Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement prohibits uploading or processing HIPAA-regulated protected health information in Cloud Products unless a separate Business Associate Agreement has been executed between the parties.
This analysis describes what Loom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision places a direct compliance obligation on the Customer to ensure that no protected health information is introduced into Atlassian's Cloud Products absent a BAA, and assigns responsibility for this gatekeeping function to the Customer rather than Atlassian.
Under this clause, the Customer is contractually responsible for ensuring that HIPAA-regulated health information is not processed through Cloud Products unless a Business Associate Agreement is separately executed; Atlassian does not assume the role of a HIPAA Business Associate absent that agreement.
Cross-platform context
See how other platforms handle HIPAA Upload Prohibition and similar clauses.
Compare across platforms →Monitoring
Loom has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Unless the parties have entered into a 'Business Associate Agreement,' Customer must not (and must not permit anyone else to) upload to the Cloud Products (or use the Cloud Products to process) any patient, medical or other protected health information regulated by the Health Insurance Portability and Accountability Act.Excerpt from Loom's Terms of Service
1. REGULATORY LANDSCAPE: This provision directly engages the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations, enforced by HHS Office for Civil Rights. The requirement for a Business Associate Agreement before processing protected health information (PHI) reflects the HIPAA Privacy and Security Rule requirements for covered entities and business associates. Customers who are covered entities or business associates under HIPAA that upload PHI without a BAA may face regulatory exposure independent of this contractual provision. 2. GOVERNANCE EXPOSURE: High for healthcare-adjacent customers. The provision places compliance responsibility entirely on the Customer, meaning that if PHI is uploaded by a User without the Customer's knowledge, the contractual breach and potentially the HIPAA violation risk falls on the Customer. Organizations in healthcare, life sciences, or benefits administration should treat this as a high-priority control point in their data governance frameworks. 3. JURISDICTION FLAGS: HIPAA applies to covered entities and business associates regardless of geography, but enforcement is US-centric. EMEA customers processing health data in Cloud Products may separately need to assess compliance with GDPR special categories of personal data provisions (Article 9), which operate independently of this contractual prohibition and may impose additional obligations on both Customer and Atlassian. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams at covered entities or business associates must confirm whether a BAA with Atlassian has been executed before onboarding any workflows involving PHI. Atlassian's website and legal documentation should be reviewed to determine whether a BAA is available and under what conditions. If a BAA is not offered for the relevant Cloud Products, those products may be categorically unsuitable for PHI processing regardless of this contractual provision. 5. COMPLIANCE CONSIDERATIONS: Healthcare and benefits-adjacent organizations should conduct a data mapping exercise to identify whether any current or planned Atlassian Cloud Product workflows could involve PHI, including in project management, service desk, or collaboration tools. HIPAA compliance programs should include this provision as a training and policy control point for Users who may inadvertently upload clinical or patient data. Legal teams should confirm whether a BAA is available from Atlassian and document its execution status as part of vendor management records.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision places a direct compliance obligation on the Customer to ensure that no protected health information is introduced into Atlassian's Cloud Products absent a BAA, and assigns responsibility for this gatekeeping function to the Customer rather than Atlassian.
Under this clause, the Customer is contractually responsible for ensuring that HIPAA-regulated health information is not processed through Cloud Products unless a Business Associate Agreement is separately executed; Atlassian does not assume the role of a HIPAA Business Associate absent that agreement.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Loom.