Is Notion HIPAA Compliant?
Learn how Notion can be used to handle sensitive PHI in compliance with HIPAA standards.
Is Notion HIPAA Compliant?
Notion is a productivity app offering a range of organizational tools such as task management, project tracking, and web bookmarking. A large number of organizations, including healthcare organizations, use Notion for tasks such as project management, collaboration, and documentation.
The good news is that Notion can be used in a way that is HIPAA compliant. However, healthcare organizations should note that Notion’s basic plans are not suitable for handling PHI. In order to comply with HIPAA’s technical safeguarding requirements, specific configuration settings must be applied within Notion.
Notion can be configured to support the following security measures:
To make their Notion workspace HIPAA compliant, users must take the steps that effectively enable these security measures.
To comply with HIPAA, third-party vendors must have a Business Associate Agreement (BAA) in place with their partners.
Notion does offer a BAA that governs the protection of all Personal Health Information (PHI) stored in Notion. However, the BAA is only available to customers that are subscribed to Notion’s Enterprise plan and have more than 100 members.
Also note that, in meeting the terms of the BAA agreement and maintaining compliance with HIPAA, certain Notion features are not usable. These restricted features include Notion Calendar and Cron-related features, and the Notion AI Add-on.
Notion is designed as a general-purpose organization and collaboration tool. The standard plans are not designed, or able, to meet the stringent data security requirements of HIPAA, particularly around safeguarding PHI.
PHI and sensitive patient data can be stored in Notion, but only by organizations on an Enterprise plan that is configured specifically to safeguard PHI. Without implementing these required configuration settings, you risk non-compliance with HIPAA and open yourself up to significant litigation and legal risks.
Considering Notion’s use as a collaboration tool, where data can be easily shared, collaborated and exported concerns over data leaks are warranted. There are legitimate concerns over unauthorized access, but leaks of PHI and patient data from Notion could arise from multiple failures including misconfigured permissions and data interceptions.
At a minimum, the safe handling and effective safeguarding of PHI in Notion requires a BAA and a HIPAA compliant configuration.
The Strac Notion DLP app prevents data leaks, by automatically detecting and redacting sensitive data in messages and files from Notion pages, blocks, and comments.
The Strac Notion DLP adds an additional layer of security to Notion workspaces. This is a solution that is built around Strac’s extensive experience in securing Endpoint & SaaS apps.
Learn more about how Strac can help organizations comply with HIPAA with our guide to HIPAA Compliance and our complete range of DLP integrations.
Schedule a free 30-minute demo to learn more.