According to the company’s Help Center, Notion can be configured to enable HIPAA compliance; however, quite a few of its products are excluded from this type of use.
The Notion website states that HIPAA features are available to customers on an Enterprise Plan with more than 100 members. Business Associate Agreements (BAA) are offered, but not all features are covered by the agreement.
According to Notion’s FAQs about enabling HIPAA compliance, customers that need to use Notion for personal health information (PHI), should be aware of the the following limitations:
Notion cannot be used to communicate with patients, plan members, their families, or employees.
Users cannot include PHI in workspace or organization names, teamspace names, file names, account profiles, or user group names.
Support requests can’t contain PHI.