CompyMax

HIPAA compliant CRM software

Contact and pipeline management. Referral and patient records inside a general-purpose CRM need the same protection as clinical systems.

A CRM holding referral sources, enquiries and patient records needs the same protection as a clinical system, and the reason it often does not have it is that the CRM arrived through sales or marketing rather than through anyone thinking about patient data. By the time it matters, several years of records exist in fields nobody classified.

Coverage in this category is granted narrowly and almost never account-wide. The three patterns you will meet are: an enterprise-only switch that a super admin turns on, which then limits patient information to a specific list of covered tools; a service-by-service addendum signed through an account representative, where nothing is covered unless the signed document names the specific product you are using; and a model where you nominate the modules and tick each individual field that will hold health information, and anything you fail to mark keeps no protection at all.

Two properties of these systems make sequencing critical. Several of these switches are irreversible — once sensitive data handling is on, it cannot be turned off, and a field's sensitivity setting cannot be changed after it is created. And the AI layer is usually fenced off separately, with explicit prohibitions on using assistants or bots to infer, interpret or triage anyone's condition or eligibility. Map your fields and decide your AI position before importing anything.

What to check before you adopt one

  • Check the edition requirement first, because the compliance settings and field-level encryption in this category are routinely reserved for the top one or two tiers and cannot be added to a mid-tier subscription.
  • Establish exactly which tools and objects may hold patient information. Coverage is defined by a list, and common features — chatbots, playbooks, sandboxes, personalization tokens, calculated and rollup fields — frequently sit outside it.
  • Map every field that will hold health information before you import, since sensitivity settings usually cannot be changed after a field is created and the master switch often cannot be turned off once on.
  • Confirm the signed document names each specific product you use. Where coverage is service by service, a CRM addendum does nothing for the vendor's mail, helpdesk, forms or booking products.
  • Read the AI restrictions closely. Assistants and bots are commonly prohibited from being used to diagnose, triage or infer a condition, status, eligibility or outcome, and bot utterance records are often excluded outright.
  • Find out who is responsible for encryption. Several vendors place encrypting information you transmit, and where you control it what you store, squarely on the customer.
  • Enable field encryption early if you need it, because encrypted fields typically drop out of sorting, advanced filters, reports and forecasts — breaking anything built beforehand.
  • Check audit log retention against your own obligations, and extend it if the default is shorter.
  • Ask about regional availability, since support for these configurations is not always offered in every market.

The expensive mistake

Turning the compliance setting on before mapping the fields. The switch is usually one-way, a property's sensitivity cannot be changed once it exists, and any field left unmarked keeps none of the export, API and transfer restrictions — so an intake note typed into an ordinary description field sits unguarded inside an account everyone believes is covered. The other version of this is signing for the CRM alone while patient email runs through the same vendor's mail product and tickets through its helpdesk, neither of them named in the agreement.

Tracking which of these your organization uses?

The vendor and BAA register keeps every tool that touches patient information, its agreement status and its renewal date in one place — seeded from this research. See pricing.

Information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change terms without notice — confirm anything you rely on directly with them.