HubSpot has opened a private beta for something healthcare operations teams have been asking about for years: a native app connection to Epic, the electronic medical record system that most large US health systems run on. Records sync from Epic directly into HubSpot, where they map automatically to contacts, appointments, and sensitive data properties in real time. If you work in a hospital, health system, clinic group, or any organization that touches patient data and also runs HubSpot, this is the most significant healthcare release HubSpot has shipped since it added Sensitive Data support.

Here is what the integration is, some background on why Epic is the system that matters, and a detailed look at what you can actually build once the data lands in HubSpot, including the constraints that will shape your first build.

First, a quick primer on Epic

If you have received care at a major US hospital in the last decade, your chart almost certainly lives in Epic. Judy Faulkner founded the company in 1979 in a Madison, Wisconsin basement with roughly $70,000 in startup capital. It is now headquartered in Verona, Wisconsin, is still privately held, and by its own count more than 325 million patients have an electronic record in its system.

The market position is what makes this integration matter. According to KLAS Research's 2026 acute care EHR market share report, Epic holds 43.7% of the acute care EHR market, covering 43.7% of hospitals and 56.9% of inpatient beds. In 2025 Epic was the only vendor selected by health systems with more than 10 hospitals, and it added 77 hospitals and 18,679 beds while competitors lost ground. If you are integrating with one EMR, Epic is the one that reaches the most patients.

Two Epic products are worth knowing by name because patients and staff interact with them constantly:

  • MyChart is Epic's patient portal, the most widely used in the US. It is where patients view results, message their care team, and manage appointments.
  • Care Everywhere is Epic's record-sharing network between organizations that run Epic, which is a big part of why health systems consolidate onto it.

Epic is also, historically, a difficult system to get data out of for anything that is not clinical. It is the clinical system of record, it is tightly governed, and non-clinical teams who wanted patient data in a CRM have typically needed middleware, an HL7 or FHIR project, an integration vendor, or a series of manual exports. That is the friction this app removes.

What the HubSpot Epic app actually does

The Epic app provides a real-time, one-way sync from Epic into HubSpot. Epic remains the source of truth. Data is managed in Epic and read in HubSpot. Nothing your marketing or service team does in HubSpot writes back into the chart, which is exactly the boundary most clinical governance committees will want to see.

What syncs today:

What syncs Direction Where it lands in HubSpot
Contacts Epic to HubSpot, real time Contact records, mapped automatically
Appointments Epic to HubSpot, real time Appointment data mapped to the right places
Health data, including ePHI Epic to HubSpot, real time Sensitive Data properties
GDPR special category data Epic to HubSpot, real time Sensitive Data properties

The sensitive data handling is the part worth pausing on. The app is built to carry special categories of data under GDPR, such as race or religion, and health data including electronic protected health information (ePHI), for both HIPAA-covered and non-covered entities. HubSpot already supported storing sensitive data; the Epic app closes the remaining gap of getting health records in from the system most customers actually use. HubSpot has said more data types are under consideration and coming soon, so treat the current scope as a starting point rather than the finished product.

What this lets you do inside HubSpot

HubSpot names three capabilities once your Epic data is in the CRM: list segmentation, automation, and reporting. That undersells it in one direction and oversells it in another, so here is the detailed version, tool by tool, including where HubSpot's Sensitive Data rules will stop you.

Segmentation and lists

Because the sync is real time rather than a nightly file drop, segments built on Epic data stay current on their own. Practical segments a health system can maintain without anyone touching a spreadsheet:

  • Patients with an upcoming appointment in the next 7, 14, or 30 days, split by service line, department, or appointment type.
  • Patients whose most recent visit is older than 12 months, for recall and annual-visit campaigns.
  • New patients versus established patients, based on first appointment date, so onboarding communication differs from routine communication.
  • Patients whose appointment status changed to cancelled or no-show, feeding a rebooking queue.
  • Geographic and facility-level segments for location-specific service announcements, closures, or new provider introductions.
  • Suppression lists, which matter as much as targeting lists. If certain patients or conditions must never receive marketing, the segment that excludes them is now maintainable from real data instead of memory.

One note on mechanics: HubSpot documents Sensitive Data properties working with when a filter criteria is met enrollment triggers, which is the same criteria engine list filters use. Confirm behavior for your specific properties during the beta rather than assuming parity.

Workflow automation

This is where the integration earns its keep, and also where the guardrails are tightest. HubSpot explicitly supports Sensitive Data properties in when a filter criteria is met enrollment triggers and in AND/OR branches. That is enough to build real operational automation:

  • No-show and cancellation recovery. Enrollment fires when appointment status changes, a task is created for the scheduling team, the patient is routed to the right coordinator, and a follow-up branch checks whether a new appointment ever appeared.
  • Pre-visit preparation sequences. Arrival instructions, parking and check-in details, fasting or prep requirements by appointment type, and forms to complete in advance.
  • Post-visit follow-up. Satisfaction surveys, care instructions, billing questions routed to the right queue, and escalation when a survey score falls below threshold.
  • Internal routing and SLAs. Auto-create and assign service tickets, set priority by appointment type or urgency, notify the right team, and escalate when a ticket ages past its SLA.
  • Referral and provider relations. Trigger provider relations tasks off referral volume patterns, keep referring practice records current, and flag practices whose volume drops.
  • Data hygiene. Branch on missing or conflicting fields and route them to the right owner rather than letting bad records quietly accumulate.

Three workflow limitations to design around, per HubSpot's documentation: copy property actions cannot reference Sensitive Data properties, personalization tokens cannot use or reference them, and when an event occurs enrollment triggers based on changes to Sensitive Data property values are not supported. HubSpot also recommends restricting access to the workflows tool itself once sensitive properties are in play, since a workflow builder can otherwise infer values through branch logic.

Reporting and dashboards

Reporting is the quietly transformative part, because it closes a loop most health systems have never been able to close in one system:

  • Full-funnel service line reporting. First website visit or form submission through to a scheduled appointment, in one report, instead of manually reconciling Epic scheduling reports against marketing analytics.
  • Campaign and channel attribution to actual appointments rather than to form fills, which changes how you defend a marketing budget.
  • Access center and intake operations dashboards. Volume, response time, ticket aging, and rebooking rate by team and by location.
  • No-show and cancellation analysis by appointment type, provider, day of week, or lead time, which is the input to fixing the underlying scheduling problem.
  • Referring practice performance using companies and deals alongside synced appointment volume.
  • Cohort and recency analysis for retention: how many patients from a given intake cohort returned within 12 months.

Who can see these reports depends entirely on the field-level permissions you set on the underlying properties, so design permissions before you build dashboards, not after someone runs an access review.

The record view and day-to-day team work

Beyond lists and reports, the everyday value is a single record. The access center, referral coordinators, patient experience team, and service reps see Epic-sourced fields alongside the emails, calls, forms, notes, and tickets that already live in HubSpot. Supporting details that matter operationally:

  • Field-level permissions. Super Admins can restrict view and edit access on each Sensitive Data property to specific users and teams. HubSpot strongly recommends this rather than treating it as optional.
  • Audit logging. Super Admins can review user actions on Sensitive Data property values in the audit log.
  • Highly Sensitive Data requires click-to-decrypt before a permitted user can view or edit the value, which gives you a stronger tier for the most restricted fields.
  • Encrypted attachments. Files uploaded to records, to notes, via one-to-one email, through the mobile app, via file-type properties, through form submissions, or via import get an additional layer of encryption once Sensitive Data is on. Two caveats: only files uploaded after you enable the setting are protected, and files hosted in the Files tool do not get the additional protection, so sensitive documents should never live there.
  • Notification previews are hidden by default so a mention or task notification does not leak a value into someone's inbox. A Super Admin can turn previews back on, and usually should not.
  • HubSpot employees cannot view Sensitive Data property values even when support access is enabled, and cannot access protected attachments.

Forms and intake

HubSpot forms and non-HubSpot forms can both collect sensitive information into Sensitive Data properties, encrypted on the way into the CRM. That makes pre-visit questionnaires, intake forms, and document uploads a legitimate HubSpot workflow rather than something you route around. Only users with the right permissions can see those submission values and files, and submission notifications respect the same permissions. Notably, forms are one of the few places Highly Sensitive Data is supported.

Breeze and AI

Breeze Assistant works in accounts with Sensitive Data turned on, but Sensitive Data property values are deliberately excluded from Breeze to prevent exposure. Accounts with Sensitive Data enabled are also automatically opted out of HubSpot AI model training and cannot opt back in while it is on. So plan for Breeze to help with content and general CRM work, not to summarize PHI fields. And keep sensitive information out of prompts.

The support matrix worth printing out

HubSpot documents specific tools where Sensitive Data does and does not work. This table is the single most useful thing to have in front of you when scoping a build:

Tool or capability Sensitive Data status
Workflow enrollment on filter criteria is met, AND/OR branches Supported
HubSpot forms and non-HubSpot forms, including file uploads Supported, including Highly Sensitive
Record attachments, notes, one-to-one email, mobile app, import Supported, encrypted
Data sync field mappings with data sync apps Supported, can be bi-directional
Field-level permissions and audit logging Supported, strongly recommended
Personalization tokens Not supported
Chatbots, playbooks, sandboxes Not supported
Workflow copy property actions referencing sensitive properties Not supported
When an event occurs triggers on sensitive value changes Not supported
Breeze use of Sensitive Data property values Restricted, and AI training opt-out is forced
Source account for multi-account data mirroring Not allowed with Sensitive Data on
Migrating data centers after indicating HIPAA data storage Not allowed
Snowflake Data Share with HIPAA-protected data AWS US_EAST_1 and AWS EU_CENTRAL_1 only
Files tool storage No additional protection, do not store sensitive files there

What that matrix actually means for your first build

Read the personalization token line again, because it is the one that reshapes plans. If a field is a Sensitive Data property, you cannot drop it into an email as a personalization token. So an email that says "your cardiology appointment on Tuesday at 2:15" only works if those specific appointment fields are not flagged sensitive. That is a deliberate decision to make with your compliance team, and it is the single most important question to put to HubSpot during the beta, since the app maps data automatically and property configuration is effectively permanent once created.

The practical consequence: the highest-value early builds are internal operations and reporting, where sensitive fields drive segmentation, routing, branching, tasks, and dashboards without ever appearing in outbound content. Patient-facing personalized messaging is achievable, but it depends on a carefully drawn line between which Epic fields are sensitive and which are not, and on the consent and HIPAA marketing rules that govern the message regardless.

Which leads to the boundary worth stating plainly. This is not a clinical tool and it does not replace anything in Epic. It is one-way, so HubSpot cannot update the chart. And having ePHI in HubSpot does not by itself give you permission to market to a patient. The integration solves the data plumbing problem. Governance is still your job.

What to have in place before you apply

A few prerequisites and planning notes, based on how HubSpot's Sensitive Data functionality works today:

  1. You need an Enterprise subscription. Sensitive Data functionality requires HubSpot Enterprise. If you are on Professional, that is the first conversation.
  2. A Super Admin has to turn Sensitive Data on. To store HIPAA-covered data you must enable both the Health/Medical Data setting and the setting confirming you are a HIPAA-covered entity or business associate. Identifying yourself that way is how HubSpot tracks application of the Business Associate Agreement.
  3. Plan your property architecture before you build it. This one bites people. Once a property is created, its Sensitive Data setting cannot be changed. A sensitive property cannot be made non-sensitive later, and a non-sensitive property cannot be converted to sensitive. Default properties also cannot be converted to sensitive ones. Decide what is Sensitive versus Highly Sensitive, and which properties carry PHI, before you start creating fields.
  4. Check your data center and downstream tooling. Once you indicate HIPAA data storage you cannot migrate to another regional data center, and Snowflake Data Share support narrows to two regions. If a data warehouse sits downstream of HubSpot, confirm the path before you flip the setting.
  5. Decide who can see what. Field-level permissions, user roles, workflow tool access, and audit log review should be designed deliberately, not discovered after the first access review.
  6. Bring your Epic and IT teams in early. Any connection to Epic goes through your organization's own governance and Epic-side approvals. A marketing team cannot stand this up alone, and should not try to.
  7. Confirm the specifics with HubSpot. This is a private beta, and beta scope, covered services, and terms can change. Verify the current details for your account rather than relying on a summary, including this one.

How to get into the beta

The Epic app is in private beta with limited spots. HubSpot is accepting applications through an interest form linked from the Epic app entry in the Product Updates section of your HubSpot portal. If you are a healthcare organization running both Epic and HubSpot Enterprise, applying early is worth it, both for the access and for the chance to shape which data types get added next.

Where Selworthy fits

Integrations like this succeed or fail on the unglamorous parts: property architecture you cannot undo, field-level permissions, consent handling, and workflows that reflect how your access, marketing, and service teams actually operate. That is the work we do inside HubSpot every day, and we start by mapping the current state before anything gets built. If you are evaluating whether the Epic app fits your organization, or want help preparing your HubSpot instance so you are ready when access comes through, get in touch.

Sources: HubSpot Product Updates (Epic app for medical records, private beta, updated July 29, 2026); KLAS Research 2026 acute care EHR market share report; HubSpot Knowledge Base, "Store Sensitive Data in HubSpot" and "Understand how Sensitive Data is used in HubSpot tools" (last updated July 2, 2026).