Skip to main content
Guide

HIPAA-Compliant Marketing Automation: Who Signs a BAA

Which marketing automation and email platforms sign a BAA, on which plans, and how to keep the ad tracking around them HIPAA compliant.

4 min read

HIPAA-compliant marketing automation starts with a platform that signs a Business Associate Agreement for the patient data it holds. HubSpot signs one on Enterprise subscriptions with Sensitive Data turned on, Salesforce for Marketing Cloud Engagement and its other HIPAA Covered Services, Adobe Marketo Engage under a HIPAA-Ready license, Braze for HIPAA-eligible instances, Customer.io on its Premium and Enterprise plans, and GoHighLevel with its HIPAA add-on, while Mailchimp, Klaviyo and Brevo bar health information outright. The second half is the ad tracking around those tools: Curve Compliance sends conversions from your site and CRM to Meta, Google and TikTok server-side with PHI filtered out, under a BAA on every plan.

Book a call. Curve Compliance keeps the ad side of your marketing automation HIPAA compliant: server-side conversions, PHI-like pattern detection, attribution through booking tools and CRM outcomes, and a BAA on every plan. Book a call with Curve.

Every answer below comes from the vendor's own page, quoted with its source in the BAA Directory, checked on October 1, 2026. Plans and terms change, so confirm the BAA in writing before any patient data flows.

Marketing automation and CRM platforms

PlatformBAAConditionsTypical use
HubSpotOn specific plansEnterprise subscriptions with Sensitive Data enabledCRM, email and forms
SalesforceOn specific plansHIPAA Covered Services only, such as Sales Cloud and Marketing Cloud EngagementCRM and enterprise email journeys
Adobe Marketo EngageOn specific plansHIPAA-Ready license and signed BAAB2B and enterprise marketing automation
BrazeOn specific plansHIPAA-eligible instance named on the Order FormLifecycle messaging for apps and DTC
Customer.ioOn specific plansPremium and Enterprise plansBehavior-triggered email and SMS
ActiveCampaignOn specific plansEligible plans; Enterprise named by ActiveCampaignEmail automation for smaller teams
GoHighLevelOn specific plansPaid HIPAA Compliance add-on, any agency planAll-in-one agency CRM and funnels
KeapSigns a BAAStandard BAA after enabling HIPAA controlsSmall-practice CRM and automation
IterableNo public statementHIPAA compliance listed; no BAA statement foundCross-channel lifecycle messaging

Email-only and transactional senders

PlatformBAAConditionsTypical use
Constant ContactSigns a BAAStandard BAA on request; contact details onlyNewsletters
MailchimpDoes not signData Processing Addendum bars health informationNewsletters
KlaviyoDoes not signAcceptable Use Policy bars PHIDTC email and SMS
BrevoDoes not signTerms of Use: not for HIPAA communicationsEmail and SMS campaigns
Amazon SESSigns a BAAUnder the AWS BAA; SES is a HIPAA Eligible ServiceTransactional email at volume
MailgunSigns a BAAHIPAA Addendum to the Mailgun Terms of ServiceTransactional email
SendGridDoes not signNot HIPAA eligible; no BAA for SendGridTransactional email
PostmarkDoes not signNot HIPAA-compliant; cannot sign BAAsTransactional email

What a BAA does not cover

A BAA covers how that vendor handles the patient data you give it. It does not cover the ad pixels on the same forms and landing pages, the platforms the automation tool syncs audiences or conversions to, or the automation layer between your tools. Two points catch most teams:

  • Ad platform syncs. Meta and Google do not sign BAAs, and their terms bar health information, so a CRM-to-Meta audience or conversion sync needs the same care as a pixel. See whether Meta signs a BAA.
  • Connectors. Zapier says it can't sign BAAs and that PHI isn't supported, so patient data should never pass through a Zap. HIPAA-compliant automation services such as Keragon sign one.

Where Curve Compliance fits

Curve Compliance is the ad side of a HIPAA-compliant marketing stack. It replaces browser pixels with one script, sends conversions server-side to Meta Conversions API, Google Ads, TikTok, Microsoft Advertising and LinkedIn with a fixed list of fields per platform, and flags PHI-like patterns before anything leaves. Bookings in IntakeQ, Calendly, Jane and other schedulers keep their ad attribution, and outcomes from HubSpot, other CRMs and EHRs arrive through webhooks, Keragon or offline uploads, so the campaigns that fill your automation are credited for the patients they bring in. For the head-to-head with a lifecycle tool, see Curve vs Customer.io, and for a CRM in particular, whether HubSpot is HIPAA compliant.

Book a call. Curve's team will review what your site, forms and CRM send to the ad platforms today and set up HIPAA-compliant conversion tracking around your automation. Book a call with Curve.

Frequently Asked Questions

What is the best HIPAA-compliant marketing automation platform?

It depends on the plan you can buy and what you send. HubSpot Enterprise with Sensitive Data, Salesforce Marketing Cloud Engagement, Adobe Marketo Engage, Braze, Customer.io Premium or Enterprise, and GoHighLevel with its HIPAA add-on all sign a BAA. Pair the one you choose with HIPAA-compliant ad tracking such as Curve Compliance, because the platform's BAA does not cover your ad pixels.

Is Mailchimp HIPAA compliant?

No. Mailchimp's Data Processing Addendum says customers will not provide health information, so it fits only email that carries no patient data. See Mailchimp in the BAA Directory.

Does Klaviyo sign a BAA?

No. Klaviyo's Acceptable Use Policy says you may not store or send Protected Health Information in the platform.

Which email providers sign a BAA for transactional email?

Amazon SES is a HIPAA Eligible Service under the AWS BAA, and Mailgun offers a HIPAA Addendum to its Terms of Service. SendGrid and Postmark say they do not support HIPAA use.

Does a BAA with my automation platform make my ads HIPAA compliant?

No. It covers that vendor only. Ad pixels and platform syncs need their own answer: Curve Compliance sends conversions to Meta, Google and TikTok server-side with PHI filtered out, under a BAA on every plan.

Next step

Check your own site

See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.

Or book a tracking audit

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit