Adobe Experience Platform is a customer experience data platform that enables organizations to collect, standardize, and integrate data from multiple systems. It can create unified customer profiles and support analytics, data governance, audience management, and personalized experiences.
With Adobe Experience Platform, organizations can centralize customer data and make it available to Adobe applications and approved destinations.
Is Adobe Experience Platform HIPAA compliant? Yes, Adobe Experience Platform can be HIPAA compliant, but there are limitations.
What changed this year?
As of August 2026, our review identified a material change in Adobe's public guidance compared with our 2025 assessment. An Adobe Experience League page updated April 30, 2026, now tells customers implementing healthcare use cases to ensure that Adobe Experience Platform is provisioned as a HIPAA eligible service and that a BAA is in place with Adobe.
Adobe's HIPAA guidance, updated in May 2026, confirms that Adobe acts as a business associate for its designated HIPAA ready services and makes business associate agreements (BAAs) available for those services. However, the current list names specific AEP-based applications and editions rather than Adobe Experience Platform as an unrestricted standalone service.
Adobe also expanded Healthcare Shield to include Health Data-Ready Services for certain consumer health data that may fall outside HIPAA. This expansion does not remove the separate licensing, provisioning, and BAA requirements that apply when a customer processes PHI.
Will Adobe Experience Platform sign a BAA?
Yes, Adobe will sign a BAA for its designated HIPAA-ready services. For an Adobe Experience Platform use case, the organization must confirm that its particular AEP instance, licensed applications, features, and data flows are included in the HIPAA-eligible configuration and the executed BAA.
Adobe does not provide a public, self-service AEP BAA for review. Its HIPAA guidance directs customers to contact their Adobe sales representative or customer success manager to execute a BAA for HIPAA-ready services.
What does the Adobe Experience Platform BAA cover?
Adobe does not publicly post the full AEP-specific BAA, so its precise contractual coverage must be confirmed in the executed agreement. Adobe's current healthcare documentation says organizations must ensure that AEP is "provisioned as a HIPAA-eligible service" before using it for healthcare patterns involving PHI.
The current public list of HIPAA-ready AEP-based services includes:
- Adobe Customer Journey Analytics, excluding CJA Labs
- Adobe Customer Journey Analytics B2B Edition, excluding CJA Labs
- Adobe Journey Optimizer
- Adobe Real-Time Customer Data Platform B2C Prime and Ultimate Editions
- Adobe Real-Time Customer Data Platform B2P, limited to Consumer Audiences in the Prime and Ultimate Editions
Adobe's product description for Real-Time CDP describes Healthcare Shield as an Adobe Experience Platform add-on. Depending on the licensed application, Healthcare Shield provides:
- Automated consent policy enforcement
- Customer-managed encryption keys
- Extended thresholds for automated dataset expiration
- Additional privacy, governance, and security controls for HIPAA-ready use
Adobe's public documentation does not establish that every AEP feature is automatically covered. Healthcare organizations must check the service names and editions in their sales order and BAA before placing PHI in the platform.
What does the Adobe Experience Platform BAA exclude?
Adobe excludes products and services that are not designated as HIPAA-ready or are not covered by the customer's correct license and signed BAA. Adobe's Trust Center guidance states, "Customers are not permitted to create, receive, maintain, or transmit PHI" through services outside that approved scope.
This means a standard or unprovisioned AEP environment should not be treated as suitable for PHI. The current public scope also excludes CJA Labs and does not extend to unlisted editions or applications merely because they connect to AEP.
Adobe's datastream documentation provides a practical example. When schemas contain sensitive-data labels, Adobe permits the data to be sent to AEP but disables Adobe Target, Adobe Analytics, Adobe Audience Manager, event forwarding, and edge destinations because those destinations are not HIPAA-ready for that workflow.
Individual features also require separate review. For example, Adobe states that AI Assistant is HIPAA ready only when it is used with Adobe Experience Platform Healthcare Shield.
Conclusion
Adobe Experience Platform may be HIPAA compliant, but only when it is provisioned as HIPAA eligible, used with the correct HIPAA-ready services and Healthcare Shield where required, and covered by a signed BAA. A standard AEP deployment or an unlisted connected service should not be used to create, receive, maintain, or transmit PHI.
See also: HIPAA Compliant Email: The Definitive Guide
FAQs
What is a BAA?
A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.
What is HIPAA?
HIPAA sets national standards for protecting the privacy and security of certain health information, known as PHI.
HIPAA is designed to protect the privacy and security of individuals' health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.
Who does HIPAA apply to?
HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.
