The list that matters
Ask an admissions director where last month's census came from and the answer is rarely a form fill. It is a therapist who has referred to you for six years, a hospital case manager, an interventionist, a former patient's family. Those relationships are held by phone and by showing up, and email is what keeps you in the room between visits.
So the referral list gets built and segmented first. What a discharge planner needs from you is different from what a private-practice therapist needs, and both need something different from a family. share of admissions that come from professional referral sources — pull from the CRM
The second list is people who inquired and did not admit. They raised their hand, they gave you contact information, and in most facilities nobody follows up past two calls. Those sequences bring back admissions at a cost nothing else touches, because the lead was already bought and paid for.
What you can legally put in an email
HIPAA permits unencrypted email to a patient if the patient has been warned about the risk and still prefers it. That covers direct communication. Marketing to that same person is a different question, and marketing communications generally require written authorization.
42 CFR Part 2 is stricter than HIPAA and it is the rule most agencies have never read. It protects the fact that a person received substance use treatment, which means a list of your former patients is itself protected. Mailing that list requires written consent that names the disclosure. A batch send with addresses in the wrong header field tells every recipient that everyone on the list was in treatment, and that is a breach with names attached.
So patient and alumni mail runs on documented consent through a platform that will sign a business associate agreement. Referral source and general subscriber mail carries no PHI at all and can run on ordinary tooling. confirm whether the current email platform will sign a BAA — several mainstream platforms will not
Deliverability decides the rest
Since February 2024, Google and Yahoo require bulk senders to authenticate with SPF and DKIM, publish a DMARC record, offer one-click unsubscribe, and keep spam complaints under 0.3%. Mail that fails those checks does not bounce. It lands in spam quietly, which is worse, because the open rate looks like a content problem and you spend three months rewriting subject lines.
Purchased lists are the fastest way to burn a sending domain, and in this industry they are also a legal problem. We never buy them. Lists get built from real relationships and real inquiries, and dead addresses get removed rather than mailed until they hard bounce.
CAN-SPAM sits on top of all of it: accurate sender information, a real physical address, and an unsubscribe that works within ten business days.