Skip to main content
Guide

Healthcare CRM Integrations & HIPAA: HubSpot, Salesforce Health Cloud, Klaviyo Compared

A single misconfigured CRM integration can convert a routine marketing campaign into a reportable HIPAA breach. With OCR maintaining tracking technologies as an enforcement priority and HIPAA civil...

10 min read

Healthcare CRM Integrations & HIPAA: HubSpot, Salesforce Health Cloud, Klaviyo Compared

A single misconfigured CRM integration can convert a routine marketing campaign into a reportable HIPAA breach. With OCR maintaining tracking technologies as an enforcement priority and HIPAA civil monetary penalties now reaching [1] $2,134,831 per violation per calendar year, healthcare marketers cannot afford guesswork about which platforms are actually safe to use.

The healthcare CRM HIPAA question gets murky fast because vendors describe compliance in their own language. HubSpot, Salesforce Health Cloud, and Klaviyo each take a different position on Business Associate Agreements (BAAs), what data their platforms cover, and what configurations are required. This comparison breaks down where each platform stands, what risks remain when you integrate them with Google and Meta ad campaigns, and how to keep Protected Health Information out of ad tech pipelines.

Why Healthcare CRM HIPAA Compliance Breaks Down at the Integration Layer

Risk #1: The CRM Is Compliant, the Ad Pixel Is Not

HIPAA-eligible CRMs only cover what happens inside their own walls. The moment data leaves the CRM through a tracking pixel, audience sync, or webhook, a separate compliance analysis applies. [2] OCR has stated that regulated entities may not use tracking technologies in ways that result in impermissible disclosures of PHI to vendors, and a covered entity disclosing PHI to a tracking vendor without a BAA creates a presumption of breach unless the entity can demonstrate a low probability that the PHI was compromised.

Client-side pixels (Meta Pixel, Google Analytics gtag, standard Klaviyo onsite tracking) fire in the patient's browser and transmit IP address, user agent, URL path, form field values, and event metadata directly to the ad platform before any CRM sanitization can occur. Server-side tracking via Meta's Conversions API or the Google Ads API moves that event collection to your infrastructure, where PHI can be stripped before transmission. The distinction matters because server-side delivery is the only architecture that lets you control what leaves your environment.

Risk #2: Marketing Modules That Sit Outside the BAA

A single vendor often offers some HIPAA-eligible products and some that explicitly exclude PHI. [3] Salesforce will only enter into a BAA for certain services, and many of the covered services are restricted in how they can be used, with the BAA not extending to third-party integrations with access to PHI. [4] HubSpot's BAA, which became generally available to Enterprise subscribers on September 17, 2024, does not cover analytics reporting (including the Custom Report Builder), customer journey reporting, or Snowflake Data Sharing, and although call logs are permitted, call recordings and transcripts that include PHI are not permitted sensitive data. [5] Klaviyo's own Privacy FAQs confirm that the Acceptable Use Policy prohibits the use of sensitive or special categories of data, including PHI as defined under HIPAA, within the platform.

Risk #3: Hidden Costs Beyond the Fine

[6] OCR has resolved more than 31,000 investigations and imposed civil money penalties or settlements totaling roughly $144.8 million across 152 cases. Direct fines are only part of the exposure: breach notification mailings, state attorney general parallel actions, class action plaintiffs' fees, paused ad accounts during platform audits, and lost revenue from disabled retargeting all compound the cost. [7] In July 2023, HHS-OCR and the FTC sent joint warning letters to 130 hospitals using third-party tracking technology, and class action suits have since been filed against providers alleging damages from tracking technology use.

HubSpot, Salesforce Health Cloud, Klaviyo: Side-by-Side HIPAA Status

Each platform sits in a different position on the healthcare CRM HIPAA spectrum. Here is what the documentation and BAAs actually say.

HubSpot

  • BAA status: [8] Available. In June 2024 HubSpot launched sensitive data tools, and in September 2024 HIPAA support moved from public beta to generally available, with the company automatically entering into a BAA with customers that identify as HIPAA covered entities or business associates when activating the sensitive data settings.
  • Tier requirement: [4] Enterprise plan only. Covered entities and business associates must subscribe to an Enterprise plan and activate the necessary sensitive data settings before the BAA applies.
  • Covered services: Marketing, Sales, Service, and CMS Hub Enterprise plus CRM Activities (notes, emails, calls, tasks, and meetings, added with the September 2024 update).
  • Excluded: Reporting Analytics (including Custom Report Builder), Customer Journey Reports, Snowflake Data Sharing, personalization tokens with PHI, and call recordings or transcripts containing PHI.
  • Integration risk: Each marketplace app is a separate vendor that requires its own BAA evaluation. For a deeper breakdown, see our analysis of HubSpot CRM and marketing automation risks for clinics.

Salesforce Health Cloud

  • BAA status: [9] Available. Salesforce directs customers who want to build healthcare applications that comply with US HIPAA to contact their account representative regarding a Business Associate Addendum (BAA), with current BAA restrictions and HIPAA Covered Services published on the Salesforce legal site.
  • Covered services: [10] Per Salesforce's own HIPAA Security Rule white paper, the BAA covers services branded as Health Cloud, Lightning Platform (including Force.com but excluding Lightning Platform Developer Edition), Sales Cloud, Service Cloud, Community Cloud, Site.com, Database.com, Chatter, Einstein Analytics, and IoT Explorer.
  • Excluded: [3] The BAA does not apply to third-party integrations with access to PHI, and Salesforce takes no responsibility for ePHI in transit between a covered entity and Salesforce's servers, placing the responsibility for data encryption in transit on the covered entity.
  • Configuration burden: Even within covered services, many features are restricted in how they may be used with PHI, and customers must comply with the specific restrictions on each covered service listed in the BAA.
  • Related reading: What Salesforce Health Cloud covers and what it does not.

Klaviyo

  • BAA status: [5] Not available for healthcare use. Klaviyo's Privacy FAQs explicitly state that the Acceptable Use Policy prohibits the use of sensitive or special categories of data within the platform, with customers permitted to use Klaviyo only for non-sensitive data relating to end customers.
  • Use case fit: Built for ecommerce email and SMS marketing. Direct-to-consumer wellness brands that do not handle PHI can use it, but any sender identifiable as a healthcare provider tying a contact to a condition or treatment is at risk.
  • Integration risk: Klaviyo's onsite tracking, embedded forms, and Meta/Google audience sync features will transmit identifiers tied to product or content interactions, which can constitute PHI when the brand sells condition-specific therapeutics.
  • Related reading: Email and SMS marketing risks for DTC health brands using Klaviyo.

How Curve Closes the Gap Between Compliant CRMs and Ad Platforms

Dual-Layer PHI Stripping Architecture

Even with a properly configured HIPAA-eligible CRM, conversion events still need to reach Google Ads and Meta to optimize campaigns. Curve sits between the user's browser and the ad platforms with two layers of PHI removal.

Client-side protection. A lightweight script intercepts form submissions and page events in the browser before any data reaches a third-party endpoint. Email addresses, phone numbers, names, IP addresses, and free-text fields are filtered, hashed, or replaced with safe identifiers. The browser never transmits raw identifiers to Meta Pixel, Google's gtag, or any other client-side collector.

Server-side safeguards. Sanitized events route through Curve's infrastructure, where a second pass scans for PHI patterns missed at the edge (free-text symptom descriptions, appointment notes, condition keywords in URL parameters). Clean events are then forwarded to Meta's Conversions API and the Google Ads API with hashed user identifiers that meet platform matching requirements without exposing PHI.

Implementation Process

  1. Initial setup: Sign Curve's BAA, install a single script tag, and connect Meta and Google Ads accounts via OAuth. No developer tickets, no GTM container surgery.
  2. CRM integration: Map conversion events from HubSpot Enterprise, Salesforce Health Cloud, or your intake system to standard and custom events. PHI fields are flagged automatically.
  3. Testing and verification: Use Meta's Test Events tool and Google's tag diagnostics to confirm events arrive without PHI. Curve provides a sanitization log showing exactly what was stripped on each event.
  4. Ongoing maintenance: Monthly compliance reports document every event sent, every field stripped, and any policy changes from Meta or Google that require configuration updates.

Compliance Guarantees

  • Signed BAA: Curve executes a Business Associate Agreement with every healthcare customer before any data flows.
  • Technical safeguards: Encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access, audit logging aligned with the HIPAA Security Rule, which OCR has stated is its enforcement priority in tracking technology investigations.
  • Documentation: Per-event sanitization logs and quarterly access reviews give you the paper trail OCR requests in tracking-technology investigations.

Three Optimization Strategies for Compliant CRM-to-Ad-Platform Pipelines

Strategy #1: Replace Client-Side Pixels With Server-Side Conversion APIs

Remove the Meta Pixel and Google gtag from any page that could surface a health condition, symptom, provider, or treatment interest. Route all conversion events through Meta CAPI and the Google Ads API instead. This single change eliminates the most common source of PHI leakage: identifiable cookies and IP addresses transmitted in the same payload as health-related URL paths.

Expected outcomes: event match quality typically improves because server-side delivery can include hashed first-party identifiers from the CRM rather than relying on cookies that iOS and browser privacy features increasingly block. Common pitfalls: leaving the pixel in place "for analytics" defeats the purpose, as does sending raw email addresses to Meta CAPI without SHA-256 hashing.

Strategy #2: Use Enhanced Conversions With Hashed CRM Data, Not Raw Form Fields

Google Enhanced Conversions and Meta's Advanced Matching both accept hashed customer data to improve attribution. The compliant pattern is to hash identifiers inside your environment, then transmit only the hashes. Pull the data from your HubSpot Enterprise or Health Cloud record after consent has been documented, hash with SHA-256 server-side, and pass the hash through CAPI or the Google Ads API.

Technical requirements: Meta and Google both expect lowercased, trimmed inputs before hashing. Curve handles normalization automatically. Performance benchmark: properly implemented server-side conversions with hashed matching typically restore a meaningful share of conversion signal lost when third-party cookies are blocked, without ever transmitting raw PHI.

Strategy #3: Segment Audiences in the CRM, Not in the Ad Platform

Building "diabetes patients" or "GLP-1 prospects" audiences inside Meta Ads Manager or Google Ads using uploaded customer lists is the fastest way to create an impermissible disclosure. Even hashed uploads link a user to a condition-specific list label inside the ad platform. Instead, segment inside your BAA-covered CRM and pass only the conversion event (e.g., "consultation booked") to the ad platform, then let lookalike modeling do the targeting work on the platform side.

Best practice: keep condition labels, ICD codes, medication names, and any clinical metadata inside the CRM. Compliance consideration: this approach aligns with the HIPAA minimum necessary standard and avoids creating audience names in ad platforms that themselves constitute PHI when combined with identifiers.

Ready to Run Compliant Google/Meta Ads?

Book a HIPAA Strategy Session with Curve

Frequently Asked Questions

Is a healthcare CRM HIPAA compliant just because the vendor signed a BAA?

No. A BAA covers only the specific services listed in the agreement, and it does not cover misconfigurations, unsanctioned integrations, or PHI sent from the CRM to non-BAA vendors like Meta or Google through pixels and audience syncs. HubSpot's BAA, for example, excludes several reporting and data-sharing features, and integrating non-compliant marketplace apps can break compliance even on a fully BAA-covered Enterprise account.

Can I use Klaviyo for a healthcare brand if I only collect email addresses?

Generally not, if your brand identifies you as a healthcare provider or your products tie users to specific conditions. Klaviyo's Acceptable Use Policy expressly prohibits storing or transmitting PHI as defined under HIPAA, and an email address combined with a health-related context can itself qualify as PHI under OCR's interpretation.

What is the difference between Salesforce Health Cloud and Marketing Cloud for HIPAA?

Health Cloud is one of the Salesforce Covered Services that may be used with PHI under a signed BAA, while Marketing Cloud is not within the standard list of Salesforce Covered Services published by Salesforce. Using Marketing Cloud for patient outreach with appointment reminders or condition-specific campaigns puts PHI in a non-eligible product.

What does Curve do that a HIPAA-eligible CRM does not?

HIPAA-eligible CRMs protect data inside the CRM. Curve protects data on the way out, specifically the conversion events sent to Google Ads and Meta. Curve strips PHI client-side and server-side, signs a BAA, and delivers sanitized events through Meta CAPI and the Google Ads API so your campaigns optimize without disclosing PHI to ad platforms that will not sign BAAs.

What are the current penalties if my CRM integration leaks PHI to Meta or Google?

Civil monetary penalties for HIPAA violations were raised in 2024 to a maximum of $2,134,831 per violation per calendar year for the willful neglect (uncorrected) tier, with lower tiers carrying their own per-violation amounts.[1] Beyond CMPs, OCR can require resolution agreements with multi-year corrective action plans, and impermissible disclosures to a vendor without a BAA are presumed to be reportable breaches.

Sources

  1. HIPAA Journal: HHS Updates Civil Monetary Penalty Amounts for HIPAA Violations
  2. HHS OCR: Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
  3. HIPAA Journal: Is Salesforce HIPAA Compliant?
  4. The HIPAA Guide: Is HubSpot HIPAA Compliant?
  5. Klaviyo Privacy FAQs (Sensitive Data section)
  6. HHS OCR Enforcement Highlights
  7. Dentons: HHS-OCR Revises Guidance on Use of Online Tracking Technologies
  8. HIPAA Journal: Is HubSpot HIPAA Compliant?
  9. Salesforce Compliance Site: HIPAA
  10. Salesforce White Paper: Salesforce and the HIPAA Security Rule

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit