HIPAA · Docs and wiki
Is Notion HIPAA compliant?
Conditional
Notion supports HIPAA on the Enterprise plan only. HIPAA compliance is free of charge at that tier, but it must be switched on explicitly — accepting the BAA in workspace settings — and Beta Services stay outside the agreement.
- Which plans the BAA covers
- Enterprise plan only. Activated in Settings → Workspace settings → HIPAA compliance → Activate, where the signed BAA is shown before acceptance.
Scope
What the BAA does and does not cover.
Covered
- The Notion Service as configured under the HIPAA Product Configuration Guide, once the BAA is accepted on an Enterprise workspace
Not covered
- Every plan below Enterprise
- Beta Services, which Notion states may not be used to process PHI
- Any usage that departs from Notion's HIPAA Product Configuration Guide
Your side of the agreement
A signed BAA is not a configured system.
Signing shifts liability; it does not change a setting. These are the steps that remain yours once Notion is in scope.
- 1Confirm the workspace is on Enterprise, then activate HIPAA compliance in workspace settings — it is off by default
- 2Follow the HIPAA Product Configuration Guide rather than assuming defaults are compliant
- 3Keep Beta Services disabled for workspaces that hold PHI
- 4Review guest and external access to PHI-bearing pages
Evidence
What an auditor will actually ask for.
Every item below is evidence someone has to produce, date and re-produce at the next audit. Screenata's agent collects these on a schedule instead.
- Screenshot of the workspace HIPAA compliance status showing it activated, with the acceptance date
- The signed BAA retrieved from workspace settings
- Member, guest and external-sharing reports for PHI-bearing spaces
- Configuration evidence mapped to the HIPAA Product Configuration Guide
See how Screenata handles this on HIPAA programs, or read what healthcare SaaS needs beyond SOC 2.
Sources
Verified against vendor documentation on 2026-08-08. BAA terms change — re-check before relying on this.