Directory · verified September 8, 2026
HIPAA marketing tools: the BAA matrix.
The recurring gotcha in telehealth marketing is discovering, after launch, that a tool in your stack will not sign a business associate agreement, or signed one that does not cover what you thought. This matrix answers the question tool by tool from each vendor's own legal and pricing pages: who signs and on which plan, whose BAA carries product carve-outs, who prohibits PHI outright in their terms, and the HIPAA-native alternatives. Prohibition language is quoted verbatim, because the exact words are the compliance fact.
Published by EmbedCare, whose operated platform includes HIPAA-compliant patient communications, so read it knowing that. Every posture was checked against the vendor's own pages on the date above; three claims common in third-party roundups failed that verification and are corrected in their rows. Nothing is ranked, no vendor paid to appear, and inclusion implies no relationship with EmbedCare in either direction. Postures change with a legal-page edit; verify before relying. Corrections: anthony@embedcare.com.
Group 1: mainstream tools that sign, with a plan gate
These tools will sign a BAA, but almost never on the plan you started on: the gate is a top tier, an add-on, or a sales conversation. The gate, in each vendor's own words, is the fact that matters.
Customer.io
Source pageEmail/SMS/push automation
- BAA posture
- Signs: Premium and Enterprise tiers only
- The detail that matters
- Its pricing page lists HIPAA compliance as 'Available by Consultation' on Premium and Enterprise, and not on Essentials; those tier prices are not published (September 8, 2026).
ActiveCampaign
Source pageEmail marketing / automation / CRM
- BAA posture
- Signs: on 'eligible plans' (its wording); exact tier unstated
- The detail that matters
- Its own guide says a BAA is 'Available on eligible plans' and prices its own example configuration at roughly $229 a month for a Professional plan with BAA (its approximate figure as of September 8, 2026, not a rate card). Which plans are eligible is not clearly stated publicly; confirm the tier with sales.
- Correction note
- Third-party roundups say Enterprise-only; the vendor's own example contradicts that, so this page prints neither as fact.
HubSpot
Source pageCRM + marketing automation
- BAA posture
- Signs: Enterprise hubs only, with tool carve-outs
- The detail that matters
- Sensitive data including PHI requires Enterprise subscriptions, and its KB states the carve-outs verbatim: 'Sensitive Data properties are unavailable in certain tools, including personalization tokens, sandboxes, chatbots and playbooks.' Its BAA is a public PDF (February 2025 version).
- Correction note
- A posture change worth knowing: HubSpot refused BAAs until its 2024 sensitive-data launch, so older advice saying it won't sign is stale.
Zoho (Marketing Automation / Campaigns)
Source pageMarketing suite
- BAA posture
- Signs: BAA template on request
- The detail that matters
- Its HIPAA page says to request the BAA template by email, and documents built-in features: marking ePHI fields, restricting ePHI export, audit logs. No plan gate stated on the HIPAA page.
GoHighLevel
Source pageAgency CRM / automation
- BAA posture
- Signs: via a paid HIPAA add-on, any plan
- The detail that matters
- Its pricing guide states HIPAA compliance is '$297/mo as an account-wide add-on' and that 'Agencies on any plan can subscribe' (September 8, 2026). The add-on is on top of the base subscription.
Jotform
Source pageOnline forms
- BAA posture
- Signs: Gold and Enterprise plans only
- The detail that matters
- Its pricing page marks HIPAA features unavailable on Starter, Bronze, and Silver, and available on Gold ($129 a month, or $1,188 a year) and Enterprise (custom). A BAA is available on the HIPAA plans on request (its support answer).
Typeform
Source pageOnline forms
- BAA posture
- Signs: Enterprise or Growth Custom plans only
- The detail that matters
- Its help article states it 'can currently provide a BAA for customers on our Enterprise or Growth Custom plans' (recorded at secondary quality: the article's host blocks automated reading, so the sentence comes from its indexed text; tier prices unpublished).
Formstack
Source pageForms / documents / e-sign
- BAA posture
- Signs: standard BAA on HIPAA account types
- The detail that matters
- Its feature page offers 'Formstack's Standard BAA' or evaluation of custom BAA requests; HIPAA-compliant forms run on a dedicated account type. No published HIPAA-plan price.
Acuity Scheduling (Squarespace)
Source pageScheduling
- BAA posture
- Signs: Powerhouse or Premium plans, in-app BAA
- The detail that matters
- Squarespace's help states you can make Acuity HIPAA-enabled on those two plans and sign the BAA in-app, with the scope limit verbatim: 'Acuity Scheduling is the only Squarespace feature currently designed to offer services consistent with HIPAA obligations.'
Zendesk
Source pageSupport / helpdesk
- BAA posture
- Signs: via the Advanced Compliance add-on (Professional and up)
- The detail that matters
- Its docs state the add-on lets customers 'sign a BAA or HDS Exhibit for accounts that may store PHI', available on Professional, Enterprise, or Enterprise Plus, directly or in certain Suite plans. Add-on price unpublished.
- Correction note
- Don't confuse Advanced Compliance with the separate Advanced Data Privacy and Protection add-on; they are different products.
Intercom
Source pageSupport / messaging
- BAA posture
- Signs: 'applicable customers', plan-dependent, sales path
- The detail that matters
- Its announcement offers a BAA 'which can be made available for execution with applicable customers' via sales; which plans qualify is not published.
Piwik PRO
Source pagePrivacy analytics
- BAA posture
- Signs: BAA available; customizable BAA is Enterprise
- The detail that matters
- Its HIPAA page says 'We provide a BAA tailored to your needs, regardless of your hosting option'; its plan-comparison copy places the customizable BAA under Enterprise, and the exact Business-plan coverage is ambiguous on its own pages, so confirm plan coverage with sales.
Freshpaint
Source pageHealthcare privacy layer for tracking
- BAA posture
- Signs: the BAA is the product
- The detail that matters
- Its FAQ answers plainly: 'Freshpaint is built specifically for HIPAA-regulated environments and offers a Business Associate Agreement (BAA).' It is the BAA-covered middle layer that lets analytics and ad tools work without receiving PHI.
Group 2: tools that refuse, prohibit, or quietly say nothing
The rows behind the classic 'does X sign a BAA' searches, answered from each vendor's own legal pages. Meta's business tools belong here too: their terms bar sharing health information at all, which our pixels guide covers in depth. And three tools state no public posture at all (Brevo, Kit, and Fathom Analytics); treat no stated posture as no, until sales says otherwise in writing.
Klaviyo
Source pageEmail/SMS marketing (e-commerce)
- BAA posture
- Does not sign; its AUP prohibits PHI outright
- The detail that matters
- Its Acceptable Use Policy prohibits storing or sending 'medical records or health information, including Protected Health Information as defined in the Health Insurance Portability and Accountability Act' (verbatim, September 8, 2026). PHI in Klaviyo is a terms violation, not just an uncovered risk.
Mailchimp (Intuit)
Source pageEmail marketing
- BAA posture
- No BAA offered; its terms disclaim HIPAA suitability
- The detail that matters
- Its Standard Terms say you're responsible for determining suitability under regulations like HIPAA and that Mailchimp 'won't be liable if the Service doesn't meet those requirements'; no BAA is referenced anywhere in its terms. Its own resource page on HIPAA email recommends other providers.
- Correction note
- The oft-repeated claim that Mailchimp's AUP bans PHI did not verify against today's AUP; the terms disclaimer above is the accurate hook.
Postscript
Source pageSMS marketing (DTC)
- BAA posture
- Prohibits PHI in its content terms
- The detail that matters
- Its subscriber messaging terms prohibit content that 'implicates and/or references' HIPAA-protected health information (verbatim, September 8, 2026); even referencing protected health info is out of bounds.
Attentive
Source pageSMS marketing (DTC)
- BAA posture
- Prohibits PHI in its content policy
- The detail that matters
- Its content policy prohibits 'Any Protected Health Information as defined by HIPAA' (verbatim, September 8, 2026). Like Postscript above, it sits on the prohibition side of the line.
Constant Contact
Source pageEmail/SMS marketing
- BAA posture
- The teaching row: signs a BAA, yet prohibits sensitive PHI
- The detail that matters
- Its knowledge base says it 'will only sign our business associate agreement' with no changes, and the same article says its Terms prohibit 'sensitive personal or health information of any kind, including sensitive PHI' beyond subscriber contact data. A signed BAA is not permission to put PHI in a tool; scope is everything.
Calendly
Source pageScheduling
- BAA posture
- Does not sign
- The detail that matters
- Its own community staff answer: 'we don't currently offer a BAA', and Calendly 'isn't intended for collecting Protected Health Information' (September 8, 2026). Its security hub covers SOC 2, ISO 27001, and GDPR with zero HIPAA articles.
- Correction note
- Roundups listing Calendly as HIPAA-capable via Enterprise are wrong per the vendor's own answer.
Google Analytics
Source pageWeb analytics
- BAA posture
- Does not sign, in Google's own words
- The detail that matters
- Google's help states it 'does not offer Business Associate Agreements in connection with this service' and that HIPAA-regulated entities 'must refrain from exposing to Google any data that may be considered Protected Health Information.' Google does sign BAAs for Workspace and Cloud covered services; Analytics is simply not one of them.
Keap (a Thryv brand)
Source pageSmall-business CRM / automation
- BAA posture
- Messaging carve-out: email and SMS are explicitly not for PHI
- The detail that matters
- Thryv acquired Keap in 2024, and the Thryv page titled as a CRM BAA reads as a disclaimer: the email and SMS functionalities 'are not HIPAA-compliant and are not intended for the transmission, storage, or processing of protected health information' (verbatim, September 8, 2026). For a marketing stack, that is the operative fact.
- Correction note
- Older roundups saying simply that Keap signs a BAA predate the Thryv-era terms and should not be relied on.
Group 3: platform BAAs with product-scope limits
These vendors sign, but the BAA covers a named list of products, and the products a marketer would reach for first are often the excluded ones. Read the eligible-products list, not the press release.
Twilio (and the SendGrid exception)
Source pageProgrammable SMS/voice + email API
- BAA posture
- Signs on Security or Enterprise Edition, for HIPAA-eligible products only; SendGrid email is never covered
- The detail that matters
- Its HIPAA page requires Security or Enterprise Edition to sign a BAA and limits PHI workflows to HIPAA Eligible Products (programmable SMS and voice qualify). Its SendGrid doc is blunt: 'Twilio is not able to sign Business Associate Agreements for SendGrid' and customers 'should not use SendGrid for any purpose or in any manner involving Protected Health Information' (verbatim).
Salesforce (including Marketing Cloud)
Source pageCRM / marketing cloud
- BAA posture
- Signs a standardized addendum for listed covered services
- The detail that matters
- Marketing Cloud Engagement is on the covered list; the restrictions doc states 'The Marketing Cloud Einstein features included with Marketing Cloud Growth and Advanced are not covered by the BAA', customers must encrypt PHI, and Account Engagement (Pardot) is absent from the covered list as fetched September 8, 2026.
AWS (SES email, End User Messaging SMS)
Source pageDeveloper email/SMS infrastructure
- BAA posture
- Signs the AWS-wide BAA; SES and End User Messaging are HIPAA-eligible
- The detail that matters
- Amazon SES and End User Messaging (formerly Pinpoint, excluding voice and WhatsApp) appear on AWS's HIPAA Eligible Services Reference, under the standard AWS BAA (self-serve via AWS Artifact). The punchline pairing: SendGrid email can never be covered; Amazon SES email can.
Group 4: HIPAA-native communications tools
Built for healthcare, so the BAA is table stakes rather than a gate. The trade is reach and polish versus compliance-by-default; the details still matter, down to which HIPAA tier lets you migrate your existing opt-in list.
Paubox
Source pageHIPAA email (marketing + API)
- BAA posture
- Signs: 'A business associate agreement (BAA) comes with every plan, including the free tier' (verbatim)
- The detail that matters
- Encrypted email delivery without portals, plus a marketing product; the anti-gotcha row in this directory.
LuxSci
Source pageHIPAA email / secure marketing
- BAA posture
- Signs: BAA mandatory at signup for HIPAA accounts
- The detail that matters
- Customers with HIPAA accounts must sign its BAA before using HIPAA-eligible services with PHI (its page); HITRUST CSF certified, with the BAA document public.
Textline
Source pageBusiness texting
- BAA posture
- Signs: HIPAA Essentials and HIPAA Pro plans, BAA at onboarding
- The detail that matters
- Its comparison page shows the gotcha inside the HIPAA tiers: Essentials does not allow bulk consent requests or manual consent overrides (so you cannot import previously collected opt-ins), while Pro does; both tiers' base fees are unpublished ('Please contact us').
IntakeQ / PracticeQ
Source pageIntake forms + practice management
- BAA posture
- Signs: self-service BAA inside the app
- The detail that matters
- Its docs walk through signing the BAA from the account's BAA tab; forms start at just under $50 a month plus per-practitioner fees, with the BAA listed as an included feature (its pricing page, September 8, 2026).
Klara (ModMed)
Source pageEnterprise patient communications
- BAA posture
- HIPAA-native; BAA via enterprise contract
- The detail that matters
- klara.com now redirects to ModMed's patient-engagement line (Klara was acquired by ModMed in 2022), and its help center describes it as 'a HIPAA-compliant secure messaging app' (recorded at secondary quality: the help article's host blocks automated reading, so the description comes from its indexed text); no public self-serve BAA is posted.
Artera
Source pageEnterprise patient communications
- BAA posture
- HIPAA-native; BAA via enterprise contract
- The detail that matters
- The former WELL Health Inc. (renamed October 2022; not the Canadian WELL Health Technologies). Its certifications page states its controls are mapped to HITRUST and HIPAA, with HITRUST certification since 2019; no public self-serve BAA is posted.
Postures reflect each vendor's own pages as verified on September 8, 2026; quoted language is verbatim from the linked source pages. Rows noted at secondary quality (Typeform's BAA sentence; Acuity's tier price, which this page therefore omits) come from vendor-domain content whose host blocked automated reading. Checked but skipped by triage: OhMD and Curogram (the HIPAA-native group was already deep). This page is re-verified quarterly and on any change to a listed vendor's terms; a BAA posture is one legal-page edit from stale, so confirm before you rely on it.
Marketing tools and BAAs: FAQ
Does Klaviyo sign a BAA?
No, and it goes further: Klaviyo's Acceptable Use Policy prohibits storing or sending medical records or health information, including PHI as defined in HIPAA, as of September 8, 2026. Putting patient data in Klaviyo is a terms violation, not a gray area. Telehealth operators typically pair a HIPAA-native sender (Paubox, LuxSci) or a covered substrate (Amazon SES under the AWS BAA) for anything touching care, and keep Klaviyo-class tools for strictly non-PHI audiences.
Does Mailchimp sign a BAA?
No. Its Standard Terms disclaim HIPAA suitability outright and reference no BAA, and its own resource page about HIPAA-compliant email recommends other providers. One accuracy note: the widely repeated claim that Mailchimp's acceptable-use policy bans PHI did not verify against its live AUP as of September 8, 2026; the terms disclaimer is the accurate basis, and the practical answer is the same either way.
If a tool signs a BAA, can I put PHI in it?
Not automatically, and the exceptions are where operators get hurt. Constant Contact will sign its standard BAA while its terms still prohibit sensitive health information in the platform; HubSpot signs but carves specific tools out of coverage; Salesforce covers listed services and excludes others by name; Twilio covers eligible products only. Three questions per tool: which plan carries the BAA, which products and features the BAA actually covers, and what the terms still prohibit even with a BAA signed.
Which email and SMS tools are actually HIPAA-compliant?
The workable stack as of September 2026: HIPAA-native senders (Paubox with a BAA on every plan, LuxSci, Textline's HIPAA tiers) for anything touching PHI; mainstream tools that sign with a plan gate (Customer.io on Premium and up, ActiveCampaign on eligible plans, Zoho by request, GoHighLevel via its add-on) when you can live inside their gates and scopes; and for developer stacks, Amazon SES is HIPAA-eligible under the AWS BAA while Twilio SendGrid email never is. Tools are one layer; HIPAA compliance is your program's posture, not a product you buy.
This matrix is diligence material, not legal advice and not a recommendation of any tool; whether HIPAA applies to a given data flow, and what a specific BAA covers, are questions for your healthcare counsel with the actual contracts in hand.
On EmbedCare, patient communications ship HIPAA-compliant out of the box. Get the partner overview and see which layers you can stop shopping for.
One email, no sequence. A human follows up with your program scoped.
Your marketing stack shouldn't be a compliance investigation.
EmbedCare's operated programs keep patient data on covered rails, and licensed clinicians make every prescribing decision.