Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision prohibits Customer from processing Protected Health Information through the Services unless a Business Associate Agreement has been separately executed between Customer and Perplexity.
This analysis describes what Perplexity AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause establishes a prerequisite BAA requirement for any healthcare-adjacent use case, and non-compliance creates both contractual breach exposure and potential HIPAA regulatory liability for Customer organizations that process PHI without the required agreement in place.
This addition establishes explicit guardrails for healthcare data and creates a pathway for HIPAA compliance through BAA, critical for enterprise customers in regulated industries.
View full change record →Under this provision, Customer organizations in healthcare or adjacent industries must confirm execution of a Business Associate Agreement with Perplexity before using the Services in any workflow involving Protected Health Information as defined by HIPAA.
Cross-platform context
See how other platforms handle HIPAA Protected Health Information Restriction and similar clauses.
Compare across platforms →Monitoring
Perplexity AI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Customer may not use the Services to create, receive, maintain, transmit, or otherwise process any information that includes or constitutes 'Protected Health Information', as defined under the HIPAA Privacy Rule (45 C.F.R. Section 160.103), unless Customer and Perplexity have executed a Business Associate Agreement.Excerpt from Perplexity AI's Perplexity Enterprise Terms
1. REGULATORY LANDSCAPE: This provision directly engages the HIPAA Privacy Rule and Security Rule, enforced by the HHS Office for Civil Rights. Under HIPAA, covered entities and business associates are required to execute BAAs before sharing PHI with service providers. Absent an executed BAA, any Customer processing of PHI through the Services could expose both Customer and Perplexity to HHS OCR enforcement, including civil monetary penalties. 2. GOVERNANCE EXPOSURE: High for healthcare-adjacent enterprise customers. Organizations in healthcare, health insurance, or adjacent industries that deploy the Services without first confirming BAA status risk HIPAA violations that may not be remediable after the fact. The agreement places sole responsibility on Customer to ensure this condition is satisfied before use. 3. JURISDICTION FLAGS: HIPAA applies federally across U.S.-based covered entities and business associates; state health privacy laws in California, New York, and other jurisdictions may impose additional requirements beyond HIPAA that compliance teams should separately evaluate. 4. CONTRACT AND VENDOR IMPLICATIONS: Healthcare enterprise customers should obtain confirmation from Perplexity of BAA availability and execution status before deployment. Procurement teams should include BAA status as a gating condition in vendor onboarding for any health-related use case. 5. COMPLIANCE CONSIDERATIONS: Legal and compliance teams in healthcare-adjacent organizations should verify that existing enterprise agreements with Perplexity include an executed BAA, document that verification, and implement technical or administrative controls to prevent inadvertent PHI processing through the Services absent BAA coverage.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This clause establishes a prerequisite BAA requirement for any healthcare-adjacent use case, and non-compliance creates both contractual breach exposure and potential HIPAA regulatory liability for Customer organizations that process PHI without the required agreement in place.
Under this provision, Customer organizations in healthcare or adjacent industries must confirm execution of a Business Associate Agreement with Perplexity before using the Services in any workflow involving Protected Health Information as defined by HIPAA.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Perplexity AI.