The agreement prohibits storage of HIPAA-regulated or HDS-regulated health data in the Services unless a Business Associate Agreement is in place, and places the compliance configuration responsibility for HIPAA, HDS, and other applicable regulations on the Customer.
This analysis describes what Zendesk's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision places affirmative HIPAA compliance configuration obligations on the Customer rather than Zendesk, and creates a contractual prohibition on health data storage absent a BAA. The agreement defines Health Data to include medical, patient, or other identifiable health information regulated under HIPAA or Article L1111-8 of the French Public Health Code, meaning healthcare-adjacent customers using Zendesk for support operations must assess whether their Service Data includes such information.
The agreement prohibits storing health data in the Services without a Business Associate Agreement and requires the Customer to configure the Services for HIPAA and HDS compliance. Health data is defined in the agreement to include medical, patient, or other identifiable health information regulated under HIPAA or French HDS law.
Cross-platform context
See how other platforms handle Health Data Restriction and HIPAA Compliance Obligation and similar clauses.
Compare across platforms →"Unless the parties have entered into a Business Associate Agreement or similar exhibit, Customer will not (and will not permit others to) store Health Data in the Services. Customer is responsible for configuring the Services to comply with HIPAA, HDS, and other applicable regulations.Excerpt from Zendesk's Terms of Service
(1) REGULATORY LANDSCAPE: This provision directly engages the U.S.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision places affirmative HIPAA compliance configuration obligations on the Customer rather than Zendesk, and creates a contractual prohibition on health data storage absent a BAA. The agreement defines Health Data to include medical, patient, or other identifiable health information regulated under HIPAA or Article L1111-8 of the French Public Health Code, meaning healthcare-adjacent customers using Zendesk for support operations …
The agreement prohibits storing health data in the Services without a Business Associate Agreement and requires the Customer to configure the Services for HIPAA and HDS compliance. Health data is defined in the agreement to include medical, patient, or other identifiable health information regulated under HIPAA or French HDS law.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zendesk.