Internal hosts with a one-to-one static translation will be able to PPTP out through the PIX, only PAT'd hosts will have the problem. You will need to allow GRE into these hosts with an access-list, since the PIX won't open up a hole for this since it isn't a TCP/UDP protocol. Something like:
> access-list inbound permit gre any host
> access-group inbound in interface outside
The PPTP (TCP 1723) packets will automatically be allowed back in, so just the static and the GRE ACL is all that's needed.