Zendesk · Zendesk Terms of Service · View original document ↗

Health Data Restriction and HIPAA Compliance Obligation

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Zendesk changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Zendesk Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement prohibits storage of HIPAA-regulated or HDS-regulated health data in the Services unless a Business Associate Agreement is in place, and places the compliance configuration responsibility for HIPAA, HDS, and other applicable regulations on the Customer.

This analysis describes what Zendesk's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision places affirmative HIPAA compliance configuration obligations on the Customer rather than Zendesk, and creates a contractual prohibition on health data storage absent a BAA. The agreement defines Health Data to include medical, patient, or other identifiable health information regulated under HIPAA or Article L1111-8 of the French Public Health Code, meaning healthcare-adjacent customers using Zendesk for support operations must assess whether their Service Data includes such information.

Consumer impact (what this means for users)

The agreement prohibits storing health data in the Services without a Business Associate Agreement and requires the Customer to configure the Services for HIPAA and HDS compliance. Health data is defined in the agreement to include medical, patient, or other identifiable health information regulated under HIPAA or French HDS law.

Cross-platform context

See how other platforms handle Health Data Restriction and HIPAA Compliance Obligation and similar clauses.

Compare across platforms →

Monitoring

Zendesk has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Unless the parties have entered into a Business Associate Agreement or similar exhibit, Customer will not (and will not permit others to) store Health Data in the Services. Customer is responsible for configuring the Services to comply with HIPAA, HDS, and other applicable regulations.

Excerpt from Zendesk's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages the U.S. Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, enforced by HHS Office for Civil Rights. For French customers, Article L1111-8 of the Public Health Code (HDS certification framework) is referenced. HIPAA requires covered entities and business associates to execute BAAs before sharing protected health information with service providers. (2) GOVERNANCE EXPOSURE: High for healthcare-sector customers. The agreement places compliance configuration responsibility on the Customer, meaning Zendesk's warranty and security obligations may not fully address HIPAA-specific requirements absent a BAA and Customer-side configuration. Inadvertent storage of protected health information without a BAA creates regulatory exposure under HIPAA's breach notification and enforcement provisions. (3) JURISDICTION FLAGS: U.S. healthcare covered entities and business associates face heightened exposure under HIPAA. French healthcare organizations face exposure under the HDS framework. Customers in other jurisdictions with health data regulations, such as the EU under GDPR Article 9 special category processing, should assess whether additional agreements beyond the standard DPA are required. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams in healthcare-adjacent industries should confirm whether a BAA has been executed with Zendesk before any Service Data containing patient or health information is submitted to the platform. The agreement provides a BAA PowerForm as referenced in the document index. The Customer's responsibility for compliance configuration means reliance on default Zendesk settings is not sufficient for HIPAA compliance. (5) COMPLIANCE CONSIDERATIONS: Healthcare customers should audit Service Data flows to confirm whether support tickets, chat logs, or other submissions may contain protected health information. A BAA must be in place before any such data is stored. Compliance teams should also assess whether Zendesk's Innovation Services security measures are consistent with HIPAA's technical safeguard requirements, as the agreement maintains different security measure documentation for Enterprise and Innovation Services.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • Hhs Ocr
    HHS Office for Civil Rights enforces HIPAA, which is directly referenced in this provision as the regulatory framework governing the Health Data prohibition and BAA requirement.
    File a complaint →

Provision details

Document information
Document
Zendesk Terms of Service
Entity
Zendesk
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074293
Document ID
CA-D-00638
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
ad77187ab3fa29ea6328dd21e4556f4c93c2d37a21097e73f14eb557afc4482f
Analysis generated
July 12, 2026 15:18 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Zendesk
Document: Zendesk Terms of Service
Record ID: CA-P-074293
Captured: 2026-07-12 15:18:58 UTC
SHA-256: ad77187ab3fa29ea…
URL: https://conductatlas.com/platform/zendesk/zendesk-terms-of-service/provision/CA-P-074293/health-data-restriction-and-hipaa-compliance-obligation/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Zendesk's Health Data Restriction and HIPAA Compliance Obligation clause do?

This provision places affirmative HIPAA compliance configuration obligations on the Customer rather than Zendesk, and creates a contractual prohibition on health data storage absent a BAA. The agreement defines Health Data to include medical, patient, or other identifiable health information regulated under HIPAA or Article L1111-8 of the French Public Health Code, meaning healthcare-adjacent customers using Zendesk for support operations …

How does this clause affect you?

The agreement prohibits storing health data in the Services without a Business Associate Agreement and requires the Customer to configure the Services for HIPAA and HDS compliance. Health data is defined in the agreement to include medical, patient, or other identifiable health information regulated under HIPAA or French HDS law.

Is ConductAtlas affiliated with Zendesk?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zendesk.