Content

HubSpot Will Sign a BAA. Here's Everything It Still Doesn't Cover.

Blog
Content

HubSpot will sign a BAA. Most of the articles that mention this stop right there, which is exactly what makes them misleading.

It's true for Enterprise accounts that turn on HubSpot's Sensitive Data feature and confirm the organization qualifies as a covered entity or business associate. It is not true for Starter or Professional, which is where most dental groups, med spas, and multi location practices are actually running their appointment reminders and referral campaigns.

Upgrading doesn't cover what already happened

Getting the BAA isn't automatic even on Enterprise. A super admin has to deliberately activate Sensitive Data Terms. Nobody stumbles into it by accident, which means plenty of Enterprise accounts are running patient data without one simply because nobody flipped the switch.

And the timing matters more than the tier question. If a group builds workflows and stores patient information on Starter or Professional first, then upgrades later, the BAA only covers data going forward from the contract date. Whatever PHI moved through the account before that point was never covered, and upgrading doesn't retroactively fix it.

So the honest first question for a HubSpot using practice isn't "does HubSpot sign a BAA." It's which tier the account is actually on right now, and how long patient data has already been sitting in it.

Enterprise plus Sensitive Data still leaves real gaps

This is where most comparison articles stop, and it's the part that matters more once a group has actually upgraded.

The BAA covers CRM object properties and APIs, workflows, forms, and attachments. It does not cover HubSpot's reporting layer. Custom Report Builder, Customer Journey Reports, Data Sets, and Snowflake data sharing all sit outside the agreement, which means a marketing team that likes to build dashboards on top of patient activity is building them on uncovered ground.

Personalization tokens can't use Sensitive Data properties either. That sounds like a technical footnote until a practice tries to send a recall email that references a procedure or a last visit date by name, the exact detail that makes a reminder feel useful instead of generic. It can't be pulled from a field HubSpot has classified as PHI.

And the BAA doesn't extend past HubSpot itself. Every integrated app in the stack needs its own agreement. Popular connections like Shopify and WhatsApp aren't HIPAA eligible, so a workflow that hands patient data to either one breaks compliance even inside an Enterprise account with Sensitive Data configured correctly everywhere else.

What this means for the tools actually built for healthcare

None of this makes HubSpot a bad product. It makes it a general marketing platform that added a compliance layer on top, the same pattern Klaviyo runs into from the other direction, built for a different kind of customer first. The filter that should decide any marketing tool for a healthcare organization isn't whether it can eventually be configured to sign a BAA. It's how much of the platform still works normally once that BAA is in place.

PatientCampaign starts from the other direction. Every plan holds PHI under a BAA by default, so a practice isn't choosing between the tier with real marketing features and the tier with compliance, or discovering after the fact that half the reporting and personalization its campaigns depend on sits outside the agreement it signed.

If a group is already on HubSpot and the workflows are staying, the fix isn't necessarily switching platforms. It's an honest audit: which tier the account is actually on, how far back patient data goes, and which of those workflows quietly depend on a feature the BAA doesn't cover. That audit is most of what HIPAA compliant marketing actually requires, and it's worth doing before assuming an upgrade already solved the problem.