Is Zapier HIPAA compliant?
No — Zapier states plainly that it is not HIPAA compliant and does not sign business associate agreements on any plan, so patient information must never pass through a Zap.
Applies to Zapier automation. Last reviewed against Zapier's own documentation. Next review December 9, 2026.
Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.
If you keep using it anyway
- If you use Zapier elsewhere in the business, make sure no trigger, action, field or filter can pull patient information out of an EHR, intake form or patient inbox.
- Avoid connecting Zapier to any app that stores patient records, even for steps that appear to move only names or appointment times.
- Keep Zapier to back-office automation with no patient data — supply orders, staff notifications, accounting, and marketing to non-patient lists.
Does Zapier sign a business associate agreement?
Zapier does not offer one. Not applicable. Zapier states it cannot sign business associate agreements or equivalents for handling patient information.
What this means in practice
Zapier's own position is unambiguous: it is not HIPAA compliant and it does not sign business associate agreements on any plan, Enterprise included. The security features on the Enterprise tier improve how Zapier itself is run, but they do not create an agreement and do not alter that stance.
What makes Zapier risky in a small organization is not malice, it is invisibility. Zaps are built by whoever felt the friction, often a receptionist or a practice manager, and they run silently for years. Nobody documents them, and after a system migration nobody can say for certain which apps a given Zap still reads from. The usual justification is that a particular automation only moves a name and an appointment time, but that pairing already tells the world that a named person is a patient of your practice.
The workable position is a hard boundary rather than careful configuration. Zapier stays on the back office: supply orders, staff notifications, accounting, marketing to non-patient lists. It gets connected to nothing that holds patient records, including intake forms and shared patient inboxes.
How organizations get this wrong
The specific mistakes we see with Zapier, not generic advice.
- A receptionist building a Zap that copies new appointments into a spreadsheet, on the view that a name and a time are harmless.
- Connecting Zapier to a shared patient inbox so unread messages become tasks, which pulls message content through Zapier itself.
- Upgrading to Zapier Enterprise for the security controls and treating that purchase as equivalent to having an agreement.
- Leaving old Zaps running after a system change, with nobody able to say which applications they still read from or write to.
What the agreement does not cover
- Every Zapier plan including Enterprise.
- Zapier's Enterprise security features improve posture but do not create an agreement or change its stated position.
Use instead
Listed on merit. We take no payment for placement and use no affiliate links.
Named on Google's Included Functionality list, so custom automation across Gmail, Calendar, Drive and Sheets is covered by the Workspace amendment
Both are on Twilio's eligible services list, giving a workflow builder that a signed addendum can cover
You just found one. What else is in your stack?
If Zapier was a surprise, it is rarely the only one. Most small organizations are running fifteen to thirty tools and have written agreements with a handful of them. A vendor register tracks which of yours touch patient information, which have a signed agreement, when each expires and who owns it — and exports as part of the evidence pack when a client asks.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Zapier’s own published documentation, read on the date shown.
- Is Zapier HIPAA compliant? — Zapier. No publication date given. Read July 29, 2026.
- Data Privacy Overview — Zapier. No publication date given. Read July 29, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Zapier’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.