HIPAA and Your Medicare CRM: The Questions to Actually Ask

Published August 19, 2026

If you sell Medicare, you handle protected health information every working day — diagnoses, medications, providers. Most agents assume their CRM handles the HIPAA side. Here is how to check rather than assume.

What you are actually holding

A Medicare client record is not a sales contact. It contains, at minimum, the medications someone takes, the doctors they see, and frequently enough to infer what is wrong with them. Under HIPAA that is protected health information, and as a business associate handling it you carry obligations that do not disappear because you are a one-person agency.

The practical risk is not usually a hacker. It is a laptop in a car, a spreadsheet emailed to a personal address, a shared password, or a former assistant who still has access.

Five questions to ask your CRM vendor

1. Will you sign a Business Associate Agreement?

This is the first question and it is disqualifying. If a vendor storing PHI on your behalf will not sign a BAA, the conversation is over. Ask for it in writing before you migrate anything.

2. Which certifications do you actually hold, and who audits them?

“HIPAA compliant” is a claim anyone can print on a website. What you want are named attestations with an auditor behind them — SOC 2 Type 2 in particular, because Type 2 tests whether the controls actually operated over a period rather than existed on paper on one day.

Ask for the list. A vendor that takes this seriously will have a compliance page; ours is the Trust Center.

3. Is data encrypted at rest as well as in transit?

Nearly everyone encrypts in transit — that is just HTTPS. At rest is the one worth confirming, because that is what protects you when the failure is physical or internal.

4. What does access control look like?

Specifically: can you enforce multi-factor authentication, can you set permissions so a downline agent sees only their own book, and can you revoke access immediately when someone leaves? The last one is the one that catches agencies out.

5. What is the audit trail?

If someone asks who viewed a client record and when, can the system tell you? For a small agency this feels like overkill right up until the day you need it.

The questions to ask yourself

Vendor compliance does not make you compliant. The gaps are usually on the agent’s side:

  • Where does client data live outside the CRM? Spreadsheets on a desktop, PDFs in an email inbox, photos of forms on a phone. Every copy is a separate exposure and none of them are covered by your vendor’s certifications.
  • Who has access, and is that list current? Include former staff, VAs, and anyone who has ever used your login.
  • How do you send documents to clients? An unencrypted email attachment containing a medication list is a disclosure.
  • What happens if a device is lost? If the answer involves data stored locally rather than accessed through a browser, that is worth changing.
  • How long do you keep records, and where? Retention obligations do not end when a client leaves.

Why the platform underneath matters

An independent agency cannot fund an enterprise security programme — penetration testing, continuous monitoring, formal incident response, third-party audits. Nobody expects it to.

What you can do is put your data somewhere that already funds one. HowardCRM runs on the Salesforce platform, which means it inherits Salesforce’s security posture: bank-level encryption, multi-factor authentication, and a compliance programme covering HIPAA and SOC 2 Type 2 among a long list of others. That is not marketing language on our part; it is the reason the product was built on Salesforce rather than from scratch.

The practical version: the security question becomes “have I configured this properly” rather than “is this safe at all”.

A short self-audit

  • Do you have a signed BAA with every vendor touching client data?
  • Is MFA on for every user, without exception?
  • Is there any client PHI in a spreadsheet, an inbox or a phone right now?
  • Could you produce a list of everyone with access in five minutes?
  • Do you know what you would do in the first hour after a breach?

Most agents fail at least two of these. It is worth fixing the ones you fail before AEP, not during it.

See how HowardCRM handles this

Built on Salesforce, HIPAA and SOC 2 Type 2, with your book of business in one place instead of five. Read the full certification list on the Trust Center, or ask us the awkward questions directly.

Read the Trust Center
Book a walkthrough

This article is general guidance, not legal advice. Confirm your own obligations with a qualified compliance professional.

← All Medicare agent resources