Healthcare teams ask us the same first question: "Is HubSpot HIPAA compliant?" It is the wrong question, and HubSpot's own terms say why. Compliance is how you run a system, and HubSpot's Sensitive Data Terms put the assessment on the customer. The useful questions are what HubSpot lets you store, where, and what you have to set up so the marketing team never sees what the clinical team records.
Every HubSpot requirement below was read in HubSpot's knowledge base and legal center on 29 September 2026, with HubSpot's own update date next to each source.
Can HubSpot store protected health information?
Yes, on Enterprise. HubSpot's Sensitive Data feature lets an Enterprise account store health and medical data in dedicated properties once a Super Admin turns it on, ticks the Health/Medical Data and HIPAA-covered entity or business associate boxes, and accepts HubSpot's Business Associate Agreement. On Professional or Starter there is no route to storing PHI.
The details that matter:
- Tier. Enterprise on Marketing, Sales, Service, Data, Content or Revenue Hub, or Smart CRM. Source: Store Sensitive Data in HubSpot, last updated by HubSpot 21 September 2026.
- The BAA. HubSpot's BAA is Annex I of its Sensitive Data Terms (last modified 14 April 2026). You accept it in the Sensitive Data settings; there is no separate negotiation for the standard terms.
- Your obligations. Section 2.3 of those terms makes you responsible for deciding whether your use meets your compliance obligations, for managing Sensitive Data in the account and for answering access requests about it.
- One-way choices. Once a data category is selected it cannot be removed, and an account that has declared HIPAA data cannot migrate to another data center.
Which HubSpot fields should hold PHI, and which should not?
PHI belongs only in custom properties created as Sensitive Data, with the "contains Protected Health Information" box ticked and view and edit access limited to the people who need it. Everything a marketer or salesperson needs to act on, such as lifecycle stage, location and consent, stays in ordinary properties that carry no clinical meaning.
This is the split we use on clinic network and digital health builds:
| Data | Where it lives | Why |
|---|---|---|
| Diagnosis, treatment, clinical notes, results | The EHR (Epic, Cerner, athena) | HubSpot is not the record of care. Nothing in a commercial workflow needs it. |
| Procedure of interest, referral reason, insurance member ID | HubSpot, Sensitive Data property flagged as PHI, field-level access | Intake and scheduling staff need it on the record; marketing does not. |
| Social security number | HubSpot, Highly Sensitive Data property, or not at all | Values are encrypted and must be decrypted to view. Most builds do not need it. |
| EHR patient ID | HubSpot, tokenized identifier, standard property | Links the two systems without carrying clinical meaning. |
| Lifecycle stage, location, service line, appointment status | HubSpot, standard properties | Drives routing, reporting and retention. Keep the values non-clinical: "Active patient", not the condition. |
| Consent and subscription status | HubSpot, subscription types and consent properties | Decides who may receive what. |
Two rules decide whether this plan survives the build. First, a property's Sensitive Data setting cannot be changed once it is created, so a field created as standard and later found to hold PHI has to be rebuilt and its data moved. Second, calculation, rollup and property sync properties cannot store Sensitive Data, so any score or rollup has to be built from non-clinical inputs. HubSpot offers a beta that converts existing custom properties, but we would not plan a healthcare build around a beta.
Our earlier piece on storing sensitive data securely in HubSpot CRM walks through the property screens themselves.
What stops working when you turn on Sensitive Data?
Sensitive Data properties cannot be used in personalization tokens, chatbots, playbooks or sandboxes, and Highly Sensitive Data is restricted further to viewing, forms and attachments. Workflows can filter and branch on a Sensitive Data property, but cannot copy it, use it as a token or trigger on a change to it.
The rest of the list, from HubSpot's Sensitive Data in HubSpot tools article (last updated 24 September 2026):
- Breeze. Breeze Assistant works, but it will not use Sensitive Data property values, and the account is opted out of HubSpot AI model training while Sensitive Data is on. HubSpot asks you not to put sensitive information in prompts.
- Files. Attachments uploaded to records, notes, forms and file properties after Sensitive Data is on get an extra layer of encryption. Files in the Files tool do not, so PHI never goes there.
- Notifications. Previews of notes and comments are hidden in notification emails by default.
- Multi-account. An account with Sensitive Data on cannot be a source for data mirroring.
- Integrations. Data synced to a third-party app is governed by that vendor's policies, not HubSpot's BAA. Every app that touches PHI needs its own BAA.
The practical effect: a sequence that says "following up on your knee consultation" is out, and it should be. The same sequence built on a service line value of "Orthopedics enquiry" and a non-clinical template works, and it is the version your compliance lead will sign off.
How do you set up consent for healthcare marketing in HubSpot?
Turn on HubSpot's data privacy settings, limit marketing email to contacts with a subscription, create subscription types per service line, and record where and when each consent was given. Then keep PHI out of marketing entirely, because HIPAA requires the patient's authorization before PHI is used for marketing.
The rule is in the HIPAA Privacy Rule at 45 CFR 164.508(a)(3), read on 29 September 2026: a covered entity must obtain an authorization for any use or disclosure of PHI for marketing, with narrow exceptions for face-to-face communication and promotional gifts of nominal value. Whether a given message counts as marketing is a question for your counsel, not your CRM.
In HubSpot, the setup is:
- Data privacy settings on. Settings, Privacy & Consent, then turn on data privacy settings and switch on "Limit emails to contacts with a subscription". Source: Manage data privacy settings, last updated 11 September 2026.
- Subscription types by purpose. Separate types for appointment reminders, service line news and events, so opting out of one does not silence the others.
- Consent text on every form. New forms get a privacy notice by default; existing forms need it added by hand.
- A consent record. A property for the source and date of consent, and, where marketing authorization is needed, the signed authorization stored as an attachment on the record.
- Clinical messages outside marketing email. Appointment and care messages go through the EHR's patient channel or a BAA-covered messaging tool, not a marketing email.
For one U.S. surgical provider, INSIDEA automated patient consent documents inside HubSpot: generated, sent and tracked from one property update, with no third-party e-signature tool.
What does a HIPAA-aware HubSpot setup cost and how long does it take?
The cost is mostly the Enterprise tier that Sensitive Data requires, plus the build. A clinic network running Service Hub Enterprise on ten seats pays $18,000 a year in licences and a $3,500 HubSpot onboarding fee before any partner work. INSIDEA's healthcare build is a fixed fee from $2,000 and runs on a twelve-week plan.
The figures, with sources: Service Hub Enterprise starts at $150 a seat a month with a $3,500 setup fee, per HubSpot's Service Hub pricing guide (updated 28 August 2026, checked 29 September 2026). Marketing Hub Enterprise is $3,600 a month with five seats and a $7,000 onboarding fee, per the Marketing Hub pricing guide (updated 14 September 2026, checked the same day). Confirm current figures in your HubSpot quote.
Worked example for that ten-seat clinic network: $150 x 10 seats x 12 months is $18,000, plus the $3,500 onboarding fee, is $21,500 from HubSpot in year one. The partner build is scoped at proposal from $2,000. BAA-enabled middleware for the EHR connection is priced by its vendor and is not included; we have not put a number on it because it varies by EHR and volume.
The twelve weeks run: weeks 1 to 3, audit and the PHI map; weeks 4 to 9, the build, with Sensitive Data on and properties created from the map; weeks 10 and 11, migration and training; week 12, handoff and the compliance review. The implementation timeline page covers how scope moves those weeks.
When is HubSpot the wrong system for a healthcare organization?
When the need is clinical. HubSpot is a commercial CRM: intake, referrals, patient experience, retention and B2B sales for digital health and medtech. If you need a record of care, e-prescribing or deep EHR workflows, the EHR ecosystem is the answer, and federal pre-clearance requirements can point to Salesforce Health Cloud instead.
HubSpot also stops making sense if your team cannot justify Enterprise. Storing PHI on Professional is not an option, so a practice that only needs newsletters and a booking form should keep PHI out of HubSpot entirely and stay on the tier it needs.
INSIDEA
Ready to get more out of HubSpot?
We are an Elite HubSpot Partner rated 4.99 across 450+ verified reviews. Let's make your portal work harder.
How INSIDEA sets up HubSpot for healthcare
INSIDEA is an Elite HubSpot Partner rated 4.99 across 450+ verified reviews. We sign Business Associate Agreements as standard on healthcare engagements, draw the PHI map before anything is built, and keep clinical detail in the EHR while HubSpot holds what the commercial motion needs. The build is a fixed fee from $2,000, scoped at proposal. One published result: a U.S. medical imaging provider cut its ticket volume from 18,000 to 13,000 by merging duplicates, with zero data loss. The HubSpot healthcare partner page lists what to verify before you hire anyone, us included, and the healthcare industry page has the full scope.

