Is HubSpot HIPAA compliant?
Yes now, but only on an Enterprise subscription where a super admin switches on Sensitive Data, identifies the account as a covered entity and accepts the agreement — and only in the specific tools HubSpot lists.
Applies to HubSpot CRM and Hubs. Last reviewed against HubSpot's own documentation. Next review January 4, 2027.
Reviewed by David Kim — Billing and RCM Operations Director.
What you must do
- Be on an Enterprise edition. HubSpot states customers with an Enterprise subscription may enable Sensitive Data.
- A super admin turns it on: Settings → Security → Sensitive Data → toggle Sensitive Data Protection on.
- Tick both the health/medical data category and the covered-entity box — this is what triggers application of the agreement.
- Read and accept the Sensitive Data Terms and the business associate agreement, which sits at Annex I of those terms.
- Create each field holding patient information as a sensitive data property and confirm it contains health information.
- Plan your fields first. A property's sensitivity setting cannot be changed once created, and Sensitive Data cannot be switched off once on.
- Keep patient information inside the covered features: sensitive-flagged properties, CRM activities, attachments, forms, call recordings and the named assistant features.
Does HubSpot sign a business associate agreement?
Yes. HubSpot offers one. Enterprise editions only. Self-serve in product. Super admin → Settings → Security → Sensitive Data → toggle on → select health/medical data and the covered-entity checkbox → accept the Sensitive Data Terms and the agreement at Annex I.
What this means in practice
HubSpot's position has changed. For years the answer was a flat no; today HubSpot publishes a business associate agreement as Annex I of its Sensitive Data Terms and lets an Enterprise customer accept it inside the product without talking to sales.
The catch is scope. Only Enterprise editions can switch Sensitive Data on, and once on it cannot be switched off. Patient information is permitted only in the features HubSpot names as covered — sensitive-flagged properties, forms, notes, calls, tasks, one-to-one email, meetings, attachments and call recordings. Chatbots, playbooks, sandboxes and personalization tokens are excluded, which rules out merging any clinical detail into an automated send.
Every field holding patient information also has to be created as a sensitive data property and flagged as containing health information, and that setting cannot be changed afterwards. Map your fields before you import anything.
How organizations get this wrong
The specific mistakes we see with HubSpot, not generic advice.
- Reading a pre-2024 article and concluding HubSpot never signs. It does now, but only on Enterprise and only through the Sensitive Data settings.
- Turning on Sensitive Data before mapping fields. The switch is permanent, and a property's sensitivity cannot be changed once created.
- Putting patient details into a chatbot or personalization token — both are unsupported, so that data sits outside the covered features.
- Assuming an Enterprise seat alone is enough. You must also tick the covered-entity box and accept the agreement in settings.
What the agreement does not cover
- Every subscription below Enterprise.
- Chatbots, playbooks, sandboxes and personalization tokens, where sensitive data properties are unavailable.
- Calculation, rollup, property sync and HubSpot user properties.
- Any use of patient information outside the features HubSpot lists as covered, which it classes as prohibited in any feature.
- HubSpot notes support for this is not available in all areas, so regional limits apply.
Alternatives
Listed on merit. We take no payment for placement and use no affiliate links.
Broader covered-service list including Health Cloud if you need clinical data models
Available well below enterprise pricing, with field-level restrictions you control
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with HubSpot, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from HubSpot’s own published documentation, read on the date shown.
- Store Sensitive Data in HubSpot — HubSpot. Published May 8, 2026. Read July 29, 2026.
- HubSpot Sensitive Data Terms — HubSpot. Published April 14, 2026. Read July 29, 2026.
- Understand how Sensitive Data is used in HubSpot tools — HubSpot. Published July 2, 2026. Read July 29, 2026.
Change history
- — First published. HubSpot historically did not sign; it now publishes an agreement at Annex I of its Sensitive Data Terms for Enterprise customers.
This page is information, not certification and not legal advice. It reflects HubSpot’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.