Skip to main content
BAA Directory

Does Iterable sign a BAA?

The answer

No public statement

No public statement about a BAA. Iterable's Trust Center lists HIPAA compliance, but we found no statement about signing a BAA on its own pages.

CRM and email. Checked on the vendor's own pages on .

Using Iterable on a healthcare site? Curve Compliance keeps your ad tracking HIPAA-compliant around it, under a BAA on every plan. Book a call

On this page

What Iterable says

“Iterable maintains the highest global standards for data security, including SOC 2, ISO 27001, and HIPAA compliance.”

Source: Iterable Trust Center, overview, checked .

What this means for ad tracking

Iterable sends lifecycle email, SMS and push messages from customer data, and teams often sync its segments or events back to ad platforms as audiences or conversions. Each sync sends data from Iterable to Meta, Google or TikTok.

Until Iterable signs a BAA with you, keep Protected Health Information out of it, and nothing from it should reach an ad platform with health details attached.

Curve Compliance closes that gap: it sends the conversion itself server-side, under a BAA it signs on every plan, so your campaigns keep a conversion signal without a pixel carrying patient data. Book a call to see it on your own funnel.

How Curve helps

  • Curve Compliance gives you a conversion signal that does not depend on Iterable or a browser pixel carrying patient details.
  • Server-side conversions to Meta, Google Ads, TikTok, Microsoft Advertising and LinkedIn, sent from Curve's servers with neutral event names and SHA-256 hashed identifiers.
  • PHI-like pattern detection flags condition names, form answers and emails in URLs before data reaches an ad platform, so they can be stopped at the source.
  • Attribution is kept through booking tools, so a booked appointment is credited to the ad that brought the patient in, even when it is made days later.
  • A HIPAA-compliant setup done by Curve's team, in about a week, with a BAA signed on every plan.

Book a call with Curve and Curve's team will walk through your tracking setup with you.

Frequently asked questions

Does Iterable sign a BAA?

No public statement about a BAA. Iterable's Trust Center lists HIPAA compliance, but we found no statement about signing a BAA on its own pages. In Iterable's words: “Iterable maintains the highest global standards for data security, including SOC 2, ISO 27001, and HIPAA compliance.” We checked Iterable's own pages on October 1, 2026.

Can I use Iterable with patient data?

Not until Iterable signs a BAA with you. Its Trust Center lists HIPAA compliance, but we could not find a statement about a BAA on its own pages, so ask Iterable directly and keep Protected Health Information out of Iterable until a BAA is in place.

Can I still track ad conversions that come through Iterable?

Yes, when the conversion reaches your ad platforms without health information. Curve Compliance sends conversions server-side under a BAA it signs on every plan, with neutral event names and SHA-256 hashed identifiers.

Does Curve Compliance sign a BAA?

Yes. Curve Compliance signs a BAA on every plan, and Curve's team does the HIPAA-compliant setup in about a week. Book a call to get started.

Sources

Last checked . Vendors change their plans and terms, so confirm the current terms with Iterable before you send it patient data.

See every tool in the BAA Directory.

Track ad conversions under a BAA

Curve signs a BAA on every plan. Curve's team sets up HIPAA-compliant conversion tracking for you in about a week, sending conversions server-side in place of pixels.

Book a call