Legal
Nov 13, 2025
HIPAA Readiness
Table of Contents
This page explains how customers can use Pivot in a HIPAA‑eligible manner. It is an informational overview, not a certification of HIPAA compliance and not legal advice.
Pivot supports HIPAA‑eligible use cases when customers sign a Business Associate Agreement (BAA) with Pivot and configure the product appropriately. Customers remain responsible for their own HIPAA compliance, including workforce training and adhering to the “minimum necessary” standard.
If you are a Covered Entity or Business Associate using Pivot to create, receive, maintain, or transmit Protected Health Information (PHI), Pivot acts as your Business Associate. You must have a signed BAA with Pivot before storing or processing PHI in the Services.
To use Pivot with PHI, customers should:
Customers must not transmit PHI via:
Pivot will publish and maintain a list of HIPAA‑eligible product areas and supported integrations. For clarification, contact [email protected].
Pivot maintains administrative, physical, and technical safeguards designed to meet the HIPAA Security Rule, including:
Pivot engages vetted Subcontractors to help deliver the Services. Where those Subcontractors handle PHI on Pivot’s behalf, Pivot executes BAAs (or equivalent) with them. The current list of Sub‑processors is available HERE and customers can subscribe to updates.
Customers control access, retention, deletion, and export of PHI stored in Pivot.