. Verify: is organic traffic branded (comes with the reputation) or non-branded (fragile, rankings-dependent)? Any manual actions, deindexing events, or staging clones indexed? Red flag: traffic concentrated in pages you plan to kill in a rebrand — that's a migration project, not a footnote (plan: Post-Acquisition Brand & Domain Migration).

15. Lead-to-patient math.
Request: the seller's marketing reports and, separately, new-patient counts from the PMS. Verify: do "leads" reconcile to kept appointments in the practice system — patients who actually showed, not just booked? Red flags: marketing reports counting form fills and calls with no linkage to booked patients (the growth story may be spam and wrong numbers), or CAC quoted per booked appointment at a practice with an untracked no-show rate. Deal impact: adjusts your revenue-growth assumptions directly — a 25% no-show rate silently inflates every acquisition-cost claim in the CIM.

16. Booking and phone infrastructure.
Request: how patients schedule (tools, integrations) and who owns the phone numbers. Verify: BAA on the scheduler; whether tracking numbers are portable or vendor-held. Red flags: no-BAA scheduler (the Calendly problem); tracking numbers that die at contract end — those numbers are in citations everywhere. Deal impact: number porting and booking replacement go in week one of integration.

Scoring and what happens next

Tally the reds. In our experience the same three appear in almost every practice deal: pixels on intake paths (item 1), no-BAA vendors (item 5), and personally-owned GBPs (item 11). None should kill a deal — all should shape it: price the remediation, escrow the tail risk, and put access transfer in the purchase agreement, not in a post-close email thread. A fourth pattern is rising fast as more sellers hire "HIPAA-compliant" agencies: stacked resold tooling (item 7), where the target's marketing line item quietly contains two or three pass-through subscriptions — worth a hard look before you model the synergy case, because consolidation there is one of the few day-one savings that's real.

Then hand the completed checklist to whoever runs integration — it is literally the input to the portfolio standardization playbook, and the vendor screen from item 6 is expanded in the HIPAA-compliant agency checklist.

Actually doing the marketing

Diligence tells you what you bought; the 100-day plan makes it grow. Post-close: kill the exposures, consolidate onto compliant infrastructure under one BAA, stand up EHR-integrated booking and per-location attribution, and start reallocating spend on real CAC-per-kept-appointment numbers (no-show-aware, closed in the practice system) — the full sequence lives in the enterprise pillar.

Or bring us in at LOI: PilotPractice runs this checklist on targets for acquirers, then executes the integration on a platform that's SOC 2 + HIPAA with a live trust center — so the marketing stack you inherit becomes a marketing stack you can put in your own data room. Book a demo and bring a target domain; we'll run Section 1 while you watch.

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

Let’s Discuss Your Growth

Monthly Email Blast Cardiologist Marketing Company Banner
Virtual Patient Coordinator Impact
Client: Just Go Lipo in Scottsdale, AZ
Woman in blue bikini with text 'TOP MIAMI PLASTIC SURGERY CENTER' on dark blue background
Shirtless man with sunglasses at beach with text 'Look Good, Feel Good'
Woman's face showing eye makeup with velyss logo and 'SAY IT WITH YOUR EYES' text
Revive Surgical Institute website homepage showcasing cosmetic and plastic surgery services in Miami with before and after gallery and patient testimonials
Exert Clinic Website
New! Voice AI