ActiveCampaign is a marketing automation platform that provides email marketing, customer relationship management, segmentation, reporting, forms, landing pages, and messaging tools.

With ActiveCampaign, organizations can automate customer communications, personalize campaigns, manage contact information, and track engagement across the customer journey.

Is ActiveCampaign HIPAA compliant? Yes, ActiveCampaign can be HIPAA compliant for customers who sign a business associate agreement (BAA) and use an eligible, properly configured account.

 

What changed this year?

In January 2026, ActiveCampaign published more detailed guidance about its HIPAA compliant marketing capabilities. The company now states that a BAA is available on eligible plans and lists an estimated price for a Professional plan with a BAA.

However, ActiveCampaign’s current plan overview lists “HIPAA support” as an Enterprise feature. Healthcare organizations should therefore confirm the required plan, account configuration, and covered services directly with ActiveCampaign before uploading protected health information (PHI).

 

Will ActiveCampaign sign a business associate agreement (BAA)?

Yes, ActiveCampaign will sign a BAA for eligible customers. The BAA can be requested and reviewed through the ActiveCampaign support team.

ActiveCampaign’s HIPAA compliant marketing guidance states that its BAA is available on eligible plans. The agreement must be executed before a healthcare organization stores, processes, or transmits PHI through the platform.

 

What does the ActiveCampaign BAA cover?

The ActiveCampaign BAA covers the use and disclosure of PHI through eligible ActiveCampaign services. ActiveCampaign states, “Business Associate Agreement (BAA): Available on eligible plans to cover the use and disclosure of PHI.”

According to ActiveCampaign’s public guidance, its HIPAA related offering includes:

  • Use and disclosure of PHI through eligible services
  • Marketing automation within a HIPAA-covered account
  • Role-based access controls
  • Audit logs
  • Automatic PHI detection
  • SSL/TLS-encrypted forms and landing pages

ActiveCampaign also states on its security page, “ActiveCampaign is heavily focused on GDPR, SOC 2, and HIPAA compliance.”

Customers should review the executed BAA to determine which specific products, features, integrations, and communication channels are covered.

 

What does the ActiveCampaign BAA exclude?

ActiveCampaign’s publicly available legal terms identify services that cannot be used with PHI.

The ActiveCampaign Conversations Policy states, “Under no circumstances shall Customer use the Conversations Platform to process, store, or transmit any … protected health information.”

The company’s Conversations Facebook Messenger Terms also prohibit customers from using that integration to send, collect, or otherwise transmit PHI.

ActiveCampaign’s general Terms of Service state that third-party services and integrations may be governed by separate agreements. Healthcare organizations should not assume that an integration, add-on, AI feature, messaging channel, or third-party service is covered unless it is expressly included in the executed BAA.

 

Conclusion

ActiveCampaign can be HIPAA compliant, but customers must sign a BAA, use an eligible account, and limit PHI to covered services. Healthcare organizations should confirm the applicable plan and BAA scope because ActiveCampaign’s current public materials provide conflicting information about whether HIPAA support is available on Professional or limited to Enterprise plans.

See also: HIPAA Compliant Email: The Definitive Guide

 

FAQS

What is a BAA?

A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.

 

What is HIPAA?

HIPAA sets national standards for protecting the privacy and security of certain health information, known as PHI.

HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.