Skip to main content

<< Return to help center
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

HIPAA compliance

Is LACRM HIPAA-compliant?

Yes, we are HIPAA-compliant!

How do I enable HIPAA on my account?

All you need to do is click here to sign a BAA with us. A BAA (Business Associate Addendum) is a contract that HIPAA requires between you and any vendor you use. Just click that link and submit the form to confirm that you read and agree to the contract.

Until you sign the BAA, your LACRM account is not HIPAA-compliant. Don’t store PHI in LACRM until signing that agreement.

Does it cost extra?

No! Everything in LACRM is included in our one simple price, and that includes HIPAA-compliance. As a matter of fact, because we don’t charge extra the way most CRMs do, we’re by far the most affordable HIPAA-compliant CRM, and it’s not even close.

(note: If you find a cheaper HIPAA-compliant CRM, please let us know)

What do I need to know about using LACRM in a HIPAA-compliant way?

First and foremost, when we say that LACRM is HIPAA-compliant, what we mean is that we allow you to be HIPAA-compliant. Compliance is ultimately your responsibility, so you need to follow all the appropriate rules and regulations regardless of what CRM you use.

As for LACRM-specific info you should know, here are the main things:

  • PHI should only go in specific fields within the CRM. You can see the full list in the BAA you sign, but mostly it's: Contact and company custom fields, pipeline fields, notes, task/event descriptions, and the body of files. Medical information should not go in name fields (task name, event name, etc.) or anywhere else that is not specifically approved for PHI.
  • You should not send PHI to our support team via any channel. The data within your CRM is HIPAA-compliant, but support channels are not. If you need our help importing a file, you can securely upload it via our import tool, but do not email it to us directly.
  • You should not use our “Manual email logging” feature to log emails with PHI in them. If you forward/BCC an email to us (which is how manual email logging works), it goes through a third-party email processor which is not HIPAA-compliant. Automatic email logging is fine to use with PHI, but manual email logging is not.

To enable HIPAA on your account, click here to sign our BAA.

Next up:
Tags:
Keywords:
HIPAA, HIPPA, health, PHI, Business Associate Agreement
How do I can you are you able to can I how to is it possible