Vendor compliance profile

Is Salesforce HIPAA compliant?

Salesforce may support HIPAA-regulated workflows only for covered Salesforce services, configured features, and contract scope. Verify the current Business Associate Addendum restrictions, HIPAA covered services, Shield or Health Cloud requirements, and integrations before storing or processing PHI.

Reviewed by Evidence: Public first-party sourcesConfidence: High
Visit vendor site

Direct compliance answer

Salesforce HIPAA, BAA, PHI, and SOC 2 snapshot

Last checked: 2026-08-09 | Confidence: High

Direct answerSalesforce may support HIPAA-regulated workflows only for covered Salesforce services, configured features, and contract scope. Verify the current Business Associate Addendum restrictions, HIPAA covered services, Shield or Health Cloud requirements, and integrations before storing or processing PHI.
BAA availabilitySalesforce's current Business Associate Addendum lists covered services and conditions. Buyers should confirm the executed agreement, exact product and infrastructure, any required Shield capabilities, and excluded or adjacent features before introducing PHI.
Can it handle PHI?CRM fields, notes, tasks, Chatter, email sync, Einstein features, Slack, Marketing Cloud, support cases, APIs, and third-party AppExchange apps can all create PHI exposure.
SOC 2 caveatSalesforce publishes SOC 2 categories and product-specific compliance documents through the Salesforce Compliance site. Review the current report for the services in use.
What to verifyWhether the organization has executed the current Salesforce BAA and whether every product, cloud, infrastructure option, edition, and feature used with PHI is listed as covered. Whether Salesforce Shield or other security capabilities are required for the selected services and how encryption, permissions, audit history, event monitoring, retention, and deletion are configured.

HIPAA status signal

Conditional

BAA public signal

Covered services only

SOC 2 evidence signal

Public evidence

PHI warning: CRM fields, notes, tasks, Chatter, email sync, Einstein features, Slack, Marketing Cloud, support cases, APIs, and third-party AppExchange apps can all create PHI exposure.

Search query answers

Is Salesforce HIPAA compliant?

Salesforce should not be treated as universally HIPAA compliant. Some Salesforce services may support HIPAA-regulated workflows only when the exact service is covered by an executed Business Associate Addendum and the customer follows the product, security, configuration, and data-handling restrictions in that agreement.

Does Salesforce offer a BAA?

Salesforce publishes a Business Associate Addendum for listed covered services. Buyers must execute the applicable agreement and verify that every cloud, feature, infrastructure option, integration, support path, and data flow used with PHI is included rather than assuming account-wide coverage.

Is Salesforce Health Cloud automatically HIPAA compliant?

No. A healthcare product name does not make the customer's implementation automatically compliant. Verify that Health Cloud and its underlying Salesforce services are listed in the current BAA, then review Shield requirements, permissions, encryption, audit history, integrations, AI features, support, and the intended PHI workflow.

Does Salesforce SOC 2 prove HIPAA compliance?

No. Salesforce SOC 2 reports can support security diligence, but they do not establish BAA coverage or approve PHI use. HIPAA review still depends on the exact covered services, contract, configuration, workforce access, integrations, retention, and customer responsibilities.

HIPAA, BAA, and SOC 2 summary

HIPAASalesforce publishes HIPAA compliance documentation and a Business Associate Addendum with a defined covered-services list and restrictions. Eligibility remains product- and contract-specific rather than applying to every Salesforce service or feature.
BAASalesforce's current Business Associate Addendum lists covered services and conditions. Buyers should confirm the executed agreement, exact product and infrastructure, any required Shield capabilities, and excluded or adjacent features before introducing PHI.
SOC 2Salesforce publishes SOC 2 categories and product-specific compliance documents through the Salesforce Compliance site. Review the current report for the services in use.
PHI riskCRM fields, notes, tasks, Chatter, email sync, Einstein features, Slack, Marketing Cloud, support cases, APIs, and third-party AppExchange apps can all create PHI exposure.
CategoryHIPAA-Compliant CRM and Marketing Tools
Last checked2026-08-09
ConfidenceHigh

Public evidence and open questions

What public sources say

  • Salesforce maintains a public HIPAA compliance category and directs customers to its current HIPAA documentation and covered-service terms.
  • Salesforce's Business Associate Addendum identifies covered services and contains product-specific restrictions rather than granting blanket coverage to every Salesforce offering.
  • Salesforce publishes SOC 2 materials through its compliance portal, but SOC 2 evidence is separate from HIPAA agreement and product-scope review.

What remains unconfirmed

  • Whether the buyer's exact Salesforce clouds, editions, infrastructure, add-ons, AI features, integrations, and support channels are listed in the executed BAA.
  • Whether email sync, Marketing Cloud, Slack, Tableau, MuleSoft, AppExchange apps, data exports, sandboxes, logs, and support cases remain inside the reviewed PHI boundary.
  • Whether the customer's permissions, encryption, audit history, retention, deletion, mobile access, and incident response satisfy its own obligations.

What it may be used for

  • Covered Salesforce services after the applicable BAA, product scope, required security capabilities, configuration, and PHI workflow are verified.
  • Healthcare CRM or service workflows where fields, files, notes, communications, integrations, exports, and workforce access are governed together.
  • Security and procurement review where HIPAA documentation, SOC reports, product terms, and implementation controls are evaluated separately.

What not to use it for

  • Putting PHI into Salesforce products or features that are not covered by the BAA.
  • Using email capture, inbox sync, AI, marketing, messaging, or analytics features without covered-service confirmation.
  • Assuming Health Cloud claims apply to Sales Cloud, Service Cloud, Marketing Cloud, Slack, Tableau, or every Salesforce add-on.

What to verify with the vendor

  • Whether the organization has executed the current Salesforce BAA and whether every product, cloud, infrastructure option, edition, and feature used with PHI is listed as covered.
  • Whether Salesforce Shield or other security capabilities are required for the selected services and how encryption, permissions, audit history, event monitoring, retention, and deletion are configured.
  • Whether PHI can enter email capture, Einstein or other AI features, Chatter, Slack, Marketing Cloud, Tableau, MuleSoft, AppExchange apps, sandboxes, exports, logs, support cases, or mobile notifications.
  • Whether the current SOC 2 report covers the exact Salesforce services and operating period used by the buyer.

Safer alternatives and related profiles

Safer alternatives to consider

  • A healthcare-specific CRM with explicit BAA coverage for the exact communications, intake, automation, and integration workflow.
  • HubSpot only where eligible Enterprise products, Sensitive Data settings, and an executed BAA cover the intended PHI use.
  • Keeping PHI in an EHR or patient platform while Salesforce receives only minimized, non-PHI operational data.

FAQ

Is Salesforce HIPAA compliant?

Salesforce should not be treated as universally HIPAA compliant. Some Salesforce services may support HIPAA-regulated workflows only when the exact service is covered by an executed Business Associate Addendum and the customer follows the product, security, configuration, and data-handling restrictions in that agreement.

Does Salesforce offer a BAA?

Salesforce publishes a Business Associate Addendum for listed covered services. Buyers must execute the applicable agreement and verify that every cloud, feature, infrastructure option, integration, support path, and data flow used with PHI is included rather than assuming account-wide coverage.

Is Salesforce Health Cloud automatically HIPAA compliant?

No. A healthcare product name does not make the customer's implementation automatically compliant. Verify that Health Cloud and its underlying Salesforce services are listed in the current BAA, then review Shield requirements, permissions, encryption, audit history, integrations, AI features, support, and the intended PHI workflow.

Does Salesforce SOC 2 prove HIPAA compliance?

No. Salesforce SOC 2 reports can support security diligence, but they do not establish BAA coverage or approve PHI use. HIPAA review still depends on the exact covered services, contract, configuration, workforce access, integrations, retention, and customer responsibilities.

Will Salesforce sign a BAA?

Salesforce's current Business Associate Addendum lists covered services and conditions. Buyers should confirm the executed agreement, exact product and infrastructure, any required Shield capabilities, and excluded or adjacent features before introducing PHI.

Can Salesforce be used with PHI?

Do not use this vendor with PHI until your organization verifies BAA scope, covered services, configuration, access controls, data retention, and connected integrations.

Does SOC 2 mean Salesforce is HIPAA compliant?

No. SOC 2 evidence can support security diligence, but it does not prove HIPAA compliance, confirm BAA coverage, or approve PHI use. Review HIPAA terms, BAA scope, covered services, configuration, and intended workflow separately.

What should buyers verify before using Salesforce with PHI?

Whether the organization has executed the current Salesforce BAA and whether every product, cloud, infrastructure option, edition, and feature used with PHI is listed as covered. Whether Salesforce Shield or other security capabilities are required for the selected services and how encryption, permissions, audit history, event monitoring, retention, and deletion are configured. Whether PHI can enter email capture, Einstein or other AI features, Chatter, Slack, Marketing Cloud, Tableau, MuleSoft, AppExchange apps, sandboxes, exports, logs, support cases, or mobile notifications. Whether the current SOC 2 report covers the exact Salesforce services and operating period used by the buyer.

Last checked and source notes

Last checked
2026-08-09
Confidence
High
Dataset rows
274 vendors