CompyMax

Is Salesforce HIPAA compliant?

Only under specific conditions

Yes, if you sign Salesforce's business associate addendum through your account representative and it names the specific Salesforce service you are putting patient information into.

Applies to Salesforce (Health Cloud, Sales Cloud, Service Cloud). Last reviewed against Salesforce's own documentation. Next review January 3, 2027.

Reviewed by David Kim — Billing and RCM Operations Director.

What you must do

  • Sign an addendum that names the service you use. Salesforce requires the agreement to include the specific covered service, and that you comply with its restrictions article.
  • Check your service is on the covered list. Health Cloud, Sales Cloud, Service Cloud, Experience Cloud, Marketing Cloud Engagement, Lightning Platform, Salesforce Shield, the mobile app and Tableau Cloud are named on the list last updated 18 March 2026.
  • Request it through your account representative — there is no self-serve acceptance screen.
  • Encrypt patient information yourself. Salesforce makes the customer responsible for encrypting information transmitted through the services and, where within your control, stored in them.
  • Where you control it, enable and maintain data masking in the Einstein Trust Layer configuration.
  • Treat anything deployed on your own premises as outside the agreement.

Does Salesforce sign a business associate agreement?

Yes. Salesforce offers one. No edition is named. Coverage is granted service by service — the signed addendum must include the specific covered service you use. Contact your Salesforce account representative and ask for the HIPAA Business Associate Addendum, naming every cloud and service you intend to put patient information into.

See their documentation.

What this means in practice

Salesforce grants coverage service by service rather than edition by edition. The covered list is long — Health Cloud, Sales Cloud, Service Cloud, Experience Cloud and Marketing Cloud Engagement are all on it — but nothing is protected until you and Salesforce have signed an addendum naming the specific service you are using.

Two obligations catch practices out. You must encrypt patient information you transmit to Salesforce and, where you control it, what you store there; Salesforce puts that squarely on the customer. And the AI layer is fenced off: Agentforce and Einstein may not be used to diagnose, treat or infer anyone's condition, eligibility or outcome, and Einstein Bots must never see patient information in utterance records.

Because the request runs through an account executive rather than a settings page, allow weeks rather than minutes, and get the executed copy in hand before your first patient record is loaded.

How organizations get this wrong

The specific mistakes we see with Salesforce, not generic advice.

  • Assuming a Salesforce subscription automatically includes the addendum. Nothing is covered until a signed agreement names the specific cloud you use.
  • Turning on Agentforce or Einstein to triage patients — Salesforce forbids using them to infer or interpret a health condition or eligibility.
  • Connecting Slack through Salesforce and assuming it is covered. Slack counts only once Slack itself confirms the plan is HIPAA-enabled.
  • Relying on the platform to encrypt everything. The restrictions article makes encrypting transmitted patient information the customer's own responsibility.

What the agreement does not cover

  • Any Salesforce service not named on the covered services list.
  • Any portion of a covered service deployed on the customer's own premises.
  • Using Einstein or Agentforce as a substitute for medical advice or diagnosis, as a medical device, or to infer or interpret an individual's health condition, status, eligibility or outcome.
  • Einstein Bots utterance records, and the answer automation and input recommender features.
  • Slack under the Salesforce agreement until Slack itself confirms the plan is HIPAA-enabled.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • HubSpot

    Enterprise customers can accept the agreement themselves in settings instead of waiting on a sales cycle

  • Zoho CRM

    Comparable contact and pipeline management at a far lower price point

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Salesforce, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Salesforce’s own published documentation, read on the date shown.

  1. Business Associate Addendum RestrictionsSalesforce. Published March 18, 2026. Read July 29, 2026.
  2. HIPAA — Salesforce ComplianceSalesforce. No publication date given. Read July 29, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects Salesforce’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.