Is Insightly HIPAA Compliant? What to Know About BAAs, Security, and Healthcare Use

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Is Insightly HIPAA Compliant? What to Know About BAAs, Security, and Healthcare Use

Kevin Henry

HIPAA

April 22, 2026

7 minutes read
Share this article
Is Insightly HIPAA Compliant? What to Know About BAAs, Security, and Healthcare Use

Overview of Insightly HIPAA Compliance

Whether a CRM such as Insightly can be used in a HIPAA-compliant program hinges on two pillars: a signed Business Associate Agreement (BAA) and rigorous security configuration aligned to the HIPAA Security Rule. Without a BAA in place, you should not store or process Protected Health Information (PHI) in the platform.

Even with a BAA, treat a CRM as an operational tool—not a substitute for an EHR. Limit data to the minimum necessary, focus on workflows like referrals, patient engagement, and revenue operations, and build controls that protect healthcare data privacy end to end.

  • Decide if PHI is truly required for the use case; prefer de-identified data when possible.
  • Execute a BAA that explicitly covers all Insightly modules and subprocessors you plan to use.
  • Configure and enforce security controls before importing any records.
  • Continuously monitor access, audit logs, and integrations that touch PHI.

Understanding Business Associate Agreements

A Business Associate Agreement is the contract that makes a vendor a HIPAA Business Associate, defining permitted uses of PHI, security obligations, breach notification timelines, and responsibilities for data return or deletion. No BAA means no PHI in the system—regardless of technical controls.

Before enabling healthcare workflows in Insightly, ensure the BAA covers every product you will use (e.g., CRM, marketing, service, AI features) and any connected services. Confirm how the vendor handles encryption, subcontractors, incident response, and data residency.

What to verify in the BAA

  • Scope: All modules, environments, and subprocessors that may handle PHI are in scope.
  • Data Encryption Standards: Encryption in transit and at rest, key management, and backup protections are specified.
  • Access and Audits: Right to audit, timely breach notification, and cooperation on investigations.
  • Use and Disclosure: Clear limits on data use, analytics, and product improvement activities.
  • Data Lifecycle: Data return/deletion SLAs, retention controls, and procedures for termination.
  • Support Channels: Rules for avoiding PHI in tickets, chat, and email with vendor support.

Insightly Security Features for Healthcare

Your objective is a defense-in-depth configuration that aligns with the HIPAA Security Rule’s technical safeguards. Confirm availability by edition and enable them across all users and integrations.

Core controls to request and enable

  • Data Encryption Standards: TLS 1.2+ for data in transit and strong encryption (e.g., AES-256) at rest, including encrypted backups.
  • Two-Factor Authentication: Enforce 2FA for all accounts; prefer phishing-resistant options where supported.
  • Role-Based Access Controls: Use RBAC and least-privilege roles, field-level permissions, and team-based record visibility.
  • Single Sign-On: SAML/OIDC SSO and SCIM provisioning for centralized identity and rapid offboarding.
  • Audit Logging: Immutable logs for logins, permission changes, data exports, API activity, and admin actions.
  • Network Controls: IP allowlisting, session timeouts, device checks, and anomaly detection alerts.
  • Data Loss Prevention: Export controls, watermarking, attachment restrictions, and content scanning.
  • API and Integration Security: Scoped tokens, rotation policies, and per-integration RBAC.
  • Resilience: Encrypted backups, tested restore procedures, and documented RPO/RTO targets.

Validate configurations with routine access reviews, change management, and test runs of user offboarding, key rotations, and backup restores.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Limitations of Insightly Copilot

AI assistants can accelerate work, but they also introduce unique risks. Unless your BAA explicitly covers Copilot (or similar AI features) and the vendor confirms HIPAA-eligible processing for that feature, do not input PHI into prompts or allow generated content to expose PHI.

Safe-use checklist for AI features

  • Coverage: Confirm the BAA includes Copilot and any underlying models or subprocessors.
  • Data Handling: Verify retention, training, and logging policies; ensure inputs are not used to train models outside your tenancy.
  • Access Controls: Restrict Copilot to specific roles; disable for users who handle PHI.
  • Redaction: Automate removal of identifiers before prompts; keep outputs free of PHI.
  • Use Cases: Limit to non-PHI tasks such as writing process docs or de-identified summaries.
  • Human Review: Require human approval for any AI-generated content that could affect patient communications.

Managing Protected Health Information Securely

Start with the minimum necessary principle. Map what constitutes PHI in your workflows—names, addresses, appointment details, treatment information—and decide where it truly needs to live. When feasible, replace identifiers with tokens and store the crosswalk only in HIPAA-eligible systems.

Practical PHI handling patterns

  • Use pseudonymous IDs in the CRM; keep clinical details exclusively in the EHR.
  • Apply field-level masking and restrict report exports that include identifiers.
  • Control attachments aggressively; prevent uploads of clinical documents into general CRM records.
  • Enable DLP rules on notes, tasks, and email integrations to block PHI leakage.
  • Set retention schedules so sensitive records and logs are purged when no longer needed.
  • Document administrative, physical, and technical safeguards per the HIPAA Security Rule.

Best Practices for Healthcare CRM Use

  1. Perform a HIPAA risk analysis for CRM data flows, integrations, and user devices.
  2. Execute a BAA that covers all planned modules, environments, and third-party services.
  3. Harden access: enforce Two-Factor Authentication, SSO, Role-Based Access Controls, and IP allowlisting.
  4. Define data classifications and apply “minimum necessary” to fields, views, and reports.
  5. Establish data lifecycle controls: retention, export governance, and vetted destruction procedures.
  6. Train your workforce on acceptable use, PHI redaction, and incident reporting.
  7. Monitor continuously: audit logs, API usage, data exports, and anomalous access.
  8. Test incident response and breach notification playbooks at least annually.
  9. Vet integrations (marketing, telephony, forms) and ensure each has its own BAA if it touches PHI.
  10. Document everything: policies, procedures, configurations, and periodic compliance reviews.

Compliance Challenges and Considerations

CRMs are optimized for sales and service, not clinical documentation. Risks arise from free-text notes, email sync, and integrations that quietly copy PHI into marketing tools. Mobile access and bring-your-own-device practices add exposure if devices lack encryption and MDM controls.

Plan for downstream obligations beyond HIPAA, including state privacy laws, patient consent preferences, and messaging rules. Confirm data residency needs, exit/export options, and vendor support protocols that avoid PHI in tickets. Finally, ensure your governance keeps pace with org changes—new clinics, new vendors, and staff turnover.

Conclusion

In short, Insightly can participate in HIPAA-aligned workflows only when you have a signed BAA, configure robust security, and keep PHI to the minimum necessary. Treat the CRM as a support system, verify controls like encryption, Two-Factor Authentication, and Role-Based Access Controls, and sustain compliance with continuous monitoring and clear procedures.

FAQs

Does Insightly provide a HIPAA-compliant BAA?

Availability and terms can vary by product and plan. You must request and execute a BAA with Insightly before storing any PHI. Ensure the agreement explicitly covers all modules and subprocessors you will use and spells out encryption, breach notification, and data lifecycle obligations.

What security measures does Insightly use to protect PHI?

Expect enterprise-grade controls such as encryption in transit and at rest, Two-Factor Authentication, Role-Based Access Controls, SSO/SAML, audit logging, IP allowlisting, and data loss prevention options. Confirm which features are included in your edition, enable them for every user and integration, and verify settings through periodic access reviews.

Can Insightly Copilot be used with PHI data?

Only if your BAA explicitly includes Copilot and the vendor confirms HIPAA-eligible processing for that feature. Otherwise, do not put PHI in prompts or allow outputs to display PHI. Prefer de-identified data, restrict access by role, and require human review for any AI-assisted content.

How can healthcare organizations ensure HIPAA compliance using Insightly?

Execute a BAA, complete a targeted risk analysis, and configure security baselines (2FA, RBAC, SSO, logging). Limit PHI to the minimum necessary, enforce DLP on notes and exports, train staff, monitor continuously, test incident response, and document policies and reviews on a defined cadence.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles