Healthcare and adjacent companies have wanted one thing from HubSpot for years: a way to run sales and marketing without keeping protected health information in a separate, disconnected system. HubSpot now offers HIPAA support that lets eligible accounts store protected health information (PHI) in the CRM — but "supported" is not the same as "safe by default." It only works if you sign the right agreement, turn on the right controls, and stay disciplined about what data goes where. Here's the practitioner's read on what HIPAA support actually means and how to set it up without creating risk.
It lets eligible HubSpot accounts store and process protected health information inside the CRM under a Business Associate Agreement — instead of forcing PHI into a separate, siloed tool. PHI is any health information tied to an identifiable person: a treatment, a condition, an appointment for care. Before HIPAA support, putting that into a standard CRM was a compliance problem. With it, healthcare organizations can keep contact data, communications, and care-related context in one place and still meet their obligations — provided the account is set up for it. The key word is eligible: this is not a switch every portal can flip, and it requires a formal agreement with HubSpot first.
A signed Business Associate Agreement (BAA) with HubSpot, the HIPAA settings enabled, and a clear internal rule for what counts as PHI. The BAA is the legal foundation — without it, storing PHI in HubSpot is not compliant, full stop. Once that's in place, you enable the HIPAA-specific settings in your account and tighten the controls around them: who can access which records, how data is logged, and what's blocked from leaving the system. Worked example: a clinic that wants to nurture patients by email must confirm which fields hold PHI, restrict access to the team that needs it, and make sure no PHI leaks into tools or integrations that sit outside the agreement. The setup is where compliance is won or lost — not in the marketing copy.
Treating "HIPAA support" as a guarantee instead of a framework you have to operate correctly. The common failures are predictable: storing PHI before the BAA is signed; sending PHI through an integration or email tool that isn't covered; giving the whole team access to records only a few people should see; or pasting sensitive details into free-text notes nobody governs. HubSpot provides the capability and the controls — your team is responsible for using them. Compliance is a process, not a setting, and the portals that stay safe are the ones with clear rules about what data is allowed in, who can see it, and where it's never allowed to flow.
Lock down access, govern your properties and integrations, and review the setup on a schedule — because a portal drifts toward risk if nobody maintains it. Start by mapping exactly which properties and records hold PHI and restricting them with permission sets. Audit every integration to confirm it's covered by the agreement, and disable any data flow that isn't. Then put a recurring review on the calendar: new users, new automations, and new tools all create new exposure. This is the order we follow when we configure a healthcare portal — agreement first, controlled setup second, ongoing review third — because the risk isn't the initial build, it's the slow erosion of discipline after go-live.
HIPAA support in HubSpot is a real step forward for healthcare teams that were tired of running on two disconnected systems — but it's a capability, not a safety net. The portals that handle PHI well are the ones that treat the BAA, access controls, and integration governance as the actual product, and the marketing automation as what runs on top. As a HubSpot Gold Solutions Partner, our role is making sure the foundation is configured so the team can move fast without crossing a line they can't uncross.
Handling sensitive or regulated data in HubSpot? Book a 30-minute portal audit — we'll review your access, properties, and integrations and flag where you're exposed. For the full picture, see how we approach HubSpot implementation and optimization.
Can every HubSpot account store protected health information?
No. HIPAA support is available to eligible accounts and requires a signed Business Associate Agreement with HubSpot before any PHI is stored. Confirm your account's eligibility and current terms with HubSpot directly.
What is a Business Associate Agreement and why does it matter?
It's the contract that makes HubSpot a compliant partner for handling PHI on your behalf. Without it, storing PHI in HubSpot isn't HIPAA-compliant — it's the legal foundation everything else sits on.
Does enabling HIPAA support make my whole portal automatically compliant?
No. It gives you the capability and controls; compliance still depends on how you configure access, govern properties, vet integrations, and train your team. The setting is the start, not the finish.
What's the biggest risk when storing PHI in HubSpot?
PHI leaking into a place that isn't covered — an uncovered integration, an overly broad permission, or a free-text note. Map where PHI lives, restrict it tightly, and audit every data flow that could carry it out.