New Relic is an observability platform that helps software and IT teams monitor applications, infrastructure, logs, and other telemetry data to identify performance and reliability issues.

With New Relic, organizations can collect and analyze metrics, events, logs, and traces across their technology environments.

Is New Relic HIPAA compliant? Yes, New Relic can be HIPAA compliant.

 

What changed this year?

In February 2026, New Relic updated its public HIPAA scope documentation. The current page lists seven services as outside the business associate agreement (BAA) ; Community Cloud for Pixie, Pixie auto-telemetry, Schedule NRQL Searches, New Relic AI Model Context Protocol, Response Intelligence RAG Data Indexing and Management, Agentic Platform, and SRX Agent.

New Relic continues to offer a BAA for eligible services. Its current documentation also states that it has discontinued HITRUST r2 certification and now relies on a third-party HIPAA attestation as evidence of its HIPAA controls.

 

Will New Relic sign a BAA?

Yes, New Relic will sign a BAA. Its HIPAA & BAA FAQ can be reviewed here, although customers must contact their New Relic account executive to obtain and sign the BAA.

According to New Relic’s HIPAA enablement requirements, a healthcare organization must have a current Enterprise subscription with the Data Plus option, or another subscription approved by New Relic. A New Relic representative must also confirm in writing that the HIPAA-enabled account is ready before the organization sends protected health information (PHI).

 

What does the New Relic BAA cover?

New Relic states, “The New Relic BAA is an addendum to the main agreement between New Relic and our customer and forms part of that agreement.”

The BAA and related public documentation cover:

  • Eligible services within the New Relic Observability Platform on AWS and first-party infrastructure
  • Limited, incidental PHI in permitted telemetry data, such as an IP address, an email address, or limited data elements captured in a log
  • Confidentiality and security controls for customer data
  • The use of approved business associates that undergo New Relic’s security and privacy review
  • Notification and assistance if a breach at New Relic affects customer data
  • Independent assessment of New Relic’s HIPAA security and privacy controls

New Relic explains, “We engineered our HIPAA offering using the same privacy and security framework we used for FedRAMP.” The customer remains responsible for configuring the account correctly, controlling the telemetry sent to New Relic, limiting user access, and complying with HIPAA.

 

What does the New Relic BAA exclude?

The New Relic BAA does not cover every New Relic service or every type of health information. New Relic’s terms state, “You agree that you will not send Designated Record Sets, substantial portions of Designated Record Sets, or any other health records in full.”

The restriction includes full medical claims, pharmacy claims, electronic prescriptions, medical images, clinical case notes, billing records, explanations of benefits, and other complete health records. New Relic cannot be used as an electronic medical record, a personal health record, a health information exchange, or a system of record for patient care or payment.

The current HIPAA scope page also excludes Community Cloud for Pixie, Pixie auto-telemetry, Schedule NRQL Searches, New Relic AI Model Context Protocol, Response Intelligence RAG Data Indexing and Management, Agentic Platform, and SRX Agent from BAA coverage.

Additional limitations apply. HIPAA enabled accounts must use the US data region. Organizations must disable log patterns, cannot place PHI in alert conditions or use email as the notification channel for an alert policy containing PHI, and cannot send PHI through New Relic’s Zoom, Google Workspace, or Slack support channels. New Relic’s unpaid-account terms prohibit PHI and state that New Relic is not acting as a HIPAA business associate for those services.

 

Conclusion

New Relic can be HIPAA compliant, but only for eligible services used through a properly configured HIPAA-enabled account under a signed BAA. It is not HIPAA compliant for unpaid accounts, excluded services, or use cases involving full health records and other prohibited data.

See also: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is a BAA?

A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.

 

What is HIPAA?

HIPAA sets national standards for protecting the privacy and security of certain health information, known as PHI.

HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.