Splunk is an advanced and scalable data platform that indexes and searches log files across a system and analyzes data to generate operational intelligence. The software captures, correlates, and indexes real-time data to create alerts, dashboards, graphs, reports, and visualizations.

With Splunk, organizations can recognize common data patterns, diagnose potential problems, apply intelligence to business operations, and generate actionable metrics across IT, security, and healthcare.

Is Splunk HIPAA compliant? Yes, based on our research, Splunk can be HIPAA compliant.

 

What changed this year?

As of April 2026, our review did not identify any publicly disclosed changes to Splunk's HIPAA-related policies or BAA terms. Splunk's compliance page was updated in February 2026 and confirms that HIPAA-eligible products continue to undergo annual independent third-party audits.

 

Will Splunk sign a business associate agreement (BAA)?

Yes, Splunk will sign a business associate agreement, which can be reviewed and downloaded here. Customers subject to HIPAA who want to use HIPAA compliant Splunk Cloud products involving PHI must review and accept Splunk's BAA. Importantly, Splunk BAAs are not available for and do not apply to trials, evaluations, beta, or free licenses. A BAA executed in connection with any such license will be deemed null and void.

 

What does the Splunk BAA cover?

The Splunk BAA covers the use and disclosure of protected health information (PHI). Their Cloud Security Addendum states, "In the case of HIPAA, Splunk complies with the HIPAA security rule and data breach notification requirements for the processing of protected health information (PHI)."

Their HIPAA compliance commitments include:

  • Encryption of PHI in transit and at rest
  • Annual third-party HIPAA compliance audits
  • Breach notification procedures aligned with HITECH Act timelines
  • Audit logging and access controls across the Splunk Cloud Platform
  • HITECH Act compliance provisions incorporated directly into the BAA

 

What does the Splunk BAA exclude?

Splunk Cloud operates under a shared responsibility model. Splunk secures the underlying service, while customers are responsible for governing data inputs, configuring access controls, and validating that ePHI is properly minimized, masked, or protected end-to-end. Healthcare organizations should implement field hashing and masking at ingest to prevent unnecessary PHI from entering Splunk, and apply role-based access controls to limit exposure in results and dashboards.

HIPAA compliance at Splunk applies to Splunk Cloud Platform only; on-premises Splunk deployments are not covered by Splunk's BAA, and organizations running self-managed Splunk infrastructure are solely responsible for meeting HIPAA requirements in that environment.

 

Conclusion

Splunk signs a BAA and is therefore HIPAA compliant.

Learn more: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is a business associate agreement?

A business associate agreement (BAA) is a legally binding contract establishing a relationship between a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its business associates. The purpose of this agreement is to ensure the proper protection of personal health information (PHI) as required by HIPAA regulations.

 

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting the privacy and security of certain health information, known as protected health information (PHI).

HIPAA is designed to protect the privacy and security of individuals' health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.