Paubox blog: HIPAA compliant email - easy setup, no portals or passcodes

Is Canva HIPAA compliant? (2025 update)

Written by Kirsten Peremore | August 29, 2025

Canva is a visual communication platform empowering users to create designs like presentations, social graphics, and more. Based on current information, Canva is not HIPAA compliant, as it does not engage in any HIPAA-specific safeguards or BAA agreements.

 

Will Canva sign a Business Associate Agreement (BAA)?

No, Canva does not sign a BAA and offers no indication that it will. Therefore, it is not HIPAA compliant.

 

Conclusion

Canva does not sign BAAs and is, therefore, not HIPAA compliant.

See also: HIPAA Compliant Email: The Definitive Guide (2025 Update)

 

FAQs

What is a BAA?

A legally binding contract between a HIPAA-covered entity and its vendor (business associate), obligating proper protection of PHI under HIPAA rules.

 

What is HIPAA?

HIPAA sets standards to safeguard individuals' PHI and ensure secure electronic exchange of health data.

 

Who does HIPAA apply to?

HIPAA applies to covered entities (e.g., healthcare providers, health plans, clearinghouses) and their business associates—vendors handling PHI on behalf of covered entities.