Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Compliance Operations

Is Notion HIPAA Compliant? Yes, on Enterprise (2026)

Notion supports HIPAA compliance on the Enterprise plan with a signed BAA and HIPAA compliance switched on in workspace settings. Free, Plus and Business do not qualify.

Patient ProtectPatient Protect Editorial Team·March 19, 2026·7 min read

Written and reviewed by the Patient Protect team — Joseph A. Perrin, CTO (federal infrastructure background, platform security architect), Angie Perrin, CSO (CHPC, 10+ years clinical practice), and Alexander Perrin, CEO (20 years enterprise SaaS, primary author of the Secure Care Research Institute research program). See editorial standards.

Share
Notion HIPAA compliance requirements for healthcare documentation and knowledge bases

Notion can be HIPAA compliant — but only on the Enterprise plan with a signed Business Associate Agreement (BAA). Notion introduced HIPAA compliance support in 2024, making Enterprise the only tier where protected health information (PHI) can be stored or referenced. The BAA covers Notion pages, databases, and wikis. Free, Plus, and Business plans do not qualify under any configuration.

This matters because Notion has become a go-to tool for internal documentation in healthcare. Dental offices use it for SOPs. Therapy practices build onboarding checklists. Medical groups track clinical workflows. Most of these practices are on plans that cannot support a BAA — and the line between safe documentation and PHI exposure is thinner than most teams realize.

When Notion Can Be HIPAA Compliant

Notion Enterprise with a signed BAA supports HIPAA compliance for core platform functionality: pages, databases, wikis, and file uploads. Enterprise also provides AES-256 encryption at rest, TLS 1.2+ in transit, SAML-based SSO, SCIM provisioning for automated user management, workspace-level admin controls, and audit logging. Notion maintains SOC 2 Type II certification, validating its security controls around data confidentiality and integrity.

The key point: the Enterprise Plan makes you eligible to sign the BAA. It does not by itself cover anything. Notion states HIPAA compliance is free of charge on Enterprise, and an admin switches it on at Settings → Workspace settings → HIPAA compliance. Eligible, signed, enabled — three steps, and the gap between the first and the third is where most practices actually sit.

When Notion Fails HIPAA

Free, Plus, and Business plans — not eligible for the BAA. Notion states you must subscribe to the Enterprise Plan to be eligible to sign its BAA. Without a BAA, storing or referencing PHI in Notion is an unauthorized disclosure regardless of workspace settings. Encryption does not compensate for the absence of an agreement.

Beta Services — the exclusion that is actually written down. Notion's HIPAA article states that Beta Services are not covered by the BAA and may not be used in a manner that processes PHI. Because what counts as beta changes as features ship, this is a standing governance question rather than a one-time setting. Notion AI itself is not excluded — Notion states it "enables HIPAA compliance by utilizing LLM provider's zero-retention APIs and allows for the processing of protected health information (PHI)". The setting to govern is the one Notion exposes for administrators to enable data-retaining LLMs where a feature requires them. See Is Notion AI HIPAA compliant?.

PHI in the wrong fields. Notion prohibits PHI in workspace or organization names, teamspace names, file names, account or user profile, and the names of user groups. Content is fine; labels are not. Support requests and their attachments must also contain no PHI.

Patient-facing use. Notion may not be used to communicate with patients, plan members, or their families or employers. It is a workforce-internal tool, the same limit Slack carries.

Third-party integrations and embeds. Notion connects to Slack, Google Drive, Figma, and dozens of other tools. Each integration that accesses PHI-containing pages is a potential exposure point. The Notion BAA does not cover third-party tools — every integration that touches PHI requires its own BAA. Whether a given integration is eligible to hold PHI in the first place is answered by category in which tools can hold patient information.

Public page sharing. Notion allows users to publish pages to the public web with a single toggle. If a page containing PHI is shared publicly — even momentarily — that is an unauthorized disclosure of ePHI.

How Healthcare Practices Use Notion (And Where It Gets Risky)

Compliance risk scales directly with how your practice uses Notion.

SOPs and clinical protocols — generally safe. Standard operating procedures and workflow templates typically do not contain PHI. If your SOPs reference procedures without naming patients, these pages are not compliance liabilities.

Patient tracking databases — high risk. The moment a Notion database includes patient names, appointment dates, diagnosis codes, or treatment notes, it contains PHI. On any plan without a BAA, this is a violation.

Onboarding checklists with employee health information. Workflows that include vaccination records, drug screening results, or health clearance documentation contain personally identifiable health information protected under HIPAA.

Meeting notes that reference patient cases. Treatment planning sessions, case reviews, and clinical huddles generate notes that contain PHI the moment a patient is identifiable. Staff documenting these in Notion are creating ePHI records.

Clinical workflow templates. Templates themselves are safe. Completed templates with patient-specific data are not. The risk is not the template — it is what gets filled in.

The practical question: does your Notion workspace contain information that could identify a patient in connection with their health condition or treatment? If yes, you need Enterprise with a BAA — or you need to move that data out of Notion.

Settings to Configure on Enterprise

Having Enterprise and a signed BAA is the starting point. These configurations make the workspace defensible:

  • Execute the BAA — it is not automatic with an Enterprise subscription. Request it, review the terms, and sign it before any PHI enters the workspace.
  • Configure SAML-based SSO — centralize authentication, enforce MFA, and tie access to your identity provider.
  • Set up SCIM provisioning — automate user creation and deactivation so that access is revoked automatically when someone leaves.
  • Restrict external sharing — disable public page sharing entirely for any workspace that contains or may contain PHI.
  • Audit workspace membership — review access on a regular schedule. Remove inactive users and restrict guest accounts.
  • Record the Notion AI configuration — Notion states AI is covered on the same HIPAA-enabled Enterprise basis as the workspace, so the question is not whether to disable it but what state it is in. Document that Beta Services stay out of PHI workflows, and note who may enable a data-retaining LLM where a feature requires one, since that changes the configuration Notion describes its HIPAA support against.
  • Restrict guest access — guests not covered by your compliance program should not reach pages or databases containing PHI.

Common Mistakes

Using Notion for patient databases on non-Enterprise plans. A practice manager builds a patient tracker on a Plus or Business plan because the database features are excellent. The database includes names, appointments, and treatment notes. No BAA exists. Every record is a HIPAA violation.

Sharing pages publicly that contain PHI. Notion's "Share to web" feature is a single click. A staff member publishes a page for convenience and forgets to unpublish it. If it contains patient information, it is now accessible to anyone on the internet.

Using Notion AI before the workspace is actually HIPAA-enabled. Notion covers AI on the same basis as the workspace, so the exposure is not the AI feature — it is using any of Notion with PHI while the Enterprise plan is in place but the BAA is unsigned or HIPAA compliance was never switched on.

Not restricting guest access to workspaces containing PHI. If a guest — a contractor, consultant, or vendor — is not covered by your compliance program and can access PHI, that is an unauthorized disclosure.

Frequently Asked Questions

Is Notion Free HIPAA compliant?

No. Notion Free does not support a Business Associate Agreement and does not provide the administrative controls required by the HIPAA Security Rule. Storing or referencing PHI on Notion Free is a violation regardless of workspace settings.

Does Notion sign a BAA?

Yes, but only for Enterprise plan customers. Notion introduced BAA support in 2024. The BAA covers pages, databases, wikis, and file uploads. You must request and execute it separately from the subscription purchase.

Can I use Notion AI with PHI?

That depends on your BAA terms. Notion AI processes content through large language models, and whether that processing is covered varies by agreement. Confirm directly with Notion before using AI features with any content that references patients. If AI is not covered, disable it for PHI-containing workspaces.

Is Notion safe for clinical SOPs?

SOPs, protocols, and workflow templates that do not contain patient-specific information are generally safe on any Notion plan. The risk begins when documents are filled in with patient names, diagnosis codes, or treatment details. Keep templates generic and store patient-specific records in a BAA-covered system.

What about Notion for team wikis that reference patients?

If your wiki includes information that could identify a patient in connection with a health condition — case notes, treatment summaries, patient-specific protocols — it contains PHI and requires a BAA-covered environment. On Notion, that means Enterprise with a signed BAA. Wikis limited to general policies and non-patient content are fine on any plan.


Patient Protect tracks your full compliance state, including vendor BAAs and documentation tool configurations, starting at $39/month.

Was this useful? Share it.

Share

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Next step

What would an OCR investigator find on your website?

Free 30-second scan — tracking pixels, security gaps, missing policies. See what’s visible before they do.

Stay informed

Subscribe to HIPAA Pulse.

Breach alerts, enforcement updates, and compliance intelligence — every two weeks.

© 2026 Patient Protect LLC. All rights reserved. Content may not be reproduced, scraped, or used to train AI models without written permission. Terms · DMCA