Ask Mailchimp directly whether it will sign a business associate agreement and the answer is no. Not on a higher tier, not with an add-on, not ever. Its own terms of use put the obligation on the customer, stating you are responsible for determining whether the service is appropriate for your regulatory obligations under HIPAA, and that Mailchimp will not be responsible if the service does not comply.
That's a different answer than HubSpot or Constant Contact give. Both of those will sign something, with real limits attached. Mailchimp doesn't offer the document at all. If a patient's name is attached to anything clinical, an appointment type, a treatment, a diagnosis, there's no path to putting it in Mailchimp legally, regardless of plan.
PatientCampaign signs a BAA on every plan, no upgrade required and no separate request to legal. Mailchimp doesn't sign one at all, at any tier, which means a plain contact list with a name and email address is close to the ceiling of what the platform can legally hold for a covered entity.
Recall and reactivation campaigns are built from clinical facts: when someone was last seen, what they were being treated for, whether they finished a plan of care. PatientCampaign is built to segment on exactly that. Mailchimp's own restriction rules it out before the automation even starts, since the segment itself would have to reference protected health information.
Mailchimp sells SMS and MMS as a paid add on layered onto its Standard and Premium plans, aimed mainly at ecommerce order updates, and it inherits the same BAA gap as the rest of the platform. PatientCampaign's texting runs on the same compliant infrastructure as its email, covered under the same agreement, and built around the consent rules the TCPA adds on top of HIPAA.
Mailchimp is built for ecommerce and small business marketing, and it's a genuinely good tool for that job. It was never built around a patient, and the compliance gap isn't a bug. It's a reflection of who the product is for. PatientCampaign starts from the other direction, built specifically for healthcare organizations that need to talk to patients about their care.
A lot of practices end up on Mailchimp because someone on staff already knew it, not because anyone evaluated it against HIPAA. If patient information, even something as basic as a diagnosis or a procedure name, has gone into a Mailchimp list or an email, that's worth an honest look before assuming it was fine because "email marketing" felt like a low risk category.
If a practice mostly sends generic newsletters using nothing more specific than a name and an email address, Mailchimp's restriction may never actually bind it. We've covered where that line usually gets crossed for a med spa running exactly that kind of program, and most of what applies there applies broadly.
The deciding question isn't which platform has better templates. It's whether the platform can be told the truth about who a patient is and what they need to hear next.