What can we help you with?

monday.com and HIPAA

Your team's privacy and security are one of our top priorities! We know that you put your trust into monday.com every day to keep your team's information secure. We want to assure you that responsible custodianship of your data is one of the core values of our company. That's why we offer HIPAA-compliant plans so that you can trust that your sensitive healthcare data is safe and secure in your monday.com account. 


What is HIPAA?

The Health Insurance Portability and Accountability (HIPAA) act is designed to help protect people’s healthcare data. Organizations such as hospitals, doctors' offices, health plans, or companies dealing with protected health information (PHI) are required to be HIPAA-compliant. This may also extend to companies that work with these businesses and come into contact with PHI on their behalf.


Here are some key terms you should know:

  • Protected Health Information - PHI

Protected Health Information (PHI) is healthcare data relating to a patient and collected by a healthcare provider, employer, or plan. It includes names, social security numbers, phone numbers, medical history, current medical condition, test results, and more. PHI is the content that HIPAA aims to protect and keep private.

  • Covered entity

A covered entity is anyone who provides treatment, payment, and operations in healthcare. Examples include doctors, hospitals, pharmacies, insurance companies, and more. These covered entities are responsible for the privacy and security of health information.

  • Business associate

A business associate is anyone who has access to a patient's information whether it is directly, indirectly, physically, or virtually. A business associate does not work under the covered entity’s workforce but instead performs some type of service on their behalf (i.e. a lawyer, a phone company, etc...). A business associate is subject to HIPAA/HITECH rules.

  • Business associate agreement (BAA)

A BAA is a contractual assurance from the business associate to the covered entity that they follow HIPAA's requirements. This agreement must be in place before the transfer of PHI from the covered entity to the business associate. You can read our BAA here.


Is monday.com HIPAA-compliant?

HIPAA is available on monday.com on our Enterprise plan. Please note that if you are on this plan and later downgrade to another plan, you will no longer be covered under the HIPAA compliance program anymore. 

You can reach out to a Customer Success Agent or to your account manager to set up your account as HIPAA compliant. This feature will only be granted to Enterprise plans with 25 users or more. 


Note: On all HIPAA-compliant Enterprise plans, the broadcast feature and the ability to preview files are disabled to prevent accidental disclosure of Protected Health Information (PHI). Account admins that are interested in enabling preview of PDF files for their account may contact us for additional details.



How to set up BAA with monday.com

In order for your account to be HIPAA compliant, you must first sign on to the BAA and configure your account as HIPAA. You can sign a BAA electronically in just a few steps:

  • Click on your profile picture at the bottom left of your screen
  • Select Admin
  • Click on Security and then choose Compliance
  • Click on the BAA link and then review and accept the BAA
Once done, click on "activate HIPAA" and you are all set. 

How to activate/deactivate HIPAA

To activate the HIPAA, follow the below steps:
  • Click on your profile picture at the bottom right of your screen
  • Select Admin
  • Click on Security and then Compliance
  • Click on "activate"



To deactivate the HIPAA:

  • Follow the same steps as the section above, and click on "deactivate"



Note: Once this action is performed, all admins in the account will receive an email that HIPAA compliance has been deactivated.


Is the monday.com mobile app HIPAA compliant? 
Yes, our mobile app is HIPAA compliant starting from version 3.331 for iOS and version 3.190715 for Android.

How to keep your data secure

We want to make it as easy as possible for you to learn how to keep your account secure and meet your legal requirements. We have put together a few tips that you should consider when configuring your accounts.

1. Strengthen authentication

We recommend using one of these two security features to add a layer of protection to your monday.com account:


2. Conduct regular access reviews

To ensure that any sensitive data in your monday.com account can only be accessed by appropriate people, we recommend that you frequently review the list of your members. To learn how to access this list, check out this article.


3. Monitor for unusual activity

As an admin, you have the ability to control the sessions for all account users through the Audit Log.

The Audit Log allows you to see when the users have last logged into the account, what device they used, and what their IP address for the session was. In case of any suspicious activities, you can activate the Panic Button.


4. Evaluate third-party apps

Our Integrations allow you to seamlessly connect monday.com to external platforms and turn your monday.com account into your personal work hub. While these third-party apps can be great complements to your account, it’s important to remember that they’re not part of our included services. If you want to keep the HIPAA compliance, you must ensure that any third-party app or service you use will also be HIPAA compliant. 


If you have any questions, please reach out to our team by using our contact form. We're available 24/7 and happy to help!

Have more questions? Submit a request