CompyMax

Is Notion HIPAA compliant?

Only under specific conditions

Yes, if you are on the Enterprise plan, accept the agreement inside workspace settings and lock the workspace down as Notion requires — and even then you may not use Notion to communicate with patients.

Applies to Notion workspace. Last reviewed against Notion's own documentation. Next review December 15, 2026.

Reviewed by Dr. Rachel Foster, MD — Pediatrician and small practice owner.

What you must do

  • Subscribe to the Enterprise plan. Notion states you must be on Enterprise to be eligible to sign.
  • Activate in-product: Settings → Workspace settings → HIPAA compliance → Activate, review the agreement, then Accept.
  • Enable SAML single sign-on with verified domains and set the default login method to SSO only.
  • Enable domain verification and implement SCIM for user provisioning and deprovisioning.
  • Shorten session duration from the 180-day default and enable force logout and force password reset.
  • Disable public page sharing, guest invitations (or require approval), page moving and duplication, export, workspace creation and external workspace access.
  • Disable third-party extensions or maintain an explicit allowlist.
  • Configure data retention and review the audit log regularly.
  • Never put patient information in workspace, teamspace, page or file names, user profiles or group names — and never in a support request or its attachments.
  • For Notion Mail and Notion Calendar, enable HIPAA compliance on the underlying Google Workspace separately.

Does Notion sign a business associate agreement?

Yes. Notion offers one. Enterprise Enterprise customers self-serve: Settings → Workspace settings → HIPAA compliance → Activate, then review and Accept. If not on Enterprise, contact Notion sales.

See their documentation.

What this means in practice

Notion will sign, but only on Enterprise, and the configuration it requires strips out most of what makes Notion pleasant. Public page sharing off. Guest invitations off or approval-gated. Page moving and duplication off. Export off. External workspace access off. Extensions disabled or on a strict allowlist. Add SAML single sign-on with verified domains, SCIM provisioning, a session length far shorter than the 180-day default, and regular audit log review.

The rule most often broken is about names. Patient information may not appear in workspace, teamspace, page or file names, in user profiles or in group names, and never in a support request or its attachments. That runs directly against how people actually use Notion, where a descriptive page title is how you find anything six months later.

Two boundaries matter beyond configuration. Notion may not be used to communicate with patients, their families or their employers at all. And beta services are excluded, which is worth pausing on before assuming newer AI surfaces are in scope. Notion Mail and Calendar also need HIPAA compliance enabled separately on the underlying Google Workspace.

How organizations get this wrong

The specific mistakes we see with Notion, not generic advice.

  • Titling a page with a patient's name so colleagues can find it by search, when names must stay out of page and file names.
  • Sharing a page publicly to get a document to an outside party, which is exactly the setting the configuration requires you to disable.
  • Leaving the 180-day session default on shared front-desk machines instead of shortening it and enabling force logout.
  • Pasting a screenshot showing patient details into a Notion support ticket while trying to get a technical problem resolved.

What the agreement does not cover

  • Any beta service. Notion states beta services are not covered and may not be used to process patient information.
  • Using Notion to communicate with patients, plan members or their families or employers.
  • Notion Mail and Notion Calendar unless separately enabled through Google Workspace.
  • Publicly shared pages, non-allowlisted third-party extensions, and external workspace access.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Google Workspace

    Docs, Drive and Gmail covered under one amendment without an enterprise-only gate

  • Microsoft 365

    OneNote, SharePoint and Teams in scope on standard business plans

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Notion, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Notion’s own published documentation, read on the date shown.

  1. HIPAA configuration in NotionNotion. No publication date given. Read July 29, 2026.
  2. Notion AI security & privacy practicesNotion. No publication date given. Read July 29, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects Notion’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.