Is Slack HIPAA Compliant?

Slack can meet HIPAA requirements, but only on Enterprise Grid with a signed BAA and specific admin configuration.

Get started for free
Yes, with conditions

Yes, with conditions. Slack supports HIPAA compliance only on its Enterprise Grid plan. Slack will sign a BAA for Enterprise Grid customers, but the organization is responsible for configuring the workspace to meet HIPAA requirements. Standard, Pro, and Business+ plans are not eligible for a BAA.

Why?

BAA available only on Enterprise Grid

Slack offers a Business Associate Agreement exclusively for Enterprise Grid customers. Standard, Pro, and Business+ plans do not qualify for a BAA, making them ineligible for HIPAA-governed use.

Source: Slack HIPAA compliance (Enterprise Grid)

Organization responsible for configuration

Signing a BAA does not automatically make Slack HIPAA compliant. The organization must configure data loss prevention, retention policies, access controls, and channel restrictions to meet HIPAA requirements.

Source: Slack HIPAA compliance (Enterprise Grid)

Lower-tier plans are not eligible

Slack's Free, Pro, and Business+ plans do not include the security and compliance features required for HIPAA-governed use. Only Enterprise Grid provides the admin controls, audit logs, and data residency options needed.

Source: Slack HIPAA compliance (Enterprise Grid)

Requires dedicated admin oversight

Maintaining HIPAA compliance on Slack Enterprise Grid requires ongoing admin work: monitoring DLP policy violations, managing channel permissions, reviewing audit logs, and updating configurations as Slack releases new features. The HIPAA Security Rule requires covered entities to implement and maintain these administrative safeguards.

Source: HHS HIPAA Security Rule

What Slack says

Slack's compliance documentation states that Enterprise Grid supports HIPAA compliance and that Slack will enter into a BAA with Enterprise Grid customers. Slack also states that the customer is responsible for configuring the workspace in accordance with HIPAA requirements.
Source: Slack HIPAA compliance (Enterprise Grid)

What you would need to configure

Required plan: Slack Enterprise Grid

  1. Contact Slack sales to provision Enterprise Grid and execute a BAA
  2. Enable multi-factor authentication for all users
  3. Configure Data Loss Prevention rules to prevent PHI from being shared in unauthorized channels or with external users
  4. Set message and file retention policies in accordance with HIPAA record-keeping requirements
  5. Restrict channel creation and external sharing to authorized admins
  6. Enable and monitor Slack audit logs for access and activity tracking
  7. Train staff on compliant use of Slack for PHI — including which channels are approved for healthcare communication

Requires IT staff who can configure and maintain Enterprise Grid security settings. Enterprise Grid pricing is not published — contact Slack sales for a quote. Not a one-time setup — policies need ongoing review as Slack releases new features and integrations.

HIPAA-compliant alternatives

BloomText

Purpose-built HIPAA messaging that ships compliant out of the box. Signed BAA included at signup on every plan, including the free plan. No enterprise contract required.

TigerConnect

Enterprise clinical messaging for hospitals and health systems with role-based routing, EHR integrations, and care team assignments.

Spruce Health

HIPAA-compliant communication platform for medical practices with secure messaging, phone, fax, and telehealth in one system.

Frequently Asked Questions

Is Slack HIPAA compliant?

Only on Enterprise Grid. Slack will sign a BAA for Enterprise Grid customers and the plan includes the admin controls needed for HIPAA-governed use. Standard, Pro, and Business+ plans are not eligible.

Does Slack sign a BAA?

Yes, but only for Enterprise Grid customers. Slack will enter into a Business Associate Agreement as part of the Enterprise Grid contract. Lower-tier plans do not qualify for a BAA.

What Slack plan do I need for HIPAA compliance?

Slack Enterprise Grid is the only plan eligible for HIPAA-compliant use. It includes the admin controls, audit logs, DLP capabilities, and data residency options required to meet HIPAA requirements.

Can a small practice use Slack for HIPAA messaging?

Enterprise Grid is designed for large organizations and its pricing reflects that. Smaller practices may find the cost and configuration overhead disproportionate to their messaging needs.

Sources

Last verified May 26, 2026.

  1. BloomText pricing
  2. Slack HIPAA compliance (Enterprise Grid)
  3. Slack Trust and Compliance
  4. HHS HIPAA Security Rule

Need HIPAA-compliant messaging?

Get started for free

Trusted by today's leading healthcare professionals

Streamlined appointment schedulingWith BloomText Broadcast SMS Messaging, I literally took the job of 20 employees and I can do it by myself in three and a half hours.Chief Administrative Officer, Radiology
Best HIPAA app on the marketBloomText has brought our clinic into the modern age, and our patients love being able to communicate with us via text or through our website.Office Administrator, Family Medicine
Excellent for acute careBloomText is the nervous system for my business. It helps us differentiate ourselves in terms of our communication and our quality of care.Clinical Director, Acute Care