Vendor compliance profile
Is Zapier HIPAA compliant?
Zapier should not be used to automate workflows involving PHI. Zapier's own HIPAA guidance says it is not HIPAA compliant and should not be used to store, send, or automate protected health information, even though Zapier maintains SOC 2 security evidence.
HIPAA status signal
Not supported for PHI
BAA public signal
Unable to confirm
SOC 2 evidence signal
Public evidence
PHI warning: Zaps can copy PHI across forms, CRMs, spreadsheets, email, AI tools, storage, webhooks, logs, task history, and connected app metadata.
HIPAA, BAA, and SOC 2 summary
| HIPAA | Zapier states in its HIPAA guidance that it is not HIPAA compliant and that customers should not automate workflows involving PHI through Zapier. |
|---|---|
| BAA | Unable to confirm public BAA availability for PHI workflows. Treat Zapier as out of scope for regulated PHI automation unless Zapier directly provides current written terms for your exact product and workflow. |
| SOC 2 | Zapier's security and compliance documentation references SOC 2 Type II and SOC 3 reports available through its Trust Center. SOC evidence does not override the stated HIPAA limitation. |
| Category | HIPAA-Compliant Forms and Intake Software |
What it may be used for
- General business workflows that do not include PHI.
- Healthcare-adjacent operations after BAA scope and configuration have been verified.
- Vendor risk review, procurement research, and compliance planning.
What not to use it for
- Moving patient intake responses, diagnosis details, appointment reasons, files, or identifiers between SaaS tools.
- Using webhook payloads, task history, or AI automation with PHI.
- Treating SOC 2 evidence as permission to process PHI.
What to verify with the vendor
- Whether the vendor will sign a BAA for your exact product, plan, and use case.
- Which services, add-ons, regions, and support channels are covered by the agreement.
- Whether your intended workflow stores, transmits, or processes PHI.
- Which admin, access control, retention, audit log, and encryption settings must be enabled.
Safer alternatives and related profiles
FAQ
Is Zapier HIPAA compliant?
Zapier should not be used to automate workflows involving PHI. Zapier's own HIPAA guidance says it is not HIPAA compliant and should not be used to store, send, or automate protected health information, even though Zapier maintains SOC 2 security evidence.
Will Zapier sign a BAA?
Unable to confirm public BAA availability for PHI workflows. Treat Zapier as out of scope for regulated PHI automation unless Zapier directly provides current written terms for your exact product and workflow.
Can Zapier be used with PHI?
Do not use this vendor with PHI until your organization verifies BAA scope, covered services, configuration, access controls, data retention, and connected integrations.
Last checked and source notes
- Last checked
- 2026-04-30
- Confidence
- High
- Dataset rows
- 267 vendors
- ComplySaaS public vendor dataset entry.
- Vendor trust center, legal terms, BAA documentation, and covered services should be re-checked before use.
- Zapier: Is Zapier HIPAA compliant?
- Zapier security and compliance