Healthcare
Seedly CRM for Healthcare: What HIPAA Mode Does (and Doesn't)
One switch enforces two-factor login, six-year audit logs, idle timeouts and BAA-aware integrations. Here's exactly what Seedly's HIPAA mode covers and where your responsibility starts.
Clinics, med spas, dental practices and therapists run on appointment reminders and follow-ups, which makes them ideal CRM customers. They’re also among the most cautious buyers you’ll meet. Seedly has a dedicated mode for them, and its documentation is unusually honest about the limits.
One switch, agency-wide
HIPAA mode lives in Settings → Compliance. Only the agency owner can switch it on, and only after turning on two-factor authentication for themselves. It applies to every sub-account.
What it does
- Requires two-factor authentication for every member
- Keeps audit logs for six years instead of one, and keeps that retention for six years even if the mode is later turned off
- Logs record views, not just edits
- Leaves patient details out of notifications that leave the app
- Signs out idle users after 15 minutes by default, adjustable from 5 to 60
- Gates integrations by vendor:
- vendors that can never sign a BAA (ad conversion uploads, Slack, product analytics, Zapier) are switched off
- vendors that offer a BAA are allowed once you record that you have one
- email providers that won’t sign a BAA (Postmark, SendGrid) block HIPAA mode from being turned on while they’re connected
Once on, it can’t be switched off from inside the app. Turning it off takes a server-side command, which is written to the audit log. That’s the right design. A compliance setting a staff member can toggle in a hurry isn’t much of one.
What it doesn’t do
Seedly’s own docs say this plainly, and you should take it seriously:
- It doesn’t sign BAAs or check that they exist. The checklist records what you tell it.
- It doesn’t cover your hosting stack (Convex, Vercel, Sentry). Check whether each offers a BAA on your plan.
- It doesn’t redact what staff write. A text that includes a diagnosis goes out as written.
- Contact records and messages aren’t encrypted by the app itself. Encryption at rest is your database host’s job. The app does encrypt provider credentials and tokens.
Why ownership matters more here
On a hosted CRM, patient data lives on the vendor’s infrastructure and you rely on their BAA chain. With Seedly, data lives in your database account, email goes through your AWS account, and you decide which vendors touch it. You can name every vendor that touches patient data, and the audit trail sits in your own database.
Not legal advice. Use HIPAA mode alongside a compliance adviser, not instead of one. Seedly says the same.
See everything else Seedly includes →
Questions people ask
Is Seedly CRM HIPAA compliant?
No software makes you HIPAA compliant by itself. Seedly CRM includes a HIPAA mode that enforces two-factor authentication, extends audit log retention to six years, logs record views, strips patient details from outbound notifications, signs idle users out and blocks integrations that cannot sign a Business Associate Agreement. Your BAAs, risk assessment, policies and training remain your responsibility.
Which email provider works with Seedly's HIPAA mode?
Amazon SES, through your own AWS account. Postmark and SendGrid will not sign a BAA, so HIPAA mode cannot be turned on while they are connected.
Keep reading
- 01Release notesSeedly CRM 5.9: What's New, and Why the Pace MattersAmazon SES, HIPAA mode, a Google Local Services lead assistant and a security overhaul in 5.9, on top of 18 releases in September alone. What changed, why it matters and why now is the time to buy.
- 02AlternativesGoHighLevel Alternatives in 2026: Why Ownership Beats Another SubscriptionMost GoHighLevel alternatives are just cheaper subscriptions. Here's how the three kinds of alternative compare, and why buying the software outright is the one that changes the economics.
- 03MigrationMoving From GoHighLevel to Seedly CRM: A Practical ChecklistExport, clean, import, rebuild, cut over. A step-by-step plan for moving an agency off GoHighLevel and onto Seedly CRM without losing contacts or clients.