Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement prohibits storage of HIPAA-regulated or HDS-regulated health data in the Services unless a Business Associate Agreement is in place, and places the compliance configuration responsibility for HIPAA, HDS, and other applicable regulations on the Customer.
This analysis describes what Zendesk's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision places affirmative HIPAA compliance configuration obligations on the Customer rather than Zendesk, and creates a contractual prohibition on health data storage absent a BAA. The agreement defines Health Data to include medical, patient, or other identifiable health information regulated under HIPAA or Article L1111-8 of the French Public Health Code, meaning healthcare-adjacent customers using Zendesk for support operations must assess whether their Service Data includes such information.
The agreement prohibits storing health data in the Services without a Business Associate Agreement and requires the Customer to configure the Services for HIPAA and HDS compliance. Health data is defined in the agreement to include medical, patient, or other identifiable health information regulated under HIPAA or French HDS law.
Cross-platform context
See how other platforms handle Health Data Restriction and HIPAA Compliance Obligation and similar clauses.
Compare across platforms →Monitoring
Zendesk has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Unless the parties have entered into a Business Associate Agreement or similar exhibit, Customer will not (and will not permit others to) store Health Data in the Services. Customer is responsible for configuring the Services to comply with HIPAA, HDS, and other applicable regulations.Excerpt from Zendesk's Terms of Service
(1) REGULATORY LANDSCAPE: This provision directly engages the U.S. Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, enforced by HHS Office for Civil Rights. For French customers, Article L1111-8 of the Public Health Code (HDS certification framework) is referenced. HIPAA requires covered entities and business associates to execute BAAs before sharing protected health information with service providers. (2) GOVERNANCE EXPOSURE: High for healthcare-sector customers. The agreement places compliance configuration responsibility on the Customer, meaning Zendesk's warranty and security obligations may not fully address HIPAA-specific requirements absent a BAA and Customer-side configuration. Inadvertent storage of protected health information without a BAA creates regulatory exposure under HIPAA's breach notification and enforcement provisions. (3) JURISDICTION FLAGS: U.S. healthcare covered entities and business associates face heightened exposure under HIPAA. French healthcare organizations face exposure under the HDS framework. Customers in other jurisdictions with health data regulations, such as the EU under GDPR Article 9 special category processing, should assess whether additional agreements beyond the standard DPA are required. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams in healthcare-adjacent industries should confirm whether a BAA has been executed with Zendesk before any Service Data containing patient or health information is submitted to the platform. The agreement provides a BAA PowerForm as referenced in the document index. The Customer's responsibility for compliance configuration means reliance on default Zendesk settings is not sufficient for HIPAA compliance. (5) COMPLIANCE CONSIDERATIONS: Healthcare customers should audit Service Data flows to confirm whether support tickets, chat logs, or other submissions may contain protected health information. A BAA must be in place before any such data is stored. Compliance teams should also assess whether Zendesk's Innovation Services security measures are consistent with HIPAA's technical safeguard requirements, as the agreement maintains different security measure documentation for Enterprise and Innovation Services.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision places affirmative HIPAA compliance configuration obligations on the Customer rather than Zendesk, and creates a contractual prohibition on health data storage absent a BAA. The agreement defines Health Data to include medical, patient, or other identifiable health information regulated under HIPAA or Article L1111-8 of the French Public Health Code, meaning healthcare-adjacent customers using Zendesk for support operations …
The agreement prohibits storing health data in the Services without a Business Associate Agreement and requires the Customer to configure the Services for HIPAA and HDS compliance. Health data is defined in the agreement to include medical, patient, or other identifiable health information regulated under HIPAA or French HDS law.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zendesk.