> For the complete documentation index, see [llms.txt](https://docs.keeping.com/help/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeping.com/help/security-and-privacy/hipaa-security-configuration-requirements.md).

# HIPAA Security Configuration Requirements

This page describes the configuration requirements that apply to every HIPAA Enabled Account on Keeping. These are the "Security Configuration Requirements" referenced in Section 4.1 of Keeping's Business Associate Agreement ("BAA"). They exist so that Protected Health Information ("PHI") in your account flows only through the pathways covered by your BAA with Keeping.

Meeting these requirements is a precondition to Keeping provisioning your account as HIPAA Enabled, and a continuing obligation for as long as your account remains HIPAA Enabled.

{% hint style="warning" %}
**Important:** Only a HIPAA Enabled Account is covered by your BAA with Keeping. Do not store or transmit PHI in any other Keeping account, plan, or trial.
{% endhint %}

### Before Keeping can enable HIPAA mode

Keeping provisions HIPAA Enabled Accounts only after all of the following are in place:

#### 1. A signed BAA

You must have an executed Business Associate Agreement with Keeping covering your account. If you don't have one, contact us at <support@keeping.com> before introducing any PHI into Keeping.

#### 2. Every mailbox connected via Sign in with Google

Each shared mailbox in your account must be connected to Keeping exclusively through a direct Google (Gmail API) connection using Sign in with Google. Mailboxes connected through email forwarding, a Google Group, a Gmail Alias, or a web form are not eligible. If any mailbox in your account is not connected via Google, the account cannot be HIPAA Enabled.

#### 3. Every agent signed in with Google

Each agent with access to your account must authenticate to Keeping exclusively through Google Sign-On (OAuth), using an account in your Google Workspace domain. Keeping never sees or stores your password.&#x20;

#### 4. Your own Google Workspace BAA

Keeping works on top of Gmail, so your email lives in your own Google Workspace environment. You must maintain your own business associate agreement with Google covering the Google Workspace (Gmail) accounts you connect to Keeping, for as long as PHI is present in your account. Google's Workspace BAA is available through your Google Workspace Admin Console - see Google's documentation on HIPAA compliance with Google Workspace.

{% hint style="danger" %}
**Good to know:** Consumer (free) @gmail.com accounts are not eligible for HIPAA Enabled Accounts and may not be connected. A Google Workspace account is required.
{% endhint %}

### Maintaining these requirements after enablement

HIPAA Enabled status depends on your configuration staying in place. After enablement, you must:

* Keep every mailbox in your account connected via its direct Google connection. Do not switch a mailbox to forwarding, or disconnect and reconnect it by another method.
* Make sure every newly invited agent signs in via Google, and that existing agents don't fall back to other sign-in methods.
* Maintain your Google Workspace BAA with Google without lapse.

If a configuration change causes your account to stop meeting these requirements, Keeping may suspend or revoke the account's HIPAA Enabled status under Section 4.1(c) of the BAA. While status is suspended or revoked, Keeping's consent to store or transmit PHI in the account is revoked and the consequences in Section 5.2 of the BAA apply, until the required configuration is restored and Keeping re-provisions the account as HIPAA Enabled.

### Integrations and third-party products

HIPAA Enabled Accounts restrict the connection of third-party integrations. Any Third-Party Product you connect to, enable within, or integrate with a HIPAA Enabled Account - including automation and workflow platforms and anything enabled through Keeping's API - is outside the scope of your BAA with Keeping.

You are solely responsible for any PHI you cause to be transmitted to a Third-Party Product, including entering a separate business associate agreement with that provider where required. See Sections 3.4, 4.4, and 9 of the BAA.

### Don't send PHI to Keeping support

Keeping's own support channels - including email to Keeping support addresses and any chat or feedback mechanism we operate - are **not** HIPAA Enabled Accounts and are outside the scope of the BAA.

{% hint style="warning" %}
**Important:** Never include PHI in a message to Keeping support. If you need help with a specific conversation that contains PHI, reference it by its ticket ID rather than pasting its contents.
{% endhint %}

### Recommended practices

These are not preconditions to enablement, but we recommend them as part of your HIPAA compliance program:

* Enforce 2-Step Verification for all users in your Google Workspace domain.
* Review agent access to HIPAA Enabled mailboxes periodically, and remove agents who no longer need it.
* Set an internal policy for what may be sent to outside recipients from a HIPAA Enabled mailbox.
* Export or back up any data you need before a plan downgrade or cancellation - downgrading or lapsing revokes HIPAA Enabled status immediately (BAA §§1.3, 5.2), and you are responsible for exporting PHI before termination (BAA §5.4).

### Questions

If you're unsure whether your configuration meets these requirements, or you'd like to enable HIPAA mode for your account, contact us at <support@keeping.com>.
