Writer · Writer Terms of Service · View original document ↗

HIPAA and Protected Health Information Restriction

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Writer changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Writer recorded 6 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Writer Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement prohibits users from submitting or processing Protected Health Information through the non-Enterprise platform. This prohibition applies until and unless the user has subscribed to the Enterprise version and executed a Business Associate Agreement with Writer.

This analysis describes what Writer's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a clear contractual and compliance boundary for HIPAA-regulated information, restricting PHI processing to Enterprise accounts with an executed BAA. Users or organizations submitting PHI outside these conditions would be operating in breach of these terms and outside the HIPAA-compliant service boundary.

Consumer impact (what this means for users)

Under this clause, submitting patient, medical, or other Protected Health Information through Writer's non-Enterprise platform is prohibited. Organizations in healthcare or other HIPAA-covered sectors must subscribe to the Enterprise tier and execute a BAA before using Writer for any PHI-related workflows.

Cross-platform context

See how other platforms handle HIPAA and Protected Health Information Restriction and similar clauses.

Compare across platforms →

Monitoring

Writer has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
to process any patient, medical or other protected health information regulated by the Health Insurance Portability and Accountability Act of 1996 ('HIPAA') or any similar U.S. federal or state laws, rules or regulations ('Protected Health Information') or otherwise share such information with us until and unless you subscribe to the Enterprise version of our Platform and have entered into a business associate agreement (a 'BAA') with us

Excerpt from Writer's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: This provision directly engages HIPAA and its implementing regulations, including the Privacy Rule and Security Rule. HHS Office for Civil Rights is the primary enforcement authority for HIPAA compliance. Unauthorized processing of PHI through a platform without a BAA may constitute a HIPAA violation by the covered entity or business associate involved, regardless of the contractual prohibition in Writer's terms. GOVERNANCE EXPOSURE: High for any organization operating in a HIPAA-covered sector or handling PHI. The contractual prohibition shifts responsibility to the user for ensuring PHI is not submitted through non-Enterprise accounts, but regulatory liability under HIPAA may remain with the covered entity regardless of this contractual provision. JURISDICTION FLAGS: HIPAA applies to covered entities and business associates in the United States. State health data privacy laws, including California's Confidentiality of Medical Information Act and similar statutes in other states, may impose additional obligations beyond HIPAA. Organizations operating internationally should assess equivalent health data protection requirements in applicable jurisdictions. CONTRACT AND VENDOR IMPLICATIONS: Healthcare organizations and any entity handling PHI must confirm the existence of an executed BAA and active Enterprise subscription before deploying Writer for any PHI-related use case. Procurement teams should treat the absence of a BAA as a blocking condition for HIPAA-regulated workflows. The BAA, once executed, will govern the specific obligations and liability allocations for PHI processing. COMPLIANCE CONSIDERATIONS: Compliance teams should implement access controls or acceptable use training to prevent non-Enterprise account users from inadvertently submitting PHI through Writer's platform. Any existing non-Enterprise deployments in healthcare-adjacent contexts should be audited against this restriction. Organizations should verify that the Enterprise BAA covers all relevant use cases and that subprocessors listed by Writer are also appropriately covered.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • Hhs Ocr
    HHS Office for Civil Rights enforces HIPAA requirements for covered entities and business associates, including obligations related to processing PHI with technology vendors.
    File a complaint →

Provision details

Document information
Document
Writer Terms of Service
Entity
Writer
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014112
Document ID
CA-D-00518
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
90b5f4dda25362f359ac1fc209cf2d1f2c646f84bf1299afb1f5739e2f2c4e74
Analysis generated
July 9, 2026 04:47 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Writer
Document: Writer Terms of Service
Record ID: CA-P-014112
Captured: 2026-07-09 04:47:37 UTC
SHA-256: 90b5f4dda25362f3…
URL: https://conductatlas.com/platform/writer/writer-terms-of-service/provision/CA-P-014112/hipaa-and-protected-health-information-restriction/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Writer's HIPAA and Protected Health Information Restriction clause do?

This provision establishes a clear contractual and compliance boundary for HIPAA-regulated information, restricting PHI processing to Enterprise accounts with an executed BAA. Users or organizations submitting PHI outside these conditions would be operating in breach of these terms and outside the HIPAA-compliant service boundary.

How does this clause affect you?

Under this clause, submitting patient, medical, or other Protected Health Information through Writer's non-Enterprise platform is prohibited. Organizations in healthcare or other HIPAA-covered sectors must subscribe to the Enterprise tier and execute a BAA before using Writer for any PHI-related workflows.

Is ConductAtlas affiliated with Writer?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Writer.