Skip to content
Skip to content

Directory · verified September 8, 2026

HIPAA marketing tools: the BAA matrix.

The recurring gotcha in telehealth marketing is discovering, after launch, that a tool in your stack will not sign a business associate agreement, or signed one that does not cover what you thought. This matrix answers the question tool by tool from each vendor's own legal and pricing pages: who signs and on which plan, whose BAA carries product carve-outs, who prohibits PHI outright in their terms, and the HIPAA-native alternatives. Prohibition language is quoted verbatim, because the exact words are the compliance fact.

Published by EmbedCare, whose operated platform includes HIPAA-compliant patient communications, so read it knowing that. Every posture was checked against the vendor's own pages on the date above; three claims common in third-party roundups failed that verification and are corrected in their rows. Nothing is ranked, no vendor paid to appear, and inclusion implies no relationship with EmbedCare in either direction. Postures change with a legal-page edit; verify before relying. Corrections: anthony@embedcare.com.

Group 1: mainstream tools that sign, with a plan gate

These tools will sign a BAA, but almost never on the plan you started on: the gate is a top tier, an add-on, or a sales conversation. The gate, in each vendor's own words, is the fact that matters.

Customer.io

Source page

Email/SMS/push automation

BAA posture
Signs: Premium and Enterprise tiers only
The detail that matters
Its pricing page lists HIPAA compliance as 'Available by Consultation' on Premium and Enterprise, and not on Essentials; those tier prices are not published (September 8, 2026).

ActiveCampaign

Source page

Email marketing / automation / CRM

BAA posture
Signs: on 'eligible plans' (its wording); exact tier unstated
The detail that matters
Its own guide says a BAA is 'Available on eligible plans' and prices its own example configuration at roughly $229 a month for a Professional plan with BAA (its approximate figure as of September 8, 2026, not a rate card). Which plans are eligible is not clearly stated publicly; confirm the tier with sales.
Correction note
Third-party roundups say Enterprise-only; the vendor's own example contradicts that, so this page prints neither as fact.

CRM + marketing automation

BAA posture
Signs: Enterprise hubs only, with tool carve-outs
The detail that matters
Sensitive data including PHI requires Enterprise subscriptions, and its KB states the carve-outs verbatim: 'Sensitive Data properties are unavailable in certain tools, including personalization tokens, sandboxes, chatbots and playbooks.' Its BAA is a public PDF (February 2025 version).
Correction note
A posture change worth knowing: HubSpot refused BAAs until its 2024 sensitive-data launch, so older advice saying it won't sign is stale.

Zoho (Marketing Automation / Campaigns)

Source page

Marketing suite

BAA posture
Signs: BAA template on request
The detail that matters
Its HIPAA page says to request the BAA template by email, and documents built-in features: marking ePHI fields, restricting ePHI export, audit logs. No plan gate stated on the HIPAA page.

GoHighLevel

Source page

Agency CRM / automation

BAA posture
Signs: via a paid HIPAA add-on, any plan
The detail that matters
Its pricing guide states HIPAA compliance is '$297/mo as an account-wide add-on' and that 'Agencies on any plan can subscribe' (September 8, 2026). The add-on is on top of the base subscription.

Online forms

BAA posture
Signs: Gold and Enterprise plans only
The detail that matters
Its pricing page marks HIPAA features unavailable on Starter, Bronze, and Silver, and available on Gold ($129 a month, or $1,188 a year) and Enterprise (custom). A BAA is available on the HIPAA plans on request (its support answer).

Typeform

Source page

Online forms

BAA posture
Signs: Enterprise or Growth Custom plans only
The detail that matters
Its help article states it 'can currently provide a BAA for customers on our Enterprise or Growth Custom plans' (recorded at secondary quality: the article's host blocks automated reading, so the sentence comes from its indexed text; tier prices unpublished).

Formstack

Source page

Forms / documents / e-sign

BAA posture
Signs: standard BAA on HIPAA account types
The detail that matters
Its feature page offers 'Formstack's Standard BAA' or evaluation of custom BAA requests; HIPAA-compliant forms run on a dedicated account type. No published HIPAA-plan price.

Acuity Scheduling (Squarespace)

Source page

Scheduling

BAA posture
Signs: Powerhouse or Premium plans, in-app BAA
The detail that matters
Squarespace's help states you can make Acuity HIPAA-enabled on those two plans and sign the BAA in-app, with the scope limit verbatim: 'Acuity Scheduling is the only Squarespace feature currently designed to offer services consistent with HIPAA obligations.'

Support / helpdesk

BAA posture
Signs: via the Advanced Compliance add-on (Professional and up)
The detail that matters
Its docs state the add-on lets customers 'sign a BAA or HDS Exhibit for accounts that may store PHI', available on Professional, Enterprise, or Enterprise Plus, directly or in certain Suite plans. Add-on price unpublished.
Correction note
Don't confuse Advanced Compliance with the separate Advanced Data Privacy and Protection add-on; they are different products.

Intercom

Source page

Support / messaging

BAA posture
Signs: 'applicable customers', plan-dependent, sales path
The detail that matters
Its announcement offers a BAA 'which can be made available for execution with applicable customers' via sales; which plans qualify is not published.

Piwik PRO

Source page

Privacy analytics

BAA posture
Signs: BAA available; customizable BAA is Enterprise
The detail that matters
Its HIPAA page says 'We provide a BAA tailored to your needs, regardless of your hosting option'; its plan-comparison copy places the customizable BAA under Enterprise, and the exact Business-plan coverage is ambiguous on its own pages, so confirm plan coverage with sales.

Freshpaint

Source page

Healthcare privacy layer for tracking

BAA posture
Signs: the BAA is the product
The detail that matters
Its FAQ answers plainly: 'Freshpaint is built specifically for HIPAA-regulated environments and offers a Business Associate Agreement (BAA).' It is the BAA-covered middle layer that lets analytics and ad tools work without receiving PHI.

Group 2: tools that refuse, prohibit, or quietly say nothing

The rows behind the classic 'does X sign a BAA' searches, answered from each vendor's own legal pages. Meta's business tools belong here too: their terms bar sharing health information at all, which our pixels guide covers in depth. And three tools state no public posture at all (Brevo, Kit, and Fathom Analytics); treat no stated posture as no, until sales says otherwise in writing.

Email/SMS marketing (e-commerce)

BAA posture
Does not sign; its AUP prohibits PHI outright
The detail that matters
Its Acceptable Use Policy prohibits storing or sending 'medical records or health information, including Protected Health Information as defined in the Health Insurance Portability and Accountability Act' (verbatim, September 8, 2026). PHI in Klaviyo is a terms violation, not just an uncovered risk.

Mailchimp (Intuit)

Source page

Email marketing

BAA posture
No BAA offered; its terms disclaim HIPAA suitability
The detail that matters
Its Standard Terms say you're responsible for determining suitability under regulations like HIPAA and that Mailchimp 'won't be liable if the Service doesn't meet those requirements'; no BAA is referenced anywhere in its terms. Its own resource page on HIPAA email recommends other providers.
Correction note
The oft-repeated claim that Mailchimp's AUP bans PHI did not verify against today's AUP; the terms disclaimer above is the accurate hook.

Postscript

Source page

SMS marketing (DTC)

BAA posture
Prohibits PHI in its content terms
The detail that matters
Its subscriber messaging terms prohibit content that 'implicates and/or references' HIPAA-protected health information (verbatim, September 8, 2026); even referencing protected health info is out of bounds.

Attentive

Source page

SMS marketing (DTC)

BAA posture
Prohibits PHI in its content policy
The detail that matters
Its content policy prohibits 'Any Protected Health Information as defined by HIPAA' (verbatim, September 8, 2026). Like Postscript above, it sits on the prohibition side of the line.

Constant Contact

Source page

Email/SMS marketing

BAA posture
The teaching row: signs a BAA, yet prohibits sensitive PHI
The detail that matters
Its knowledge base says it 'will only sign our business associate agreement' with no changes, and the same article says its Terms prohibit 'sensitive personal or health information of any kind, including sensitive PHI' beyond subscriber contact data. A signed BAA is not permission to put PHI in a tool; scope is everything.

Calendly

Source page

Scheduling

BAA posture
Does not sign
The detail that matters
Its own community staff answer: 'we don't currently offer a BAA', and Calendly 'isn't intended for collecting Protected Health Information' (September 8, 2026). Its security hub covers SOC 2, ISO 27001, and GDPR with zero HIPAA articles.
Correction note
Roundups listing Calendly as HIPAA-capable via Enterprise are wrong per the vendor's own answer.

Google Analytics

Source page

Web analytics

BAA posture
Does not sign, in Google's own words
The detail that matters
Google's help states it 'does not offer Business Associate Agreements in connection with this service' and that HIPAA-regulated entities 'must refrain from exposing to Google any data that may be considered Protected Health Information.' Google does sign BAAs for Workspace and Cloud covered services; Analytics is simply not one of them.

Keap (a Thryv brand)

Source page

Small-business CRM / automation

BAA posture
Messaging carve-out: email and SMS are explicitly not for PHI
The detail that matters
Thryv acquired Keap in 2024, and the Thryv page titled as a CRM BAA reads as a disclaimer: the email and SMS functionalities 'are not HIPAA-compliant and are not intended for the transmission, storage, or processing of protected health information' (verbatim, September 8, 2026). For a marketing stack, that is the operative fact.
Correction note
Older roundups saying simply that Keap signs a BAA predate the Thryv-era terms and should not be relied on.

Group 3: platform BAAs with product-scope limits

These vendors sign, but the BAA covers a named list of products, and the products a marketer would reach for first are often the excluded ones. Read the eligible-products list, not the press release.

Twilio (and the SendGrid exception)

Source page

Programmable SMS/voice + email API

BAA posture
Signs on Security or Enterprise Edition, for HIPAA-eligible products only; SendGrid email is never covered
The detail that matters
Its HIPAA page requires Security or Enterprise Edition to sign a BAA and limits PHI workflows to HIPAA Eligible Products (programmable SMS and voice qualify). Its SendGrid doc is blunt: 'Twilio is not able to sign Business Associate Agreements for SendGrid' and customers 'should not use SendGrid for any purpose or in any manner involving Protected Health Information' (verbatim).

Salesforce (including Marketing Cloud)

Source page

CRM / marketing cloud

BAA posture
Signs a standardized addendum for listed covered services
The detail that matters
Marketing Cloud Engagement is on the covered list; the restrictions doc states 'The Marketing Cloud Einstein features included with Marketing Cloud Growth and Advanced are not covered by the BAA', customers must encrypt PHI, and Account Engagement (Pardot) is absent from the covered list as fetched September 8, 2026.

AWS (SES email, End User Messaging SMS)

Source page

Developer email/SMS infrastructure

BAA posture
Signs the AWS-wide BAA; SES and End User Messaging are HIPAA-eligible
The detail that matters
Amazon SES and End User Messaging (formerly Pinpoint, excluding voice and WhatsApp) appear on AWS's HIPAA Eligible Services Reference, under the standard AWS BAA (self-serve via AWS Artifact). The punchline pairing: SendGrid email can never be covered; Amazon SES email can.

Group 4: HIPAA-native communications tools

Built for healthcare, so the BAA is table stakes rather than a gate. The trade is reach and polish versus compliance-by-default; the details still matter, down to which HIPAA tier lets you migrate your existing opt-in list.

HIPAA email (marketing + API)

BAA posture
Signs: 'A business associate agreement (BAA) comes with every plan, including the free tier' (verbatim)
The detail that matters
Encrypted email delivery without portals, plus a marketing product; the anti-gotcha row in this directory.

HIPAA email / secure marketing

BAA posture
Signs: BAA mandatory at signup for HIPAA accounts
The detail that matters
Customers with HIPAA accounts must sign its BAA before using HIPAA-eligible services with PHI (its page); HITRUST CSF certified, with the BAA document public.

Textline

Source page

Business texting

BAA posture
Signs: HIPAA Essentials and HIPAA Pro plans, BAA at onboarding
The detail that matters
Its comparison page shows the gotcha inside the HIPAA tiers: Essentials does not allow bulk consent requests or manual consent overrides (so you cannot import previously collected opt-ins), while Pro does; both tiers' base fees are unpublished ('Please contact us').

IntakeQ / PracticeQ

Source page

Intake forms + practice management

BAA posture
Signs: self-service BAA inside the app
The detail that matters
Its docs walk through signing the BAA from the account's BAA tab; forms start at just under $50 a month plus per-practitioner fees, with the BAA listed as an included feature (its pricing page, September 8, 2026).

Klara (ModMed)

Source page

Enterprise patient communications

BAA posture
HIPAA-native; BAA via enterprise contract
The detail that matters
klara.com now redirects to ModMed's patient-engagement line (Klara was acquired by ModMed in 2022), and its help center describes it as 'a HIPAA-compliant secure messaging app' (recorded at secondary quality: the help article's host blocks automated reading, so the description comes from its indexed text); no public self-serve BAA is posted.

Enterprise patient communications

BAA posture
HIPAA-native; BAA via enterprise contract
The detail that matters
The former WELL Health Inc. (renamed October 2022; not the Canadian WELL Health Technologies). Its certifications page states its controls are mapped to HITRUST and HIPAA, with HITRUST certification since 2019; no public self-serve BAA is posted.

Postures reflect each vendor's own pages as verified on September 8, 2026; quoted language is verbatim from the linked source pages. Rows noted at secondary quality (Typeform's BAA sentence; Acuity's tier price, which this page therefore omits) come from vendor-domain content whose host blocked automated reading. Checked but skipped by triage: OhMD and Curogram (the HIPAA-native group was already deep). This page is re-verified quarterly and on any change to a listed vendor's terms; a BAA posture is one legal-page edit from stale, so confirm before you rely on it.

Marketing tools and BAAs: FAQ

Does Klaviyo sign a BAA?

No, and it goes further: Klaviyo's Acceptable Use Policy prohibits storing or sending medical records or health information, including PHI as defined in HIPAA, as of September 8, 2026. Putting patient data in Klaviyo is a terms violation, not a gray area. Telehealth operators typically pair a HIPAA-native sender (Paubox, LuxSci) or a covered substrate (Amazon SES under the AWS BAA) for anything touching care, and keep Klaviyo-class tools for strictly non-PHI audiences.

Does Mailchimp sign a BAA?

No. Its Standard Terms disclaim HIPAA suitability outright and reference no BAA, and its own resource page about HIPAA-compliant email recommends other providers. One accuracy note: the widely repeated claim that Mailchimp's acceptable-use policy bans PHI did not verify against its live AUP as of September 8, 2026; the terms disclaimer is the accurate basis, and the practical answer is the same either way.

If a tool signs a BAA, can I put PHI in it?

Not automatically, and the exceptions are where operators get hurt. Constant Contact will sign its standard BAA while its terms still prohibit sensitive health information in the platform; HubSpot signs but carves specific tools out of coverage; Salesforce covers listed services and excludes others by name; Twilio covers eligible products only. Three questions per tool: which plan carries the BAA, which products and features the BAA actually covers, and what the terms still prohibit even with a BAA signed.

Which email and SMS tools are actually HIPAA-compliant?

The workable stack as of September 2026: HIPAA-native senders (Paubox with a BAA on every plan, LuxSci, Textline's HIPAA tiers) for anything touching PHI; mainstream tools that sign with a plan gate (Customer.io on Premium and up, ActiveCampaign on eligible plans, Zoho by request, GoHighLevel via its add-on) when you can live inside their gates and scopes; and for developer stacks, Amazon SES is HIPAA-eligible under the AWS BAA while Twilio SendGrid email never is. Tools are one layer; HIPAA compliance is your program's posture, not a product you buy.

This matrix is diligence material, not legal advice and not a recommendation of any tool; whether HIPAA applies to a given data flow, and what a specific BAA covers, are questions for your healthcare counsel with the actual contracts in hand.

On EmbedCare, patient communications ship HIPAA-compliant out of the box. Get the partner overview and see which layers you can stop shopping for.

One email, no sequence. A human follows up with your program scoped.

Your marketing stack shouldn't be a compliance investigation.

EmbedCare's operated programs keep patient data on covered rails, and licensed clinicians make every prescribing decision.