HIPAA Tracking · Q&A
Is HubSpot HIPAA Compliant for Healthcare Marketing?
Last updated: July 13, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.
Yes, conditionally — HubSpot will sign a BAA and support PHI, but only on Enterprise-tier plans with its sensitive-data features enabled. On Starter or Professional, HubSpot is not HIPAA compliant and its own terms prohibit storing PHI. And there's a second question hiding inside the first that most articles skip: even a fully BAA-covered HubSpot portal doesn't make the HubSpot tracking code on your website compliant. CRM storage and website tracking are separate analyses.
Part 1: HubSpot as CRM and marketing automation
The compliant configuration requires all of: an Enterprise-tier subscription, a countersigned BAA, sensitive-data features turned on (field-level encryption and controls for designated properties), access controls treating PHI fields accordingly, and connected integrations that don't relay PHI onward to non-BAA tools.
Miss any one and you're out of bounds — the most common misses we see are teams on Professional storing "reason for inquiry" fields (PHI, wrong tier, no BAA), and workflow integrations syncing contact health context into Slack, spreadsheets, or ad platforms.
Part 2: The HubSpot tracking code on your site
HubSpot's tracking script is a client-side behavioral tracker: it follows identified contacts across your pages and builds a page-view timeline on the contact record. On a healthcare site, that timeline reads "viewed /services/fertility-treatment 4x this week" — attached to a name and email. Now apply the standard tests: this is health-revealing behavioral data being collected client-side, page-level browsing history is "consumer health data" under state laws like Washington's MHMDA (separate opt-in consents, private right of action), and the wiretapping-suit theories that target other client-side trackers don't care about your CRM's BAA status.
Our recommendation for health brands: keep the tracking code off health-revealing and authenticated pages entirely (allowlist approach, as with session recording), gate what remains behind real consent, and feed conversion data to marketing systems server-side rather than via behavioral trails.
FAQ
Which HubSpot plans support HIPAA? Enterprise tiers with the sensitive-data capability and a signed BAA. HubSpot's terms prohibit PHI on lower tiers — being careful on Professional isn't a compliance posture, it's a terms violation carrying PHI.
Does HubSpot's BAA cover email sends to patients? Covered infrastructure, yes — but HIPAA's marketing rules still govern content and purpose: communications that require authorization still require it regardless of the sending platform. Platform compliance and message compliance are different questions.
Should we replace HubSpot with a "HIPAA-native" CRM? Not necessarily. Enterprise HubSpot under BAA with disciplined configuration is a legitimate stack. The decision usually turns on cost (Enterprise pricing vs. alternatives) and whether your team will maintain the configuration discipline.
We configure healthcare marketing stacks on HubSpot and off it — Coast Studio.
Related
Jason Garrett
Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.
Connect on LinkedIn →HIPAA-compliant tracking, done right
Coast Studio runs privacy-compliant performance marketing for telehealth, healthtech, and DTC health brands — including the server-side tracking architecture described here.
Book a Consultation