What does HIPAA mean for a CRM?
A CRM handling health information needs a signed Business Associate Agreement and the required safeguards. The software alone is never HIPAA compliant.

HIPAA and CRMs — HIPAA, applied to a CRM, means the system that stores protected health information is covered by a Business Associate Agreement with the vendor and configured with the required safeguards: access control, audit, encryption, retention. No CRM is "HIPAA compliant" by itself. The arrangement is.
Why it matters
HIPAA governs protected health information. When a CRM stores or processes that kind of data, the law's requirements attach to the arrangement between the business and the vendor. Not to the software as a standalone product. A Business Associate Agreement, a specific contract between the covered entity and the vendor, has to be in place. The system has to be configured with the safeguards HIPAA requires. Access control limiting who can see records. Audit logging of who accessed what. Encryption of data at rest and in transit. Defined retention practices.
The phrase "HIPAA compliant CRM" is misleading on its own. Compliance is not a property a piece of software has by itself. The same software can be part of a compliant arrangement for one customer, with a signed BAA and the right configuration. It can be part of a non-compliant one for another customer who never signed a BAA and never turned on the required controls. A common mistake is treating a field as safe to fill with patient information because it "is just a name". A name combined with any appointment or treatment context is itself protected health information under the law.
What a HIPAA-covered CRM arrangement requires
- 1
Confirm a Business Associate Agreement exists
A signed BAA between the covered entity and the vendor must be in place before any PHI is stored.
- 2
Configure access control
Limit which users can view or modify records containing protected health information.
- 3
Enable audit logging
Track who accessed which records and when.
- 4
Apply encryption
Data must be encrypted both at rest and in transit.
- 5
Define retention practices
Set and follow rules for how long records are kept and how they are disposed of.
The mistake to watch for
Questions
- How is HIPAA compliance different from a BAA?
- A Business Associate Agreement is the specific contract that sets the vendor's obligations under HIPAA for a given arrangement. Compliance is the broader outcome. That agreement is in place, and the required technical and administrative safeguards are configured and followed.
- Is any CRM 'HIPAA compliant' out of the box?
- No. Compliance describes the arrangement between the covered entity and the vendor, including a signed BAA and correctly configured safeguards. It is not a property the software has apart from how it is set up and used.
- What counts as protected health information in a CRM?
- Identifying information, such as a name, combined with any health or appointment context, such as a treatment or visit, generally counts as protected health information. Not only data explicitly labeled as medical.