HIPAA-Compliant Marketing Automation: Who Signs a BAA
Which marketing automation and email platforms sign a BAA, on which plans, and how to keep the ad tracking around them HIPAA compliant.
HIPAA-compliant marketing automation starts with a platform that signs a Business Associate Agreement for the patient data it holds. HubSpot signs one on Enterprise subscriptions with Sensitive Data turned on, Salesforce for Marketing Cloud Engagement and its other HIPAA Covered Services, Adobe Marketo Engage under a HIPAA-Ready license, Braze for HIPAA-eligible instances, Customer.io on its Premium and Enterprise plans, and GoHighLevel with its HIPAA add-on, while Mailchimp, Klaviyo and Brevo bar health information outright. The second half is the ad tracking around those tools: Curve Compliance sends conversions from your site and CRM to Meta, Google and TikTok server-side with PHI filtered out, under a BAA on every plan.
Book a call. Curve Compliance keeps the ad side of your marketing automation HIPAA compliant: server-side conversions, PHI-like pattern detection, attribution through booking tools and CRM outcomes, and a BAA on every plan. Book a call with Curve.
Every answer below comes from the vendor's own page, quoted with its source in the BAA Directory, checked on October 1, 2026. Plans and terms change, so confirm the BAA in writing before any patient data flows.
Marketing automation and CRM platforms
| Platform | BAA | Conditions | Typical use |
|---|---|---|---|
| HubSpot | On specific plans | Enterprise subscriptions with Sensitive Data enabled | CRM, email and forms |
| Salesforce | On specific plans | HIPAA Covered Services only, such as Sales Cloud and Marketing Cloud Engagement | CRM and enterprise email journeys |
| Adobe Marketo Engage | On specific plans | HIPAA-Ready license and signed BAA | B2B and enterprise marketing automation |
| Braze | On specific plans | HIPAA-eligible instance named on the Order Form | Lifecycle messaging for apps and DTC |
| Customer.io | On specific plans | Premium and Enterprise plans | Behavior-triggered email and SMS |
| ActiveCampaign | On specific plans | Eligible plans; Enterprise named by ActiveCampaign | Email automation for smaller teams |
| GoHighLevel | On specific plans | Paid HIPAA Compliance add-on, any agency plan | All-in-one agency CRM and funnels |
| Keap | Signs a BAA | Standard BAA after enabling HIPAA controls | Small-practice CRM and automation |
| Iterable | No public statement | HIPAA compliance listed; no BAA statement found | Cross-channel lifecycle messaging |
Email-only and transactional senders
| Platform | BAA | Conditions | Typical use |
|---|---|---|---|
| Constant Contact | Signs a BAA | Standard BAA on request; contact details only | Newsletters |
| Mailchimp | Does not sign | Data Processing Addendum bars health information | Newsletters |
| Klaviyo | Does not sign | Acceptable Use Policy bars PHI | DTC email and SMS |
| Brevo | Does not sign | Terms of Use: not for HIPAA communications | Email and SMS campaigns |
| Amazon SES | Signs a BAA | Under the AWS BAA; SES is a HIPAA Eligible Service | Transactional email at volume |
| Mailgun | Signs a BAA | HIPAA Addendum to the Mailgun Terms of Service | Transactional email |
| SendGrid | Does not sign | Not HIPAA eligible; no BAA for SendGrid | Transactional email |
| Postmark | Does not sign | Not HIPAA-compliant; cannot sign BAAs | Transactional email |
What a BAA does not cover
A BAA covers how that vendor handles the patient data you give it. It does not cover the ad pixels on the same forms and landing pages, the platforms the automation tool syncs audiences or conversions to, or the automation layer between your tools. Two points catch most teams:
- Ad platform syncs. Meta and Google do not sign BAAs, and their terms bar health information, so a CRM-to-Meta audience or conversion sync needs the same care as a pixel. See whether Meta signs a BAA.
- Connectors. Zapier says it can't sign BAAs and that PHI isn't supported, so patient data should never pass through a Zap. HIPAA-compliant automation services such as Keragon sign one.
Where Curve Compliance fits
Curve Compliance is the ad side of a HIPAA-compliant marketing stack. It replaces browser pixels with one script, sends conversions server-side to Meta Conversions API, Google Ads, TikTok, Microsoft Advertising and LinkedIn with a fixed list of fields per platform, and flags PHI-like patterns before anything leaves. Bookings in IntakeQ, Calendly, Jane and other schedulers keep their ad attribution, and outcomes from HubSpot, other CRMs and EHRs arrive through webhooks, Keragon or offline uploads, so the campaigns that fill your automation are credited for the patients they bring in. For the head-to-head with a lifecycle tool, see Curve vs Customer.io, and for a CRM in particular, whether HubSpot is HIPAA compliant.
Book a call. Curve's team will review what your site, forms and CRM send to the ad platforms today and set up HIPAA-compliant conversion tracking around your automation. Book a call with Curve.
Frequently Asked Questions
What is the best HIPAA-compliant marketing automation platform?
It depends on the plan you can buy and what you send. HubSpot Enterprise with Sensitive Data, Salesforce Marketing Cloud Engagement, Adobe Marketo Engage, Braze, Customer.io Premium or Enterprise, and GoHighLevel with its HIPAA add-on all sign a BAA. Pair the one you choose with HIPAA-compliant ad tracking such as Curve Compliance, because the platform's BAA does not cover your ad pixels.
Is Mailchimp HIPAA compliant?
No. Mailchimp's Data Processing Addendum says customers will not provide health information, so it fits only email that carries no patient data. See Mailchimp in the BAA Directory.
Does Klaviyo sign a BAA?
No. Klaviyo's Acceptable Use Policy says you may not store or send Protected Health Information in the platform.
Which email providers sign a BAA for transactional email?
Amazon SES is a HIPAA Eligible Service under the AWS BAA, and Mailgun offers a HIPAA Addendum to its Terms of Service. SendGrid and Postmark say they do not support HIPAA use.
Does a BAA with my automation platform make my ads HIPAA compliant?
No. It covers that vendor only. Ad pixels and platform syncs need their own answer: Curve Compliance sends conversions to Meta, Google and TikTok server-side with PHI filtered out, under a BAA on every plan.
Related articles
Check your own site
See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit