Tool comparisons

Is Zapier or Make HIPAA compliant? What clinics should use instead

Flow Mesh · · 5 min read

Clinics run on repetitive admin: intake forms, appointment reminders, referral letters, billing follow-ups. Zapier and Make are the first tools most practice managers find when they want to automate that work, and the first question that follows is whether they are allowed to put patient information through them.

The short answer for US practices covered by HIPAA: no. Zapier says plainly that it is not HIPAA compliant and does not sign a Business Associate Agreement, and Make does not publish a BAA either. That does not mean a clinic cannot automate. It means you have to decide which workflows touch protected health information (PHI), keep those on platforms that will sign a BAA, and use general automation tools only for the work that never touches patient data.

This article explains the reasoning, not the law. Check with your compliance lead or healthcare lawyer before you put any workflow involving patient data live.

Why the BAA is the deciding question

Under HIPAA, a vendor that creates, receives, maintains or transmits PHI on your behalf is a business associate, and you need a signed Business Associate Agreement with it. The US Department of Health and Human Services guidance on cloud computing makes clear this applies to cloud services that process electronic PHI, even if the data is encrypted and the provider cannot read it. HHS also publishes general guidance on business associates.

An automation platform does exactly that: it receives the data from one app, holds it while the steps run, usually logs it, and sends it to the next app. Strong security certifications do not replace the BAA. They tell you a vendor is well run; they do not create the contractual obligations HIPAA requires.

Zapier's position

Zapier's own article, Is Zapier HIPAA compliant?, answers "No, Zapier isn't HIPAA compliant" and says you cannot use it to automate anything involving PHI because Zapier does not sign a BAA. The same page lists its SOC 2 Type II and SOC 3 reports and its GDPR and CCPA positions. Those matter for ordinary business data; they do not change the HIPAA answer.

Make's position

Make does not publish a BAA or a HIPAA program. Its public security materials focus on frameworks such as SOC 2 and ISO 27001, not HIPAA. When users asked on the Make community forum whether Make would sign a BAA, the moderator directed them to support, and a user reported that Make refused. Treat Make as unsuitable for PHI unless Make itself gives you a signed BAA in writing.

What about n8n?

n8n comes up because it can be self-hosted. The logic is different from Zapier and Make:

  • n8n Cloud is a hosted service, so the BAA question applies to n8n the company in the same way. Ask n8n directly and get the answer in writing before sending any PHI through it.
  • Self-hosted n8n is software you run yourself. There is no automation vendor holding your data, but the server does. You then need a BAA with whoever hosts that server (a major cloud provider, for example), plus the security work HIPAA's Security Rule expects: access controls, encryption, audit logs, backups, patching and a risk analysis.

Self-hosting moves the burden from a vendor contract to your own operations. For a 15 person clinic with no in-house IT, that is a real commitment, not a free workaround. Someone has to own the server, update it and review its logs every month.

Alternatives that can carry PHI

OptionFits whenWatch out for
Native integrations in your EHR or practice management systemThe vendor already connects to the tool you needCheck the vendor's BAA covers the connected service
Microsoft Power AutomateYou already use Microsoft 365 under Microsoft's BAAMicrosoft lists Power Automate cloud flows as in scope for its BAA; desktop flows need separate checking
Healthcare-focused automation platformsYou need many PHI workflows across toolsAsk for the signed BAA before the demo, not after
Self-hosted n8nYou have reliable IT supportHosting BAA, patching, logging and backups are now yours

Coverage lists change, so confirm what is in scope with each vendor at the time you sign. Every app in the chain needs a BAA too: the form tool, the email or SMS provider, the e-signature tool and any AI service you call.

What clinics can safely automate with Zapier or Make

General automation tools are still useful in a clinic for work that never touches patient data:

  • Staff onboarding and offboarding checklists.
  • Supplier invoices and purchase approvals.
  • Marketing tasks that do not involve patients' health information, after checking with your compliance lead what counts.
  • Internal reporting built from aggregated, de-identified numbers.
  • Team scheduling and internal notifications that do not name patients.

The hard part is keeping that line clean. A form that starts as "book a consultation" often grows a "reason for visit" field, and at that point the workflow is carrying health information. Review automations whenever someone adds a field.

A simple way to sort your workflows

  1. List every automation and every one you want. Include the ones staff built themselves.
  2. Mark each one: does it ever carry patient names, contact details linked to care, appointment details or clinical information? If in doubt, mark it yes.
  3. For each "yes", check every tool in the chain for a signed BAA. No BAA anywhere in the chain means the workflow needs a different design.
  4. Move or rebuild the PHI workflows onto covered tools, and keep Zapier or Make for the rest.
  5. Assign an owner who reviews the list when tools or forms change.

Outside the US, the rules differ (GDPR in Europe, the nLPD in Switzerland, provincial law in Canada), but the same sorting exercise applies: know where patient data goes and have the right contract with every processor. Our article on why automations break covers the ownership habits that keep this list accurate.

How Flow Mesh helps

Our fixed-fee stack audit (€1,500) maps every tool and automation in your clinic, flags where patient data flows, and gives each tool a verdict (keep, configure, consolidate or replace) with a written scope. Any build is quoted in writing after the audit and done inside your own accounts, under an NDA; a DPA is available on request. Compliance decisions stay with your compliance lead. See our work with healthcare clinics.

Key takeaways

  • Zapier says it is not HIPAA compliant and does not sign a BAA; Make publishes no BAA. Keep PHI out of both.
  • Security certifications do not replace a BAA for a vendor that handles PHI.
  • Self-hosted n8n shifts the obligations to your hosting provider and your own operations.
  • Native EHR integrations, BAA-covered Microsoft services and healthcare-focused platforms are the usual routes for PHI workflows.
  • Sort every workflow by whether it touches patient data, and check every tool in the chain.

More articles

See all articles →