Skip to main content
BAA Directory

Does Calendly sign a BAA?

The answer

Does not sign a BAA

No. Calendly says it does not currently offer a BAA and is not intended for collecting Protected Health Information.

Scheduling and intake. Checked on the vendor's own pages on .

On this page

What Calendly says

“as it stands today it isn't intended for collecting Protected Health Information, and we don't currently offer a BAA.”

Source: Calendly Community, answer from Calendly's Community Manager (July 17, 2026), checked .

“Calendly does not currently comply with HIPAA, GLBA, or similar health and financial regulations.”

Source: Calendly Help Center, Notetaker FAQ, checked .

What this means for ad tracking

The booking is the conversion most clinics optimize their ads for, so Calendly usually sits right where the ad tracking happens. A pixel on a booking or confirmation page can send the page address, the appointment type and the visitor's identifiers to Meta, Google or TikTok.

Without a BAA, keep patient details out of Calendly, and keep ad pixels off any Calendly page that shows a condition, a service or an appointment. The booking still needs to count as a conversion, or your campaigns lose the signal they optimize for.

Curve Compliance closes that gap: it sends the conversion itself server-side, under a BAA it signs on every plan, so your campaigns keep a conversion signal without a pixel carrying patient data. Book a call to see it on your own funnel.

How Curve helps

  • Curve gives you a conversion signal that does not depend on Calendly or a browser pixel carrying patient details.
  • Server-side conversion tracking in place of pixels: conversions reach your ad platforms from Curve's server, not from the patient's browser.
  • PHI-like pattern detection checks every event before it goes out, and neutral event names keep conditions and treatments out of what the platforms see.
  • Identifiers are hashed with SHA-256 to each platform's requirements.
  • Attribution is kept through booking tools, so a booked appointment is credited to the ad that brought the patient in.
  • Consent management for your site, alongside the tracking.
  • A HIPAA-compliant setup done by Curve's team, in about a week, with a BAA signed on every plan.

Book a call with Curve and Curve's team will walk through your tracking setup with you.

Read the full guide

For the full picture on Calendly and patient data, read Is Calendly HIPAA Compliant? Scheduling Tool Risks for Healthcare Providers.

Frequently asked questions

Does Calendly sign a BAA?

No. Calendly says it does not currently offer a BAA and is not intended for collecting Protected Health Information. In Calendly's words: “Calendly does not currently comply with HIPAA, GLBA, or similar health and financial regulations.” We checked Calendly's own pages on September 29, 2026.

Can I use Calendly with patient data?

Not under a BAA from Calendly, based on its own pages. Keep Protected Health Information out of Calendly, and check what it sends to other services.

Can I still track ad conversions that come through Calendly?

Yes, when the conversion reaches your ad platforms without health information. Curve sends conversions server-side under a BAA it signs on every plan, with neutral event names and SHA-256 hashed identifiers.

Does Curve Compliance sign a BAA?

Yes. Curve Compliance signs a BAA on every plan, and Curve's team does the HIPAA-compliant setup in about a week. Book a call to get started.

Sources

Last checked . Vendors change their plans and terms, so confirm the current terms with Calendly before you send it patient data.

See every tool in the BAA Directory.

Track ad conversions under a BAA

Curve signs a BAA on every plan. Curve's team sets up HIPAA-compliant conversion tracking for you in about a week, sending conversions server-side in place of pixels.

Book a call