A patient record reaching your CRM does not settle how your team may use it. As checked August 31, 2026, HubSpot lists its Epic app as a Beta for U.S.-based Enterprise customers, with real-time, one-way patient and appointment sync from Epic into HubSpot.
The useful question is not how much data you can move. It is which approved process the data should support. We would plan the first build around four steps: Map, Classify, Test, Monitor. This guide separates the documented integration scope from proposed workflows and the decisions your privacy, security and Epic teams still need to make.
If your organization uses Epic, start with the boundaries between its clinical system, patient-facing services and HubSpot. This article covers the CRM connection, not a replacement for your clinical workflows.
Two related Epic services illustrate why those boundaries matter:
Keep the CRM use case specific. An intake coordination requirement is not the same as clinical record exchange, and neither should be treated as blanket permission for marketing outreach.
The official app listing describes patients becoming HubSpot contacts and appointments linking to those contacts. This connection runs from Epic to HubSpot, not back into Epic. Custom field mappings have a separate Data Hub Starter requirement. Confirm your account’s complete subscription requirements before implementation.
Use this scope check when discussing the integration with your team:
| Item | Documented scope | Confirm before use |
|---|---|---|
| Patients | Patient demographic and contact data become HubSpot contacts. | Which fields belong in the approved CRM process? |
| Appointments | Appointment records sync and associate with contacts. | Which statuses and associations are available in your account? |
| Custom mappings | The listing specifies Data Hub Starter. | Are source and destination classifications appropriate? |
HubSpot’s Sensitive Data terms require appropriate identification of sensitive information and restrict processing to permitted data and covered services. Do not leave known sensitive fields unclassified to gain access to a feature. A product connection does not decide whether your intended use is permitted.
The following are proposed design questions, not preconfigured workflows or measured results. Evaluate them only for approved data, supported fields and the tools included in your account. Keep clinical decisions with the appropriate clinical systems and people.
Start with one operational audience, not a large library of campaigns. For each proposed segment, write down its purpose, data owner, permitted use and exclusion rules.
Test the audience with approved synthetic records first. Include missing dates, changed statuses and excluded records, and document expected membership before you inspect the result.
HubSpot’s Sensitive Data guide documents filter-based workflow enrollment and AND/OR branches, but excludes event enrollment based on sensitive-value changes. Do not treat those trigger types as interchangeable.
There is a documentation conflict to resolve before using sensitive tokens. The July 2 Sensitive Data guide excludes copying and token references in workflows, while HubSpot’s August 3 Edit records guide specifically allows Sensitive Data tokens in that action, but not Highly Sensitive Data. Confirm the exact action with HubSpot. The narrower Edit records statement is not evidence of support for sensitive personalization in marketing emails.
Define the decision a report should support before choosing its fields. We would separate integration health from operational outcomes, then evaluate whether the available data can answer each question. Treat the following as a proposed measurement plan, not dashboards supplied by the Epic app.
Include report, dashboard, export and sharing access in your test plan. Do not assume a restricted property alone proves every downstream view is safe. Keep this access review separate from whether the numbers are accurate.
For day-to-day work, map the minimum information each role needs. Review administrators, operators and reporting users separately, including what each role can view, change and share.
If intake forms are part of your proposed scope, first identify the precise form, fields, attachment route and authorized viewers. Confirm those surfaces against the current Sensitive Data documentation. Do not move an existing clinical intake form into HubSpot merely because contact sync is available.
HubSpot warns against sensitive information in Breeze prompts and restricts Sensitive Data property use. Keep patient details out of the inputs for any proposed AI automation test. Begin with approved synthetic examples and verify the intended tool’s scope.
HubSpot’s tool restrictions include chatbots, playbooks and sandboxes. Files-tool assets do not receive the additional Sensitive Data attachment protection; sharing a CRM attachment URL with another authenticated account user is also a separate access risk. Do not use either route as an assumed safe repository.
A field setting is not a way to redefine sensitive information. HubSpot’s identification requirement applies to the data itself. If your proposed workflow depends on treating a known sensitive value as ordinary CRM data, stop and redesign it with your organization’s privacy and security teams.
HHS explains that HIPAA generally requires written authorization for marketing uses or disclosures of protected health information, with limited exceptions. Have your organization’s qualified privacy or legal advisers determine the requirements for your specific communication. This guide is implementation planning, not legal or clinical advice.
For a first release, we would choose a narrow administrative use case with a defined owner, clear exclusions and an explicit acceptance test. Expand only after your team has verified the permitted use and the actual account behavior. A successful sync is the beginning of that review, not its conclusion.
Use this checklist to prepare a scope discussion, not as a substitute for the app’s account-specific setup instructions:
Start with your HubSpot account team and Epic administrator. Ask for the current enrollment and installation instructions, supported field mappings and any account-specific restrictions. We could not inspect the password-protected setup guide during this check, so this article does not claim that installation is self-service or that Beta places are available.
Bring your proposed use case, field inventory and unresolved questions to a scope discussion with us. We can discuss how CRM architecture, reporting and operator training fit together without treating a connector as a finished operating process. Contact Selworthy to discuss that scope.
Documentation checked August 31, 2026. Product availability and restrictions can change. The featured image is an illustration, not an actual patient record, HubSpot screen or documented customer result.