a detailed document that gives covered entities permission to use protected health information for specified purposes, which are generally other than treatment, payment, or health care operations, or to disclose protected health information to a third party specified by the individual.Marketing falls into the category described above.
[T]he Privacy Rule allows HIPAA authorizations to be obtained electronically from individuals, provided any electronic signature is valid under applicable law.For more details, visit HHS' Use of Electronic Informed Consent: Questions and Answers. Electronic authorization can come in many forms, such as in an opt-in button on your website or as part of an online purchase or scheduling an appointment.