Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
HIPAA-covered entities and business associates must execute a separate Business Associate Addendum with Asana to establish HIPAA-compliant use of the platform; the standard DPA alone does not provide HIPAA coverage.
This analysis describes what Asana's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that HIPAA compliance requires a separately executed BAA, which is an operationally distinct step from the DPA incorporation by reference, creating an affirmative obligation for healthcare-regulated customers to independently execute this agreement.
This provision establishes that organizations subject to HIPAA must execute Asana's Business Associate Addendum as a separate step to enable HIPAA-compliant use. Under these terms, use of Asana without a BAA by a HIPAA-covered entity may not satisfy the organization's regulatory obligations.
Cross-platform context
See how other platforms handle HIPAA Compliance via Separate Business Associate Addendum and similar clauses.
Compare across platforms →Monitoring
Asana has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Businesses that are subject to HIPAA can use Asana to support HIPAA-compliant work management. HIPAA compliance for Asana is governed by Asana's Business Associate Addendum (BAA).Excerpt from Asana's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision directly implicates HIPAA's Privacy and Security Rules, enforced by HHS Office for Civil Rights. A BAA is a mandatory contractual requirement under HIPAA for covered entities and business associates engaging service providers with access to protected health information. Absence of a BAA where required constitutes a HIPAA compliance gap. (2) GOVERNANCE EXPOSURE: High for healthcare-regulated customers. The standard DPA does not substitute for the BAA, meaning healthcare organizations using Asana without executing the BAA may face HIPAA exposure regardless of the DPA's security commitments. (3) JURISDICTION FLAGS: US healthcare organizations, including covered entities and their business associates, face heightened exposure. The provision applies federally across all US jurisdictions; some states have additional health data privacy laws (such as Washington's My Health MY Data Act) that may impose further requirements. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams at healthcare organizations should confirm BAA execution prior to deploying Asana for any workflow that may involve protected health information. The document references an Asana HIPAA Data Sheet for additional detail, which should be reviewed as part of vendor due diligence. (5) COMPLIANCE CONSIDERATIONS: Healthcare compliance teams should document BAA execution, confirm the BAA version aligns with current HIPAA regulatory requirements, and assess whether Asana's technical and organizational measures (as disclosed in the Trust Center) satisfy their Security Rule obligations.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that HIPAA compliance requires a separately executed BAA, which is an operationally distinct step from the DPA incorporation by reference, creating an affirmative obligation for healthcare-regulated customers to independently execute this agreement.
This provision establishes that organizations subject to HIPAA must execute Asana's Business Associate Addendum as a separate step to enable HIPAA-compliant use. Under these terms, use of Asana without a BAA by a HIPAA-covered entity may not satisfy the organization's regulatory obligations.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Asana.