In September 2020, OCR announced a $2.3 million settlement with a HIPAA business associate over a breach affecting the protected health information of more than 6 million individuals. Numbers that size come from systems that hold a lot of people in one place. A CRM is that kind of system, and a healthcare organization's CRM holds patients.
Is Salesforce HIPAA compliant? Yes, with a signed Business Associate Addendum, for the services the addendum names, and only if you meet Salesforce's published restrictions. Salesforce's compliance site says "customers who want to build healthcare applications on Salesforce that comply with US HIPAA can contact your account representative regarding a Business Associate Addendum (BAA)," and points to a Business Associate Addendum Restrictions page, last updated July 31, 2026. That page is the real answer to the question, because it describes what the B.A.A. (Business Associate Agreement, which Salesforce calls an Addendum) requires of the customer, service by service. This guide walks the signing path, the two conditions for coverage, the encryption rule that surprises people, the AI restrictions, and a setup list.
Is Salesforce HIPAA Compliant: The Addendum, the Covered Services, and the Restrictions
When Salesforce Signs a BAA
Yes, through the account representative. There is no self-service acceptance in the admin setup, and no published statement ties the addendum to a particular edition. What Salesforce does publish is the condition for coverage. From the restrictions page: "For Customer's use of a HIPAA Covered Service to be covered by the BAA: (1) Customer and Salesforce must sign a BAA that includes the HIPAA Covered Service; and (2) Customer must comply with the terms of the BAA and this article, to the extent applicable." Both halves matter. A signed addendum that does not list the service you are using does not cover it, and a listed service used in a way the restrictions prohibit is not covered either.
The regulation frames the same idea from your side. 45 CFR 164.502(e)(2) requires "satisfactory assurances ... documented through a written contract," and 45 CFR 164.504(e)(2)(i) says that contract must "establish the permitted and required uses and disclosures of protected health information by the business associate." Salesforce's addendum plus its restrictions page is where those permitted uses are spelled out. Read both before the first patient record is imported. The business associate agreement guide lists what the contract itself must contain.
The Salesforce Services the Addendum Covers
Salesforce publishes HIPAA Security Rule documentation for a defined set of offerings. Its white paper "Salesforce and the HIPAA Security Rule: Securing EPHI in the Cloud" applies to the Agentforce and Einstein Platform, Government Cloud Plus, Salesforce Services on first-party infrastructure, and Salesforce Services on Hyperforce. Separate papers cover Slack, Tableau Cloud, and the Informatica data management cloud. The definitive list of HIPAA Covered Services is inside the addendum you sign, which is why the restrictions page keeps sending readers back to it.
| Salesforce offering | HIPAA documentation published | Notes from the restrictions page |
|---|---|---|
| Core platform (Sales Cloud, Service Cloud, Health Cloud on first-party or Hyperforce) | Yes | Covered when listed in the signed addendum; customer must encrypt PHI |
| Agentforce and Einstein services | Yes | Covered with restrictions: not for diagnosis or treatment decisions; Data Masking required in the Einstein Trust Layer; no PHI in Einstein Bots utterance records |
| Slack | Yes (separate paper) | Tier-dependent; see the Slack requirements |
| Heroku | Covered only in Shield Private Spaces | "Standard Private Spaces and the Common Runtime are not covered by the BAA" |
| Commerce Cloud Einstein | Excluded | "Not covered by the BAA" |
The Encryption Rule Most Customers Miss
The restrictions page contains one sentence that reorganizes a Salesforce project: "Customer must encrypt all PHI: (1) transmitted using the HIPAA Covered Services; and (2) to the extent within Customer's control, stored in the HIPAA Covered Services." The required standard is HHS's guidance on rendering PHI "unusable, unreadable, or indecipherable to unauthorized individuals," the same guidance that defines "unsecured protected health information" at 45 CFR 164.402 and decides whether a lost record is a reportable breach.
Under the Security Rule alone, encryption of stored ePHI at 164.312(a)(2)(iv) is Addressable, meaning implement it or document why not. Under the Salesforce addendum, it is a contract term, so the Addressable flexibility described in the HIPAA encryption guide is gone for anything in Salesforce. In practice that means budgeting for Salesforce's own encryption offerings for stored data and enforcing TLS for every integration that moves PHI in or out.
The AI Restrictions
Salesforce is specific about its AI features, and the wording repeats across Agentforce Contact Center, Einstein Personalization, and the Einstein Services: the customer "may not use" them "as a substitute for professional medical or healthcare advice, diagnosis, or treatment," as a medical device or software "for the direct diagnosis of ... a disease or other condition," or "to infer, predict or interpret an individual's medical or health diagnosis, condition, status, program eligibility, or outcome." An AI agent that triages patient messages by likely condition is on the wrong side of that line.
Two more: "Customer must enable, maintain, and use Data Masking in the Einstein Trust Layer configuration" for HIPAA Covered Services, and where a third-party large language model is used with the Einstein GPT features, "Customer is responsible for ensuring that its use of any third-party Large Language Model (LLM) service provider ... meets HIPAA requirements." That third-party LLM needs its own BAA with you, on the same logic as the ChatGPT analysis.
What the Addendum Does Not Cover
- Services not listed in your signed addendum. Coverage is per service, not per company.
- Unencrypted PHI. By contract, encryption is your job. Data you leave in plain text is outside the terms.
- AppExchange apps and integrations. Each one that touches PHI is a separate business associate.
- Telephony. For Agentforce Contact Center, "Customer is responsible for ensuring that its use of any third-party telephony service ... meets HIPAA requirements."
- Your users. Field-level security, profiles, and permission sets are configuration, and misconfiguration is not a Salesforce breach. The principles are in the ePHI access control guide.
How to Set Up Salesforce for HIPAA
- Sign the addendum through the account representative and confirm, in writing, that every service you will use with PHI is listed in it. File it with the date.
- Save the restrictions page as a dated PDF next to the addendum, since Salesforce says it is part of the terms you must follow.
- Encrypt stored PHI with Salesforce's encryption offerings and enforce TLS on every integration, API user, and email relay.
- Map PHI to objects and fields. Know which objects hold PHI, then apply field-level security and least-privilege profiles under 45 CFR 164.308(a)(4).
- Configure the AI features to the restrictions: Data Masking on, no PHI in bot utterances, no diagnosis or eligibility inference, and a BAA for any external LLM.
- Keep Heroku PHI inside Shield Private Spaces if Heroku is in the picture, and follow the logging rules on the restrictions page.
- Vet AppExchange apps before installation. No BAA, no PHI.
- Apply minimum necessary to reports and exports. A CRM makes it trivial to export every patient with one click. 45 CFR 164.502(b)(1) still applies, as the minimum necessary guide explains.
- Enable audit logging and review it, satisfying the information system activity review at 164.308(a)(1)(ii)(D).
- Add Salesforce to the risk analysis as a system that stores ePHI, with the integrations listed.
Common Salesforce HIPAA Mistakes
Assuming Health Cloud means covered. The product name is not the addendum. The signed list is.
Plain-text PHI in standard fields. The addendum requires encryption; the default configuration does not provide it.
Letting marketing segment by condition. A campaign built on diagnosis fields is a marketing use of PHI that needs an authorization under 45 CFR 164.508(a)(3).
Installing apps first, asking later. Every connected app is a vendor.
Alternatives for Patient Relationship Management
| Option | BAA path | Notes |
|---|---|---|
| Salesforce | Business Associate Addendum via account representative | Per-service coverage, customer-side encryption mandate, detailed AI restrictions |
| HubSpot | BAA within its Sensitive Data terms on Enterprise editions | PHI limited to flagged properties and listed features |
| EHR patient engagement module | Usually inside the EHR vendor's BAA | Less flexible, far less to configure |
Salesforce is honest about the deal: it will be a business associate for the services it names, provided you encrypt what you store, keep the AI away from clinical judgment, and read the restrictions. That is a workable arrangement for an organization with an administrator who owns it. For a small practice, the EHR's own tools are usually the shorter road.
---
FAQ
Does Salesforce sign a HIPAA Business Associate Agreement?
Yes. Salesforce offers a Business Associate Addendum through the account representative. Coverage requires that the signed addendum lists the specific HIPAA Covered Service and that the customer follows the addendum and Salesforce's published BAA Restrictions page.
Do I need a specific Salesforce edition for HIPAA?
Salesforce's public pages do not tie the addendum to an edition. They tie coverage to the services listed in your signed addendum and to compliance with the restrictions, including customer-side encryption of stored and transmitted PHI.
Does Salesforce encrypt PHI for me?
Not by default under the addendum. The restrictions page says the customer must encrypt all PHI transmitted through, and to the extent within its control stored in, the HIPAA Covered Services, consistent with HHS guidance. Plan for Salesforce's encryption offerings.
Can I use Agentforce or Einstein with patient data?
Within limits. Salesforce prohibits using them for diagnosis, treatment, or inferring a person's condition or eligibility, requires Data Masking in the Einstein Trust Layer, bars PHI in Einstein Bots utterance records, and makes you responsible for any third-party LLM provider.
Is Heroku covered by the Salesforce BAA?
Only Shield Private Spaces, Shield Private Dynos, Shield Private Postgres, and related Shield services. Standard Private Spaces and the Common Runtime are not covered.
Conclusion
A CRM full of patients is a designated record set with a sales interface, and it deserves the same scrutiny as the EHR. One Guy Consulting's Full-Scope plan includes vendor and BAA management, the risk analysis, and consulting time to map every Salesforce object and integration that holds PHI against the addendum's restrictions. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- Salesforce Compliance: HIPAA category page (vendor page)
- Salesforce: Business Associate Addendum Restrictions (vendor legal page)
- Salesforce Compliance: Salesforce and the HIPAA Security Rule, Securing EPHI in the Cloud (vendor document page)
- 45 CFR 164.502 (uses and disclosures)
- 45 CFR 164.504 (business associate contract requirements at (e))
- 45 CFR 164.312 (technical safeguards)
- 45 CFR 164.402 (unsecured PHI definition)
Related Reading