Slack is a workplace collaboration platform that helps teams communicate through channels, direct messages, file sharing, integrations, huddles, workflows, and AI-supported productivity tools.
With Slack, organizations can centralize team communication, connect third-party apps, and manage work across departments from one platform.
Is Slack HIPAA compliant? Yes, Slack is HIPAA compliant.
What changed this year?
As of July 2026, we did not identify any publicly disclosed changes to Slack’s HIPAA related policies or BAA terms.
Slack’s current HIPAA documentation still states that covered entities or business associates must use an Enterprise subscription, execute a business associate agreement, and follow Slack’s HIPAA requirements before Slack can support HIPAA regulated use.
Will Slack sign a business associate agreement (BAA)?
Yes, Slack will sign a BAA, which can be reviewed by contacting Slack for more information.
Slack states, “When a covered entity or business associate has executed a business associate agreement with Slack and is using Enterprise Grid to transmit, upload, or communicate about PHI, Slack is deemed a business associate.”
What does the Slack BAA cover?
The Slack BAA covers certain HIPAA regulated use of Slack Enterprise Grid. Slack states, “If you’re a covered entity or business associate subject to HIPAA, Slack can be configured to support PHI within uploaded files and message content.”
Their BAA covers:
- PHI in message content
- PHI in uploaded files
- Direct, group, and channel messaging when used on Enterprise Grid
- HIPAA regulated collaboration when the customer has signed a BAA and follows Slack’s requirements
- Customer-side monitoring through Slack DLP or Slack’s Discovery APIs
Slack’s public guidance on HIPAA compliant collaboration with Slack also says that teams using Enterprise Grid can share PHI “within direct, group and channel messaging and in file uploads” when Slack is configured and used according to Slack’s HIPAA requirements.
What does the Slack BAA exclude?
Slack’s HIPAA coverage is not unlimited. It does not allow healthcare organizations to use Slack for patient-facing communication, and it does not turn Slack into a system of record for health information.
Slack says, “You may not use Slack to communicate with patients, subscription members or their families or employers.” It also states, “Slack does not maintain the designated record set and should not be the system of record for your health information.”
Slack also excludes PHI from features outside messages and files. Its HIPAA documentation states, “Excluding messages and files, members of your organisation may not include PHI when using other Slack features.”
Third-party apps are another limitation. Slack says it “does not have a business associate agreement with any third-party application providers, including those in the Slack Marketplace,” meaning healthcare organizations must assess whether a separate BAA is needed before enabling any app that may access PHI.
Slack also notes that HIPAA compliant organizations cannot send emails to Slack.
Conclusion
Slack may be HIPAA compliant, but only for enterprise customers that execute a BAA and configure Slack according to Slack’s HIPAA requirements.
Slack is not HIPAA compliant by default, and its HIPAA support excludes patient-facing communication, system-of-record use, third-party apps without separate review, and PHI use outside message content and file uploads.
See also: HIPAA Compliant Email: The Definitive Guide
FAQs
What is a business associate agreement?
A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.
What is HIPAA?
HIPAA sets national standards for protecting the privacy and security of certain health information.
HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.
Who does HIPAA apply to?
HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.
