Slack HIPAA Compliance: The Definitive Guide | Nightfall AI

Slack HIPAA Compliance: The Definitive Guide

Michael Osakwe

May 9, 2023

Slack allows organizations of all sizes and across industries to collaborate with ease. While healthcare organizations can benefit from the power of Slack, it is essential that any Covered Entities or organizations that are otherwise handling PHI to understand what they can and cannot do in Slack to ensure they stay compliant with HIPAA.

Read this online guide, for free, to learn about Slack requirements for Covered Entities and how to ensure PHI is not at risk of exposure in Slack. You may also download this content here.

Is Slack HIPAA compliant?

Slack is not HIPAA compliant out of the box. This is something that Slack's user agreement explicitly specifies. In order for Covered Entities, like healthcare providers to leverage Slack, specific standards and controls must be in place within their Slack instance to ensure the satisfaction of HIPAA requirements. Before adopting Slack, covered entities need to understand their requirements as well as their intended use case for Slack. This analysis helps organizations determine if they can maintain HIPAA compliance on Slack.

The requirements to enable and maintain HIPAA compliance on Slack can broadly be grouped into four categories:

What are examples of HIPAA compliant use cases?

Slack has a blog post listing examples of HIPAA compliant use cases. The TL;DR is Slack is meant to streamline collaboration within healthcare organizations and is not sanctioned for communications between patients and care providers.

Some examples of HIPAA compliant Slack uses cases include:

What are Slack's requirements for maintaining HIPAA compliance?

Slack also details important technological processes and standards you will need to consider:

The last requirement can be accomplished with tools like:

How do you maintain good cyber hygiene on Slack?

The purpose of data and cyber hygiene is to implement policies and best practices that normalize behaviors that limit oversharing sensitive information as preemptive security measure. For example, the 2020 Twitter hack entailed an external threat actor finding a password to Twitter's backend in Slack. It was presumably shared months, or maybe years ago by an engineer who was trying to work with a collaborator.

With regard to Slack hygiene, you'll want to consider the following:

Use consistent channel naming conventions that complement business objectives and security policies

Within a HIPAA compliant Slack workspace, there are private channels that are intended to be used to discuss sensitive topics involving PHI. One way to ensure that PHI is not accidentally shared outside these channels is to use a clear and consistent process for naming all channels where PHI will be shared. When developing your organization’s channel creation policies, you should make sure that channels are clearly named using Slack’s recommended naming conventions.

Use automated deletion to remove sensitive information and accounts no longer in use

Slack makes it easy to create automated policies around message retention and user account management. For example, Slack guest accounts can be set to expire after a time limit, ensuring that external collaborators or contractors meant only to have temporary access to your workspace are automatically removed once after an appropriate amount of time. Similarly, messages and files in Slack channels or entire workspaces can be automatically deleted after a specified time limit.

Leverage engaged stakeholders to manage Slack workspaces

Within Slack Enterprise Grid the following administrative roles exist:

Watch these five areas of data exposure risk with Data Loss Prevention

Within Slack, the following areas can contribute to sensitive data exposure:

What are important HIPAA Security Rule Considerations on Slack?

The HIPAA Security Rule provides a number of guidelines that are relevant to organizations on Slack, including:

Bottom line: In addition to following Slack’s rules for maintaining HIPAA compliance, organizations will need to ensure they have security tools like Data Loss Prevention (DLP) in their workspaces because Slack relies on third-party vendors to provide the controls necessary to satisfy HIPAA Security Rule guidelines.

What is data loss prevention in Slack?

Collaborative SaaS applications like Slack create environments where data policy and security best practices are difficult to maintain or enforce without an excessive time or resource commitment. Data loss prevention helps provides companies with a feasible alternative to address this problem.

What is Nightfall DLP?

Nightfall is a platform to discover, classify and protect sensitive data across cloud SaaS & cloud infrastructure.