Last updated: March 2026
Is Slack HIPAA Compliant?
Quick Answer
Slack can be HIPAA compliant with Enterprise Grid, a signed Business Associate Agreement, and strict security controls. Standard and Pro plans do not support HIPAA BAAs. You must implement channel restrictions, message retention policies, DLP rules, and disable guest access to use Slack for healthcare communications.
Enterprise Grid Requirements for HIPAA
Plan Requirements
Only Slack Enterprise Grid supports HIPAA Business Associate Agreements. Slack Standard and Pro plans cannot be used for Protected Health Information. Enterprise Grid plans provide organization-wide security controls necessary for compliance, including advanced permissions, audit logging, and security integrations.
Business Associate Agreement
Slack provides BAAs for Enterprise Grid customers. Contact Slack directly through your Enterprise account manager to request a HIPAA-compliant BAA. The BAA covers all workspace data transmission, storage, and processing. Ensure BAA is executed before using Slack for any PHI.
Channel Management & Access Control
| Control |
HIPAA Requirement |
| Private Channels |
All PHI communication must use private channels only; public channels prohibited |
| Channel Access |
Restrict to only those with job-related necessity for PHI access |
| Guest Access |
Disable entirely; never invite external users to PHI channels |
| Shared Channels |
Avoid for PHI; if used, restrict to pre-approved organizations only |
| App Integrations |
Restrict; only approve apps that support encryption and have their own BAAs |
Channel Configuration Best Practices
- Create separate channels for different care teams with minimal cross-access
- Archive channels containing patient-specific conversations after 30 days
- Remove users immediately upon role change or termination
- Audit channel membership monthly
- Use channel names that don't reveal PHI content (avoid patient names)
Message Retention & Data Deletion
Retention Policies
Configure Slack workspace retention policies to automatically delete messages after 90 days (or your compliance requirement). Messages containing PHI must not persist indefinitely. Enable workspace-level retention rules that apply to all channels equally to ensure consistent deletion patterns.
Data Export & Compliance
Regularly export workspace data for audit purposes and legal holds. Slack provides eDiscovery tools for identifying and preserving messages during investigations. Configure alerts when data exports are requested to detect unauthorized access attempts.
Data Loss Prevention (DLP) & Security
| Security Feature |
Configuration |
| Encryption In Transit |
TLS 1.2+ required for all connections; enforced by default |
| Encryption at Rest |
Slack-managed encryption; customer-managed keys not available |
| Message Content DLP |
Use Slack Connect rules to detect PHI patterns and block sending |
| File Upload Restrictions |
Disable file uploads in public channels; require approval in private channels |
| Third-Party App DLP |
Require explicit approval for each app with security review |
DLP Rule Configuration
- Block messages containing medical record numbers or SSN patterns
- Prevent sharing of insurance policy numbers in Slack
- Restrict file uploads containing health condition keywords to private channels only
- Alert on messages with medication names sent to external Slack workspaces
- Log all DLP violations for compliance review
Guest Access & External Security Risks
Disable Guest Access
Never invite external guests or contractors to Slack workspaces containing PHI. Guest access introduces security risks and complicates BAA obligations. If external collaboration is necessary, use dedicated non-PHI channels and never grant access to clinical conversations.
Shared Channel Risks
Slack Shared Channels connect workspaces across organizations. Do not use for PHI unless the external organization has executed their own HIPAA BAA and you have formal business associate agreements. Shared channels expose PHI to third-party risks and compliance complications.
Authentication & Permissions
Workspace-Level Controls
- Single Sign-On (SSO): Implement SAML/OAuth with your identity provider
- Strong Passwords: Enforce complexity requirements; prohibit password reuse
- Session Management: Configure automatic logout after 8 hours of inactivity
- Admin Audit Logs: Review admin actions weekly for unauthorized changes
- API Token Control: Disable legacy API tokens; use OAuth only
Workspace Permissions
- Limit workspace owners to essential administrators only
- Use Org Owner role for enterprise-wide policy enforcement
- Enable Member Approval to control new user sign-ups
- Require admin approval for file uploads and app installations
Compliance Monitoring & Audit
Admin Audit Logging
Enable and regularly review Slack Admin Audit Logs. Monitor for permission changes, member removals, app installations, and configuration modifications. Export logs monthly and retain for at least 6 years for regulatory compliance. Use log data to identify suspicious activity patterns.
Compliance Checklist
- ✓ Enterprise Grid plan active with HIPAA BAA signed
- ✓ Guest access disabled at workspace level
- ✓ All PHI channels set to private with access restrictions
- ✓ Message retention policy set to 90 days or less
- ✓ DLP rules configured and tested
- ✓ File uploads restricted or disabled
- ✓ Shared channels not used for PHI
- ✓ Admin Audit Logs enabled and monitored
- ✓ User training completed on PHI handling
- ✓ Monthly compliance audits scheduled
Frequently Asked Questions
Can we use Slack Pro for occasional healthcare chats?
+
No. Slack Pro and Standard plans do not support HIPAA BAAs under any circumstances. You must use Enterprise Grid. Even "occasional" PHI in non-compliant plans violates HIPAA regulations. Upgrade to Enterprise Grid before sharing any protected health information.
What happens to archived Slack messages containing PHI?
+
Archived messages are retained according to your workspace retention policy. If retention is set to 90 days, archived messages are deleted automatically. For legal holds or audits, Slack's eDiscovery prevents deletion of messages on hold. Always configure retention policies to align with your healthcare data retention requirements.
Can third-party apps access PHI from Slack channels?
+
Yes, any installed app can access channel content if permissions allow. Never install third-party apps unless they have their own HIPAA BAA and you've reviewed their privacy policy. Restrict app permissions to the minimum necessary. Consider disabling all non-essential apps entirely for PHI channels.
Is Slack Connect compliant with HIPAA?
+
Slack Connect (Shared Channels) can be used between organizations only if both have executed HIPAA BAAs. However, this complicates compliance. Most healthcare organizations avoid Shared Channels for PHI. Use Slack Connect only for non-sensitive communications with pre-vetted partners.
Ensure Your Slack Workspace is HIPAA Compliant
Medcurity audits Slack Enterprise Grid deployments to verify HIPAA BAA coverage, channel security, and DLP configuration. Get expert guidance on secure healthcare communication.
Schedule a Slack Audit