Provision record
Shopify · Shopify Acceptable Use Policy · View original document ↗

HIPAA Protected Health Information Upload Prohibition

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Shopify changes these terms. Follow Shopify →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Shopify Monitor emails you the same day this changes. The archive stays free.
Follow Shopify →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy prohibits merchants from uploading Protected Health Information (PHI) as defined under HIPAA to the Shopify platform, identifying this as a category of business activity the platform does not support.

This analysis describes what Shopify's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that Shopify does not function as a HIPAA-compliant platform for PHI storage or processing, and that merchants who upload PHI are in violation of this policy regardless of their own HIPAA status.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, merchants operating in healthcare-adjacent industries who handle PHI are prohibited from uploading such data to Shopify, meaning platform use must be structured to exclude PHI from any data submitted to the platform.

Cross-platform context

See how other platforms handle HIPAA Protected Health Information Upload Prohibition and similar clauses.

Compare across platforms →

Monitoring

Shopify has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Shopify → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
You must likewise respect that certain business activities are not supported by our platform, such as uploading Protected Health Information subject to HIPAA.

Excerpt from Shopify's Acceptable Use Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA, enforced by the HHS Office for Civil Rights. It also implicates the FTC Health Breach Notification Rule to the extent non-HIPAA-covered entities handle health data. The provision asserts a platform prohibition on PHI uploads but does not address whether Shopify has executed Business Associate Agreements with any merchants, or whether such agreements are available. (2) GOVERNANCE EXPOSURE: High for merchants in health, wellness, medical device, pharmacy, or telehealth-adjacent categories. If a merchant uploads PHI in violation of this clause, Shopify may take enforcement action and the merchant remains exposed to independent HIPAA liability. The provision does not describe any technical controls Shopify uses to detect or prevent PHI uploads, which means enforcement relies on merchant self-compliance. (3) JURISDICTION FLAGS: HIPAA applies federally to covered entities and business associates in the United States. State health privacy laws in California, Texas, and Washington may create additional obligations for health data beyond HIPAA scope. EU/EEA merchants handling health data face additional constraints under GDPR Article 9 governing special category data. (4) CONTRACT AND VENDOR IMPLICATIONS: Merchants in healthcare-adjacent categories should assess whether their Shopify integration could result in incidental PHI upload, including through customer-submitted form data, order notes, or product descriptions. Legal teams should confirm whether a Business Associate Agreement with Shopify is available or required and whether the absence of such an agreement creates independent HIPAA exposure. (5) COMPLIANCE CONSIDERATIONS: Compliance teams at health-adjacent merchants should conduct a data mapping review to confirm no PHI flows through the Shopify platform. If PHI upload risk exists, technical controls or workflow modifications may be required to satisfy this prohibition. Merchants should also assess whether state health privacy laws impose obligations beyond the HIPAA prohibition stated here.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • Hhs Ocr
    HHS Office for Civil Rights enforces HIPAA, which this provision directly references in prohibiting the upload of Protected Health Information to the Shopify platform.
    File a complaint →

Provision details

Document information
Document
Shopify Acceptable Use Policy
Entity
Shopify
Document last updated
May 5, 2026
Tracking information
First tracked
April 27, 2026
Last verified
July 9, 2026
Record ID
CA-P-014680
Document ID
CA-D-00124
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
6bcbcd993283622da5bbda5cc852b26aa776f43b0a6c622e698b0106daaff31f
Analysis generated
April 27, 2026 12:48 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Shopify
Document: Shopify Acceptable Use Policy
Record ID: CA-P-014680
Captured: 2026-04-27 12:48:34 UTC
SHA-256: 6bcbcd993283622d…
URL: https://conductatlas.com/platform/shopify/shopify-acceptable-use-policy/provision/CA-P-014680/hipaa-protected-health-information-upload-prohibition/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Shopify's HIPAA Protected Health Information Upload Prohibition clause do?

This provision establishes that Shopify does not function as a HIPAA-compliant platform for PHI storage or processing, and that merchants who upload PHI are in violation of this policy regardless of their own HIPAA status.

How does this clause affect you?

Under this clause, merchants operating in healthcare-adjacent industries who handle PHI are prohibited from uploading such data to Shopify, meaning platform use must be structured to exclude PHI from any data submitted to the platform.

Is ConductAtlas affiliated with Shopify?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Shopify.