Is Mailchimp HIPAA Compliant? No BAA, and the Addendum Bars PHI

Practical guidance for healthcare teams and business associates

In December 2018, OCR announced a settlement with a Florida physicians' group that had shared protected health information with an unknown vendor without a business associate agreement. The listing does not say the vendor was an email platform. It does not need to. The pattern is the same one that plays out in practices every week: someone exports the patient list, uploads it to a marketing tool, and sends a nice newsletter about flu shots. Nobody asked whether the tool would sign anything.

So, is Mailchimp HIPAA compliant? No. Mailchimp does not offer a B.A.A. (Business Associate Agreement) on any public page. Its Standard Terms of Use say that if you are subject to HIPAA and you use the Service, "we won't be liable if the Service doesn't meet those requirements." And its Data Processing Addendum goes further than silence: it defines "health information" as Sensitive Data and states that the "Customer will not provide (or cause to be provided) any Sensitive Data to Mailchimp for processing." A patient list in Mailchimp is not just uncovered by HIPAA paperwork. It is a breach of Mailchimp's own contract. This guide explains why a list of email addresses counts as P.H.I. (Protected Health Information), what the marketing rules add on top, and what to use for patient communication instead.

Is Mailchimp HIPAA Compliant? Its Own Terms, and Why a List Is PHI

Does Mailchimp Sign a BAA?

No. Nothing on Mailchimp's legal pages offers one, and the terms are written to put the entire question on the customer. Section 21 of the Standard Terms of Use reads: "You're responsible for determining whether the Service is suitable for you to use in light of your obligations under any regulations like HIPAA." The next sentence is the disclaimer of liability quoted above. Mailchimp is telling you, politely, that it is not your business associate and does not intend to become one.

The Data Processing Addendum closes the door. Its definition of Sensitive Data includes "employment, financial, credit, genetic, biometric or health information." Section 2.3, titled Prohibited data, states that Mailchimp "will have no liability whatsoever for Sensitive Data, whether in connection with a Security Incident or otherwise." Annex A adds that "Mailchimp does not want to, nor does it intentionally, collect or process any Sensitive Data." Compare that with the contract HIPAA requires. 45 CFR 164.504(e)(2)(ii)(B) says a business associate must agree to "use appropriate safeguards and comply, where applicable, with subpart C of this part with respect to electronic protected health information." Mailchimp's contract says the opposite: do not send it, and if you do, that is on you. What a real BAA has to contain is in the business associate agreement guide.

Which Mailchimp Plan Is HIPAA-Eligible?

None. Free, paid, and the highest tier all sit under the same Terms and the same DPA. This is not a case where an enterprise plan unlocks a compliance program, the way it does for some other vendors. There is no tier to buy.

Why "Just Email Addresses" Is Still PHI

The pushback is always the same: the newsletter has no diagnoses in it, so where is the health information? The answer is in the definition. Under 45 CFR 160.103, individually identifiable health information is "a subset of health information, including demographic information collected from an individual," that "relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care," and that identifies the person. A list of the people who receive care from a dermatology practice is demographic information that relates to the provision of health care. The fact of being a patient is the health information. Email addresses are one of the identifiers on the list of 18 HIPAA identifiers, and the list itself is PHI the moment it comes out of the EHR or the scheduling system.

That reframes every Mailchimp use case in a practice:

What is on the listPHI?Mailchimp?
Patients exported from the EHR or schedulerYesNo. No BAA, and the DPA prohibits it.
Patients segmented by service, condition, or visit typeYes, and now marketing under 164.501No, and an authorization question on top.
Appointment reminders and recall noticesYesNo. A treatment communication is still PHI in a vendor's hands.
Referring physicians, vendors, community partnersGenerally noGenerally fine. These are business contacts.
Public website newsletter signups not tied to careUsually not, if the practice cannot tell who is a patientPossible, with counsel's input on how the list was built.

The Marketing Rule Adds a Second Problem

Even with a compliant platform, patient email campaigns run into the Privacy Rule's marketing provisions. 45 CFR 164.501 defines marketing as "a communication about a product or service that encourages recipients of the communication to purchase or use the product or service," and 45 CFR 164.508(a)(3)(i) says "a covered entity must obtain an authorization for any use or disclosure of protected health information for marketing," with narrow exceptions for face-to-face communications and gifts of nominal value.

The definition carves out some things a practice does. A communication that describes "a health-related product or service ... that is provided by ... the covered entity making the communication" is not marketing, and neither are treatment communications or refill reminders, as long as the practice is not paid by a third party to send them. A flu-shot reminder to your own patients about your own clinic generally fits. A sponsored email about a device company's product does not, and it requires a signed authorization with the elements in the authorization form guide. Note that these exceptions decide whether you need the patient's permission. They say nothing about which vendor may hold the list. That is still the BAA question, and Mailchimp still fails it.

If the List Is Already in Mailchimp

Treat it as what it is: a disclosure of PHI to a vendor without a BAA, which the Privacy Rule does not permit. Under 45 CFR 164.402, an impermissible disclosure "is presumed to be a breach" unless a documented four-factor risk assessment shows a low probability that the PHI has been compromised. Do the assessment honestly, with the DPA's "no liability whatsoever" line in mind, and follow the breach notification guide for what comes next. Then delete the audience, document the deletion, and move the communication to a platform that can sign.

What to Use Instead

  1. Use Mailchimp for the audiences it is built for. Referral sources, professional contacts, and vendors are not patients. Keep those lists clean of anyone who came from the EHR.
  2. Send patient email from a covered platform. One-to-one and small-batch email through Google Workspace or Microsoft 365 with the BAA in force is covered; consumer accounts are not, as the Gmail comparison shows. For volume, choose an email platform that offers a BAA in writing and put the signed copy in the vendor register.
  3. Use the EHR's patient engagement module. Most systems already send reminders and recalls under the EHR vendor's existing BAA, which is the shortest path for a small practice.
  4. Write the marketing rule into policy. Who may send to patients, what content is treatment or operations, what needs an authorization, and who approves any campaign a third party pays for.
  5. Bring the agency inside the rules. If an outside firm runs your email, it is a business associate. The marketing agency guide covers that relationship end to end.

Common Mailchimp Mistakes in Practices

"It is only a newsletter." The content is not the problem. The audience is.

Uploading a CSV from the scheduler. The export carries names, emails, and often the appointment type. That is a patient list with a diagnosis hint attached.

Segmenting by procedure. A "Botox clients" audience is a condition-tagged list of patients sitting on a server whose owner has told you not to put it there.

Assuming the agency handled it. Agencies use Mailchimp because it is easy. Ask which platform holds the list, and ask to see the BAA.

Mailchimp is a fine tool for the marketing most businesses do. A medical practice is not most businesses, and Mailchimp's own lawyers have said so in two documents. Believe them.

---

FAQ

Does Mailchimp sign a HIPAA Business Associate Agreement?

No. Mailchimp's public legal pages offer no BAA. Its Standard Terms of Use say you are responsible for deciding whether the Service suits your HIPAA obligations and disclaim liability if it does not, and its Data Processing Addendum prohibits customers from providing health information.

Is a list of patient email addresses really PHI?

Yes. Under 45 CFR 160.103, demographic information that relates to the provision of health care to an identifiable person is individually identifiable health information. Being on a practice's patient list is itself health information, whatever the email says.

Can a paid Mailchimp plan be made HIPAA compliant?

No. Every Mailchimp plan sits under the same Terms and Data Processing Addendum. There is no tier that adds a BAA or permits health information.

Can I send a newsletter to my patients at all?

Yes, from a platform that signs a BAA. Communications about your own services to your own patients are generally not marketing under 45 CFR 164.501, but campaigns a third party pays for require a signed authorization under 164.508(a)(3).

What if my patient list is already in Mailchimp?

Treat it as an impermissible disclosure to a vendor without a BAA, run the four-factor breach risk assessment under 45 CFR 164.402, notify if required, delete the audience, and document every step.

Conclusion

Patient newsletters are worth doing. They are just not worth doing on a platform whose contract tells you not to. One Guy Consulting's Full-Scope plan includes vendor and BAA management, the marketing and authorization policy templates, and consulting time to move your patient communications onto a platform that can sign. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading