Is Slack HIPAA Compliant?
Only conditionally. Slack will sign a Business Associate Agreement for its Enterprise plan (sold as Enterprise+ as of Aug 2026, historically Enterprise Grid) and nothing below it. Even then, PHI is permitted only in messages and files, never with patients, and you have to run DLP. Free, Pro, and Business+ cannot hold PHI under any configuration.
FIG · 01Conditionally — Enterprise plan + BAA, messages and files only
Slack (owned by Salesforce) signs a BAA only for its Enterprise plan. Once signed, PHI may appear in direct, group, and channel messages, uploaded files and file names, and the names of private channels and DMs. Everything else in Slack is off-limits for PHI, and patients may never be on the other end of a conversation.
Enterprise (Enterprise+ / Grid) + signed BAA
HIPAA-eligible, with limits
Free / Pro / Business+
No BAA offered. Not HIPAA compliant
PHI allowed in: messages, files, file names, private channel and DM names
Never: patient, member, or family communication of any kind
Which Slack Plans Can Get a BAA?
One. Slack's help center states you “must be using a Slack Enterprise plan” and must execute a Business Associate Agreement before any PHI touches the platform. Slack's pricing page now lists that tier as Enterprise+; its HIPAA documentation still calls it Enterprise Grid. Same product, two names. Prices below are list prices as of Aug 2026.
| Plan | BAA | DLP | EKM | Notes |
|---|---|---|---|---|
Free $0 | 90-day history, no admin controls. Never for PHI | |||
Pro $7.25/user/mo (annual) | No BAA offered at any price | |||
Business+ $15/user/mo (annual) | Has native DLP, SSO, and audit logs, but Slack still won't sign a BAA | |||
Enterprise+ (Enterprise Grid) Contact sales | The only BAA-eligible tier. EKM is a paid add-on |
Business+ is the trap. It ships DLP, SAML SSO, and audit logs, so it looks compliant on paper. It isn't. Without a BAA, Slack is not your business associate and every message containing PHI is an impermissible disclosure. See who HIPAA applies to if you're unsure whether your vendors count.
How to Get Slack's BAA
Unlike Microsoft, which lets any business-plan admin accept a BAA in the admin center, Slack's BAA is a sales-led process. There is no self-serve toggle. Budget a few weeks, not five minutes.
Confirm you are on an Enterprise contract
Slack sells Enterprise+ only through its sales team. If you signed up with a credit card, you are on Pro or Business+ and need to migrate first.
Request Slack's HIPAA requirements
From slack.com/trust/compliance, use "Request requirements for HIPAA entities." Slack sends its Requirements for HIPAA Entities guide, which you must commit to implementing.
List every org and workspace that will hold PHI
Slack asks for the full list up front. Workspaces you leave off are not covered, so decide now which teams will be allowed to discuss PHI.
Execute the BAA through your account team
Slack's BAA is its own paper, signed through your Salesforce/Slack account executive. Expect limited negotiation. Read the exclusions section closely.
Retain the signed BAA for six years
45 CFR 164.530(j) requires you to keep it six years from the date it was last in effect. File it with your other vendor agreements.
Add Slack to your risk assessment
Record Slack as a system that stores ePHI, the safeguards in place, and your plan if Slack notifies you of a breach on their side.
Where PHI Is (and Isn't) Allowed in Slack
Slack's HIPAA article draws a narrow boundary: members “may not include PHI when using Slack features, excluding messages, files and file names, and names of private channels or DMs.” Everything Slack has shipped since 2020 (huddles, canvas, lists, AI) falls on the wrong side of that line. That is what makes the minimum necessary rule hard to enforce here.
Permitted (with BAA, on Enterprise)
Direct, group, and channel messages
Message text may contain PHI on a covered workspace
Uploaded files and file names
Attachments count as PHI in transit and at rest; keep DLP scanning them
Private channel names and DM names
Explicitly permitted by Slack's HIPAA article
Excluded or prohibited
Any other Slack feature
Slack's rule: no PHI in features other than messages, files, and private channel/DM names
Huddles, canvases, lists, clips
Not on Slack's permitted list. Treat as PHI-free zones unless your BAA says otherwise
Slack AI, search recaps, Agentforce
AI summaries and recaps are not messages or files. Keep them off PHI channels or disable them
Slack Connect and shared channels
The other org has no BAA with you. External channels are a disclosure
Public channel names, statuses, profiles
Visible to the whole workspace; not covered
Email to Slack
Unavailable for HIPAA-configured orgs. Do not forward patient email into channels
Third-party apps and bots
Slack has no BAA with any marketplace app. Each app needs its own BAA or gets blocked
Patients, members, families, employers
Slack may not be used to communicate with any of them, full stop
Huddles: marketing vs. the BAA
Slack's huddles page says the feature “meets” HIPAA standards. Its HIPAA help article does not list huddles as a permitted location for PHI. Go by the BAA and the Requirements for HIPAA Entities guide you signed, not the product page. If those documents don't name huddles, keep PHI out of them. Slack is also not a system of record: chart it in the EHR, not in a channel. Encryption alone does not settle this; see our HIPAA encryption requirements guide.
8 Settings to Lock Down After the BAA
The BAA transfers liability for Slack's side. Your side is configuration. Record each of these in your risk assessment and the matching written policy.
Turn on data loss prevention
Org dashboard → Security → Data loss prevention (or a Discovery API partner)
Add rules for SSNs, MRNs, dates of birth, and diagnosis terms. Set them to block or quarantine, not just alert
Slack's HIPAA terms make you responsible for monitoring members' use. DLP is how Slack expects you to do it
Add Enterprise Key Management
Paid add-on → AWS KMS keys you control
Bring your own keys so you can revoke access to messages and files by org, workspace, channel, or time window
Lets you cut off access during an incident without waiting on Slack, and gives you key-usage logs
Set retention deliberately
Org dashboard → Settings → Message and file retention
Pick a retention period that matches your record policy. Six years is the HIPAA documentation floor for policies, not for every chat
Indefinite history is breach surface. Deleting too fast destroys records you may need for a complaint or audit
Restrict app installs to an allowlist
Org dashboard → Integrations → App management
Require admin approval for every app. Approve only apps with their own BAA and a documented business need
Marketplace apps can read channel content. Slack has no BAA with any of them
Disable or fence Slack Connect
Org dashboard → Settings → Slack Connect
Block external shared channels org-wide, or restrict to named orgs with their own BAA and keep them PHI-free by policy
The other side of a shared channel is an outside organization. Sending PHI there is a disclosure
Export audit logs continuously
Audit Logs API → SIEM or archive
Pull logins, file downloads, channel membership changes, and admin setting changes into your log platform
The Security Rule requires activity review (45 CFR 164.308(a)(1)(ii)(D)). Slack's UI alone won't satisfy an auditor
Enforce SSO, MFA, and session limits
Org dashboard → Security → Authentication
Require SAML SSO through your identity provider with MFA. Set session duration to hours, not weeks
Stolen passwords are the most common way PHI leaks from chat tools
Manage mobile devices
Org dashboard → Security → Mobile (EMM integration)
Require managed devices or Slack for EMM, force app passcode or biometrics, and enable remote wipe
A lost phone with cached channels is a reportable breach if the device wasn't encrypted and wipeable
Make PHI channels private and few
Slack's own guidance is that channels carrying PHI should be private. Go further: name them with a prefix (for example phi-), restrict who can create them, and train staff that everything else is PHI-free. Put that in your annual HIPAA training.
6 Mistakes That Break Slack Compliance
These show up repeatedly when practices audit chat tools. Each one is a candidate for the common HIPAA violations list, and several trigger breach notification duties.
Assuming Business+ is enough because it has DLP
Slack won't sign a BAA below Enterprise. DLP without a BAA means you've found the PHI, and it's still an impermissible disclosure to a non-business-associate.
Fix: Move to Enterprise+ and execute the BAA, or keep Slack PHI-free by policy and use a covered tool for clinical chat.
Messaging patients through Slack Connect or guest accounts
Slack's HIPAA terms prohibit communicating with patients, plan members, or their families or employers. Doing so breaches the BAA itself.
Fix: Use a patient-facing platform that will sign a BAA. See our HIPAA compliant texting comparison.
Letting Slack AI summarize PHI channels
Recaps, search answers, and thread summaries are not on Slack's permitted list. They also copy PHI into new surfaces you don't retain or audit the same way.
Fix: Disable AI features on PHI workspaces, or restrict them by policy and confirm coverage in writing with your account team.
Putting handoff notes in a canvas or list
Shift handoffs and patient trackers are exactly what canvases and lists are built for, and exactly where Slack says PHI may not go.
Fix: Keep handoffs in messages or an uploaded file, or run them in the EHR. Slack is not a system of record.
Installing bots and workflow apps without review
Slack has no BAA with any marketplace app. A scheduling bot reading a phi- channel is a third party with no agreement.
Fix: Admin-approval-only app policy. Each approved app needs its own signed BAA on file.
No retention decision at all
Default settings keep every message forever. In a breach, that's every patient ever mentioned. In a complaint, deleting mid-investigation looks like spoliation.
Fix: Set an org-wide retention policy, document the reasoning, and apply legal holds when a complaint or investigation opens.
Slack is one line item in a bigger review. Work through the full HIPAA compliance checklist to catch what your other tools are missing.
Slack vs. Teams: The Cheaper Compliant Path
For a small or mid-size practice, the honest answer is usually Teams. Microsoft's BAA comes with plans that cost less than Slack Pro. Read the full Teams HIPAA guide for the settings.
| Category | Slack | Teams | Edge |
|---|---|---|---|
| BAA availability | Enterprise+ only, via sales team | Every Microsoft 365 business/enterprise plan, self-serve in admin center | TEAMS |
| Cheapest compliant seat (Aug 2026 list) | Enterprise+ quote; not published | Business Basic, about $7/user/mo annual; Business Premium $22 adds DLP + Intune | TEAMS |
| Where PHI may live | Messages, files, private channel/DM names only | Chat, channels, calls, meetings, recordings, files in SharePoint/OneDrive | TEAMS |
| Patient-facing use | Prohibited by Slack's HIPAA terms | Allowed (virtual visits, external meetings) | TEAMS |
| DLP | Native on Business+/Enterprise+, or Discovery API partner | Microsoft Purview with a built-in U.S. HIPAA template | TIE |
| Customer-managed keys | EKM add-on (Enterprise+) | Customer Key (E5 or add-on) | TIE |
| Day-to-day chat experience | Faster, cleaner, better integrations | Heavier, but bundled with mail, files, and video | SLACK |
“If you're already on an Enterprise Slack contract, add the BAA and fence PHI into private channels. If you're choosing a tool today, Teams gets you covered for a fraction of the cost, and it can talk to patients.”
Quick Reference: Slack HIPAA Compliance
One eligible plan
Enterprise+ (formerly Enterprise Grid). Free, Pro, and Business+ get no BAA under any configuration.
BAA is sales-led
Request the HIPAA requirements guide, list every workspace that will hold PHI, sign through your account team, keep it 6 years.
PHI boundary
Messages, files, file names, private channel and DM names only. No huddles, canvas, lists, AI, Slack Connect, apps, or patients.
8 settings
DLP, EKM, retention, app allowlist, Slack Connect off, audit log export, SSO + MFA + session limits, mobile management.
Related Tools & Guides
Is Microsoft Teams HIPAA Compliant?
BAA on every business plan, 8 settings to configure, and covered features.
Best HIPAA Compliant Messaging
Secure messaging platforms compared for clinical and patient communication.
Best HIPAA Compliant Texting
Patient-facing texting tools that will sign a BAA.
BAA Template Generator
Build a Business Associate Agreement for vendors that don't supply one.
HIPAA Risk Assessment Tool
Document Slack as a system that stores ePHI and score the risk.