Medcurity Get Started
Last updated: March 2026

Is Slack HIPAA Compliant?

Quick Answer

Slack can be HIPAA compliant with Enterprise Grid, a signed Business Associate Agreement, and strict security controls. Standard and Pro plans do not support HIPAA BAAs. You must implement channel restrictions, message retention policies, DLP rules, and disable guest access to use Slack for healthcare communications.

Enterprise Grid Requirements for HIPAA

Plan Requirements

Only Slack Enterprise Grid supports HIPAA Business Associate Agreements. Slack Standard and Pro plans cannot be used for Protected Health Information. Enterprise Grid plans provide organization-wide security controls necessary for compliance, including advanced permissions, audit logging, and security integrations.

Business Associate Agreement

Slack provides BAAs for Enterprise Grid customers. Contact Slack directly through your Enterprise account manager to request a HIPAA-compliant BAA. The BAA covers all workspace data transmission, storage, and processing. Ensure BAA is executed before using Slack for any PHI.

Channel Management & Access Control

Control HIPAA Requirement
Private Channels All PHI communication must use private channels only; public channels prohibited
Channel Access Restrict to only those with job-related necessity for PHI access
Guest Access Disable entirely; never invite external users to PHI channels
Shared Channels Avoid for PHI; if used, restrict to pre-approved organizations only
App Integrations Restrict; only approve apps that support encryption and have their own BAAs

Channel Configuration Best Practices

Message Retention & Data Deletion

Retention Policies

Configure Slack workspace retention policies to automatically delete messages after 90 days (or your compliance requirement). Messages containing PHI must not persist indefinitely. Enable workspace-level retention rules that apply to all channels equally to ensure consistent deletion patterns.

Data Export & Compliance

Regularly export workspace data for audit purposes and legal holds. Slack provides eDiscovery tools for identifying and preserving messages during investigations. Configure alerts when data exports are requested to detect unauthorized access attempts.

Data Loss Prevention (DLP) & Security

Security Feature Configuration
Encryption In Transit TLS 1.2+ required for all connections; enforced by default
Encryption at Rest Slack-managed encryption; customer-managed keys not available
Message Content DLP Use Slack Connect rules to detect PHI patterns and block sending
File Upload Restrictions Disable file uploads in public channels; require approval in private channels
Third-Party App DLP Require explicit approval for each app with security review

DLP Rule Configuration

Guest Access & External Security Risks

Disable Guest Access

Never invite external guests or contractors to Slack workspaces containing PHI. Guest access introduces security risks and complicates BAA obligations. If external collaboration is necessary, use dedicated non-PHI channels and never grant access to clinical conversations.

Shared Channel Risks

Slack Shared Channels connect workspaces across organizations. Do not use for PHI unless the external organization has executed their own HIPAA BAA and you have formal business associate agreements. Shared channels expose PHI to third-party risks and compliance complications.

Authentication & Permissions

Workspace-Level Controls

Workspace Permissions

Compliance Monitoring & Audit

Admin Audit Logging

Enable and regularly review Slack Admin Audit Logs. Monitor for permission changes, member removals, app installations, and configuration modifications. Export logs monthly and retain for at least 6 years for regulatory compliance. Use log data to identify suspicious activity patterns.

Compliance Checklist

Frequently Asked Questions

Can we use Slack Pro for occasional healthcare chats? +
No. Slack Pro and Standard plans do not support HIPAA BAAs under any circumstances. You must use Enterprise Grid. Even "occasional" PHI in non-compliant plans violates HIPAA regulations. Upgrade to Enterprise Grid before sharing any protected health information.
What happens to archived Slack messages containing PHI? +
Archived messages are retained according to your workspace retention policy. If retention is set to 90 days, archived messages are deleted automatically. For legal holds or audits, Slack's eDiscovery prevents deletion of messages on hold. Always configure retention policies to align with your healthcare data retention requirements.
Can third-party apps access PHI from Slack channels? +
Yes, any installed app can access channel content if permissions allow. Never install third-party apps unless they have their own HIPAA BAA and you've reviewed their privacy policy. Restrict app permissions to the minimum necessary. Consider disabling all non-essential apps entirely for PHI channels.
Is Slack Connect compliant with HIPAA? +
Slack Connect (Shared Channels) can be used between organizations only if both have executed HIPAA BAAs. However, this complicates compliance. Most healthcare organizations avoid Shared Channels for PHI. Use Slack Connect only for non-sensitive communications with pre-vetted partners.

Ensure Your Slack Workspace is HIPAA Compliant

Medcurity audits Slack Enterprise Grid deployments to verify HIPAA BAA coverage, channel security, and DLP configuration. Get expert guidance on secure healthcare communication.

Schedule a Slack Audit