HIPAA Compliant Scheduling Software: BAAs and Ad Attribution
Which scheduling tools sign a BAA, from Calendly to SimplePractice, and how Curve Compliance keeps the ad click when patients book on another site.
HIPAA compliant scheduling software is a booking tool that signs a Business Associate Agreement (BAA) with you, used on booking pages that carry no ad pixels revealing a service or condition. Going by each vendor's own pages, Healthie, IntakeQ, Jane App, SimplePractice and Tebra sign a BAA, Acuity Scheduling and GoHighLevel sign one on specific plans or with an add-on, Calendly says it does not offer one, and Zocdoc has no public statement we could quote. Whichever scheduler you pick, Curve Compliance keeps your ad attribution and conversions HIPAA-compliant: it credits each booking to the ad that brought the patient in and sends the conversion to Meta, Google and other ad platforms server-side, under a BAA it signs on every plan.
Book a call. Curve Compliance keeps the ad click when patients book on IntakeQ, Calendly, Acuity, Jane App, Zocdoc and other schedulers, sends each booking server-side to Meta, Google, TikTok, Microsoft Advertising and LinkedIn, and signs a BAA on every plan. Book a call with Curve.
What makes scheduling HIPAA compliant
A HIPAA covered entity needs a BAA with any vendor that handles its patients' Protected Health Information. A scheduler holds names, contact details and appointment types, and often intake answers too, so HIPAA compliant appointment scheduling comes down to two things.
- A BAA with the scheduler, on the plan you use. Some vendors sign on every account, some only on certain plans, and some not at all. The BAA directory answers this for each tool from the vendor's own page.
- No ad pixels on booking pages that reveal a service or condition. A pixel on a booking or confirmation page can send the page address, the appointment type and the visitor's identifiers to Meta, Google or TikTok. The scheduler's BAA does not cover that, because the ad platform is a separate recipient that has not signed it. Meta's Business Tools Terms say advertisers will not share data that "includes or is based on, directly or otherwise, health information".
A signed BAA is the start, not the finish. How you set up the scheduler and which integrations you connect to it still matter. Talk to your counsel about your own obligations.
Which scheduling tools sign a BAA
The table below summarizes what each vendor says on its own pages, as recorded in the Curve BAA directory between September 29 and October 1, 2026. Vendors change their plans and terms, so confirm the current terms with the vendor before you send it patient data.
| Scheduler | Signs a BAA? | Terms the vendor states | Ad attribution with Curve Compliance |
|---|---|---|---|
| Acuity Scheduling | On specific plans | Squarespace says an Acuity account on the Powerhouse or Premium plan can be made HIPAA-enabled with a BAA for that account, and custom BAAs are available on Enterprise. | Plain booking links handled automatically. Acuity Scheduling integration |
| Calendly | No | Calendly says it does not currently offer a BAA and is not intended for collecting Protected Health Information. | Plain booking links handled automatically. Calendly integration |
| GoHighLevel | With an add-on | HighLevel says its optional HIPAA add-on includes a signed BAA and is open to agencies on any plan. HIPAA is then turned on for each sub-account. | Custom setup by Curve's team. GoHighLevel integration |
| Healthie | Yes | Healthie says its BAA is entered into when your Healthie account is created. | Healthie sends bookings to Curve through Keragon. |
| IntakeQ | Yes | IntakeQ says the account admin signs its BAA inside the account. | Plain booking links handled automatically. IntakeQ integration |
| Jane App | Yes | Jane says it is HIPAA compliant and can work with you to develop a BAA. | Plain booking links handled automatically. Jane App integration |
| SimplePractice | Yes | SimplePractice says you agree to its BAA when you create your trial account, and you do not need to sign it again when you upgrade. | Outcomes from your EHR come in as offline conversion uploads. |
| Tebra | Yes | Tebra says its BAA is part of its Terms of Service for customers that are covered entities. | Outcomes from your EHR come in as offline conversion uploads. |
| Zocdoc | No public statement | Zocdoc's privacy pages did not give a statement about a BAA that could be quoted. Ask Zocdoc directly. | Plain booking links handled automatically. Zocdoc integration |
What each vendor's terms say
Acuity Scheduling. Squarespace says an account only becomes HIPAA-enabled when a separate BAA is entered into for that account, and that the BAA does not cover other Squarespace features. It says calendar syncing with Office 365, Outlook.com, Live.com, Exchange and iCloud is not available, and that third-party integrations such as Google Calendar or Stripe are yours to assess. More in Is Acuity Scheduling HIPAA compliant?
Calendly. Calendly's Community Manager wrote in July 2026 that Calendly "isn't intended for collecting Protected Health Information, and we don't currently offer a BAA." Without a BAA, keep patient details out of Calendly, and keep ad pixels off any Calendly page that shows a condition, a service or an appointment. More in Is Calendly HIPAA compliant?
GoHighLevel. HighLevel says its account-wide HIPAA add-on enables encryption of ePHI, BAAs, audit logging and MFA enforcement. It also says HighLevel accounts are not HIPAA compliant by default, and that agency owners must then turn on HIPAA for each sub-account in Advanced Settings. More in Is GoHighLevel HIPAA compliant?
IntakeQ. IntakeQ says only the account admin needs to sign its BAA, and that a BAA is especially important if you plan to process payments through PracticeQ.
Zocdoc. The directory checked Zocdoc's Privacy Policy and its intake and HIPAA authorization page and found no BAA statement to quote. Ask Zocdoc directly, and keep patient details out of it until a BAA is in place.
The ad attribution problem with scheduling software
For most clinics the booking is the conversion their ads optimize for, and it usually happens on the scheduler's domain, not yours. The evidence that an ad brought the visitor lives in their browser on your site: the click ID Meta or Google put in the URL, and the UTM parameters. When the visitor clicks through to IntakeQ, Calendly, Jane App or another scheduler, that evidence stays behind. The scheduler later reports the appointment, but its webhook carries a name and an email, not a click ID. On its own, that booking cannot be credited to the ad.
Putting an ad pixel on the scheduler's confirmation page brings back the problem from the first section. Matching on email alone is less reliable, because it depends on the patient using the same address on both sides.
How Curve Compliance keeps the ad click: bridge tokens
When a visitor clicks a link to a recognized booking platform, Curve Compliance keeps that visitor's ad attribution (click IDs, UTM parameters, session and the page the click came from) and passes the scheduler a short reference to it, called a bridge token, as part of the booking link. The token carries no form content and is not a patient identifier. Curve records a booking intent event at the same moment, so you can see intent even if the booking is never completed.
The scheduler keeps the token with the appointment and includes it in the webhook it sends when the booking is made. Curve's team configures that webhook with you, including the custom field most schedulers use to carry the token. When the webhook arrives, Curve credits the booking to the original visit and forwards the conversion, with its click IDs and UTMs, to Meta Conversions API, Google Ads, TikTok, Microsoft Advertising and LinkedIn from Curve's servers. Each platform receives only a fixed list of fields, contact identifiers are off by default and SHA-256 hashed when enabled, and events can use neutral names.
- Plain links are handled automatically. This covers plain booking links to IntakeQ, Calendly, Acuity, Jane App, OptiMantra, Boulevard, Zocdoc, Mindbody, Vagaro, Square, Setmore, Booker and others. A booking link to any other platform can be included on request.
- Embedded widgets and GoHighLevel get a custom setup from Curve's team. Buttons that open the scheduler with JavaScript, pop-ups, embedded booking widgets, and platforms such as GoHighLevel that are not reached through a plain link get a small custom setup. Tell Curve's team how your booking flow works and they configure it for you.
- Bookings made days later still match. The token stays with the appointment, so a booking made days after the ad click is still credited to the visit that started it.
See how it works for each scheduler: IntakeQ, Calendly, Acuity Scheduling, Jane App, Zocdoc and GoHighLevel.
Healthie, SimplePractice, Tebra and other practice platforms
Practice platforms that combine booking with intake and records connect a different way. Healthie sends bookings to Curve Compliance through Keragon, and Curve credits each one to the original ad click. Curve also receives outcomes from Athenahealth, OptiMantra, IntakeQ and Jane through Keragon. For SimplePractice, Tebra or another EHR, outcomes can come in as offline conversion uploads, and booking systems, CRMs and call tracking can send them through incoming webhooks.
Event Logs show what Curve sent to each platform and what the platform accepted. Campaign Reporting puts ad spend next to Curve-tracked bookings for each platform and campaign, and shows a single prospect's journey from ad click to booking.
Book a call. Curve's team will look at your booking flow, whichever scheduler you use, and set it up so each booking is credited to the ad that brought the patient in. Setup is done for you, typically live in about a week. Book a call with Curve.
How to choose HIPAA compliant scheduling software
- Get the BAA on the plan you will use. Some BAAs come with the account, as with Healthie, SimplePractice and Tebra. Others depend on a plan or add-on, as with Acuity Scheduling and GoHighLevel.
- Read what the BAA leaves out. Squarespace says its BAA does not cover other Squarespace features. Tebra says its BAA does not apply to payment processing. HighLevel says HIPAA is turned on per sub-account.
- Check every integration you connect. Calendar sync, payments and email tools are separate vendors with their own terms.
- Keep ad pixels off booking pages. Run a free website scan on your booking and confirmation pages. It lists the pixels and trackers on a page.
- Decide how bookings reach your ad platforms. In Curve Compliance, plain links use bridge tokens, widgets get a custom setup, and practice platforms use Keragon or offline uploads.
- Make sure late bookings still count. Ask whether a booking made days after the click is still credited to the ad. With Curve Compliance it is.
- Confirm you can see what each ad platform accepted. Curve Compliance Event Logs show this for every conversion.
More in the Curve Compliance FAQ and Curve's healthcare integrations.
Frequently Asked Questions
Which scheduling software is HIPAA compliant?
Going by each vendor's own pages, Healthie, IntakeQ, Jane App, SimplePractice and Tebra sign a BAA. Acuity Scheduling signs one on its Powerhouse and Premium plans, and GoHighLevel with its HIPAA add-on. Pair the scheduler with Curve Compliance to keep your ad conversions HIPAA-compliant.
Is Calendly HIPAA compliant?
Calendly says it does not currently offer a BAA and is not intended for collecting Protected Health Information. See Calendly's BAA entry for the quotes and sources.
Does SimplePractice sign a BAA?
Yes. SimplePractice says you agree to its Business Associate Agreement when you create your trial account, and you do not need to sign it again when you upgrade. See SimplePractice's BAA entry.
Is Acuity Scheduling HIPAA compliant?
Squarespace says an Acuity account on the Powerhouse or Premium plan can be made HIPAA-enabled with a BAA for that account. That BAA does not cover other Squarespace features.
Does a scheduler's BAA cover my ad pixels?
No. A BAA covers the data that one vendor handles for you. A pixel sends data from the visitor's browser to Meta, Google or TikTok, and none of them is a party to that BAA.
Can I put the Meta pixel on my booking page?
Not on a booking page that reveals a service or condition. Meta's Business Tools Terms say advertisers will not share data that includes or is based on health information. Send the booking server-side with a neutral event name instead, as Curve Compliance does.
How do I track ad conversions when patients book on another website?
Curve Compliance passes the scheduler a bridge token with the booking link, then credits the booking to the original ad click when the scheduler's webhook comes back, and sends the conversion server-side. Plain links are handled automatically, and embedded widgets and GoHighLevel get a custom setup from Curve's team.
Can a booking made days after the ad click still be credited?
Yes. The bridge token stays with the appointment, so Curve Compliance still matches a booking made days after the click to the ad that started it.
Related articles
Check your own site
See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.
Stay Compliant. Scale Confidently.
Curve's team sets up HIPAA-compliant ad tracking for you, and most customers are live in about a week.
Book a free tracking audit