Are we sure Opsgenie is HIPAA compliant?

Are we sure Opsgenie is HIPAA compliant? | Paubox

Today we’ll research whether Opsgenie provides HIPAA compliant service or not.

WHY IT MATTERS

Organizations that fall under HIPAA regulations face hefty fines for using cloud software that isn’t HIPAA compliant.

THE BIG PICTURE

About Opsgenie

Opsgenie is a cloud-based incident management and alerting platform that helps organizations to manage and respond to IT incidents, infrastructure problems, and service disruptions. It allows teams to receive alerts from various sources such as monitoring tools, helpdesk software, and application performance management tools, and then quickly route those alerts to the right team members for resolution.

Overall, Opsgenie is designed to help teams improve their incident response processes, minimize downtime, and ensure business continuity.

Opsgenie is made by Atlassian.

Opsgenie and the business associate agreement

There’s a primary item to consider when it comes to Opsgenie and its ability to provide a HIPAA compliant service.

First, let’s start with a quick recap of terms. The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that protects the privacy of individuals’ personal health information, otherwise known as protected health information (PHI).

As we’ve previously discussed, HIPAA applies to covered entities, which includes healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.

business associate agreement (BAA) is a written contract between a covered entity and a business associate. It is required by law for HIPAA compliance. In the case of Opsgenie, the service would certainly fall into the category of business associate if it’s servicing customers that would store, process, or transmit PHI on its platform.

We checked the Atlassian site and found:

In a nutshell:

  • Atlassian will sign a BAA, but customers must be on an Enterprise plan and the BAA only applies to two of its products: Jira and Confluence.
  • “Currently, we’re able to sign BAAs for Jira Software and Confluence for customers with Enterprise plans.”

Are we sure Opsgenie is HIPAA compliant?

The BAA is a key component to HIPAA compliance between a covered entity and a business associate.

While Atlassian, the company that makes Opsgenie, will sign a BAA with customers, there are two important caveats:

  • Customers must enter an Enterprise plan
  • The BAA only applies to Jira and Confluence

Conclusion: Opsgenie is not covered by the Atlassian BAA and is therefore not HIPAA compliant.

About the author

Hoala Greevy

Founder CEO Paubox. Kayak fishing when I can.

Read more by Hoala Greevy

Get started with
end-to-end protection

Bolster your organization's security with state-of-the-art email encryption and inbound email security.

Highest rated HIPAA compliant email solution on G2

EmailEncryption BestMeetsRequirements MeetsRequirements
SecureEmailGateway MostImplementable Total
SecureEmailGateway Leader Leader
SecureEmailGateway EasiestToUse EaseOfUse
SecureEmailGateway EasiestAdmin EaseOfAdmin
SecureEmailGateway BestUsability Total
SecureEmailGateway BestResults Total
SecureEmailGateway BestRelationship Total
EmailEncryption UsersMostLikelyToRecommend Nps
EmailEncryption MomentumLeader Leader
SecureEmailGateway BestSupport Mid Market QualityOfSupport
EmailEncryption BestMeetsRequirements MeetsRequirements
SecureEmailGateway MostImplementable Total
SecureEmailGateway Leader Leader
SecureEmailGateway EasiestToUse EaseOfUse
SecureEmailGateway EasiestAdmin EaseOfAdmin
SecureEmailGateway BestUsability Total
SecureEmailGateway BestResults Total
SecureEmailGateway BestRelationship Total
EmailEncryption UsersMostLikelyToRecommend Nps
EmailEncryption MomentumLeader Leader
SecureEmailGateway BestSupport Mid Market QualityOfSupport