The Three Consents Healthcare Companies Have To Track In HubSpot
A patient says yes to texts from a sales rep. Two weeks later, a workflow texts them about a prescription refill. Same person, same number, same platform. Completely different permission, and they never gave it.
If you run HubSpot at a healthcare or healthcare-adjacent company, you already know the shape of this problem. Telehealth, benefits platforms, TPAs, multi-location provider groups, home health, digital health vendors, life sciences services. Different businesses, same structural issue: the CRM is holding permissions that answer to three different bodies of law, and it usually stores them in one field.
Here's how the three break down, and what we find when nobody has separated them.
Consent one, marketing
Marketing consent is permission to promote something. Offers, product information, campaign sends, anything encouraging a purchase.
Under HIPAA, using PHI for marketing requires written authorization, with narrow exceptions. Not everything that feels like outreach counts. Refill reminders, care coordination, and treatment communications generally fall outside the marketing definition. A note that a follow-up appointment is due isn't marketing. An email promoting an elective procedure to patients with a specific diagnosis on file almost certainly is.
Then there's a second layer with nothing to do with HIPAA. Texting or calling anyone triggers TCPA and carrier obligations regardless of whether PHI is involved. A HIPAA authorization does not get you a compliant text program. Two stacks, both required, neither covering the other.
Consent two, clinical
Treatment consent is a different thing entirely, and it mostly belongs in the clinical system.
But the CRM needs to know it happened, because that fact changes what the CRM is allowed to do. Before consent, a prospect. After consent, a patient with a record governed by different rules.
This is the architectural line, and it's where healthcare portals go wrong most often. Blur it and you get marketing automation firing at patients.
So the CRM holds the flag. Not the protocol, not the diagnosis, not the treatment plan.
Consent three, recording
If reps are on the phone converting, calls get recorded.
That's a third permission from a third source of law, the federal wiretap statute plus whatever the caller's and the patient's states require. It has nothing to do with HIPAA or the TCPA, and it's the one teams most often don't track at all.
What separating them looks like
On a Salesforce to HubSpot migration for a direct-to-consumer telehealth company, we built this before a single record moved.
Three separate property sets. Not three checkboxes on one object. Each set carries the consent type, the date, and who captured it, all grouped under Consent and Compliance so the whole picture sits on one screen.
That grouping is the point. When someone asks what a given patient agreed to and when, it's answerable from the record, without reconstructing anything from form submissions and call notes.
The rest of the build followed the same logic. Two deal pipelines, onboarding and medication orders. Custom objects for Pharmacies, Providers, and Shipments. Lifecycle stages rebuilt from scratch instead of inherited. Protocol and treatment properties pulled out of the CRM entirely, because clinical logic living in two systems gives you two answers to the same question.
The 10DLC rejection proved why it matters
Their SMS registration came back denied, which stops texting cold.
Three causes. Implied consent language where explicit was required. A contact-preference field ambiguous enough that it didn't prove anything. And a privacy policy missing the carrier data-sharing carve-out.
None of those were HubSpot problems. They were consent problems sitting in copy and policy, and they blocked a platform capability anyway. That's the pattern in regulated work. More on what carriers actually flag.
What we find in portals that grew into this
Healthcare companies rarely buy a CRM for this. They grow into one.
We audited the HubSpot portal of a healthcare benefits company that had started with marketing software. By the time we opened it, it was running member acquisition, care guide routing, telephony logging, clinical treatment records, consent tracking, and partner attribution.
34 objects, six of them custom. Nineteen connected apps. 143 workflows, 63 of which hadn't fired in months. 491 properties on contacts alone.
The largest custom object wasn't a marketing object. It was clinical treatment data, nearly 48,000 records, inside a system most of the team still thought of as an email tool.
And nobody could say who owned the consent logic. Seven people could build workflows. None of them met.
Check your own portal
Four questions. If you can't answer one of them in under a minute, that's the thing to fix first.
Can more than three people build workflows, and do any of them meet?
Is PHI sitting in standard properties rather than sensitive ones? On Marketing Hub Professional the answer is yes by default, because the Sensitive Data setting isn't available below Enterprise.
Can you tell what fires when consent is signed?
Do your CRM, your clinical system, and your revenue cycle agree on whether care was actually delivered? When they don't, nobody can answer a simple question about a member.
The principle
Ownership before optimization.
Most partners open a messy healthcare portal and start deleting workflows. We don't. You can't clean a system you can't name, and 63 dormant workflows are a symptom rather than a cause.
Consent isn't a field. It's a set of separate promises with separate legal footings and separate expiration dates, and the CRM is the only place they can all be seen at once. Build for that on day one and the platform works. Bolt it on later and you're rebuilding, usually under a deadline, usually after something already got blocked.
Resources
HHS: Marketing guidance. What counts as marketing under HIPAA, and what doesn't.
eCFR: 45 CFR 164.508. The authorization requirement in full.
Cornell LII: 18 U.S.C. § 2511. The federal wiretap statute behind recording consent.
Reporters Committee for Freedom of the Press. State-by-state recording consent.
HubSpot: Store Sensitive Data. Where consent properties should live.
General information, not legal advice. Your counsel gets the final word on authorization language.