Which Automation Tools Are HIPAA Compliant? Zapier, HubSpot, n8n, Make, monday.com, Zoho and HighLevel
By Michael Oskola, Founder & AI Automation Architect · September 25, 2026 · 11 min read
As of 25 September 2026, HubSpot, monday.com, Zoho and HighLevel will sign a HIPAA business associate agreement (BAA), each on its own conditions. Zapier says it can't. Make and n8n Cloud don't mention HIPAA or a BAA on their security and legal pages. Pipedrive's terms say it isn't designed for HIPAA. The plans, exclusions and vendor sources are below.
Which automation tools will sign a HIPAA BAA?
The table records what each vendor says about itself, on which page, and when we read it. We checked every row on 25 September 2026 against the vendor's own legal, help or security pages. Review sites and AI answers were not used as sources.
"Not stated by vendor" means we found no HIPAA or BAA statement on the vendor's security and legal pages. That is different from a refusal, so we keep the two apart.
This is not legal advice. Vendor terms change, so confirm with the vendor and your compliance lead before any patient data goes into a tool.
| Tool | Signs a BAA? | Plan or condition | Main exclusions | Vendor source | Checked on |
|---|---|---|---|---|---|
| Zapier | No | None, on any plan | PHI isn't supported at all | https://zapier.com/legal/data-privacy | 25 Sep 2026 |
| Make | Not stated by vendor | Security page lists GDPR, SOC 2 Type II, SOC 3 and ISO 27001, with no HIPAA | n/a | https://www.make.com/en/security | 25 Sep 2026 |
| n8n Cloud | Not stated by vendor | No mention of HIPAA or a BAA on n8n's legal pages | n/a | https://n8n.io/legal/security/ | 25 Sep 2026 |
| n8n self-hosted | Not a vendor BAA question | You run it. The BAAs you need are with your host and with each service a workflow sends PHI to (our reading) | Deleting user data is your job | https://docs.n8n.io/privacy-security/privacy/ | 25 Sep 2026 |
| HubSpot | Yes | Enterprise subscription, Sensitive Data turned on, and you identify as a HIPAA covered entity or business associate | Chatbots, personalization tokens, sandboxes, playbooks; no data-center move | https://knowledge.hubspot.com/account-security/store-sensitive-data | 25 Sep 2026 |
| monday.com | Yes | Enterprise plan with the HIPAA compliance feature enabled | Broadcast disabled; third-party apps not covered; downgrading ends coverage | https://monday.com/l/privacy/hipaa-baa/ | 25 Sep 2026 |
| Zoho CRM | Yes, on request | Request the BAA from [email protected]. Zoho doesn't state which CRM edition you need | Only the services listed in the BAA are covered | https://www.zoho.com/hipaa.html | 25 Sep 2026 |
| HighLevel | Yes, paid add-on | HIPAA add-on at US$297 a month, available on any agency plan | Can't be disabled once bought; no PHI in AI features | https://help.gohighlevel.com/support/solutions/articles/48000983084-hipaa-compliance-with-highlevel | 25 Sep 2026 |
| Pipedrive | No BAA found | Terms say the service is "not designed to comply with" HIPAA | n/a | https://www.pipedrive.com/en/terms-of-service | 25 Sep 2026 |
Is Zapier HIPAA compliant?
No. Zapier says PHI isn't supported and it can't sign a BAA. Zapier's data privacy page says: "The use of regulated healthcare and medical data including Protected Health Information (PHI) under HIPAA isn't supported on Zapier. Zapier also can't sign business associate agreements (BAAs) or equivalent agreements for handling PHI or other similar information." (https://zapier.com/legal/data-privacy, checked 25 Sep 2026)
Zapier's enterprise agreement FAQ agrees: "Zapier hasn't undergone the HIPAA certification process, and we therefore don't offer a BAA." (https://zapier.com/legal/enterprise-agreement-faq) Neither page makes an exception for any plan, Enterprise included.
One Zapier page reads differently. The healthcare automation marketing page (https://zapier.com/automation/healthcare-automation) invites you to "Automate PHI transfers with pre-configured, HIPAA-ready workflows." Go by the legal pages, because those are Zapier's terms, and they say PHI isn't supported. If your practice uses Zapier, keep patient data out of it entirely.
Is HubSpot HIPAA compliant, and which plan do you need?
Yes. HubSpot signs a BAA, but only on an Enterprise subscription with Sensitive Data turned on. HubSpot's knowledge base lists the feature for the Enterprise tiers of Marketing Hub, Sales Hub, Service Hub, Data Hub, Content Hub, Smart CRM and Revenue Hub, and for nothing below Enterprise (https://knowledge.hubspot.com/account-security/store-sensitive-data, checked 25 Sep 2026).
You opt in through two settings. In HubSpot's words: "To store HIPAA-covered data, you must select both the Health/Medical Data checkbox and the We are a HIPAA-covered entity or business associate checkbox." The BAA itself is Annex I of HubSpot's Sensitive Data Terms (https://legal.hubspot.com/sensitive-data-terms), and it "applies only to the extent Customer is a 'covered entity' or 'business associate' as those terms are defined by HIPAA."
Some HubSpot tools stay off limits. The knowledge base says Sensitive Data properties "are unavailable in certain tools, including personalization tokens, sandboxes, chatbots and playbooks", and calculation, rollup and property sync fields can't hold Sensitive Data. Once you declare HIPAA data, "you cannot migrate to another data center" (https://knowledge.hubspot.com/account-security/sensitive-data-in-hubspot-tools). If you drop below Enterprise later, existing Sensitive Data properties remain, but you can't create new ones or edit the old ones.
Is n8n HIPAA compliant? n8n Cloud vs self-hosted
n8n Cloud: not stated by the vendor. None of n8n's legal pages mention HIPAA or a business associate agreement. On 25 September 2026 we read the security page, the self-serve terms, the master enterprise terms, the data processing agreement, the EULA, the AI terms and the acceptable use policy. The security page says n8n "aligns its security program to SOC 2", which is a security framework, not HIPAA (https://n8n.io/legal/security/).
n8n's trust centre (trust.n8n.io) returned an error when we tried to read it, so it may say something we couldn't see. On n8n's community forum, a reply from the n8n team in August 2023 said "n8n cloud is not SOC2 or HIPPA certified". That is a forum reply, not a policy page. Ask n8n sales in writing before any PHI goes to n8n Cloud.
Self-hosted n8n changes the question. n8n's privacy docs say self-hosted telemetry doesn't collect execution data, credential information or error payloads, and that you can switch telemetry off with N8N_DIAGNOSTICS_ENABLED=false. They also say: "If you self-host n8n, you are responsible for deleting user data." (https://docs.n8n.io/privacy-security/privacy/, checked 25 Sep 2026)
Our reading, not a vendor statement: when you self-host, n8n the company doesn't hold your workflow data. The BAAs that matter are with your hosting provider and with every API a workflow sends patient data to, such as an LLM, an SMS gateway, an email service or a form tool. Self-hosting doesn't make a workflow compliant on its own. You still need those agreements and a server that is configured and maintained properly.
Is Make.com HIPAA compliant?
Not stated by the vendor. Make doesn't list HIPAA or a BAA on its security page (https://www.make.com/en/security, checked 25 Sep 2026). The page names GDPR, SOC 2 Type II, SOC 3 and ISO 27001. We found no Make page saying it signs a BAA, and none saying it refuses one. Some of Make's other legal pages blocked our requests, so we couldn't read them.
The closest thing to a statement is on Make's community forum. In December 2024 a Make employee wrote that the company was "evaluating the customer's demand for other certificates (including HIPAA)". Until Make puts a BAA on a legal page or in writing to you, keep PHI out of Make, or use a tool whose vendor signs one.
Is monday.com HIPAA compliant?
Yes. monday.com signs a BAA on the Enterprise plan with the HIPAA compliance feature enabled. Its help centre says: "HIPAA is available on monday.com on our Enterprise plan." (https://support.monday.com/hc/en-us/articles/360006506699-monday-com-and-HIPAA, checked 25 Sep 2026) The BAA page is headed "For Enterprise Plan with HIPAA Compliance Feature Enabled" and says it applies only "if you are using the enterprise tier subscription and have enabled the HIPAA compliance feature on the Platform" (https://monday.com/l/privacy/hipaa-baa/).
The conditions are specific. If you downgrade from Enterprise, "you will no longer be covered under the HIPAA compliance program anymore." The broadcast feature is disabled on HIPAA plans. The mobile app is covered from version 3.331 on iOS and 3.190715 on Android.
Integrations are the bigger catch. monday.com's BAA says connected third-party services "may or may not be compliant with HIPAA", and if you use them you are "solely liable and responsible" for the PHI that moves through them. A monday.com board can be covered while the integration reading from it is not. Our healthcare reporting automation case study describes a build on monday.com Enterprise.
Is Zoho CRM HIPAA compliant?
Yes, on request. Zoho signs a BAA if you ask for one. Zoho's HIPAA page says: "Contact [email protected] to request Zoho's BAA template. The BAA defines the specific Zoho services covered, security commitments, breach notification procedures, and subcontractor flow-down requirements. No PHI should flow through any Zoho application until a signed BAA is in place." (https://www.zoho.com/hipaa.html, checked 25 Sep 2026)
Zoho CRM's own HIPAA page says: "As a Business Associate, Zoho CRM ensures its customers have the ability to comply with HIPAA." (https://www.zoho.com/crm/data-security/hipaa.html) Neither page names the Zoho CRM edition you need, so we don't name one here. Ask Zoho when you request the BAA.
Zoho is blunt about what the BAA doesn't cover: "Confine PHI exclusively to BAA-covered services. Never store it in non-covered apps or integrations without their own BAA."
Is HighLevel (GoHighLevel) HIPAA compliant?
Yes, as a paid add-on. HighLevel signs a BAA when you buy its HIPAA add-on. Its help centre says the account-wide add-on "costs US$297 per month and cannot be disabled once purchased", and that HighLevel accounts "are NOT HIPAA compliant by default" (https://help.gohighlevel.com/support/solutions/articles/48000983084-hipaa-compliance-with-highlevel, checked 25 Sep 2026). Agencies on any plan can buy it. After signing the BAA, you turn HIPAA on for each sub-account by hand, and that toggle can't be turned off either.
Plan around one limit. HighLevel's terms of service say: "You agree not to provide any sensitive personal information, Protected Health Information (PHI), or other confidential information as input into the AI features." (https://www.gohighlevel.com/terms-of-service, checked 25 Sep 2026) That sentence carries no exception for accounts with the HIPAA add-on.
Which CRMs will sign a BAA?
Four of the CRMs in this article publish a way to get a BAA: HubSpot (Enterprise, with Sensitive Data on), monday.com (Enterprise, with the HIPAA feature on), Zoho CRM (on request, edition not stated) and HighLevel (the US$297-a-month add-on).
Pipedrive is the exception. Its terms of service say: "Pipedrive Services are not designed to comply with industry-specific regulations such as the Health Insurance Portability and Accountability Act (HIPAA) or the Federal Information Security Management Act (FISMA)." (https://www.pipedrive.com/en/terms-of-service, checked 25 Sep 2026) We found no Pipedrive BAA on its site.
For a medical practice, the plan is where the cost hides. HubSpot and monday.com put the BAA on Enterprise. HighLevel sells it as an add-on to any agency plan. Zoho asks you to email its legal team. Compare the price of the plan that carries the BAA, not the entry plan.
What is a HIPAA-compliant alternative to Zapier?
There are two routes. The first is a platform whose vendor signs a BAA covering the features your workflow uses. Check that coverage feature by feature: HubSpot's terms, for example, limit you to the "Covered Services" in its Product & Services Catalog.
The second is self-hosted n8n on hosting covered by a BAA, with a BAA from every service the workflow sends patient data to. This moves the responsibility to you and your host. Neither route is compliant by default, and neither replaces a review by your compliance lead.
Retailbox deploys and manages self-hosted n8n; the n8n services page linked below covers what that involves. That is engineering work. It doesn't stand in for the BAAs above or for your own compliance review.
Where AI answers and vendor pages disagree
In September 2026 we compared ChatGPT and Google AI Overview answers on these questions with the vendors' own pages. They disagree in four places. In each one, go by the vendor's page.
- HubSpot plan scope. One AI answer said HubSpot's HIPAA support runs through a "Healthcare Hub" and excludes most Enterprise setups. HubSpot's healthcare page says it "signs a Business Associate Agreement with qualifying enterprise customers", and its knowledge base lists every Enterprise hub. We found no "Healthcare Hub" on HubSpot's healthcare page (checked 25 Sep 2026).
- HubSpot and AI tools. One AI answer said AI-powered tools can't be used with PHI. HubSpot's knowledge base says "Breeze Assistant products are compatible with accounts with Sensitive Data turned on", with some restrictions. Chatbots are the tool HubSpot excludes.
- Zapier plans. One AI answer said "standard Zapier plans" don't sign BAAs, which implies some plan does. Zapier's legal pages make no plan exception: "Zapier also can't sign business associate agreements (BAAs)." Part of the confusion is Zapier's own: its healthcare marketing page offers "HIPAA-ready workflows" while its legal pages say PHI isn't supported.
- Make and n8n. AI answers often say flatly that Make and n8n Cloud do not sign BAAs. Neither vendor says that on its security or legal pages. What those pages show is no mention of HIPAA or a BAA at all (checked 25 Sep 2026). The practical advice is the same: keep PHI out until the vendor puts a BAA in writing.
What does HIPAA-compliant automation actually require?
A BAA with every vendor on the path your patient data takes, plus your own correct setup of each tool. A workflow that reads a web form, writes to a CRM and sends a text message passes data through at least three vendors, and each one needs its own BAA.
Security certificates don't replace a BAA. SOC 2 and ISO 27001 describe a vendor's security program. Make and n8n both point to SOC 2 on their security pages, and neither page mentions HIPAA.
The vendors that do sign BAAs say the responsibility is shared. monday.com's BAA makes you "solely liable and responsible" for PHI you send to third-party services. Zoho tells you never to store PHI "in non-covered apps or integrations without their own BAA." HubSpot's terms say: "You agree to use only the Covered Services for Permitted Sensitive Data specifically allowed under the Product & Services Catalog."
Want this built for your team? n8n automation services, including self-hosted n8n — 400+ projects shipped since 2017.
Related services
Monday.com implementation and consulting
We implement and automate monday.com, including on the Enterprise plan that carries its HIPAA terms.
CRM consulting and training
Still choosing a CRM? We help teams pick one, set it up and learn to use it.
AI chatbot development services
We build SMS and web chatbots that hand off to a person when they should.
Frequently asked questions
Does a signed BAA make my workflow HIPAA compliant?+
No. A BAA covers one vendor. If a HIPAA-covered monday.com board sends data to a third-party app, monday.com's BAA says you are solely responsible for that exchange. Every tool on the path of patient data needs its own BAA, and each one still has to be set up correctly.
How do I know if a software tool is HIPAA compliant?+
Look for a business associate agreement, not a badge. Find the vendor's legal or help page that offers a BAA and names the plan it applies to, then get it signed before any patient data goes in. SOC 2 or ISO 27001 certificates describe a security program; they don't mean the vendor signs a BAA.
Can I use AI tools or a chatbot with patient data?+
Only where the vendor's BAA covers that feature. HubSpot excludes chatbots from Sensitive Data but says its Breeze Assistant products work with Sensitive Data accounts, with restrictions. HighLevel's terms forbid putting PHI into its AI features. For a custom chatbot, check the BAA of every model and hosting provider behind it.
Which CRM is best for a medical practice?+
Start with CRMs whose vendor signs a BAA on a plan you can afford. As of 25 September 2026: HubSpot on Enterprise with Sensitive Data, monday.com on Enterprise with the HIPAA feature, Zoho CRM on request, and HighLevel with its US$297-a-month add-on. Pipedrive's terms say it isn't designed for HIPAA.
Is Pipedrive HIPAA compliant?+
Pipedrive's terms of service say its services "are not designed to comply with" HIPAA, and we found no Pipedrive BAA on its site (checked 25 September 2026). For patient data, pick a CRM whose vendor signs a BAA, such as HubSpot Enterprise, monday.com Enterprise, Zoho CRM or HighLevel.
When were these vendor terms last checked?+
We checked every vendor page cited in this article on 25 September 2026. Plans, prices and BAA terms change without notice. Confirm with the vendor before you send any patient data, and have your compliance lead review the BAA itself. This article is not legal advice.