CompyMax

Is ActiveCampaign HIPAA compliant?

Only under specific conditions

Yes on the Enterprise plan, where ActiveCampaign lists HIPAA support and says a business associate agreement is available — but the agreement text, the request route and what is excluded under it are not published, so all three have to be settled with sales.

Applies to ActiveCampaign. Last reviewed against ActiveCampaign's own documentation. Next review February 13, 2027.

Reviewed by Margaret O'Brien — HIPAA Privacy Officer.

What you must do

  • Buy the Enterprise plan. ActiveCampaign's pricing page and its plans overview both list 'HIPAA support' in the Enterprise column and nowhere else.
  • Get the business associate agreement executed through your sales contact before any patient information is imported. ActiveCampaign publishes no agreement text, no signing form and no help article describing the process — the sales conversation is the route.
  • Ask sales, in writing, which features are excluded when HIPAA support is enabled. No fetched ActiveCampaign page publishes an exclusion list, and this entry deliberately does not invent one.
  • Treat compliance as configuration. ActiveCampaign's own wording is that the platform 'can be configured to support HIPAA-compliant marketing' — the features are available, not switched on.
  • Keep list names, tags, segments and merge fields free of anything that reveals a condition, and keep patient detail out of subject lines — ActiveCampaign's own guidance says as much.

Does ActiveCampaign sign a business associate agreement?

Yes. ActiveCampaign offers one. Enterprise. 'HIPAA support' appears in the Enterprise column of the pricing table and the plans overview. Not published. There is no agreement document in ActiveCampaign's legal index and no self-serve flow — request it through ActiveCampaign sales and keep the executed copy.

See their documentation.

What this means in practice

ActiveCampaign is the rare mainstream marketing platform that has moved toward healthcare rather than away from it, but the paper trail is thinner than the marketing suggests. The plan requirement is stated plainly — HIPAA support sits in the Enterprise column and nowhere else — while the agreement itself is invisible: no published text, no signing flow, no help article, and a legal index that never mentions HIPAA at all. Everything that matters ends up settled in a sales conversation.

That is workable if you treat the sales conversation as the contract negotiation it is. Get the executed agreement, get the exclusion list in writing — no ActiveCampaign page says which features are off-limits when HIPAA support is on, and platforms in this category usually carve out SMS, site tracking or predictive features — and keep both documents where an auditor can find them.

Then hold the marketing discipline that no vendor agreement supplies. A list that exists because everyone on it attends one clinic discloses a condition before any message is written, and tags, segments and merge fields disclose the same way. The agreement settles what ActiveCampaign owes you, not whether a given campaign needed the patient's authorization first.

How organizations get this wrong

The specific mistakes we see with ActiveCampaign, not generic advice.

  • Reading ActiveCampaign's own blog line about a Professional-plan BAA and buying the wrong tier — the pricing table and plans overview both put HIPAA support on Enterprise only.
  • Signing the agreement without asking which features are excluded under it, then running site tracking or predictive sending over patient records nobody scoped.
  • Naming a segment or automation after a condition or procedure, which discloses as much as any message body.
  • Importing the patient list before the agreement is executed because the Enterprise contract is 'in progress'.

What the agreement does not cover

  • Every plan below Enterprise, including Professional on the current pricing table.
  • Whatever the unpublished agreement excludes. ActiveCampaign's terms of service and acceptable use policy contain no HIPAA or patient-information language at all, so the executed agreement is the only document that defines scope.
  • Whether a given campaign is permitted marketing under the Privacy Rule — that is a question about your patient authorizations, not about the vendor.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Zoho Campaigns

    The other mainstream marketing tool where an agreement is available, without an Enterprise-tier price attached

  • Mailchimp

    The default in this category, and the reason to check alternatives at all: it offers no agreement on any plan

  • Paubox

    Where the requirement is really patient email rather than marketing campaigns

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with ActiveCampaign, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from ActiveCampaign’s own published documentation, read on the date shown.

  1. Platform Pricing & FeaturesActiveCampaign. No publication date given. Read August 30, 2026.
  2. Overview of ActiveCampaign plansActiveCampaign. Published August 20, 2026. Read August 30, 2026.
  3. Marketing Automation Software for Healthcare InstitutionsActiveCampaign. Published March 6, 2026. Read August 30, 2026.
  4. HIPAA-Compliant Marketing GuideActiveCampaign. Published January 29, 2026. Read August 30, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects ActiveCampaign’s published documentation as read on August 30, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.