Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How should security teams handle PHI in Salesforce…
Cyber Security

How should security teams handle PHI in Salesforce to reduce HIPAA risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Cyber Security

Security teams should treat Salesforce as a system that can support, but does not automatically satisfy, HIPAA requirements. PHI should only be stored with explicit access controls, encryption, auditability, and a documented DLP process for detection, redaction, and blocking. The safest posture is to minimize PHI exposure in CRM workflows and continuously validate who can view, move, or export sensitive records.

Why This Matters for Security Teams

PHI inside Salesforce changes the risk profile from ordinary CRM governance to regulated data handling, because a record can be exposed through profiles, reports, integrations, exports, sandboxes, or automation with very little friction. The operational issue is not just where PHI sits, but where it can move. Security teams need a control model that covers access, monitoring, retention, and downstream sharing, not a one-time configuration check. Guidance from the NIST Cybersecurity Framework 2.0 is useful here because it emphasizes governance, protection, detection, response, and recovery as linked functions rather than isolated tasks.

The most common mistake is assuming a HIPAA-ready platform automatically creates HIPAA-compliant use. Salesforce can support a compliant program, but it does not remove the need for administrative, technical, and procedural safeguards. Security teams also need to distinguish between legitimate business access and broad operational convenience, because over-permissioned users, third-party apps, and email-based workflows often become the real leakage paths. In practice, many security teams encounter PHI exposure only after a report export, integration failure, or support escalation has already moved the data beyond the intended audience.

How It Works in Practice

Handling PHI safely in Salesforce starts with data minimization. If a workflow can function with a patient reference number, masked fields, or a tokenized identifier, that design is preferable to storing full PHI in a standard object. Where PHI must exist, access should be restricted by role, record-level controls, and field-level permissions, with logging enabled for review of reads, exports, and administrative actions. HIPAA expectations for auditability and access control are operationally aligned with broader identity and security practices described in NIST Cybersecurity Framework 2.0.

A practical control set usually includes:

  • Field-level security for PHI fields, not just object-level permissions.
  • Strong role design so support staff see only what they need for service delivery.
  • Encryption for data at rest, plus a review of whether additional field protection is needed for highly sensitive attributes.
  • Event logging and alerting for bulk export, mass updates, privilege changes, and unusual report access.
  • DLP rules that detect PHI patterns in notes, attachments, case comments, and outbound messages.
  • Integration review for apps, middleware, and APIs that may replicate PHI into less controlled systems.

Security teams should also review Salesforce automation carefully. Flow, Apex, and connected apps can bypass the intent of a manual workflow if they are not scoped correctly, so testing needs to include service accounts, delegated administration, and exception handling. Retention matters as well: PHI that is no longer required for operations should be deleted or archived under a documented policy, not left indefinitely in open case histories. These controls tend to break down when multiple business units use different field standards and external integrations replicate PHI into unmanaged downstream systems because ownership becomes fragmented.

Common Variations and Edge Cases

Tighter PHI controls often increase operational overhead, requiring organisations to balance privacy protection against support speed, reporting flexibility, and integration convenience. That tradeoff is especially visible in healthcare sales, patient services, benefits administration, and third-party service desks where teams want broad visibility to work cases quickly. Current guidance suggests that if broad access is needed, it should be time-bound, reviewed, and limited to the minimum context required for the task.

Edge cases usually involve data that does not look like PHI at first glance. Case notes, uploaded documents, free-text fields, and email threads often contain more sensitive material than structured fields do. Another common issue is sandbox copying, where production records are replicated into environments with weaker governance. Best practice is evolving here, but de-identification, masked refreshes, and strict test-data rules are the safer pattern. Organisations operating under vendor, payer, or claims workflows should also confirm whether their Salesforce deployment, backup tooling, and support arrangements are covered by the right contractual and security controls, because compliance responsibility does not stop at the application boundary.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while PCI DSS v4.0, DORA and NIS2 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC, PR.AC, DE.CMPHI handling needs governance, access control, and monitoring across the CRM.
NIST SP 800-63Strong identity proofing and authentication reduce unauthorized access to PHI.
PCI DSS v4.0Req. 3, Req. 7, Req. 10Not a HIPAA standard, but it mirrors disciplined controls for sensitive data handling.
DORAThird-party and resilience controls matter when Salesforce integrations move regulated data.
NIS2Operational security governance supports incident handling for regulated data exposure.

Use strong authentication and lifecycle identity controls for all users who can reach PHI.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org