Is HubSpot HIPAA Compliant? (The Answer Changed — Most Articles Are Wrong) (2026)
If you Googled this question, most of what you found is wrong.
The top-ranking articles — many last touched in 2022 or 2023 — say flatly that HubSpot is not HIPAA compliant, won't sign a BAA, and prohibits health data. That answer expired in June 2024, when HubSpot rolled out sensitive-data support, including the ability to store PHI and a Business Associate Agreement, on qualifying Enterprise (and some Professional) subscriptions. In 2026, the accurate answer is: HubSpot can be HIPAA compliant — on the right tier, with the right configuration, for the right subset of features.
That nuance matters, because the cost of getting it wrong keeps going up. The University of Rochester Medical Center paid $2.85 million over marketing-related disclosures; Froedtert Health paid $2 million in litigation tied to tracking data flowing to marketing vendors; Cerebral's ad-platform data sharing became a federal case study; and Klaviyo's deplatforming of telehealth senders proved that even the vendors now enforce the line. Practices are getting hit from both directions — regulators for the data they leak, and platforms for the data they host.
What actually changed in June 2024
HubSpot introduced sensitive data support: a feature set that lets eligible customers designate specific CRM properties as sensitive (including health data), with additional encryption and access controls, and — the part that matters legally — HubSpot will enter into a BAA with those customers.
Key facts as they stand in 2026:
- It's tier-gated. Sensitive-data support requires Enterprise-level subscriptions (with limited availability on certain Professional tiers). Starter and free HubSpot accounts remain exactly as non-compliant as the old articles say.
- It's opt-in and property-scoped. You must enable sensitive data support and explicitly mark which properties hold PHI. PHI stored in unmarked fields, notes, or email bodies is outside the protected configuration.
- The BAA covers designated features, not the whole platform. HubSpot's BAA and documentation delineate which hubs and tools are in scope. Features outside that boundary — some integrations, certain beta tools, some tracking features — are not covered.
- You still shoulder the covered-entity obligations. A BAA makes HubSpot a permissible vendor. It does not grant you HIPAA marketing authorization, configure your access roles, or stop your team from pasting a patient's history into an unprotected note field.
So when a competitor's 2023 article tells you "HubSpot refuses to sign BAAs," it's describing a company policy that no longer exists. Check the date on your sources — in healthcare compliance, stale is the same as wrong.
Where HubSpot still bites practices in 2026
Signing the BAA is step one of maybe ten. The failure modes we see in real practice audits:
1. The tracking code is its own HIPAA problem
HubSpot's power comes from its tracking script — page views, form fills, email clicks, all stitched to a contact record. On a medical website, that means HubSpot is recording that an identified patient viewed /services/erectile-dysfunction/ and then booked. Inside a BAA-covered configuration that can be defensible; but the same script also historically fed data to ad-network integrations and connected apps that are not under the BAA. Every connected app in your HubSpot ecosystem needs its own PHI analysis — the BAA doesn't flow downstream.
2. Free/Starter accounts inherited patient data
The most common real-world scenario: the practice started on free HubSpot in 2021, upgraded over time, and never enabled sensitive-data support. Years of patient contacts, form fills, and email logs sit in a configuration with no BAA coverage. Upgrading your bill doesn't retroactively protect that data — you have to enable the feature, classify the properties, and honestly assess the historical exposure.
3. Forms that post PHI client-side
HubSpot forms submit through HubSpot's endpoints with the visitor's browser talking directly to HubSpot — along with cookies, click IDs, and referrer URLs that can carry condition keywords from your ad campaigns. Even under a BAA this deserves scrutiny, because the metadata often travels further than the form contents. (Our take on the safer architecture: forms should post server-to-server, stripped of tracking metadata — see Is Gravity Forms HIPAA Compliant? The Server-to-Server Architecture.)
4. Marketing email ≠ authorized marketing
HubSpot will happily let you email every contact whose record contains PHI. HIPAA's marketing rule still requires written patient authorization for most promotional communications made using PHI. No CRM enforces that for you.
5. The price of admission
Enterprise HubSpot with the hubs a practice actually needs commonly runs $20,000–$60,000+ per year before onboarding fees — and you're buying a generalist B2B platform, then paying consultants to bend it toward healthcare. For a 3-provider practice, that's a lot of money for a tool that still leaves the compliance configuration on your plate.
See it live on your own practice
EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo
The honest verdict
| Scenario | Verdict |
|---|---|
| HubSpot Free / Starter with patient data | Not compliant. No BAA available. Migrate or upgrade + reconfigure. |
| Enterprise tier, sensitive-data support enabled, BAA signed, properties classified, integrations audited | Can be compliant for covered features |
| Any tier, PHI in notes/emails outside designated properties | Gray-to-red zone — outside the protected configuration |
| Using HubSpot's ad/tracking integrations to sync patient events to ad platforms | Separate violation regardless of BAA |
HubSpot deserves credit: it did what Mailchimp and Klaviyo haven't — see Is Mailchimp HIPAA Compliant? for the contrast. But "can be compliant with an Enterprise contract and careful configuration" is a very different sentence from "is compliant."
The HubSpot-for-healthcare checklist (ungated)
If you're going to run a practice on HubSpot in 2026, verify all of these:
- Subscription tier qualifies for sensitive data support — confirm in writing with your HubSpot rep.
- BAA signed and countersigned, and you've read which features it covers.
- Sensitive data support enabled, and every property that can hold PHI is classified as sensitive.
- SSO + MFA enforced; role-based access mapped to minimum necessary; access reviews scheduled.
- Every connected app and integration audited: does it receive contact data? Does it have a BAA?
- Ad integrations configured so patient identity and health context never sync to ad platforms (offline conversions with scrubbed payloads, not audience syncs of patient lists).
- Team policy: no PHI in notes, tickets, or one-off emails outside classified fields — with training and spot audits.
- HIPAA marketing authorizations captured before promotional sends; transactional/care messages segmented separately.
- Data retention and deletion procedures documented (HubSpot's defaults are keep-forever).
- Your historical data reviewed: anything that predates the compliant configuration gets a documented risk assessment.
If your team can't confidently check all ten, the BAA is decoration.
The alternative: infrastructure that's compliant by construction
We built PilotPractice so a practice doesn't have to assemble compliance out of enterprise add-ons:
- Field-level encryption on every lead, message, call, and file record — PHI is encrypted at the field level in the database, not just "encrypted at rest" on the disk.
- An append-only HIPAA audit log with access-tracking middleware on PHI reads, login auditing (new device, impossible travel), and insider-threat analytics scoring unusual access patterns. When someone asks "who viewed this patient and when," it's a query.
- A BAA offered as standard, backed by SOC 2 and a public trust center — not a tier-gated upsell.
- And it comes with the marketing team attached: we run the campaigns, the email, the ads, and the site on this infrastructure, so the compliant configuration is our job, not your office manager's.
First, find out what your current stack is leaking. Run the free PHI leak scanner against your website — it flags trackers and forms sending patient data to third parties. No email gate, results in about a minute.
Then, if you'd rather have healthcare-native infrastructure plus the agency that runs it: book a demo.
Related: HIPAA-Compliant Marketing Automation · Is Mailchimp HIPAA Compliant? · The 2026 Guide to HIPAA-Compliant Marketing
Security details: trust.pilotpractice.com
See it live on your own practice
EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo





