Published August 19, 2026
If you sell Medicare, you handle protected health information every working day — diagnoses, medications, providers. Most agents assume their CRM handles the HIPAA side. Here is how to check rather than assume.
A Medicare client record is not a sales contact. It contains, at minimum, the medications someone takes, the doctors they see, and frequently enough to infer what is wrong with them. Under HIPAA that is protected health information, and as a business associate handling it you carry obligations that do not disappear because you are a one-person agency.
The practical risk is not usually a hacker. It is a laptop in a car, a spreadsheet emailed to a personal address, a shared password, or a former assistant who still has access.
This is the first question and it is disqualifying. If a vendor storing PHI on your behalf will not sign a BAA, the conversation is over. Ask for it in writing before you migrate anything.
“HIPAA compliant” is a claim anyone can print on a website. What you want are named attestations with an auditor behind them — SOC 2 Type 2 in particular, because Type 2 tests whether the controls actually operated over a period rather than existed on paper on one day.
Ask for the list. A vendor that takes this seriously will have a compliance page; ours is the Trust Center.
Nearly everyone encrypts in transit — that is just HTTPS. At rest is the one worth confirming, because that is what protects you when the failure is physical or internal.
Specifically: can you enforce multi-factor authentication, can you set permissions so a downline agent sees only their own book, and can you revoke access immediately when someone leaves? The last one is the one that catches agencies out.
If someone asks who viewed a client record and when, can the system tell you? For a small agency this feels like overkill right up until the day you need it.
Vendor compliance does not make you compliant. The gaps are usually on the agent’s side:
An independent agency cannot fund an enterprise security programme — penetration testing, continuous monitoring, formal incident response, third-party audits. Nobody expects it to.
What you can do is put your data somewhere that already funds one. HowardCRM runs on the Salesforce platform, which means it inherits Salesforce’s security posture: bank-level encryption, multi-factor authentication, and a compliance programme covering HIPAA and SOC 2 Type 2 among a long list of others. That is not marketing language on our part; it is the reason the product was built on Salesforce rather than from scratch.
The practical version: the security question becomes “have I configured this properly” rather than “is this safe at all”.
Most agents fail at least two of these. It is worth fixing the ones you fail before AEP, not during it.
Built on Salesforce, HIPAA and SOC 2 Type 2, with your book of business in one place instead of five. Read the full certification list on the Trust Center, or ask us the awkward questions directly.
This article is general guidance, not legal advice. Confirm your own obligations with a qualified compliance professional.
All of it lives on the resources page.