The agreement prohibits uploading or processing HIPAA-regulated protected health information in Cloud Products unless a separate Business Associate Agreement has been executed between the parties.
This analysis describes what Loom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision places a direct compliance obligation on the Customer to ensure that no protected health information is introduced into Atlassian's Cloud Products absent a BAA, and assigns responsibility for this gatekeeping function to the Customer rather than Atlassian.
Under this clause, the Customer is contractually responsible for ensuring that HIPAA-regulated health information is not processed through Cloud Products unless a Business Associate Agreement is separately executed; Atlassian does not assume the role of a HIPAA Business Associate absent that agreement.
Cross-platform context
See how other platforms handle HIPAA Upload Prohibition and similar clauses.
Compare across platforms →"Unless the parties have entered into a 'Business Associate Agreement,' Customer must not (and must not permit anyone else to) upload to the Cloud Products (or use the Cloud Products to process) any patient, medical or other protected health information regulated by the Health Insurance Portability and Accountability Act.Excerpt from Loom's Terms of Service
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision places a direct compliance obligation on the Customer to ensure that no protected health information is introduced into Atlassian's Cloud Products absent a BAA, and assigns responsibility for this gatekeeping function to the Customer rather than Atlassian.
Under this clause, the Customer is contractually responsible for ensuring that HIPAA-regulated health information is not processed through Cloud Products unless a Business Associate Agreement is separately executed; Atlassian does not assume the role of a HIPAA Business Associate absent that agreement.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Loom.