HIPAA & PRIVACY

Is Slack HIPAA Compliant?

Only conditionally. Slack will sign a Business Associate Agreement for its Enterprise plan (sold as Enterprise+ as of Aug 2026, historically Enterprise Grid) and nothing below it. Even then, PHI is permitted only in messages and files, never with patients, and you have to run DLP. Free, Pro, and Business+ cannot hold PHI under any configuration.

Cyanotype of an open-plan back office with two empty desks, blank monitors and headsetsFIG · 01
An open-plan back office with two empty desks, blank monitors and headsets.

Conditionally — Enterprise plan + BAA, messages and files only

Slack (owned by Salesforce) signs a BAA only for its Enterprise plan. Once signed, PHI may appear in direct, group, and channel messages, uploaded files and file names, and the names of private channels and DMs. Everything else in Slack is off-limits for PHI, and patients may never be on the other end of a conversation.

Enterprise (Enterprise+ / Grid) + signed BAA

HIPAA-eligible, with limits

Free / Pro / Business+

No BAA offered. Not HIPAA compliant

PHI allowed in: messages, files, file names, private channel and DM names

Never: patient, member, or family communication of any kind

Which Slack Plans Can Get a BAA?

One. Slack's help center states you “must be using a Slack Enterprise plan” and must execute a Business Associate Agreement before any PHI touches the platform. Slack's pricing page now lists that tier as Enterprise+; its HIPAA documentation still calls it Enterprise Grid. Same product, two names. Prices below are list prices as of Aug 2026.

PlanBAADLPEKM

Free

$0

Pro

$7.25/user/mo (annual)

Business+

$15/user/mo (annual)

Enterprise+ (Enterprise Grid)

Contact sales

Business+ is the trap. It ships DLP, SAML SSO, and audit logs, so it looks compliant on paper. It isn't. Without a BAA, Slack is not your business associate and every message containing PHI is an impermissible disclosure. See who HIPAA applies to if you're unsure whether your vendors count.

How to Get Slack's BAA

Unlike Microsoft, which lets any business-plan admin accept a BAA in the admin center, Slack's BAA is a sales-led process. There is no self-serve toggle. Budget a few weeks, not five minutes.

01

Confirm you are on an Enterprise contract

Slack sells Enterprise+ only through its sales team. If you signed up with a credit card, you are on Pro or Business+ and need to migrate first.

02

Request Slack's HIPAA requirements

From slack.com/trust/compliance, use "Request requirements for HIPAA entities." Slack sends its Requirements for HIPAA Entities guide, which you must commit to implementing.

03

List every org and workspace that will hold PHI

Slack asks for the full list up front. Workspaces you leave off are not covered, so decide now which teams will be allowed to discuss PHI.

04

Execute the BAA through your account team

Slack's BAA is its own paper, signed through your Salesforce/Slack account executive. Expect limited negotiation. Read the exclusions section closely.

05

Retain the signed BAA for six years

45 CFR 164.530(j) requires you to keep it six years from the date it was last in effect. File it with your other vendor agreements.

06

Add Slack to your risk assessment

Record Slack as a system that stores ePHI, the safeguards in place, and your plan if Slack notifies you of a breach on their side.

Where PHI Is (and Isn't) Allowed in Slack

Slack's HIPAA article draws a narrow boundary: members “may not include PHI when using Slack features, excluding messages, files and file names, and names of private channels or DMs.” Everything Slack has shipped since 2020 (huddles, canvas, lists, AI) falls on the wrong side of that line. That is what makes the minimum necessary rule hard to enforce here.

Permitted (with BAA, on Enterprise)

  • Direct, group, and channel messages

    Message text may contain PHI on a covered workspace

  • Uploaded files and file names

    Attachments count as PHI in transit and at rest; keep DLP scanning them

  • Private channel names and DM names

    Explicitly permitted by Slack's HIPAA article

Excluded or prohibited

  • Any other Slack feature

    Slack's rule: no PHI in features other than messages, files, and private channel/DM names

  • Huddles, canvases, lists, clips

    Not on Slack's permitted list. Treat as PHI-free zones unless your BAA says otherwise

  • Slack AI, search recaps, Agentforce

    AI summaries and recaps are not messages or files. Keep them off PHI channels or disable them

  • Slack Connect and shared channels

    The other org has no BAA with you. External channels are a disclosure

  • Public channel names, statuses, profiles

    Visible to the whole workspace; not covered

  • Email to Slack

    Unavailable for HIPAA-configured orgs. Do not forward patient email into channels

  • Third-party apps and bots

    Slack has no BAA with any marketplace app. Each app needs its own BAA or gets blocked

  • Patients, members, families, employers

    Slack may not be used to communicate with any of them, full stop

Huddles: marketing vs. the BAA

Slack's huddles page says the feature “meets” HIPAA standards. Its HIPAA help article does not list huddles as a permitted location for PHI. Go by the BAA and the Requirements for HIPAA Entities guide you signed, not the product page. If those documents don't name huddles, keep PHI out of them. Slack is also not a system of record: chart it in the EHR, not in a channel. Encryption alone does not settle this; see our HIPAA encryption requirements guide.

8 Settings to Lock Down After the BAA

The BAA transfers liability for Slack's side. Your side is configuration. Record each of these in your risk assessment and the matching written policy.

01

Turn on data loss prevention

Org dashboard → Security → Data loss prevention (or a Discovery API partner)

Add rules for SSNs, MRNs, dates of birth, and diagnosis terms. Set them to block or quarantine, not just alert

Slack's HIPAA terms make you responsible for monitoring members' use. DLP is how Slack expects you to do it

02

Add Enterprise Key Management

Paid add-on → AWS KMS keys you control

Bring your own keys so you can revoke access to messages and files by org, workspace, channel, or time window

Lets you cut off access during an incident without waiting on Slack, and gives you key-usage logs

03

Set retention deliberately

Org dashboard → Settings → Message and file retention

Pick a retention period that matches your record policy. Six years is the HIPAA documentation floor for policies, not for every chat

Indefinite history is breach surface. Deleting too fast destroys records you may need for a complaint or audit

04

Restrict app installs to an allowlist

Org dashboard → Integrations → App management

Require admin approval for every app. Approve only apps with their own BAA and a documented business need

Marketplace apps can read channel content. Slack has no BAA with any of them

05

Disable or fence Slack Connect

Org dashboard → Settings → Slack Connect

Block external shared channels org-wide, or restrict to named orgs with their own BAA and keep them PHI-free by policy

The other side of a shared channel is an outside organization. Sending PHI there is a disclosure

06

Export audit logs continuously

Audit Logs API → SIEM or archive

Pull logins, file downloads, channel membership changes, and admin setting changes into your log platform

The Security Rule requires activity review (45 CFR 164.308(a)(1)(ii)(D)). Slack's UI alone won't satisfy an auditor

07

Enforce SSO, MFA, and session limits

Org dashboard → Security → Authentication

Require SAML SSO through your identity provider with MFA. Set session duration to hours, not weeks

Stolen passwords are the most common way PHI leaks from chat tools

08

Manage mobile devices

Org dashboard → Security → Mobile (EMM integration)

Require managed devices or Slack for EMM, force app passcode or biometrics, and enable remote wipe

A lost phone with cached channels is a reportable breach if the device wasn't encrypted and wipeable

Make PHI channels private and few

Slack's own guidance is that channels carrying PHI should be private. Go further: name them with a prefix (for example phi-), restrict who can create them, and train staff that everything else is PHI-free. Put that in your annual HIPAA training.

6 Mistakes That Break Slack Compliance

These show up repeatedly when practices audit chat tools. Each one is a candidate for the common HIPAA violations list, and several trigger breach notification duties.

Assuming Business+ is enough because it has DLP

Slack won't sign a BAA below Enterprise. DLP without a BAA means you've found the PHI, and it's still an impermissible disclosure to a non-business-associate.

Fix: Move to Enterprise+ and execute the BAA, or keep Slack PHI-free by policy and use a covered tool for clinical chat.

Messaging patients through Slack Connect or guest accounts

Slack's HIPAA terms prohibit communicating with patients, plan members, or their families or employers. Doing so breaches the BAA itself.

Fix: Use a patient-facing platform that will sign a BAA. See our HIPAA compliant texting comparison.

Letting Slack AI summarize PHI channels

Recaps, search answers, and thread summaries are not on Slack's permitted list. They also copy PHI into new surfaces you don't retain or audit the same way.

Fix: Disable AI features on PHI workspaces, or restrict them by policy and confirm coverage in writing with your account team.

Putting handoff notes in a canvas or list

Shift handoffs and patient trackers are exactly what canvases and lists are built for, and exactly where Slack says PHI may not go.

Fix: Keep handoffs in messages or an uploaded file, or run them in the EHR. Slack is not a system of record.

Installing bots and workflow apps without review

Slack has no BAA with any marketplace app. A scheduling bot reading a phi- channel is a third party with no agreement.

Fix: Admin-approval-only app policy. Each approved app needs its own signed BAA on file.

No retention decision at all

Default settings keep every message forever. In a breach, that's every patient ever mentioned. In a complaint, deleting mid-investigation looks like spoliation.

Fix: Set an org-wide retention policy, document the reasoning, and apply legal holds when a complaint or investigation opens.

Slack is one line item in a bigger review. Work through the full HIPAA compliance checklist to catch what your other tools are missing.

Slack vs. Teams: The Cheaper Compliant Path

For a small or mid-size practice, the honest answer is usually Teams. Microsoft's BAA comes with plans that cost less than Slack Pro. Read the full Teams HIPAA guide for the settings.

CategorySlackTeamsEdge
BAA availabilityEnterprise+ only, via sales teamEvery Microsoft 365 business/enterprise plan, self-serve in admin centerTEAMS
Cheapest compliant seat (Aug 2026 list)Enterprise+ quote; not publishedBusiness Basic, about $7/user/mo annual; Business Premium $22 adds DLP + IntuneTEAMS
Where PHI may liveMessages, files, private channel/DM names onlyChat, channels, calls, meetings, recordings, files in SharePoint/OneDriveTEAMS
Patient-facing useProhibited by Slack's HIPAA termsAllowed (virtual visits, external meetings)TEAMS
DLPNative on Business+/Enterprise+, or Discovery API partnerMicrosoft Purview with a built-in U.S. HIPAA templateTIE
Customer-managed keysEKM add-on (Enterprise+)Customer Key (E5 or add-on)TIE
Day-to-day chat experienceFaster, cleaner, better integrationsHeavier, but bundled with mail, files, and videoSLACK

“If you're already on an Enterprise Slack contract, add the BAA and fence PHI into private channels. If you're choosing a tool today, Teams gets you covered for a fraction of the cost, and it can talk to patients.”

Quick Reference: Slack HIPAA Compliance

One eligible plan

Enterprise+ (formerly Enterprise Grid). Free, Pro, and Business+ get no BAA under any configuration.

BAA is sales-led

Request the HIPAA requirements guide, list every workspace that will hold PHI, sign through your account team, keep it 6 years.

PHI boundary

Messages, files, file names, private channel and DM names only. No huddles, canvas, lists, AI, Slack Connect, apps, or patients.

8 settings

DLP, EKM, retention, app allowlist, Slack Connect off, audit log export, SSO + MFA + session limits, mobile management.

Related Tools & Guides