Is Slack HIPAA Compliant? Only in an Enabled Workspace
An enterprise Slack plan and a BAA are not enough. Salesforce requires the HIPAA Enabled SKU and coverage only reaches workspaces actually designated HIPAA-enabled.
Written and reviewed by the Patient Protect team — Joseph A. Perrin, CTO (federal infrastructure background, platform security architect), Angie Perrin, CSO (Certified HIPAA Consultant, 10+ years clinical practice), and Alexander Perrin, CEO (20 years enterprise SaaS, primary author of the Secure Care Research Institute research program). See editorial standards.

What actually puts a Slack workspace under the BAA
The controlling document is Salesforce's BAA Restrictions, not Slack's help article — the help article omits two of the four prerequisites. Coverage requires all of these:
- An eligible enterprise-level Slack plan. GovGrid plans are not eligible for BAA coverage.
- A business associate agreement.
- The "Slack - HIPAA Enabled" SKU. For workspaces provisioned on or after 20 March 2023, Salesforce requires purchasing this SKU alongside the covered enterprise plan. Workspaces provisioned before that date needed advance written notice to Slack naming each organization or workspace, and written confirmation back that HIPAA readiness had been enabled.
- The organization or workspace designated as HIPAA-enabled. Once designated, Slack sets the backend HIPAA flag for every workspace inside that organization, including workspaces created later.
The sentence to take seriously is Salesforce's own: BAA coverage will not automatically extend to every organization or workspace owned by a given customer — only those appropriately designated as HIPAA-enabled.
That is the failure mode worth planning around. A practice signs the contract, believes Slack is now covered, and a team starts discussing patients in a workspace that was never designated. The paperwork is real. The coverage is not.
On plan naming: Slack's current pricing calls its enterprise offering Enterprise+, while Slack's HIPAA help documentation still uses the Enterprise Grid name and Salesforce's BAA Restrictions refers to "Enterprise+ and legacy Grid customers." Confirm the applicable enterprise offering with Slack when you contract rather than assuming the name on your invoice matches the name in the compliance document.
Where PHI may and may not go
Even inside a HIPAA-enabled workspace, Salesforce's BAA Restrictions draw a specific line. PHI is permitted in:
- the contents of messages
- files
- huddles, and video and audio clips
- data submitted to custom apps your organization builds to run on Slack infrastructure
PHI is prohibited in:
- Slack user profile data, and custom Slack profile fields
- custom emoji names
- custom statuses
- workspace or organization names, and URL domains
- Enterprise Mobility Management custom messages
- the name or handle of user groups
- custom platform app and workflow metadata — including app name, function name, workflow name, function code, and datastore information
Slack's own help article describes a slightly wider permitted set, including file names and the names of private channels and DMs. Where the contract document is narrower, follow the contract document.
Three further limits apply:
- No patient, member, family or employer communication. Slack may not be used to communicate with patients, plan members, or their families or employers, and those people may not be added as users or guests to any workspace or channel.
- Support requests must not contain PHI. That includes the
/feedbackcommand, the Slack website contact form, and Slack's live chat — no PHI in the request and none in attached screenshots or documents. - Marketplace and third-party apps are not covered. Slack's BAA does not extend to third-party application providers, including those in the Slack Marketplace. Any app touching PHI needs its own agreement with that provider. Slack also states it does not maintain the designated record set and should not be your system of record.
If you use Slack Connect to work across organizations, you are responsible for confirming you have permission to share PHI with those recipients.
For most independent practices — dental offices, therapy practices, small medical groups — an enterprise Slack contract plus a HIPAA-enabled SKU is not a realistic purchase. Most need HIPAA-compliant messaging on an accessible tier instead.
What an enterprise Slack plan provides
On an enterprise plan, in a workspace that has been HIPAA-enabled, Slack provides a set of security and administrative controls that support HIPAA compliance for internal team messaging. These controls are what the enterprise tier buys you; they are not themselves what puts the workspace under the BAA:
Business Associate Agreement. Salesforce will sign a BAA covering an eligible enterprise Slack plan. The BAA defines Slack's obligations as a business associate for handling PHI transmitted through channels, direct messages, and file sharing within the platform. This is available only on an eligible enterprise-level plan — no other Slack plan qualifies — and the agreement alone still does not cover a workspace that has not been designated HIPAA-enabled.
Enterprise Key Management (EKM). EKM gives your organization control over the encryption keys used to protect messages and files in Slack. You manage the keys through AWS KMS, meaning you can revoke access to your data at any time without depending on Slack to do it. This is a critical capability for meeting the HIPAA Security Rule's encryption requirements.
AES-256 encryption at rest and TLS 1.2+ in transit. All messages, files, and search indexes stored by Slack are encrypted at rest using AES-256. Data in transit between your devices and Slack's servers is protected by TLS 1.2 or higher. These are baseline encryption standards that satisfy HIPAA's technical safeguard requirements.
Data Loss Prevention (DLP) integrations. The enterprise tier supports integration with third-party DLP tools that can scan messages and files for PHI patterns — Social Security numbers, medical record numbers, diagnosis codes — and flag or block them before they reach unintended recipients.
eDiscovery and data export. Administrators can export all messages, files, and audit events from every workspace in the organization. This supports HIPAA's requirement for maintaining access to ePHI and producing records when required for compliance audits or OCR investigations.
Granular admin controls across workspaces. The enterprise tier operates as an organization-level layer above individual workspaces. Org admins can enforce security policies, manage user provisioning, and apply consistent settings across every workspace — something lower-tier Slack plans cannot do.
Audit logging with event API. The enterprise tier provides detailed audit logs tracking user actions — logins, file downloads, channel access, app installations — accessible through Slack's Audit Logs API. These logs support the HIPAA Security Rule's audit control requirements.
SAML-based SSO and session management. The enterprise tier supports SAML 2.0 single sign-on, allowing integration with your identity provider. Combined with domain claiming and session duration controls, this ensures only authorized users access PHI-containing workspaces and that sessions expire according to your security policies.
Why Most Slack Plans Fail HIPAA
The gap between Slack's enterprise tier and every other Slack plan is not incremental. It is structural. The security capabilities that make HIPAA compliance possible simply do not exist on lower tiers.
No BAA available. Slack's HIPAA documentation requires an enterprise-level plan, so Free, Pro and Business+ are outside it. This alone disqualifies those plans. Under HIPAA, any vendor that handles PHI on your behalf must execute a BAA before receiving that data. No BAA means no compliant use — regardless of encryption, passwords, or any other setting you configure.
No Enterprise Key Management. Without EKM, you have no control over the encryption keys protecting your data. Slack holds the keys. You cannot revoke access independently, and you have no mechanism to ensure your data is inaccessible if you terminate the relationship.
Limited admin controls. Pro and Business+ plans provide workspace-level administration, but they lack the organization-level governance layer the enterprise tier provides. You cannot enforce consistent security policies across multiple workspaces or manage user access at the scale HIPAA requires.
No DLP capabilities. Without DLP integrations, there is no automated mechanism to detect or prevent PHI from being shared in channels, messages, or files. Staff can paste patient names, diagnosis codes, or insurance information into any channel without the system flagging it.
Limited data retention controls. Lower-tier plans offer basic message retention settings, but they lack the granular retention policies and comprehensive data export capabilities needed for HIPAA compliance documentation and incident response.
The bottom line: the features HIPAA demands are only available on the plan designed for enterprises. That is a deliberate product decision by Salesforce, and it means Slack's HIPAA-compliant offering is priced and scoped for organizations far larger than a typical independent practice.
Settings to configure once the workspace is enabled
The four prerequisites above establish coverage. They do not configure it. These are the settings to apply before any PHI enters an enabled workspace:
- Confirm the workspace is designated HIPAA-enabled — not merely that a BAA exists. Coverage attaches to designated organizations and workspaces rather than to your account, so verify the designation reaches the specific workspace your team will use.
- Execute the BAA with Salesforce/Slack — this must be completed before any PHI is transmitted. It is not automatic with an enterprise purchase. You must request it, review the terms, and formally execute it.
- Enable Enterprise Key Management — configure EKM with your AWS KMS keys. This gives you direct control over encryption and the ability to revoke access if needed.
- Configure data retention policies — set retention windows appropriate for your compliance requirements. HIPAA requires that ePHI be available for a minimum of six years. Ensure your retention settings do not delete messages or files that may contain PHI before that window closes.
- Restrict file uploads to approved channels — create designated channels for any workflow that may involve PHI and restrict file sharing outside those channels. This limits the surface area for accidental disclosure.
- Disable third-party app integrations without BAAs — every Slack app or integration that could access message content or files must have its own BAA. If it does not, disable it. Bots, workflow automations, and custom integrations all fall under this requirement.
- Enable SSO with MFA — require SAML-based single sign-on with multi-factor authentication for every user. Password-only access does not meet HIPAA's access control requirements.
- Set up DLP policies for PHI patterns — configure your DLP integration to detect and flag common PHI identifiers: names combined with dates of birth, Social Security numbers, medical record numbers, and insurance IDs.
- Restrict external guest access — disable or tightly control Slack Connect and guest accounts. External users who are not covered by your BAA and compliance program should not have access to channels where PHI may be discussed.
These settings should be applied at the organization level by an administrator and documented as part of your compliance program.
The Independent Practice Reality
Here is where the practical analysis matters more than the technical analysis.
Slack does not publish a price for its enterprise tier — the pricing page lists it as contact-sales — and the HIPAA-Enabled SKU is a further line item on top of it. We are not going to invent a number for either. What we can say is the shape of the purchase: an enterprise contract quoted by a salesperson, plus an add-on SKU, plus the administrative work of designating and governing workspaces. For a five-person dental office, a ten-provider therapy practice, or a small medical group, that is rarely the right shape. Visit Slack's pricing page for current details.
This does not mean your practice cannot have HIPAA-compliant team messaging. It means Slack is not the right tool for the job at your scale. Several alternatives are worth evaluating:
Microsoft Teams. Microsoft 365 Business plans (starting at $6/user/month for Business Basic) support BAA execution. The BAA covers Teams, Exchange, SharePoint, and OneDrive — giving you compliant messaging, email, and file storage in a single agreement. For independent practices, this is a significantly more accessible path to compliant team communication. See our full breakdown of Microsoft Teams and HIPAA for the configuration details.
HIPAA-compliant messaging platforms. Purpose-built platforms designed for healthcare teams — such as TigerConnect, OhMD, or Halo Health — offer HIPAA-compliant messaging with BAAs at price points appropriate for small practices. These platforms are designed specifically for clinical communication workflows.
Patient Protect. Patient Protect includes HIPAA-compliant secure messaging as part of the platform, starting at $39/month. It is built specifically for independent practices that need compliant communication without the overhead of enterprise licensing. See full platform features or the broader category of HIPAA-compliant tools your stack should cover.
The right choice depends on your practice size, your existing tooling, and your budget. The wrong choice is using a non-compliant Slack plan and hoping no one notices.
Common Mistakes with Slack and HIPAA
These are the errors that create real compliance exposure — and they happen more often than most practice owners realize.
Using Slack Pro or Business+ and assuming it is compliant. This is the most common mistake. Practices see that Slack uses encryption and assume encryption equals compliance. It does not. Without a BAA, encryption is irrelevant to HIPAA compliance. The BAA is a threshold requirement, it is only available on an eligible enterprise-level plan, and even then it reaches only workspaces designated HIPAA-enabled.
Discussing patient cases in Slack channels without a BAA in place. Internal Slack channels feel private. They are not. Any discussion that includes patient names, conditions, treatment details, or other PHI in a Slack workspace without a BAA is an unsecured disclosure of ePHI. Every message is a separate violation.
Staff using personal Slack workspaces for practice communication. When your practice does not provide a sanctioned communication tool, staff improvise. Personal Slack accounts, text messages, and consumer messaging apps become the de facto communication layer. None of them have BAAs. All of them create exposure.
Not restricting third-party Slack apps and integrations. Slack's app marketplace includes thousands of integrations — project management tools, file converters, scheduling bots, AI assistants. Each one that accesses message content or files is a potential business associate under HIPAA. Unvetted integrations are uncontrolled data exposure.
Sharing PHI in direct messages thinking DMs are private enough. Direct messages in Slack are not end-to-end encrypted. Slack can access them. Without a BAA, that access is an unauthorized disclosure. Privacy is not the same as compliance, and "private enough" is not a HIPAA standard.
Frequently Asked Questions
Is Slack Free HIPAA compliant?
No. Slack Free does not support a Business Associate Agreement, does not offer Enterprise Key Management, and does not provide the administrative controls required by the HIPAA Security Rule. Using Slack Free to transmit any protected health information is a HIPAA violation.
Does Slack sign a BAA?
Yes, for an eligible enterprise-level plan. Free, Pro and Business+ are outside it. But a signed BAA on its own does not make a workspace covered — Salesforce states coverage does not automatically extend to every organization or workspace you own, and since 20 March 2023 designation requires the "Slack - HIPAA Enabled" SKU. The BAA must be specifically requested and executed as part of your enterprise deployment — it is not automatic.
Can I use Slack for patient communication?
No. Salesforce's BAA Restrictions state Slack may not be used to communicate with patients, plan members, or their families or employers, and that those people may not be added as users or guests to any workspace or channel. This is a contractual limit, not a configuration choice. Using Slack as a patient-facing communication tool introduces risks that the platform was not designed to address — including patient identity verification, consent management, and access controls for external users.
Which Slack plan is HIPAA compliant?
Only an eligible enterprise-level plan — sold today as Enterprise+, and referred to as Enterprise Grid in Slack's HIPAA documentation and as "legacy Grid" by Salesforce. The plan is a prerequisite, not the whole answer: you also need the BAA, the "Slack - HIPAA Enabled" SKU for workspaces provisioned since 20 March 2023, and the specific organization or workspace designated as HIPAA-enabled. Then Enterprise Key Management and the administrative settings outlined above properly configured. No other Slack plan qualifies.
Is there a HIPAA-compliant Slack alternative for small practices?
Yes. Microsoft Teams supports BAA execution on business plans starting at $6/user/month. Purpose-built healthcare messaging platforms like TigerConnect and OhMD offer compliant communication designed for clinical teams. Patient Protect includes secure messaging as part of its compliance platform starting at $39/month. Any of these are more practical for independent practices than an enterprise Slack contract plus a HIPAA-Enabled SKU.
Patient Protect tracks your full compliance state, including vendor BAAs and communication tool configurations, starting at $39/month.
Corrections & Updates
Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.
