Provision record
Squarespace · Squarespace Terms of Service · View original document ↗

HIPAA and Industry-Specific Compliance Prohibition

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Squarespace changes these terms. Follow Squarespace →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Squarespace Monitor emails you the same day this changes. The archive stays free.
Follow Squarespace →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement prohibits use of Squarespace services in ways that would subject Squarespace to HIPAA, GLBA, FERPA, or similar industry-specific regulations without prior written agreement from Squarespace. Handling protected health information is specifically prohibited unless the account is designated as HIPAA-enabled and a separate business associate agreement is in place.

This analysis describes what Squarespace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a contractual prohibition on processing protected health information or other regulated data through standard Squarespace services, requiring a separate written agreement and account designation. Operators in healthcare, financial services, or education sectors must obtain specific contractual authorization before using the platform for regulated data processing.

Consumer impact (what this means for users)

This provision establishes that standard Squarespace accounts cannot lawfully be used to collect or process protected health information or other data regulated under HIPAA, GLBA, or FERPA without a separately negotiated written agreement and account designation. End users submitting health or other sensitive regulated data through a non-HIPAA-enabled Squarespace site should be aware that the platform is not contractually authorized to handle such data under standard terms.

Cross-platform context

See how other platforms handle HIPAA and Industry-Specific Compliance Prohibition and similar clauses.

Compare across platforms →

Monitoring

Squarespace has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Squarespace → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If your use of the Services requires you to comply with industry-specific regulations applicable to such use, such as HIPAA, GLBA or FERPA (each, an "Industry-Specific Regulation"), you will be solely responsible for such compliance, except to the extent Squarespace has agreed with you in writing otherwise. You are not permitted to use the Services in any way that would subject Squarespace to an Industry-Specific Regulation without obtaining Squarespace's prior written agreement. For example, you may not use any Services to collect, use, disclose, protect or otherwise handle "protected health information" (as defined in 45 C.F.R. §160.103) unless your Account for such Services is designated as HIPAA-enabled and you enter into a separate business associate agreement with Squarespace.

Excerpt from Squarespace's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA (45 C.F.R. Parts 160 and 164), GLBA, and FERPA as the named industry-specific regulations. HHS Office for Civil Rights (HHS OCR) enforces HIPAA, including business associate agreement requirements under 45 C.F.R. §164.308. The provision cites the specific HIPAA definition of protected health information at 45 C.F.R. §160.103. Operators who process PHI through standard Squarespace accounts without a HIPAA-enabled designation and BAA would bear the primary regulatory exposure, though the regulatory analysis of business associate status is independent of contractual allocation. (2) GOVERNANCE EXPOSURE: High for healthcare, financial services, and education operators. The absence of a HIPAA-enabled account designation and executed BAA means that any PHI submitted through a standard Squarespace form or service would create HIPAA compliance risk for the operator. This is an operationally critical restriction for any healthcare-adjacent use case. (3) JURISDICTION FLAGS: HIPAA applies to covered entities and business associates in the US regardless of state. FERPA applies to educational institutions receiving federal funding. GLBA applies to financial institutions. Operators in these regulated sectors should assess whether their Squarespace use cases fall within the scope of these frameworks before deploying standard services. (4) CONTRACT AND VENDOR IMPLICATIONS: Healthcare operators must obtain a HIPAA-enabled account designation and execute a separate business associate agreement with Squarespace before using any services to collect or process PHI. Procurement and legal teams in regulated industries should assess whether Squarespace offers the required BAA and HIPAA-enabled account configuration as a pre-condition to deployment. (5) COMPLIANCE CONSIDERATIONS: Legal teams at healthcare, financial services, and education organizations should review all existing Squarespace deployments to confirm that no regulated data is being processed through standard accounts, assess whether HIPAA-enabled account options are available and appropriate for their use cases, and ensure that any required BAA is executed prior to processing PHI.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • Hhs Ocr
    HHS Office for Civil Rights enforces HIPAA, including business associate agreement requirements relevant to operators processing protected health information through cloud-based services
    File a complaint →

Provision details

Document information
Document
Squarespace Terms of Service
Entity
Squarespace
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
July 9, 2026
Record ID
CA-P-014277
Document ID
CA-D-00568
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
8c1008b7002b1c17faa6d73a6fbfe4b6f2113ddec20224a0206e98507380a0ef
Analysis generated
May 7, 2026 07:31 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Squarespace
Document: Squarespace Terms of Service
Record ID: CA-P-014277
Captured: 2026-05-07 07:31:39 UTC
SHA-256: 8c1008b7002b1c17…
URL: https://conductatlas.com/platform/squarespace/squarespace-terms-of-service/provision/CA-P-014277/hipaa-and-industry-specific-compliance-prohibition/
Accessed: July 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Squarespace's HIPAA and Industry-Specific Compliance Prohibition clause do?

This provision establishes a contractual prohibition on processing protected health information or other regulated data through standard Squarespace services, requiring a separate written agreement and account designation. Operators in healthcare, financial services, or education sectors must obtain specific contractual authorization before using the platform for regulated data processing.

How does this clause affect you?

This provision establishes that standard Squarespace accounts cannot lawfully be used to collect or process protected health information or other data regulated under HIPAA, GLBA, or FERPA without a separately negotiated written agreement and account designation. End users submitting health or other sensitive regulated data through a non-HIPAA-enabled Squarespace site should be aware that the platform is not contractually authorized …

Is ConductAtlas affiliated with Squarespace?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Squarespace.