Provision record
Perplexity AI · Perplexity Enterprise Terms · View original document ↗

HIPAA Protected Health Information Restriction

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Perplexity AI changes these terms. Follow Perplexity AI →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Perplexity AI recorded 11 documented changes in the last 30 days.
Follow Perplexity AI →
Monitor governance changes for Perplexity AI Monitor emails you the same day this changes. The archive stays free.
Follow Perplexity AI →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

This provision prohibits Customer from processing Protected Health Information through the Services unless a Business Associate Agreement has been separately executed between Customer and Perplexity.

This analysis describes what Perplexity AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This clause establishes a prerequisite BAA requirement for any healthcare-adjacent use case, and non-compliance creates both contractual breach exposure and potential HIPAA regulatory liability for Customer organizations that process PHI without the required agreement in place.

Change history

added Jul 23, 2026

This addition establishes explicit guardrails for healthcare data and creates a pathway for HIPAA compliance through BAA, critical for enterprise customers in regulated industries.

View full change record →

Consumer impact (what this means for users)

Under this provision, Customer organizations in healthcare or adjacent industries must confirm execution of a Business Associate Agreement with Perplexity before using the Services in any workflow involving Protected Health Information as defined by HIPAA.

Cross-platform context

See how other platforms handle HIPAA Protected Health Information Restriction and similar clauses.

Compare across platforms →

Monitoring

Perplexity AI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Perplexity AI → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Customer may not use the Services to create, receive, maintain, transmit, or otherwise process any information that includes or constitutes 'Protected Health Information', as defined under the HIPAA Privacy Rule (45 C.F.R. Section 160.103), unless Customer and Perplexity have executed a Business Associate Agreement.

Excerpt from Perplexity AI's Perplexity Enterprise Terms

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages the HIPAA Privacy Rule and Security Rule, enforced by the HHS Office for Civil Rights. Under HIPAA, covered entities and business associates are required to execute BAAs before sharing PHI with service providers. Absent an executed BAA, any Customer processing of PHI through the Services could expose both Customer and Perplexity to HHS OCR enforcement, including civil monetary penalties. 2. GOVERNANCE EXPOSURE: High for healthcare-adjacent enterprise customers. Organizations in healthcare, health insurance, or adjacent industries that deploy the Services without first confirming BAA status risk HIPAA violations that may not be remediable after the fact. The agreement places sole responsibility on Customer to ensure this condition is satisfied before use. 3. JURISDICTION FLAGS: HIPAA applies federally across U.S.-based covered entities and business associates; state health privacy laws in California, New York, and other jurisdictions may impose additional requirements beyond HIPAA that compliance teams should separately evaluate. 4. CONTRACT AND VENDOR IMPLICATIONS: Healthcare enterprise customers should obtain confirmation from Perplexity of BAA availability and execution status before deployment. Procurement teams should include BAA status as a gating condition in vendor onboarding for any health-related use case. 5. COMPLIANCE CONSIDERATIONS: Legal and compliance teams in healthcare-adjacent organizations should verify that existing enterprise agreements with Perplexity include an executed BAA, document that verification, and implement technical or administrative controls to prevent inadvertent PHI processing through the Services absent BAA coverage.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • Hhs Ocr
    HHS Office for Civil Rights enforces HIPAA Privacy and Security Rules; processing PHI without an executed BAA may constitute a reportable violation subject to HHS OCR investigation and civil monetary penalties.
    File a complaint →

Provision details

Document information
Document
Perplexity Enterprise Terms
Entity
Perplexity AI
Document last updated
May 11, 2026
Tracking information
First tracked
May 20, 2026
Last verified
July 9, 2026
Record ID
CA-P-013599
Document ID
CA-D-00762
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
90d78755a560827aa84430cfbf0802e8b6736b234f7f6d7a613e330d33540f0f
Analysis generated
May 20, 2026 20:11 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Perplexity AI
Document: Perplexity Enterprise Terms
Record ID: CA-P-013599
Captured: 2026-05-20 20:11:39 UTC
SHA-256: 90d78755a560827a…
URL: https://conductatlas.com/platform/perplexity-ai/perplexity-enterprise-terms/provision/CA-P-013599/hipaa-protected-health-information-restriction/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Perplexity AI's HIPAA Protected Health Information Restriction clause do?

This clause establishes a prerequisite BAA requirement for any healthcare-adjacent use case, and non-compliance creates both contractual breach exposure and potential HIPAA regulatory liability for Customer organizations that process PHI without the required agreement in place.

How does this clause affect you?

Under this provision, Customer organizations in healthcare or adjacent industries must confirm execution of a Business Associate Agreement with Perplexity before using the Services in any workflow involving Protected Health Information as defined by HIPAA.

Is ConductAtlas affiliated with Perplexity AI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Perplexity AI.