HIPAA and PHI Policy
Last updated: October 5, 2026
Zentrik is a product management platform. It is not a healthcare product, and it is not designed to be a system of record for patient data. Some customers connect sources, such as a support desk, that can carry Protected Health Information (“PHI”) inside ordinary product feedback.
Our role
Where a customer is a covered entity or a business associate, Zentrik acts as a business associate or as a subcontractor to that customer. Zentrik is never a covered entity, and Zentrik does not hold a designated record set. Our obligations come from the executed Business Associate Agreement (“BAA”), not from this page.
When PHI may be processed
PHI may only be processed once two things are true: a BAA is executed between the parties, and the workspace has been configured for PHI as described below. Until both are in place, customers should not connect a source or upload content that contains PHI.
A BAA is available on the Scale and Enterprise plans. Request one through legal@zentrik.ai or the form below.
Request a BAAWhere PHI can reach Zentrik
PHI reaches Zentrik only through sources a customer deliberately connects or uploads. In practice that means:
- Support desk tickets imported from a connected help desk, including public comment text.
- Meeting and research recordings imported from a connected notetaker.
- Documents and context a customer adds to a workspace.
- Text a customer types or dictates into the product.
Zentrik does not fetch help desk attachments or inline images, and private and internal notes are excluded from analysis. Before analysis, ticket descriptions, comments and transcripts pass through automated redaction of identifiers such as email addresses, phone numbers and card numbers. Redaction reduces exposure. It is not de-identification.
Configuring a workspace for PHI
Configuration is work we perform with the customer before a PHI-bearing source is enabled. It covers:
- Confirming which sources are in scope, and narrowing the import to the fields and groups required.
- Turning off public web research, and agreeing not to use the rest of the functionality listed under Outside the BAA.
- Confirming that every sub-processor able to receive workspace content is itself under a BAA. The current list is on the Sub-processors page.
- Agreeing retention and deletion expectations for the content the source will carry.
Outside the BAA
Some functionality sends content to providers that are not covered by our BAA chain. PHI should not be entered into them:
- Sending a prototype specification to an external build tool that the customer connects.
- Public web research. A workspace configured for PHI turns it off.
- Email digests with record details included.
- Any source or integration that has not been scoped with us as part of the configuration above.
Functionality not listed as excluded is not automatically in scope. Scope is set by the executed BAA and the HIPAA Guide referenced in it.
Customer responsibilities
Customers decide what enters the Service. Before enabling a PHI-bearing source, assess whether the configuration is appropriate for the use case, limit workspace membership to people who need access, and apply the minimum necessary standard to the scope of the import. Shared links and exports carry whatever the underlying record contains.
Reporting and contact
Report a suspected disclosure of PHI to security@zentrik.ai. For the BAA, the HIPAA Guide, or a security questionnaire, contact legal@zentrik.ai.
Company legal contact
Zentrik Company
490 Post St, Ste 500, PMB 2017
San Francisco, CA 94102, USA
Legal: legal@zentrik.ai | Privacy: privacy@zentrik.ai | Security: security@zentrik.ai