Venmo is a mobile payment service operated by PayPal that allows users to send and receive money, pay participating businesses, and accept payments through business profiles.

Is Venmo HIPAA compliant? No, based on our research, Venmo is not HIPAA compliant.

 

What changed this year?

As of July 2026, our review did not identify any publicly disclosed changes to Venmo’s HIPAA-related policies or BAA terms.

Venmo introduced a revised User Agreement effective May 19, 2026, and has published another version that will take effect on August 24, 2026. The forthcoming changes concern Venmo’s arbitration provision and Venmo Stash terms and do not introduce a BAA or describe Venmo as suitable for HIPAA regulated uses. Venmo’s current Privacy Statement remains effective as of November 17, 2025.

 

Will Venmo sign a business associate agreement (BAA)?

No, Venmo does not publicly offer a BAA and therefore should not be used to create, receive, maintain, or transmit protected health information (PHI) on behalf of a covered entity.

The HHS states that a financial institution may become a business associate when it performs services “above and beyond” payment processing, such as accounts receivable functions on behalf of a healthcare provider. Because Venmo does not offer a BAA, it should not be used for those additional functions.

Healthcare organizations should also prevent patients and staff from entering diagnoses, treatment information, appointment details, or other PHI into payment notes. Venmo states that payment participants can always see the amount, note, sender and recipient names, and transaction timestamp. When a payment is set to Public or Friends, the note and participant names may also be shared more broadly.

 

Conclusion

Venmo does not publicly offer a BAA and is therefore not HIPAA compliant for activities involving the handling of PHI. It may be used strictly for payment-processing activities covered by HIPAA’s Section 1179 exception, but healthcare organizations should keep PHI out of transaction notes and should not use Venmo for services that extend beyond processing payments.

See also: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is a BAA?

A BAA is a legally binding contract establishing a relationship between a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.

 

What is HIPAA?

HIPAA sets national standards for protecting the privacy and security of certain health information.

HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.