- Most mainstream CDPs and analytics tools do not qualify for HIPAA compliance out of the box. A signed Business Associate Agreement (BAA) , a contract in which a vendor formally accepts obligations under HIPAA as a business associate , is the legal floor, not a feature add-on.
- PHI includes more than medical records. IP addresses, appointment timestamps, and URL paths containing condition codes can all constitute protected health information when tied to an identifiable individual.
- The safest architecture keeps PHI inside your own infrastructure and sends only de-identified or hashed identifiers downstream. Tools that ingest raw PHI into a shared cloud environment raise breach exposure regardless of their marketing claims.
- Seven vendors on this list will sign a BAA and have documented technical safeguards. Several general-purpose tools will not sign one at all.
- If you are evaluating CDPs for a covered entity, read the BAA and compliance table below before talking to a sales rep.
For a healthcare organization that qualifies as a covered entity or business associate under HIPAA, a compliant customer data platform must do three things: sign a Business Associate Agreement, implement technical safeguards including encryption at rest and in transit, and offer data access controls that limit PHI exposure to the minimum necessary. Hightouch, Twilio Segment (with restrictions), Tealium, mParticle, Simon Data, Ours Privacy, and PatientPoint are the platforms most commonly evaluated for this use case. Each handles PHI differently, and several require architectural decisions on your side before they qualify.
Why Standard Martech Tools Break Down for Healthcare Marketers
The assumption that careful handling substitutes for compliant infrastructure is the single most common mistake healthcare marketing teams make. A tool does not become HIPAA-safe because your team avoids pasting patient names into it. The platform itself must be covered under a BAA, and its underlying architecture must satisfy the HIPAA Security Rule’s technical safeguard requirements.
A Business Associate Agreement (BAA) is a contract in which a vendor formally accepts obligations under HIPAA as a business associate , and it differs meaningfully from a standard NDA. An NDA governs confidentiality of business information between parties. A BAA is specific to HIPAA: it defines permitted uses of PHI, mandates security safeguards, requires breach notification, and obligates the vendor to flow those requirements down to any subcontractors who touch the data. Without one, you cannot legally share PHI with a vendor. With one, you still need to verify the vendor’s architecture supports the Security Rule’s administrative, physical, and technical safeguards. The BAA is a prerequisite, not a certification.
Google Analytics 4, for example, does not offer a BAA for standard accounts. Meta’s ad pixel, by default, transmits URL strings and event parameters that can encode diagnostic or appointment data. Neither company has agreed to serve as your business associate, which means any PHI flowing through those tools creates breach liability regardless of intent. The Federal Trade Commission and the HHS Office for Civil Rights have issued enforcement actions in the healthcare advertising space precisely because marketing teams treated these as normal analytics tools.
For a broader look at how healthcare data platforms fit into a modern data stack, the modern marketing data stack guide for RevOps teams covers the infrastructure layers that sit beneath any CDP decision.
What Counts as PHI in a Marketing Context?
The HHS Safe Harbor de-identification method lists 18 identifiers that, when present alongside health information, constitute PHI. Marketers routinely encounter several of them without realizing it. Full name and email address are obvious. Less obvious: geographic data smaller than a state, dates related to an individual (appointment dates, admission dates, birth dates), phone numbers, device identifiers, and IP addresses.
A URL path like /schedule-appointment/oncology/dr-smith appended to a user’s IP address in a session log is arguably PHI. An email click event that records a timestamp alongside a user’s hashed email, when combined with appointment confirmation data in your warehouse, can reconstitute an individually identifiable health record. The test is not whether the data looks like a medical record. The test is whether it can identify a person in connection with a health condition, treatment, or payment.
This is why PHI redaction at the collection layer matters. Tools that let you suppress or hash specific URL parameters, strip query strings from page paths, and intercept event payloads before they leave the browser give you control that server-side tagging alone does not.
The AboutMartech PHI Exposure Audit: Four Checks Before You Sign a Contract
Before evaluating any vendor, run these four checks. Call this the PHI Exposure Audit. It surfaces the gaps most healthcare marketing teams discover too late.
- BAA availability: Does the vendor offer a BAA as a standard contract addendum, or only on enterprise plans? Ask for the actual document before a demo. Some vendors list HIPAA compliance on their website but only provide a BAA to accounts above a revenue threshold.
- Data residency: Where does PHI at rest live? A vendor that stores data on shared multi-tenant infrastructure in a jurisdiction outside the US adds complexity to your breach notification obligations.
- Minimum necessary access: Can you configure field-level access controls so that a campaign manager pulling audience segments never sees raw PHI, only de-identified cohort membership?
- Downstream connector risk: What integrations does the platform support, and which of those destinations have also signed BAAs? A compliant CDP connected to a non-compliant ad platform still creates a PHI leak at the activation layer.
Most sales cycles skip check four entirely. A vendor can be fully HIPAA compliant and still route PHI to Google Ads or a non-BAA email provider the moment you enable a native connector. Your BAA with the CDP does not extend to that destination.
BAA and Compliance Quick-Reference Table
| Vendor | BAA Available | PHI Stays in Your Infra | HITRUST Certified | PHI Redaction at Collection | Best For |
|---|---|---|---|---|---|
| Hightouch | Yes | Yes (warehouse-native) | No (SOC 2 Type II) | Via warehouse query layer | Teams with existing data warehouse |
| Twilio Segment | Yes (enterprise plans) | No (ingests to Segment infra) | No | Partial (event filtering) | Teams that accept limited PHI scope |
| Tealium | Yes | Configurable | Yes | Yes (tag filtering, server-side) | Enterprise health systems |
| mParticle | Yes | No (ingests to mParticle infra) | Yes | Yes (data filter rules) | Mobile-first patient engagement apps |
| Simon Data | Yes | Yes (warehouse-native) | No (SOC 2 Type II) | Via warehouse query layer | Health insurance and payer teams |
| Ours Privacy | Yes | Yes (by architecture) | In progress (as reported) | Yes (core product function) | Teams needing privacy-first activation |
| PatientPoint | Yes | Yes (healthcare-only platform) | Yes | Yes | Point-of-care and provider-side marketing |
The 7 Best HIPAA-Compliant CDPs and Activation Tools
1. Hightouch: Best for Teams That Already Have a Data Warehouse

Hightouch takes a fundamentally different approach to the PHI problem. Rather than ingesting patient or member data into its own cloud environment, Hightouch connects directly to your existing data warehouse (Snowflake, BigQuery, Databricks, Redshift) and queries it to build audience segments. PHI never leaves your infrastructure. The activation layer, which pushes those segments to ad platforms, email tools, or CRMs, works with only the identifiers you explicitly expose in a query result.
Hightouch will sign a BAA and is SOC 2 Type II certified. Its SERP positioning on “HIPAA compliant CDP” is explicit: the company markets its platform directly to healthcare teams as a HIPAA-compliant agentic marketing platform where PHI never leaves your infrastructure. The practical implication is that your compliance team audits your warehouse security posture, which you likely already have, rather than auditing a third-party vendor’s shared environment.
The tradeoff is real-time data collection. Hightouch does not have a native event collection SDK. If you need to capture website or app behavior, you still need a compliant collection layer upstream. Teams that already run Snowflake or BigQuery and have a collection tool handling redaction will find Hightouch the cleanest architecture for compliant activation. Teams starting from scratch need to budget for that upstream layer separately.
Pricing is not publicly listed. Hightouch is quote-based. Their pricing page offers a free tier for basic sync volume, with enterprise contracts required for healthcare-grade BAA coverage.
For a deeper comparison of how Hightouch fits into the reverse ETL category, the Hightouch vs Segment comparison covers the architectural differences in detail.
2. Twilio Segment: Best When PHI Scope Is Narrow and Contractually Bounded

Twilio Segment is the most widely deployed CDP in general martech, and it does offer a BAA, but only on Business and Enterprise plans. The critical architectural difference from Hightouch: Segment ingests event data into Segment’s own infrastructure before routing it downstream. That means PHI you send through a Segment source lives in Segment’s cloud, which your BAA covers, but the downstream destinations must also be covered independently.
Segment’s event filtering and destination filters let you suppress specific properties before they reach a given destination. This is useful for stripping PHI from a payload before it hits a non-BAA ad platform. The burden is on your team to configure those filters correctly and audit them over time as event schemas change. A new developer adding a diagnosis_code property to a tracking call will not trigger an automatic compliance alert unless you have built that governance layer yourself.
Where Segment works well in healthcare is for teams with a narrow PHI footprint: patient portal apps where you are tracking feature usage (not health data) and using Segment to route to a BAA-covered CRM or email platform. Teams trying to build full patient analytics across clinical and marketing touchpoints will hit the architectural ceiling fast.
3. Tealium: Best for Enterprise Health Systems That Need HITRUST

Tealium is the vendor most often specified by large integrated health systems and payers that require HITRUST CSF certification as a procurement condition. HITRUST is a framework that maps to HIPAA, NIST, and ISO 27001 simultaneously, and it requires third-party audited certification, not self-attestation. For healthcare organizations that use HITRUST as their vendor vetting standard, Tealium is one of a short list of tag management and CDP vendors that has actually completed the certification.
Tealium’s server-side tag management (EventStream) gives compliance teams meaningful control over what data leaves the browser and what gets processed server-side. You can intercept a tag call, redact a URL parameter containing a condition code, and route the cleaned event to a downstream destination without the raw PHI ever hitting a third-party pixel. This is the architecture HHS guidance points toward when it discusses technical safeguards for marketing analytics.
Tealium’s AudienceStream CDP layer builds profiles from those clean events and supports BAA-covered data sharing. Pricing is enterprise and quote-based. Tealium does not publish list pricing. Implementation complexity is higher than Hightouch or Simon Data. Budget for an implementation partner if your team does not have prior Tealium experience.
4. mParticle: Best for Mobile-First Patient Engagement Apps

mParticle is HITRUST certified and will sign a BAA. Its architecture is designed around mobile event collection, which makes it the strongest option for healthcare organizations that have a patient-facing mobile application as their primary engagement surface. The mParticle SDK intercepts events at the collection layer and applies data filter rules before forwarding to any downstream kit or server connection.
Data filter rules in mParticle let you block specific attributes from specific outputs. A appointment_type attribute can be allowed for your internal data warehouse connection and blocked for your push notification provider, which may not have signed a BAA. This granular forwarding control is more mature than what Segment offers natively, though the configuration surface is also more complex.
mParticle ingests data into mParticle’s infrastructure (not your own warehouse), so the BAA covers their environment, not yours. That is a meaningful distinction for compliance teams that prefer data residency within organization-controlled infrastructure. For organizations comfortable with vendor-hosted infrastructure under BAA, mParticle’s mobile SDK quality and data plan system are genuinely strong for app-centric patient engagement workflows.
Pricing is quote-based. mParticle’s pricing page notes growth and enterprise tiers without publishing figures.
5. Simon Data: Best for Health Insurance and Payer Marketing Teams

Simon Data is a warehouse-native CDP that shares Hightouch’s fundamental architectural advantage: PHI stays in your Snowflake or BigQuery environment, and Simon Data queries it to power campaign execution. The platform is purpose-built for sophisticated cross-channel campaign orchestration, which makes it particularly well-matched to payer marketing teams running member communications across email, SMS, direct mail, and paid media simultaneously.
Simon Data will sign a BAA. It is SOC 2 Type II certified. The platform’s campaign logic handles suppression lists, consent state management, and channel-level opt-out natively, which matters for payer teams managing both HIPAA obligations and state-level insurance marketing regulations that layer on top.
Where Simon Data differentiates from Hightouch is in the campaign execution layer. Hightouch is an activation tool that syncs audiences to destinations. Simon Data is a full campaign platform with orchestration, A/B testing, and a deliverability-focused email sending infrastructure. For a team that wants a warehouse-native architecture but does not want to stitch together a separate marketing automation tool, Simon Data closes that gap. Pricing is enterprise and quote-based.
6. Ours Privacy: Best for Teams That Need Privacy-First Data Activation

Ours Privacy is the most explicitly PHI-focused vendor on this list. The platform is marketed as a HIPAA-compliant CDP that also functions as a privacy data platform, designed specifically to let healthcare marketers run ad targeting and analytics without transmitting PHI to non-compliant destinations. Their positioning describes the core function clearly: optimized ads and analytics with sensitive data kept out of non-compliant systems.
The architecture uses a layer that intercepts data before it reaches advertising platforms, applies redaction or tokenization, and passes only compliant signals downstream. This is particularly relevant for healthcare organizations running Google Ads or Meta campaigns where pixel-based tracking creates PHI leak risk. Ours Privacy positions itself as the compliance layer between your patient data and those ad platforms.
Ours Privacy is a smaller vendor compared to Tealium or mParticle. That means less integration breadth and fewer pre-built connectors. For teams whose primary pain point is the ad-pixel PHI leak problem rather than full CDP functionality, the narrower focus may actually be an advantage. BAA availability is confirmed. HITRUST certification status was listed as in progress at the time this was written. Verify current certification status directly with the vendor before procurement.
7. PatientPoint: Best for Point-of-Care and Provider-Side Marketing

PatientPoint occupies a different position than the other six vendors. It is not a general-purpose CDP adapted for healthcare. It is a healthcare-native engagement platform built specifically for the point-of-care context, connecting brands to patients and providers through a closed network of clinical environments. For pharmaceutical brands, medical device companies, and health systems running provider-facing or waiting-room campaigns, PatientPoint provides HITRUST-certified, BAA-covered data infrastructure by default.
The audience activation and analytics capabilities are built on healthcare data from within the care setting, not inferred from web behavior. That distinction matters for campaigns where clinical context drives targeting logic. PatientPoint is not the right tool for a digital health startup running app install campaigns. It is the right tool for brands whose marketing intersects directly with the clinical environment and who need a vendor that has already solved the PHI data governance problem at the infrastructure level.
How Do Healthcare Marketers Run Ads Without Leaking PHI?
The architecture that avoids PHI leakage in paid media follows a specific pattern. First, collect behavioral data server-side rather than via browser pixels. Server-side collection lets your infrastructure intercept the event before it leaves your domain, apply redaction rules, and forward only the compliant payload to the ad platform’s API. Google’s Enhanced Conversions and Meta’s Conversions API both support server-side event transmission. Neither automatically solves the PHI problem, but both give you control that a browser pixel does not.
Second, hash any personal identifiers before transmission. Email address hashing before sending a custom audience to Meta or Google is table stakes. But hashing alone is not HIPAA compliance. As noted in coverage of what it takes to make a CDP HIPAA compliant, you need to hash with a secret key, not just a public hash function, because a public hash is reversible with a known dataset. A keyed HMAC provides meaningful pseudonymization.
Third, build your audience segments from de-identified cohorts rather than individual-level PHI. A segment defined as “members with a lapsed annual wellness visit, no PII included” passed to an ad platform as a hashed email list is structurally different from passing a raw file of patient emails with appointment history attached. The former is a compliant activation pattern. The latter is a breach waiting for an audit.
Teams evaluating the analytics layer alongside activation should look at the Google Analytics 4 alternatives that offer PHI-safe configurations, since GA4 itself does not support a BAA for standard healthcare use cases.
Can You Use Segment with PHI?
Twilio Segment can be used in a HIPAA context under a BAA, but with significant architectural constraints. Segment’s official documentation and BAA terms apply to Business and Enterprise accounts. Within those accounts, you are responsible for configuring which data reaches which destination. Any destination that does not have its own BAA with you is off-limits for PHI. Segment’s native integrations include many destinations that do not offer BAAs, including several advertising platforms.
The practical answer for most healthcare teams: Segment can serve as your event pipeline for de-identified behavioral data, with PHI-containing fields stripped at the source or filtered before forwarding. Using Segment as the system of record for PHI, or routing PHI to unsupported destinations via Segment, falls outside compliant use even under a BAA.
What Is HITRUST and Do You Actually Need It?
HITRUST CSF (Common Security Framework) is a certifiable framework that maps security controls across HIPAA, NIST, ISO 27001, and other standards. Third-party assessors audit vendors against the framework and issue certification valid for two years. For large health systems, payers, and enterprise pharmaceutical companies, HITRUST certification from a vendor is often a non-negotiable procurement requirement because it provides independent verification of controls rather than vendor self-attestation.
For smaller covered entities, digital health startups, and regional providers, HITRUST may not be a hard requirement. SOC 2 Type II with a signed BAA is the more common floor in mid-market healthcare marketing procurement. The vendors on this list that hold HITRUST certification are Tealium, mParticle, and PatientPoint. Hightouch and Simon Data hold SOC 2 Type II. Evaluate based on your organization’s procurement policy and your compliance team’s requirements, not on the assumption that HITRUST always equals safer.
Understanding how data flows between systems is part of the same due diligence. The ETL vs reverse ETL vs CDP explainer covers the data movement patterns that underlie most of these vendor architectures without the compliance layer added, which helps clarify what each vendor is actually doing with your data before you add the PHI dimension.
What Should Be in a BAA Before You Sign?
A BAA that meets HHS requirements must include: a description of permitted uses and disclosures of PHI by the business associate, obligations to implement safeguards, requirements to report breaches, provisions for subcontractor BAAs, and terms for returning or destroying PHI at contract termination. A vendor that offers a BAA limited to specific data types or excluding certain product features (such as their analytics module) is not providing full coverage for your use of that product.
Ask vendors specifically whether the BAA covers all product features you intend to use, including beta features, new AI modules, and third-party integrations they have enabled. A BAA that covers the CDP core but excludes the vendor’s new AI-driven audience prediction feature is a gap your compliance team needs to evaluate. Get that clarification in writing before signing.
Frequently Asked Questions
Which CDPs will sign a BAA and are fully HIPAA compliant?
Hightouch, Tealium, mParticle, Simon Data, Ours Privacy, PatientPoint, and Twilio Segment (on Business and Enterprise plans) all offer BAAs. HIPAA compliance is not a certification a vendor can receive. It is a status that depends on their architecture and your configuration. A signed BAA is necessary but not sufficient. The vendor’s technical safeguards, your data governance configuration, and the compliance status of downstream destinations all factor into your actual compliance posture.
What is the best customer data platform for a healthcare provider?
For healthcare providers with an existing data warehouse, Hightouch is the strongest architectural choice because PHI never leaves your infrastructure. For enterprise health systems with HITRUST procurement requirements, Tealium is the most commonly specified option. For mobile-first patient engagement, mParticle’s HITRUST certification and SDK-level data filtering make it the most capable tool. The right answer depends on your infrastructure maturity, compliance requirements, and the specific marketing use cases you are solving.
What is the difference between a BAA and an NDA?
A BAA (Business Associate Agreement) is a HIPAA-specific contract. It defines permitted uses of PHI, mandates security safeguards, requires breach notification within defined timeframes, and obligates the vendor to pass those requirements to any subcontractors who handle the data. An NDA (Non-Disclosure Agreement) is a general confidentiality contract covering business information , it carries none of those HIPAA-specific obligations. Signing an NDA with a martech vendor does not substitute for a BAA and does not make sharing PHI with that vendor legally compliant.
How do healthcare marketers run targeted ads without violating HIPAA?
The compliant path for paid media targeting uses de-identified cohort segments rather than individual-level PHI. You build an audience in your warehouse or CDP using clinical and behavioral criteria, export a list of hashed email addresses (keyed HMAC, not a simple SHA-256), and upload to an ad platform’s customer match feature. No PHI travels to the ad platform in readable form. Separately, server-side conversion tracking via Google’s Enhanced Conversions API or Meta’s Conversions API replaces browser pixels that would otherwise capture PHI-bearing URL strings.
Can I use Google Analytics on a healthcare website?
Google does not offer a BAA for Google Analytics 4 on standard accounts. GA4 collects IP addresses, URL paths, and event data that can constitute PHI if your site structure encodes health information in URLs (such as condition pages, appointment schedulers, or patient portal paths). Using GA4 on a covered entity’s website without a BAA and without PHI mitigation creates breach exposure. Several GA4 alternatives offer BAAs and server-side collection modes designed for healthcare web analytics.
What PHI redaction tools exist for healthcare marketing teams?
PHI redaction at the collection layer is available through several approaches. Tealium’s server-side EventStream processes tag calls before browser data reaches third-party destinations, applying rule-based suppression of PHI-bearing parameters. mParticle’s data filter rules block specific event attributes from specific downstream connections. Ours Privacy is designed specifically as a PHI-interception layer for ad and analytics traffic. For teams building custom solutions, server-side Google Tag Manager configured to strip URL query parameters before forwarding to GA4 or ad pixels is a common interim approach, though it requires disciplined ongoing governance.
Is HITRUST the same as HIPAA compliance?
No. HIPAA is a federal law. HITRUST CSF is a privately maintained security framework that organizations and vendors can be certified against by third-party assessors. HITRUST certification demonstrates that a vendor has implemented and had audited a defined set of security controls, many of which map to HIPAA Security Rule requirements. It is a stronger form of assurance than self-attestation, but it is not a legal determination of HIPAA compliance. A HITRUST-certified vendor can still fail to meet HIPAA requirements if their operational practices or contractual terms create gaps. Treat HITRUST as a meaningful signal, not a guarantee.
What are the three safeguards required under HIPAA’s Security Rule?
The HIPAA Security Rule requires administrative safeguards (policies, training, risk analysis, access management procedures), physical safeguards (controls over physical access to systems that hold PHI, including workstations and data centers), and technical safeguards (access controls, audit controls, integrity controls, and transmission security such as encryption). When evaluating a CDP vendor, the technical safeguards are most directly relevant to the martech procurement decision: encryption at rest and in transit, role-based access controls, audit logging of data access, and integrity verification for PHI in transit.
The Architectural Decision That Determines Everything
Every other evaluation criterion in this list flows from one foundational question: does PHI enter the vendor’s infrastructure, or does the vendor query your infrastructure? Warehouse-native tools like Hightouch and Simon Data answer that question in your favor. Tools that ingest event data into their own cloud (Segment, mParticle) put the compliance burden on your BAA coverage of their environment and on your configuration discipline over time.
Neither approach is universally wrong. A large health system with mature Snowflake infrastructure and a sophisticated data engineering team will get further faster with the warehouse-native model. A mobile health startup with one data person and a patient app will find mParticle’s SDK and HITRUST certification more immediately useful than standing up a compliant warehouse environment first.
The PHI Exposure Audit framework in this article exists because the vendor conversation typically happens before the architectural conversation. Sales cycles optimize for demo impressions, not data flow diagrams. Running the four checks before the first demo call puts your compliance requirements in front of the commercial decision, which is the only order that makes sense when the downside of getting it wrong is an HHS breach investigation. The tools above are the ones that can pass those checks. Most of the martech stack cannot.
For teams building out the broader data activation layer around a compliant CDP, the warehouse-native CDP comparison covers the architectural tradeoffs in depth, and the reverse ETL tools guide explains how activation pipelines from a warehouse to downstream destinations actually work in practice.





