What does HIPAA mean for a CRM?

A CRM handling health information needs a signed Business Associate Agreement and the required safeguards. The software alone is never HIPAA compliant.

An admin approves every new account by hand. Nothing is created until then. We reply by email; no newsletter, no sequence.

app.salescrew.io/inbox
The unified reply inbox with classified threads

HIPAA and CRMsHIPAA, applied to a CRM, means the system that stores protected health information is covered by a Business Associate Agreement with the vendor and configured with the required safeguards: access control, audit, encryption, retention. No CRM is "HIPAA compliant" by itself. The arrangement is.

Why it matters

HIPAA governs protected health information. When a CRM stores or processes that kind of data, the law's requirements attach to the arrangement between the business and the vendor. Not to the software as a standalone product. A Business Associate Agreement, a specific contract between the covered entity and the vendor, has to be in place. The system has to be configured with the safeguards HIPAA requires. Access control limiting who can see records. Audit logging of who accessed what. Encryption of data at rest and in transit. Defined retention practices.

The phrase "HIPAA compliant CRM" is misleading on its own. Compliance is not a property a piece of software has by itself. The same software can be part of a compliant arrangement for one customer, with a signed BAA and the right configuration. It can be part of a non-compliant one for another customer who never signed a BAA and never turned on the required controls. A common mistake is treating a field as safe to fill with patient information because it "is just a name". A name combined with any appointment or treatment context is itself protected health information under the law.

What a HIPAA-covered CRM arrangement requires

  1. 1

    Confirm a Business Associate Agreement exists

    A signed BAA between the covered entity and the vendor must be in place before any PHI is stored.

  2. 2

    Configure access control

    Limit which users can view or modify records containing protected health information.

  3. 3

    Enable audit logging

    Track who accessed which records and when.

  4. 4

    Apply encryption

    Data must be encrypted both at rest and in transit.

  5. 5

    Define retention practices

    Set and follow rules for how long records are kept and how they are disposed of.

The mistake to watch for

Storing patient details in a CRM with no BAA because "it's just names". Names plus appointment context is PHI. This is not legal advice.

Questions

How is HIPAA compliance different from a BAA?
A Business Associate Agreement is the specific contract that sets the vendor's obligations under HIPAA for a given arrangement. Compliance is the broader outcome. That agreement is in place, and the required technical and administrative safeguards are configured and followed.
Is any CRM 'HIPAA compliant' out of the box?
No. Compliance describes the arrangement between the covered entity and the vendor, including a signed BAA and correctly configured safeguards. It is not a property the software has apart from how it is set up and used.
What counts as protected health information in a CRM?
Identifying information, such as a name, combined with any health or appointment context, such as a treatment or visit, generally counts as protected health information. Not only data explicitly labeled as medical.