How HubSpot Supports HIPAA Compliance: Sensitive Data, the BAA, and What's Covered
How HubSpot's HIPAA support actually works, and what stays out of scope.
HubSpot can be used in a HIPAA-compliant way, but only under specific conditions, and it's important to understand exactly what those are before putting any protected health information (PHI) into the system. This article lays out how HubSpot's HIPAA support actually works and, just as importantly, where its limits are.
It requires the right subscription
HubSpot's HIPAA support is available only on Enterprise-tier subscriptions. If you're on a lower tier, the sensitive-data capabilities that make HIPAA-aligned use possible simply aren't available. So the first question with any HIPAA use case is whether you're on a plan that supports it, we'll help you confirm this before anything else.
Enabling sensitive data activates the BAA
On an eligible account, HIPAA support is turned on by enabling HubSpot's sensitive data settings and identifying your organization as a covered entity. Doing this activates HubSpot's Business Associate Agreement, the BAA that commits HubSpot to handling your PHI according to HIPAA. In other words, properly enabling the feature and accepting the BAA go hand in hand; you don't get one without the other. This has to be done deliberately and correctly, which is exactly the kind of setup we handle for you.
What stays out of scope
This is the part people most often miss. Even on a properly configured HIPAA-enabled account, several HubSpot features are not covered for PHI, and you must keep protected health information out of them:
- Personalization tokens, so PHI shouldn't be inserted into emails or pages via tokens.
- Call recordings and transcripts.
- Chatbots.
- Sandboxes.
Putting PHI into any of these breaks compliance, regardless of how the rest of the account is set up. Knowing where these boundaries are is essential, and building your processes to respect them is part of doing HIPAA right in HubSpot.
How we help
Configuring HubSpot for HIPAA correctly, confirming eligibility, enabling sensitive data, activating the BAA, and designing your system so PHI stays inside the covered boundaries, is precise work with real consequences if it's done wrong. We handle it deliberately and build your processes so your team naturally stays within scope. HubSpot's own documentation on storing sensitive data is the authoritative reference, and we'll make sure your specific setup follows it.
The bottom line
HubSpot supports HIPAA, but "supports" comes with real conditions: the right tier, the right configuration, the activated BAA, and strict discipline about which features never touch PHI. Get those right and you have a compliant, capable system. Get them wrong and you have exposure. Our job is to make sure it's the former.