Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy prohibits merchants from uploading Protected Health Information (PHI) as defined under HIPAA to the Shopify platform, identifying this as a category of business activity the platform does not support.
This analysis describes what Shopify's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Shopify does not function as a HIPAA-compliant platform for PHI storage or processing, and that merchants who upload PHI are in violation of this policy regardless of their own HIPAA status.
Under this clause, merchants operating in healthcare-adjacent industries who handle PHI are prohibited from uploading such data to Shopify, meaning platform use must be structured to exclude PHI from any data submitted to the platform.
Cross-platform context
See how other platforms handle HIPAA Protected Health Information Upload Prohibition and similar clauses.
Compare across platforms →Monitoring
Shopify has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"You must likewise respect that certain business activities are not supported by our platform, such as uploading Protected Health Information subject to HIPAA.Excerpt from Shopify's Acceptable Use Policy
(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA, enforced by the HHS Office for Civil Rights. It also implicates the FTC Health Breach Notification Rule to the extent non-HIPAA-covered entities handle health data. The provision asserts a platform prohibition on PHI uploads but does not address whether Shopify has executed Business Associate Agreements with any merchants, or whether such agreements are available. (2) GOVERNANCE EXPOSURE: High for merchants in health, wellness, medical device, pharmacy, or telehealth-adjacent categories. If a merchant uploads PHI in violation of this clause, Shopify may take enforcement action and the merchant remains exposed to independent HIPAA liability. The provision does not describe any technical controls Shopify uses to detect or prevent PHI uploads, which means enforcement relies on merchant self-compliance. (3) JURISDICTION FLAGS: HIPAA applies federally to covered entities and business associates in the United States. State health privacy laws in California, Texas, and Washington may create additional obligations for health data beyond HIPAA scope. EU/EEA merchants handling health data face additional constraints under GDPR Article 9 governing special category data. (4) CONTRACT AND VENDOR IMPLICATIONS: Merchants in healthcare-adjacent categories should assess whether their Shopify integration could result in incidental PHI upload, including through customer-submitted form data, order notes, or product descriptions. Legal teams should confirm whether a Business Associate Agreement with Shopify is available or required and whether the absence of such an agreement creates independent HIPAA exposure. (5) COMPLIANCE CONSIDERATIONS: Compliance teams at health-adjacent merchants should conduct a data mapping review to confirm no PHI flows through the Shopify platform. If PHI upload risk exists, technical controls or workflow modifications may be required to satisfy this prohibition. Merchants should also assess whether state health privacy laws impose obligations beyond the HIPAA prohibition stated here.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that Shopify does not function as a HIPAA-compliant platform for PHI storage or processing, and that merchants who upload PHI are in violation of this policy regardless of their own HIPAA status.
Under this clause, merchants operating in healthcare-adjacent industries who handle PHI are prohibited from uploading such data to Shopify, meaning platform use must be structured to exclude PHI from any data submitted to the platform.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Shopify.