Notes

HIPAA-Compliant CRM: What a Clinic's Marketing Team Can Actually Use

No CRM is HIPAA compliant on its own. A CRM can be used in a HIPAA-compliant way when the vendor signs a business associate agreement, you keep protected health information inside the features that agreement covers, and you control who can see it. The logo on the pricing page tells you none of that.

Key takeaways

Contents

  1. What makes a CRM HIPAA compliant?
  2. A BAA covers features, not the whole product
  3. HubSpot and Salesforce, from their own legal pages
  4. Nine questions for any CRM vendor
  5. What belongs in a marketing CRM and what does not
  6. Where CRM setups go wrong
  7. What it costs, by route
  8. Configure what you have, switch, or keep marketing data out
  9. How I set it up
  10. Read the covered services list before the demo
HIPAA-Compliant CRM: What a Clinic's Marketing Team Can Actually Use

You are choosing a CRM for the front desk and the marketing team, or you already have one and somebody has asked whether it is allowed. The sales page says "HIPAA compliant" next to a padlock. That phrase is doing a lot of work.

I am a marketing consultant and not a lawyer. What follows is a sourced map for the conversation with your privacy officer, written from the side of the person who has to make the ad account and the CRM talk to each other without sending anything they should not.

What makes a CRM HIPAA compliant?

A CRM is used in a HIPAA-compliant way when three things are true: the vendor has signed a business associate agreement with you, protected health information is stored only in the features that agreement covers, and your own access controls, logging and staff practices meet the Security Rule. Remove any one of the three and the label means nothing.

HHS explains the contract requirement under business associates. Whether you are a covered entity at all is a separate question. A cash-pay practice that never bills insurance electronically may not be, as HHS sets out under covered entities. The FTC and state health-privacy laws can still apply.

A BAA covers features, not the whole product

Six questions about what a CRM business associate agreement covers
The answers are on the vendor's legal pages, not in the brochure.

This is the part that catches careful people. A vendor can truthfully say it signs a BAA while most of what your marketing team wants to do sits outside it. Typical limits:

Salesforce is the CRM I have built attribution in hands-on. HubSpot I describe from its own documentation. Both publish their terms. Checked on 18 September 2026. Read the current versions before you decide.

CRMBAA offered?Conditions the vendor statesSource
HubSpotYes, by accepting it inside the productEnterprise editions only. A super admin turns on Sensitive Data settings, identifies the account as a HIPAA covered entity or business associate, and accepts the Sensitive Data Terms and the BAA. PHI is permitted only in the features HubSpot lists as coveredHubSpot: store sensitive data
SalesforceYes, as a signed Business Associate Addendum arranged through your account representativeApplies only to the HIPAA covered services named in the BAA. The customer must follow Salesforce's BAA restrictions, including encrypting PHI in transit and, where within its control, at restSalesforce: Business Associate Addendum restrictions

My practical read. HubSpot's documentation describes a quicker path for a small marketing team, and the limit to watch is which tools are covered once Sensitive Data is on. Salesforce, which I know from the inside, is heavier to set up and far more configurable, which matters when you need field-level control and an audit trail across admissions, intake and marketing. In both, the click ID field and the stage history that marketing needs are ordinary data and cause no difficulty.

I am not listing other CRMs. Several advertise HIPAA support. I have not verified their terms, and a table of logos copied from other blogs is how bad decisions get made. Use the nine questions below on any of them.

Nine questions for any CRM vendor

#QuestionA good answer sounds like
1Will you sign a BAA on the plan I am buying?Yes, and here is the document
2Which features are covered services?A written list you can read before paying
3Are marketing email and SMS covered?A clear yes or no, per tool
4Are AI features covered?Named individually, with data handling explained
5Can I restrict sensitive fields by role?Field-level permissions, not only record-level
6Is there an audit log of who viewed and exported what?Yes, retained for a stated period
7What happens to PHI in support tickets and sandboxes?Covered, or explicitly kept out
8Can I add a custom text field of 255 characters that keeps upper and lower case?Yes. This is the ad click ID
9How do integrations authenticate, and can I limit what they read?Scoped access per integration

Question eight looks out of place. It is the one that decides whether your advertising can ever be judged on patients. I explain why in what a GCLID is.

What belongs in a marketing CRM and what does not

Where patient-related data should and should not travel
The CRM is the hub. The rule for every arrow leaving it: send the minimum.

Marketing and front-desk work need surprisingly little: name and contact details, how the person enquired, which service line they asked about in general terms, the pipeline stage, dates, the source and the ad click ID. That is enough to follow up, to report honestly and to tell Google which clicks became patients.

Diagnoses, clinical notes, photos, test results and treatment plans belong in your clinical system. The most reliable way to keep PHI out of places it should not be is to never put it in the CRM in the first place. The free-text notes field is where this rule usually breaks. The same applies one step earlier, on the website, which is why the enquiry form needs its own checks.

What leaves the CRM toward advertising platforms should be smaller still: a click ID, a neutral stage name and a time. I describe that design in click-ID-only conversion feeds, and the wider method in the offline conversion tracking guide.

Where CRM setups go wrong

CauseWhat actually happensHidden costWhat you seeRisk level
BAA signed, sensitive settings never switched onYou are outside the terms you signedThe BAA protects nothing you doDefault configuration, no restricted fieldsHigh
Wrong planBAA not available on your tierForced upgrade, or uncovered PHIVendor says "Enterprise only" after purchaseHigh
Automation tool connected without its own BAAPHI passes through an uncovered vendorThe cleanest CRM setup undone by a connectorA long list of connected apps nobody ownsHigh
Clinical detail typed into notesPHI spreads to every user and exportExposure grows with every recordFree-text fields full of health informationHigh
Everyone is an adminNo access control in practiceAudit log is meaninglessDozens of full-access usersMedium
Marketing email sent from an uncovered toolHealth-related messages outside the BAAA breach by newsletterCampaign lists built from treatment fieldsHigh
No click ID fieldAdvertising can never be tied to patientsYears of bidding on form fillsSource field says "website" and nothing moreMedium

The marketing email row has its own article: HIPAA-compliant marketing automation.

What it costs, by route

I do not quote vendor prices here because they change and depend on seats and editions. Ask for the price of the plan that includes the BAA, not the entry plan.

RouteTypical costTime to a defensible setupWhat it depends on
Configure the CRM you already haveStaff and admin time, possibly a plan upgradeDays for the settings, weeks for staff habits to changeWhether your plan offers a BAA at all
Move to a CRM that offers oneLicences plus migrationMonthsData volume, integrations, training
Keep the CRM PHI-free by designProcess and disciplineWeeksA clinical system that holds everything sensitive
I set up the marketing side: fields, stages, click ID, feedAudit at $500 per ad account, credited toward the first month. The build is a fixed quote from the auditScoped in the auditEntry points, call tracking, sign-off
Leave itNothing todayNeverExposure grows with every record added

Configure what you have, switch, or keep marketing data out

OptionCostTime to resultRiskWhen it makes sense
Configure your current CRM under its BAALow to mediumFastStaff drift back to old habitsYour vendor offers a BAA on your plan
Switch CRMHighSlowMigration errors, lost historyYour vendor will not sign one
Keep PHI out of the CRM entirelyLowFastDepends on discipline with free textSmall practices with a good clinical system
Do nothingNoneNoneCompounding exposureNever

A healthcare IT firm or your CRM's implementation partner is the right choice for the security configuration itself. My part is narrower: making sure the marketing data model is minimal, the click ID survives, and what leaves toward ad platforms is the smallest payload that still teaches bidding.

How I set it up

  1. I list what marketing needs from the CRM, field by field, and strike everything clinical.
  2. I add the click ID fields, text, 255 characters, case preserved, set once and never overwritten.
  3. I define three neutral pipeline stages with you that can be shared with ad platforms.
  4. I check every form, booking tool and call tracking number writes to those fields.
  5. I review connected apps with you and flag any that touch the CRM without a BAA.
  6. I build the feed to Google Ads and Microsoft Ads with a written log, and your privacy officer approves the payload.

After 30 days you can see which campaigns produce which stages. After 90 you are judging advertising on patients. It is the method behind the one result I quote: I inherited an underperforming account and rebuilt it; cost per acquisition came down by about 78% while spend grew.

AUDIT · $500 PER AD ACCOUNT

The audit covers your ad account, the tracking and the path from enquiry to booked patient, and ends with a 90-day plan. It is credited toward the first month if you continue with me.

You work with me directly. There are no account managers and no juniors.

If you want the marketing side of your CRM checked by someone who also runs the ad accounts, that sits inside my HIPAA-compliant conversion tracking work. The audit is $500 per ad account, comes with a 90-day plan, and is credited toward the first month if you continue with me. You work with me directly. Book a call or write first.

Read the covered services list before the demo

The demo will show you pipelines and dashboards. The decision is in a legal annex most buyers never open. Ask for the BAA and the list of covered services first, then the price of the plan that includes them. Keep clinical detail out of the CRM, add the click ID field on day one, and send ad platforms the minimum. If you want the marketing half of that checked, start with the audit.

Written by Lev Brovtsev, independent performance marketing consultant. I do the work myself. Last updated: September 2026.

Frequently asked questions

Is HubSpot HIPAA compliant?

HubSpot offers a BAA on Enterprise editions once Sensitive Data settings are turned on and the terms are accepted, and only for the features it lists as covered. Out of the box, on lower plans, or outside those features, it is not suitable for PHI.

Is Salesforce HIPAA compliant?

Salesforce offers a Business Associate Addendum for named covered services, arranged through your account representative, with restrictions the customer must follow, including encryption. The platform can be used compliantly. It is not compliant by default.

Do I need a BAA if I only store names and phone numbers?

If you are a covered entity and the record shows the person enquired about care, that combination can be PHI. Ask your counsel. Most clinics should assume they need one.

What does a compliant setup cost?

The main costs are the plan that includes the BAA and the time to configure it properly. On the marketing side my audit is $500 per ad account and the build is quoted from it. The expensive route is migration, which is only needed when your vendor will not sign.

Can my team set this up without help?

The BAA acceptance and basic settings, usually yes. Field-level permissions, integration review and the advertising feed benefit from someone who has done them before.

Does connecting an automation tool break compliance?

It can. Any tool that reads PHI from the CRM is a business associate and needs its own agreement. Limit what each integration can read and keep a list of who owns it.

Who does the work?

On the marketing side, I do: the data model, the click ID, the stages and the feed. Security configuration belongs to your IT or implementation partner. Nothing I do is handed to a junior or subcontracted.

How do I verify it myself?

Find the signed BAA. Open the covered services list and check it against the features you use. Open ten records and read the notes field. Open the connected apps list and ask who owns each one.

Related

Dental PPC ConsultantDental SEO That Produces Implant Patients, Not PDFsDental Implant Marketing for 5-Figure Cases