Loom · Loom Terms of Service · View original document ↗

HIPAA Upload Prohibition

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Loom changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Loom Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement prohibits uploading or processing HIPAA-regulated protected health information in Cloud Products unless a separate Business Associate Agreement has been executed between the parties.

This analysis describes what Loom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision places a direct compliance obligation on the Customer to ensure that no protected health information is introduced into Atlassian's Cloud Products absent a BAA, and assigns responsibility for this gatekeeping function to the Customer rather than Atlassian.

Consumer impact (what this means for users)

Under this clause, the Customer is contractually responsible for ensuring that HIPAA-regulated health information is not processed through Cloud Products unless a Business Associate Agreement is separately executed; Atlassian does not assume the role of a HIPAA Business Associate absent that agreement.

Cross-platform context

See how other platforms handle HIPAA Upload Prohibition and similar clauses.

Compare across platforms →

Monitoring

Loom has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Unless the parties have entered into a 'Business Associate Agreement,' Customer must not (and must not permit anyone else to) upload to the Cloud Products (or use the Cloud Products to process) any patient, medical or other protected health information regulated by the Health Insurance Portability and Accountability Act.

Excerpt from Loom's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations, enforced by HHS Office for Civil Rights. The requirement for a Business Associate Agreement before processing protected health information (PHI) reflects the HIPAA Privacy and Security Rule requirements for covered entities and business associates. Customers who are covered entities or business associates under HIPAA that upload PHI without a BAA may face regulatory exposure independent of this contractual provision. 2. GOVERNANCE EXPOSURE: High for healthcare-adjacent customers. The provision places compliance responsibility entirely on the Customer, meaning that if PHI is uploaded by a User without the Customer's knowledge, the contractual breach and potentially the HIPAA violation risk falls on the Customer. Organizations in healthcare, life sciences, or benefits administration should treat this as a high-priority control point in their data governance frameworks. 3. JURISDICTION FLAGS: HIPAA applies to covered entities and business associates regardless of geography, but enforcement is US-centric. EMEA customers processing health data in Cloud Products may separately need to assess compliance with GDPR special categories of personal data provisions (Article 9), which operate independently of this contractual prohibition and may impose additional obligations on both Customer and Atlassian. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams at covered entities or business associates must confirm whether a BAA with Atlassian has been executed before onboarding any workflows involving PHI. Atlassian's website and legal documentation should be reviewed to determine whether a BAA is available and under what conditions. If a BAA is not offered for the relevant Cloud Products, those products may be categorically unsuitable for PHI processing regardless of this contractual provision. 5. COMPLIANCE CONSIDERATIONS: Healthcare and benefits-adjacent organizations should conduct a data mapping exercise to identify whether any current or planned Atlassian Cloud Product workflows could involve PHI, including in project management, service desk, or collaboration tools. HIPAA compliance programs should include this provision as a training and policy control point for Users who may inadvertently upload clinical or patient data. Legal teams should confirm whether a BAA is available from Atlassian and document its execution status as part of vendor management records.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • Hhs Ocr
    HHS Office for Civil Rights enforces HIPAA requirements for protected health information, directly relevant to this provision's prohibition on PHI processing without a BAA.
    File a complaint →

Provision details

Document information
Document
Loom Terms of Service
Entity
Loom
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074263
Document ID
CA-D-00564
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f441c251830514f5a83e3398d892d775169e50249827f7ae34338762e14fe90c
Analysis generated
July 12, 2026 15:04 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Loom
Document: Loom Terms of Service
Record ID: CA-P-074263
Captured: 2026-07-12 15:04:00 UTC
SHA-256: f441c251830514f5…
URL: https://conductatlas.com/platform/loom/loom-terms-of-service/provision/CA-P-074263/hipaa-upload-prohibition/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Loom's HIPAA Upload Prohibition clause do?

This provision places a direct compliance obligation on the Customer to ensure that no protected health information is introduced into Atlassian's Cloud Products absent a BAA, and assigns responsibility for this gatekeeping function to the Customer rather than Atlassian.

How does this clause affect you?

Under this clause, the Customer is contractually responsible for ensuring that HIPAA-regulated health information is not processed through Cloud Products unless a Business Associate Agreement is separately executed; Atlassian does not assume the role of a HIPAA Business Associate absent that agreement.

Is ConductAtlas affiliated with Loom?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Loom.