1 min read

Is Hightail HIPAA compliant? (2025 update)

Is Hightail HIPAA compliant? (2025 update)

Hightail is a cloud-based file sharing and collaboration service that enables users to send, receive, and manage large files securely. 

With Hightail, organizations can share documents, images, and creative assets with encryption and access controls.

Is Hightail HIPAA compliant? No, based on our research, Hightail is not HIPAA compliant.

 

Will Hightail sign a business associate agreement (BAA)?

No, Hightail will not sign a business associate agreement, and therefore is not HIPAA compliant.

 

What does the Hightail BAA exclude?

Hightail explicitly states that it is not subject to HIPAA compliance. While it provides encryption (SSL/TLS, AES 256-bit) and secure data centers, these features alone do not meet HIPAA requirements without a BAA.

 

Conclusion

Hightail does not sign a BAA and is therefore not HIPAA compliant.

Learn more: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is a business associate agreement? 

A business associate agreement (BAA) is a legally binding contract establishing a relationship between a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its business associates. The purpose of this agreement is to ensure the proper protection of personal health information (PHI) as required by HIPAA regulations.

 

What is HIPAA? 

The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting the privacy and security of certain health information, known as protected health information (PHI).

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities.

Subscribe to Paubox Weekly

Every Friday we'll bring you the most important news from Paubox. Our aim is to make you smarter, faster.