Which marketing automation platforms can a clinic use under HIPAA?
The question to ask is not whether a platform is HIPAA compliant but whether the vendor signs a Business Associate Agreement on the specific plan being bought, because for most major platforms it is a tier feature rather than a product feature. As of August 2026, published comparisons indicate HubSpot offers a BAA on Enterprise only, ActiveCampaign on higher tiers, Klaviyo offers one, and Mailchimp does not on standard plans. Verify directly, because policies change. The architectural alternative to paying for an enterprise tier is keeping protected health information out of the marketing platform entirely: clinical data stays in the covered system, the marketing platform holds contacts, consent status and opaque identifiers, and clinical segmentation happens inside the covered system which exports identifier lists the marketing tool cannot interpret. The tradeoff is convenience: marketers cannot build clinical segments in the tool they work in daily, and every new segment requires an export.
The question is usually asked as “is HubSpot HIPAA compliant?”, and the honest answer is that the question is malformed. The right question is whether the vendor will sign a Business Associate Agreement on the plan you are actually buying, because for most of the major platforms the answer changes by tier.
That distinction costs practices real money, and occasionally exposes them without anyone realising.
The tier trap
As of August 2026, according to published comparisons:
| Platform | BAA available |
|---|---|
| HubSpot | Enterprise tier only. Plans below Enterprise do not offer a BAA |
| ActiveCampaign | Higher tiers only. Lower tiers do not offer one |
| Klaviyo | Offered, with HIPAA compliance features |
| Mailchimp | Not offered on standard plans |
Verify this directly with the vendor before acting on it. Policies change, tiers get renamed, and a comparison article is not a contract. What is stable is the pattern: the agreement is a tier feature, not a product feature.
The practical consequence is that a practice running HubSpot Professional, holding patient data in it, believing itself covered because HubSpot appears on lists of HIPAA-compliant platforms, is not covered. Nothing in the interface says so.
What compliance actually costs at the platform layer
The gap between a mid tier and an enterprise tier is not marginal. Moving to the tier that carries the agreement can multiply platform spend several times over, and for a single location practice that increase frequently exceeds what they were paying an agency.
At that point practices do one of three things. They pay it, which is fine if the volume justifies it. They ignore it and carry on, which is the common answer and the bad one. Or they change the architecture so the expensive tier is not required, which is the option nobody sells them.
The architecture that avoids the problem
Here is the part that vendors have no incentive to explain.
If your marketing platform never holds protected health information, you do not need a BAA with it.
That is not a loophole. It is the same boundary logic that governs what may be sent to an advertising platform, set out in HIPAA-compliant marketing automation. A system that only ever sees non-identifying data is not processing PHI on your behalf, and is not a business associate.
Concretely, that means:
PHI stays in the system that already has an agreement, which for most practices is the practice management system or the clinical CRM. That system is already covered because it has to be.
The marketing platform holds a contact record and an opaque identifier, plus consent status and non-clinical attributes. Name and email are personal data and require care under state privacy law, but they are not by themselves protected health information in the way a condition or a treatment is.
Segmentation that depends on clinical information happens inside the covered system, which exports a list of opaque identifiers to the marketing platform. The marketing platform sends to a segment it cannot interpret.
The practical test is whether someone with access to only the marketing platform could learn something clinical about an identifiable person. If a segment is called “Post bariatric follow-up”, they can. If it is called “Sequence 14” and the meaning lives in the covered system, they cannot.
What that costs you in exchange
This is a genuine tradeoff and it is worth stating rather than selling.
You lose convenience. Marketers cannot build clinical segments in the tool they work in every day, and every new segment requires an export from the covered system. That is friction, and friction in a small team means some campaigns do not happen.
You gain an architecture that does not require the enterprise tier, does not expand your business associate surface every time somebody enables a feature, and does not need unpicking when a vendor changes its policy.
For a large multi-site group with a marketing team, pay for the enterprise tier and keep everything in one place. For a single practice or a small group, the boundary architecture is usually the better trade, and it is the one we build most often.
What about the practice systems
Many aesthetic and dental practices run marketing modules inside their practice management system: PatientNow, Pabau, Zenoti and similar. Those systems already handle clinical data and already operate under an agreement, which appears to solve the problem neatly.
It does, for compliance. It creates a different problem, which is that the marketing module inside a clinical product is almost always the weakest component, existing so the platform can claim it. You get compliance and lose capability.
The honest read is that this is fine for reminders, aftercare and basic follow-up, which is most of what a practice actually needs, and inadequate for anything resembling a real acquisition programme. Deciding which of those you are doing is a better starting question than comparing feature lists.
The migration question, which is where the cost really sits
Practices discovering the tier problem usually ask whether to move platforms. The platform fee is the smallest part of that decision.
The real cost is every automation rebuilt, historical engagement data that does not transfer cleanly, a team learning a new tool while still relying on the old one, and the reporting baseline resetting on the day you switch. If you are mid-way through proving that marketing works, a migration breaks the comparison you were building.
Two things follow. If the current platform holds PHI it should not, that is an acute exposure and worth acting on now, though the first move is to stop new PHI entering rather than to migrate everything by Friday. And if you are choosing for the first time, choose with the boundary in mind, because the second migration is the expensive one.
What good looks like after this is settled
A practice that has this right can describe its stack in four sentences.
The clinical system holds patient data and has an agreement. The marketing platform holds contacts, consent status and opaque identifiers, and has no agreement because it needs none. Segments that depend on clinical information are built in the clinical system and exported as identifier lists. Nothing carrying an identifier goes to an advertising platform.
If describing your stack takes longer than that, or requires the phrase “and then somebody exports a spreadsheet”, the boundary is not drawn where you think it is.
The five questions, again
Whatever you are considering, ask these before the demo rather than after:
- Will you sign a BAA on the specific plan I am buying?
- Which features process PHI and which do not?
- Can I control exactly which fields leave for an integration?
- Do any AI features process message content or contact data, and are they covered?
- What happens to my data, and your backups of it, when I leave?
A vendor that answers all five precisely has done this before. One that answers by describing its security posture in general terms has not, and you will be the practice that finds out where the gaps are.
Show us where the revenue stops.
Thirty minutes, your real numbers, an honest read on which layer is costing you most.