CompyMax

Is Slack HIPAA compliant?

Only under specific conditions

Only on Slack's top Enterprise tier with a signed agreement, and only for staff-to-staff messages and file uploads — you may never use Slack to message patients.

Applies to Slack Enterprise Grid / Enterprise+. Last reviewed against Slack's own documentation. Next review November 30, 2026.

Reviewed by Carlos Mendez — IT Security Manager, regional healthcare network.

What you must do

  • You must be on a Slack Enterprise plan (Enterprise Grid, currently branded Enterprise+). Free, Pro and Business+ do not support this use.
  • Execute a business associate agreement with Slack.
  • Review and agree to implement Slack's 'Requirements for HIPAA Entities' document, requested through Slack's compliance page or support.
  • Confine patient information to message content and file uploads only. Slack prohibits it in other fields.
  • Set any channel where patient information may be shared to private.
  • Deploy data loss prevention able to monitor public channels, private channels and direct messages and quarantine non-compliant content in near real time — Slack's own DLP or an external provider via the Discovery APIs.
  • Deploy single sign-on, use backup and archival tooling, and monitor member usage.
  • Train your users on the restrictions. Slack requires you to inform users how to use and configure Slack.

Does Slack sign a business associate agreement?

Yes. Slack offers one. Slack Enterprise plan only (Enterprise Grid / Enterprise+) Contact Slack via slack.com/trust/compliance using the 'Request requirements for HIPAA entities' option, or through your account team. You must both execute the agreement and agree to implement Slack's requirements.

See their documentation.

What this means in practice

Slack is the entry where the honest answer for most small organizations is that the door is technically open and practically shut. Coverage exists only on Slack's top Enterprise tier, so Free, Pro and Business+ are out entirely, and there is no partial upgrade. On top of the agreement you must also agree to implement Slack's separate requirements document, which obliges you to run single sign-on, backup and archival tooling, and data loss prevention capable of watching public channels, private channels and direct messages and quarantining content in near real time.

The absolute rule is the one people trip over hardest: Slack may not be used to communicate with patients, plan members, or their families or employers, and those people may not be added as users or guests. There is no exception for a quick billing question.

Even inside the walls, patient information belongs only in message text and file uploads. Channel names, topics and other fields are outside the covered surfaces, and email into Slack does not work for organizations configured this way at all.

How organizations get this wrong

The specific mistakes we see with Slack, not generic advice.

  • Sitting on Business+ and assuming there is a middle upgrade path, when Enterprise Grid, now branded Enterprise+, is the only supported tier.
  • Adding a patient or a family member as a single-channel guest to resolve a billing query, which Slack prohibits outright.
  • Putting a patient's name or condition in a channel name or topic rather than in a message, which places it outside the covered surfaces.
  • Signing the agreement but never deploying data loss prevention that can quarantine offending content in direct messages in near real time.

What the agreement does not cover

  • Communicating with patients. Slack states it may not be used to communicate with patients, plan members or their families or employers, and they may not be added as users or guests.
  • Patient information in any Slack surface other than messages and files.
  • Email into Slack. Slack states it is not possible to send emails to Slack on HIPAA-compliant organizations.
  • All Slack plans below Enterprise.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Microsoft Teams

    In scope under Microsoft's agreement on standard business subscriptions, with no enterprise-only gate

  • Google Chat

    Covered by the Workspace amendment you accept yourself in the Admin console

  • TigerConnect

    Built for clinical messaging, including the patient-facing communication Slack forbids

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Slack, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Slack’s own published documentation, read on the date shown.

  1. Slack and HIPAASlack. No publication date given. Read July 29, 2026.
  2. Configure Enterprise Grid to be HIPAA-compliantSlack. No publication date given. Read July 29, 2026.
  3. Resources for complianceSlack. No publication date given. Read July 29, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects Slack’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.