
Challenge 1: HIPAA Compliance Is Not Automatic
Here is something many organizations discover too late: HubSpot does not come pre-configured for HIPAA compliance. It has to be set up that way, and that setup is a core part of any serious HubSpot development project in healthcare.
To handle Protected Health Information (PHI) compliantly, a healthcare organization needs an enterprise subscription, a signed Business Associate Agreement (BAA) with HubSpot, and an admin who has manually activated the sensitive data settings and flagged the account as a HIPAA-covered entity. That process is straightforward, but what is not straightforward is knowing which HubSpot features are actually covered by the BAA and which ones are not.
Using a feature that is outside the BAA’s scope to handle PHI (even accidentally) creates real compliance risk. The table below shows exactly what is and is not covered.
| HubSpot Feature |
Covered Under HIPAA BAA |
Notes |
| CRM Contacts & Companies |
Yes |
Core patient record management |
| Deals & Pipelines |
Yes |
Patient journey and referral tracking |
| Forms |
Yes |
Patient intake and inquiry capture |
| Email (Marketing Hub Enterprise) |
Yes |
Appointment reminders, care communications |
| CRM Activities (Call Logs) |
Yes |
Added September 2024, logs only, not recordings |
| Service Hub Tickets |
Yes |
Patient support case management |
| Custom Report Builder |
Not covered |
PHI must not be included in custom reports |
| Customer Journey Reports |
Not covered |
Requires anonymized data only |
| Call Recordings / Transcripts with PHI |
Not covered |
Call logs permitted; recordings are not |
| Analytics Reporting |
Not covered |
Use aggregate, de-identified data only |
How to overcome it?
Before any configuration work starts, run a compliance audit. Map every workflow, form, and integration you plan to build against this coverage boundary. This is exactly the kind of work a HubSpot Technical Consulting engagement handles, and catching issues at this stage is far less costly than discovering them mid-implementation. Strong HubSpot development expertise paired with healthcare data governance knowledge is what makes this step reliable.
Challenge 2: Connecting HubSpot to Your EHR Is Complex
HubSpot handles patient engagement and marketing. The Electronic Health Record (EHR), systems like Epic, Cerner, or Athenahealth, handles the clinical record. Both are essential, and they need to work together. That connection is harder to build than most organizations expect.
EHR systems do not integrate with HubSpot out of the box. Building a working, compliant data pipeline usually requires custom API development or middleware platforms like Mulesoft or Boomi; this is where HubSpot development work gets genuinely technical. The goal is to move the right information (appointment dates, referral sources, care program status, and communication preferences) into HubSpot while keeping clinical data safely in the EHR where it belongs.
According to Liferay’s 2026 Healthcare Digital Transformation Report, most healthcare organizations that have consolidated their EHR still operate between 15 and 30 separate legacy systems with no meaningful connection to patient-facing workflows. Custom HubSpot integrations are the development work that begins to close this gap. Getting the architecture right before coding starts is what keeps projects on time and on budget.
For organizations also moving from a previous CRM, HubSpot Migration Services add another layer of complexity. Legacy healthcare data often includes years of contact records, referral history, and campaign data, all of which needs to be cleaned, mapped, and verified for consent status before it moves. RevOps Consulting Services with healthcare sector experience are best placed to design this migration architecture from the outset.
Challenge 3: Automation Has to Follow HIPAA Rules Too
Most people think of HIPAA compliance as a data storage issue. But it applies to marketing automation as well, and this is where a lot of HubSpot development teams without healthcare experience run into trouble.
HIPAA draws a clear line between two types of outbound communication.
The first is treatment-related communication, appointment reminders, care instructions, and follow-ups. These can be sent without additional patient authorization.
The second is marketing communication, like promotional content, service announcements, and re-engagement campaigns. These require explicit patient consent.
The problem arises when HubSpot marketing automation workflows blur that line. A sequence that sends marketing content to patients who only consented to clinical updates is a compliance violation, even if the content itself is harmless. HubSpot CRM Automation needs to be built with this distinction front and center.
How to overcome it?
Before building any automations, create a communication taxonomy, a simple framework that classifies every planned workflow by its purpose, the type of consent it requires, and its regulatory category. HubSpot Marketing Hub workflows should be organized into clearly separated families: care communications, appointment reminders, and marketing campaigns. Building them as distinct workflow groups makes each one individually auditable. HubSpot Onboarding for healthcare should establish this taxonomy as a foundational deliverable from day one.
Challenge 4: Healthcare Data Is Messier Than It Looks
Poor data quality is a universal CRM challenge. In healthcare, it is both a performance problem and a compliance problem, and it tends to be more complicated to fix than in other industries.
Here is what typically shows up during a healthcare CRM migration: duplicate patient records that conflict with each other; consent status fields that reflect what someone entered into a system years ago, not what the patient actually agreed to; and historical data that includes clinical observations mixed in with administrative notes. None of this can simply be bulk-imported. It requires careful review.
HubSpot CMS migration in healthcare adds another layer. Legacy websites and patient portals often have forms that collect PHI without the right consent language in place. Those forms cannot simply be rebuilt as-is; they need to be redesigned with HIPAA-compliant data capture built in. This is where development and compliance expertise must work together. Rebuilding the form without understanding the regulatory implications just transfers the problem to a newer platform.
A good rule of thumb: plan for pre-migration data preparation to take 40 to 60 percent of your total project timeline. HubSpot engagements in healthcare consistently find that the data work (cleaning, classifying, mapping consent, and reviewing for PHI) takes significantly longer than clients initially expect. Scoping the HubSpot CRM automation and data architecture around these requirements from the start avoids the frustrating cycle of building workflows on a data foundation that is not ready to support them.
Challenge 5: Getting the Team to Actually Use It
Even a perfectly configured HubSpot portal will underperform if the people who should be using it do not trust it or find it helpful. In healthcare, that adoption challenge is more acute than in most industries.
Physician burnout rates sit between 41 and 62 percent, according to the AMA’s 2025 National Physician Survey and Medscape’s 2025 Physician Burnout Report. Administrative staff are managing more patients with the same or smaller teams. The last thing either group needs is a new system that feels like extra work.
The way to avoid this is straightforward: design HubSpot Onboarding around the actual workflows of each role, not around how a standard CRM user is supposed to operate. A patient care coordinator’s job is nothing like a sales pipeline. A referral manager is not an account executive. The development work invested in customizing the portal only delivers value when users are trained on it as configured for their role, not on a generic version of the platform.
There is also a compliance layer here. Under HIPAA’s minimum necessary standard, each user should only see the patient data they actually need for their job. HubSpot CRM Developers set this up through role-based access controls at the property, pipeline, and team level. Front-desk staff can see appointment history. Marketing staff can see consent status and engagement data. Neither can see what is outside their scope. The RevOps Agency partner value is most visible in this stage. Organizations that approach the rollout as a change management initiative rather than a software deployment consistently see stronger and faster adoption.