HIPAA · Team chat
Is Slack HIPAA compliant?
Conditional
Slack supports HIPAA only on Enterprise Grid with a signed BAA, and even then PHI is permitted only in messages and uploaded files — not in other Slack features.
- Which plans the BAA covers
- Enterprise Grid only. Slack's documentation states you must be on a Slack Enterprise plan to execute a BAA.
Scope
What the BAA does and does not cover.
Covered
- Messages and uploaded files, when a BAA is executed and Enterprise Grid is in use
Not covered
- Slack features other than messages and file uploads — Slack states members may not include PHI when using them
- Email-to-Slack, which Slack says is not possible on HIPAA-compliant organizations
- Direct communication with patients, plan members or their families
- Use of Slack as the system of record for health information
Your side of the agreement
A signed BAA is not a configured system.
Signing shifts liability; it does not change a setting. These are the steps that remain yours once Slack is in scope.
- 1Move to Enterprise Grid and execute the BAA before any PHI enters a workspace
- 2Deploy Slack DLP, or an external DLP provider via the Discovery APIs, to enforce what may be posted
- 3Train staff that PHI belongs in messages and files only, not in other Slack surfaces
- 4Keep a separate system of record for health information
Evidence
What an auditor will actually ask for.
Every item below is evidence someone has to produce, date and re-produce at the next audit. Screenata's agent collects these on a schedule instead.
- The executed BAA and confirmation the org is on Enterprise Grid
- DLP configuration showing the rules applied to PHI-bearing channels
- Retention settings for channels and DMs, matched to your retention policy
- Access reviews for workspace and channel membership
See how Screenata handles this on HIPAA programs, or read what healthcare SaaS needs beyond SOC 2.
Sources
Verified against vendor documentation on 2026-08-08. BAA terms change — re-check before relying on this.