Is Airtable HIPAA Compliant?
Is Airtable HIPAA compliant? Only on the Enterprise Scale plan, with a signed BAA — not on Team or Business plans. See BAA status, where PHI ends up, the AI/MCP gap, and how Strac protects it.
Yes, but only on one plan. Since 2024 Airtable signs a Health Information Exhibit (which contains the BAA) — but exclusively on the Enterprise Scale plan, and PHI is allowed only inside base records. Airtable AI, automations, emails, and the MCP server are explicitly outside that coverage. HIPAA compliance is never automatic — it depends on a signed Business Associate Agreement with the vendor plus how you configure and use the tool. Below is exactly where Airtable stands, where PHI ends up, the AI/MCP gap most teams miss, and how to close it. Verified August 2026.

Airtable states: “HIPAA is available on our Enterprise Scale Plan and customers will need to sign Airtable’s Business Associate Addendum,” and that anyone intending to store ePHI “must be on the Enterprise Scale plan.” Free, Team, and Business tiers cannot hold PHI. Enterprise controls include customer-managed encryption keys (EKM), SSO, and audit logs.
| Product / surface | PHI status |
|---|---|
| ✅ ePHI in base & interface records | On an Enterprise Scale environment with the executed exhibit, backed by EKM, SSO, and audit logs |
| ❌ Airtable AI | “Do not store ePHI in workspaces where Airtable AI is enabled” unless separate AI Terms are accepted |
| ❌ Automations & emails | PHI must not appear in an email body or subject line |
| ❌ Support tickets & patient-portal use | PHI barred from screenshots/tickets; Airtable may not be used as a patient portal |
| ❌ Integrations & the MCP server | Data leaving the Airtable boundary is the customer’s responsibility |
Source: Airtable HIPAA docs. Vendor terms change — reconfirm your plan’s eligibility in writing before sending PHI.
Even teams that never intend to handle PHI accumulate it in Airtable. The common places it lands:
Airtable ships an official MCP Server that lets Claude, ChatGPT, Cursor, and other models list bases and read, filter, and create records in natural language, and Airtable AI generates and summarizes at the field level. Both move base records — including any PHI — to an LLM, and Airtable AI is explicitly outside the BAA unless separate AI Terms are signed.
The BAA is Enterprise-Scale-only and narrow: PHI may live only in records, and is prohibited in automations, emails, support tickets, patient-portal use, and Airtable AI or MCP unless separately covered. This is the leak path traditional HIPAA controls were never designed to see: the data does not breach outward, it is pulled inward by an AI agent on a legitimate, authenticated tool call. Read more on MCP data loss prevention and MCP DLP.

A BAA is a contract — it makes the vendor liable for the data it holds. It does not inspect your data, and it does not follow PHI into the AI features, integrations, or exports that sit outside its scope. Whether or not Airtable signs one, three gaps remain: PHI a user pastes or uploads where it should not go; PHI an AI agent pulls out over MCP; and PHI already sitting in Airtable that no one has found. Closing them needs data-layer DLP, not just paperwork.
Strac closes the exact gaps a Airtable BAA leaves open, across every surface PHI can move:

Detection alone does not stop a HIPAA violation — remediation does. Strac does not just alert; it acts the moment PHI appears:

PHI does not stay inside Airtable. It flows into email, chat, cloud storage, GenAI tools, and AI agents — so point fixes leave gaps. Strac is one agentless-plus-endpoint platform covering SaaS, cloud, browser, GenAI, endpoint, and MCP under a single policy and classifier, live in minutes.

| Question | Answer |
|---|---|
| Does Airtable sign a BAA? | Yes — eligible plans, executed BAA required |
| Is the AI / MCP layer covered? | No — outside the BAA; the main leak path |
| Can PHI be used safely? | Yes, on an eligible plan with a BAA plus data-layer controls |
| What closes the gap? | Strac MCP + Browser + Endpoint DLP and DSPM |
No tool is. You must be on an eligible plan, execute the BAA, and configure controls before PHI.
No. That is the single most common misread — the AI/MCP layer sits outside the core BAA and is the most likely place PHI leaks to a model.
Yes. Airtable’s official MCP server lets an agent read data on an authenticated tool call. Strac redacts PHI on that path before the agent sees it.
No. A BAA assigns liability; it does not inspect your data or follow PHI into AI, integrations, or exports. You still need data-layer DLP.
Strac layers on without slowing Airtable down — redacting PHI at the MCP layer, blocking it in the browser and on the endpoint, and finding PHI already stored via DSPM.
Related reading:
Airtable can be used with PHI on an eligible plan with a signed BAA — but the BAA stops at the core workflow, while the AI/MCP layer keeps moving PHI. Strac closes the gap on every surface — redacting PHI at the MCP layer, blocking it in the browser and on the endpoint, and finding what is already stored. Book a demo to see it on Airtable.
.avif)
.avif)
.avif)
.avif)
.avif)


.gif)

