Skip to main content
Guide

Is the HubSpot MCP HIPAA Compliant? A Clinic Verdict

No. HubSpot has not named its MCP server or Claude connector as BAA-covered, and clinic contacts and notes are PHI. Keep HubSpot as CRM and use Curve for ad answers.

11 min read

No, the HubSpot MCP is not HIPAA compliant for clinic patient data, because HubSpot has not named its remote MCP server or its Claude connector as services covered by its BAA. HubSpot signs a BAA only on Enterprise plans with Sensitive Data on, and even then it blocks activity and conversation data from the MCP server rather than authorizing PHI through it. Clinic contact records and notes are PHI, and every answer also crosses to an AI vendor under separate terms. Keep HubSpot as your CRM, and use Curve, which holds your tracking data under a signed BAA on every plan, for ad-performance questions answered with aggregate weekly figures.

What the HubSpot MCP and Claude connector can reach

HubSpot gives AI clients two doors into the same CRM. Evaluate both, because staff will use whichever is easier.

  • The remote HubSpot MCP server lives at https://mcp.hubspot.com. It has been generally available since April 13, 2026, and every connection requires OAuth 2.1 with PKCE.
  • The HubSpot connector for Claude launched on July 29, 2025 with read-only access to contacts, companies, deals, tickets and their associations. HubSpot's product page now says it reads engagement history (emails, calls, meetings, notes and tasks) and object lists, and can create and update contacts, companies, deals and tickets and log notes, calls, meetings, tasks and emails. It works on any HubSpot tier, including Free, alongside a paid Claude plan (Pro, Max, Team or Enterprise).

What the MCP server can read

  • CRM records: contacts, companies, deals, tickets, leads, users, appointments, courses, listings, projects, services, custom objects and segments.
  • Revenue objects (beta): carts, invoices, orders, line items, products, quotes and subscriptions.
  • Everything around the record: activities (calls, emails, meetings, notes, tasks), conversations, content and marketing assets, and marketing emails.

What it can write

More than most clinics expect. HubSpot describes manage_crm_objects as able to "Create or update CRM records or activities," so it creates and updates contacts, leads and appointments and logs calls, meetings, notes, tasks and emails. Separate tools (manage_landing_page, manage_blog_post, manage_marketing_email) handle content, and the server also manages campaigns, pipelines, custom properties and segments. Delete is not mentioned either way.

Whose access the model inherits

You do not pick scopes when the connector is created. HubSpot derives them from the tools on the server and the permissions the user grants at install, and "All actions respect your existing HubSpot user permissions." In practice, the AI gets the reach of whoever clicked Connect. If that was a super admin, the model can see every contact a super admin can.

For the Claude connector, super admins and users with App Marketplace permissions decide who gets access at Connected Apps > HubSpot connector for Claude > Give users access. That screen is where a compliance officer should look first.

HubSpot's HIPAA stance, and where it stops

HubSpot does sign a BAA, but only down one path.

  • Sensitive Data must be on, and it exists only on Enterprise plans: Marketing Hub, Sales Hub, Service Hub, Data Hub, Content Hub and Smart CRM Enterprise.
  • Two boxes get ticked: "Health/Medical Data" and "We are a HIPAA-covered entity or business associate." HubSpot says this lets it "track the application of the Business Associate Agreement (BAA)."
  • The BAA lives in the Sensitive Data Terms (last modified April 14, 2026), and it covers only services "HubSpot has explicitly authorised for use by Customer to process PHI."
  • AI training is off: accounts with Sensitive Data on are automatically opted out of HubSpot AI model training. That applies to HubSpot's own models, not to Claude or ChatGPT, which run under their vendors' terms.

With Sensitive Data on, HubSpot says "activity and conversation data will be blocked from access through the MCP server," meaning calls, emails, meetings, notes and tasks. At launch, it said the Claude connector "does not provide access to custom Sensitive Data Properties or sensitive content from other Sensitive Data Covered Services, including Personal Health Information and other forms of Highly Sensitive Data."

Put together, HubSpot's docs treat both surfaces as places PHI should not go, but the only block they describe covers activities and conversations on the MCP server. We found no HubSpot statement naming either one as authorized to process PHI under the BAA. A BAA covers what its terms say, as we unpack in what a real BAA covers. Routing patient data through the MCP uses it for a job HubSpot has not signed up for.

The uncomfortable part is the tier gap. The connector runs on Free, Starter and Professional, and none of those can turn on Sensitive Data. So the connector reads their notes and call logs with nothing fencing them but user permissions.

Those portals have no BAA path either, and they are where a busy practice manager is most likely to click Connect. For the platform question beyond MCP, see HubSpot's HIPAA risks for clinics.

Why contact records and notes in a clinic portal are PHI

HIPAA defines individually identifiable health information as information, including demographic information, created or received by a health care provider that relates to a person's health, "the provision of health care to an individual," or payment for it, and that identifies the person or reasonably could (45 CFR 160.103). If your clinic is a HIPAA covered entity, that information is PHI in any form, and in a HubSpot portal it is electronic PHI.

A clinic's HubSpot portal meets that definition almost by construction:

  • The contact record. Name, email and phone are three of the 18 identifiers in HIPAA's Safe Harbor list, and in a clinic portal the record usually exists because the person sought or received care from you.
  • Lifecycle stages and pipelines. "Consult booked," "Patient" and "Treatment started" each state a care relationship.
  • Deals and appointments. A deal named after a procedure, or an appointment on a contact, ties a name to a service and a date.
  • Notes, calls, emails and tasks. Coordinators write down what patients tell them: symptoms, medications, insurance problems. This is the most sensitive data in the portal.
  • Segments. Membership in a segment called "Missed GLP-1 refill" is health information about everyone in it.

Sensitive Data narrows the exposure; it does not close it. HubSpot's MCP docs name only activity and conversation data as blocked, not contact fields, deal names, appointments or segment membership, which carry plenty of PHI on their own.

The AI-vendor hop nobody puts on the data map

Even a well-configured portal hands its answers to someone else. One question travels four steps:

  1. Staff ask Claude about leads or patients.
  2. Claude calls a HubSpot tool such as search_crm_objects, sending the query terms to HubSpot.
  3. HubSpot returns the matching records, and every field in that tool result enters the model's context on the AI vendor's side.
  4. The answer, and the records behind it, stay in the conversation the AI vendor processes.

Each step needs its own cover, and the AI vendor is where most setups break:

  • Anthropic offers HIPAA readiness only on Enterprise. Team, Free, Pro and Max cannot enable it, so three of the four paid plans the HubSpot connector works with cannot carry an Anthropic BAA.
  • Enterprise does not cover the connector traffic. Anthropic's BAA page says MCPs and connectors can be used, but data sent to third parties through them is not covered by its BAA. That leg falls to HubSpot, which has not named the MCP as authorized for PHI, so no BAA covers it from either side.
  • The API route is excluded. On the Claude API, the MCP connector (mcp_servers) is not HIPAA-eligible. More in is Claude HIPAA compliant.
  • ChatGPT is no shortcut. OpenAI offers ChatGPT BAAs only on sales-managed Enterprise or Edu accounts, none on ChatGPT Business, and it describes custom apps and MCP connectors as "not verified by OpenAI."

Then there is minimum necessary. HIPAA asks for "reasonable efforts to limit protected health information to the minimum necessary" (45 CFR 164.502(b)). "Which campaign books consults most cheaply?" needs zero names, so pulling contact records to answer it fails before the BAA question arises. It is the same reason you cannot paste a patient funnel into ChatGPT.

Where it goes wrong in a real portal

  1. The quick question. "Which Google Ads leads booked last week?" comes back as names and appointment records in a chat transcript.
  2. The helpful write. "Log a note that she wants to talk about side effects" puts PHI into an activity. It is in the chat transcript before HubSpot ever receives it, and HubSpot's docs say Sensitive Data blocks activity data "from access" through the MCP server without saying it blocks writes.
  3. The poisoned field. Free-text form answers reach the model as tool results, and OWASP warns that attackers hide instructions in tool return values to steer what the model does next. With manage_crm_objects connected, "what it does next" can be an update to a contact record.
  4. The agency shortcut. An agency connects a client portal to its own Claude Team workspace, where no Anthropic BAA can reach. Other CRMs share the trap, as our GoHighLevel MCP verdict shows.

How Curve answers ad questions without the CRM hop

Marketing rarely needs a person. It needs to know which campaigns book consults, and at what cost per conversion. Curve MCP answers those questions in any MCP-capable client, such as Claude, ChatGPT or Cursor, and it is built the opposite way at each HubSpot failure point above.

  • Records vs aggregates: search_crm_objects returns contact records. Curve MCP returns organization-level visitors, sessions, goal completions and funnel steps, plus a reconciliation of your server-side campaigns: each campaign's platform-reported spend, clicks and impressions next to the conversions Curve's server-side tracking recorded, with cost per conversion by completed week over fixed look-backs, counts rounded and small groups withheld. One link opens the full sent, accepted and matched view inside Curve.
  • Writes: manage_crm_objects can write notes. Curve MCP is read-only, with no write tools.
  • Free text: inputs are fixed choices, no visitor-set string (UTMs, page paths, referrers) is ever returned, and unapproved campaign names show as "(label hidden)".
  • Access: HubSpot's MCP has the reach of whoever installed it. Curve MCP is off by default, only the clinic's primary user can enable it, tokens are scoped and expire, every call is logged, and a final guard blocks any answer containing something shaped like an email, phone number, ID, date or name.

What it leaves out is deliberate: no revenue, ROAS, form data, or channel, device, region or page breakdowns.

When a question does need a person, it hands back a link that opens Curve Analyst behind a login. The link works once, expires quickly and carries no data. The suppression logic is explained in how small-group rules work.

One candid limit: Curve's BAA covers its own platform, not the AI client you connect. Nothing here makes that vendor HIPAA compliant. The goal is narrower and checkable against the HIPAA-safe MCP checklist: what leaves is aggregate, rounded and small-group suppressed.

The safer split, set up

HubSpot: the system of record, under its own terms

  • Patient portal on Enterprise: turn on Sensitive Data, tick both HIPAA boxes, and confirm the BAA covers the services you actually use.
  • Keep both AI doors away from patient records unless your compliance officer approves the whole chain, including the AI vendor's BAA on the exact plan in use. Our connector approval checklist walks through it.
  • Content work: for blog posts, landing pages or marketing emails, connect as a dedicated HubSpot user with the fewest contact permissions your portal allows.
  • Free, Starter or Professional with patients or care-seeking leads in it: do not connect an AI client. There is no Sensitive Data block and no BAA path.

Curve: ad performance and the conversion loop

Curve's server-side tracking replaces the Meta Pixel and Google tag, so events reach US-hosted infrastructure before any ad platform. Only fields you explicitly map are forwarded, identifiers are SHA-256 hashed, and neutral event aliases hide the service line. A booked consult comes back from the CRM through incoming webhooks or offline uploads matched by click ID, as covered in CRM lifecycle stages as conversions. The ad platforms learn what converted, and Claude never reads a contact record.

Frequently asked questions

Does HubSpot sign a BAA with clinics?

Yes, through its Sensitive Data Terms, for covered entities and business associates on an Enterprise plan with Sensitive Data on and the HIPAA boxes ticked. It covers only services HubSpot has explicitly authorized for PHI.

Is the HubSpot connector for Claude covered by that BAA?

We found no HubSpot statement saying so. HubSpot launched it saying it does not provide access to Sensitive Data properties or Personal Health Information. That describes a tool meant to stay away from PHI, not one authorized to carry it.

Does turning on Sensitive Data make the HubSpot MCP safe for PHI?

No. It stops the MCP server reading activity and conversation data, such as notes, calls and emails. Contacts, deals, appointments and segments are not named in that block, and answers still cross to an AI vendor with its own terms.

Can Claude write patient notes into HubSpot through the MCP?

Yes. The server's manage_crm_objects tool creates and updates records and activities, including notes. HubSpot says Sensitive Data blocks activity data from access through the MCP server, but it does not say that stops writes. Either way, a clinical detail a staff member dictates is in the AI vendor's transcript before it reaches HubSpot.

Is there any safe use of the HubSpot MCP at a clinic?

Yes, in a portal that holds no patients or care-seeking leads. In a patient portal, only content work on Enterprise with Sensitive Data on: blog posts, landing pages and marketing emails, through a dedicated, low-permission user. Anything touching patient records stays out unless the whole chain is covered.

Does Curve MCP read our HubSpot contacts?

No. It does not connect to HubSpot, and its database role cannot read contact details, form answers or journeys. It returns aggregate campaign and site figures by completed week.

Where to start

  1. Find the connections. Open Connected Apps > HubSpot connector for Claude > Give users access in every portal, and ask each team which AI clients they have pointed at mcp.hubspot.com.
  2. Classify each portal. No patients or care-seeking leads (for example a B2B or vendor portal): the MCP fits. Patients or leads with Sensitive Data on: content work only, through a dedicated user. Patients or leads without it: disconnect.
  3. Move the ad questions. Send campaign and cost-per-conversion questions to Curve, which holds the underlying data under a BAA signed on every plan and releases only aggregate, rounded, logged answers. Book a demo to see it answer them in Claude, ChatGPT or Cursor, or run the free compliance scanner first.

Reviewed September 2026. Checked against HubSpot's MCP server docs and changelogs, its Claude connector pages, its Sensitive Data articles and terms, Anthropic's and OpenAI's BAA pages, and 45 CFR 160.103 and 164.502.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit