Calendar Icon White
August 30, 2026
Clock Icon
5
 min read

Is Airtable HIPAA Compliant?

Is Airtable HIPAA compliant? Only on the Enterprise Scale plan, with a signed BAA — not on Team or Business plans. See BAA status, where PHI ends up, the AI/MCP gap, and how Strac protects it.

Is Airtable HIPAA Compliant?
ChatGPT
Perplexity
Grok
Google AI
Claude
Summarize and analyze this article with:

TL;DR

  • Is Airtable HIPAA compliant? Yes, conditionally — Airtable signs a BAA on eligible plans, but only for its core surface.
  • Airtable routinely touches PHI in a healthcare context — the moment a covered entity uses it, patient data is in scope.
  • The newest risk is AI over MCP: Airtable now exposes an official MCP server and AI features that can pull that data into an LLM with no BAA behind it.
  • A signed BAA (where one exists) covers the app’s core workflow — not the AI/MCP layer, integrations, or data leaving its boundary.
  • Strac keeps PHI safe either way — detecting and redacting it on the MCP path, in the browser, and on the endpoint, and finding PHI already stored at rest.

✨ Is Airtable HIPAA Compliant? The Direct Answer

Yes, but only on one plan. Since 2024 Airtable signs a Health Information Exhibit (which contains the BAA) — but exclusively on the Enterprise Scale plan, and PHI is allowed only inside base records. Airtable AI, automations, emails, and the MCP server are explicitly outside that coverage. HIPAA compliance is never automatic — it depends on a signed Business Associate Agreement with the vendor plus how you configure and use the tool. Below is exactly where Airtable stands, where PHI ends up, the AI/MCP gap most teams miss, and how to close it. Verified August 2026.

Strac MCP DLP redacts PHI from Airtable before it reaches an AI assistant that has not signed a BAA
Connect Airtable to an AI assistant over MCP and PHI can leave your BAA. Strac MCP DLP redacts it on the path.

Does Airtable Sign a BAA?

Airtable states: “HIPAA is available on our Enterprise Scale Plan and customers will need to sign Airtable’s Business Associate Addendum,” and that anyone intending to store ePHI “must be on the Enterprise Scale plan.” Free, Team, and Business tiers cannot hold PHI. Enterprise controls include customer-managed encryption keys (EKM), SSO, and audit logs.

Product / surfacePHI status
✅ ePHI in base & interface recordsOn an Enterprise Scale environment with the executed exhibit, backed by EKM, SSO, and audit logs
❌ Airtable AI“Do not store ePHI in workspaces where Airtable AI is enabled” unless separate AI Terms are accepted
❌ Automations & emailsPHI must not appear in an email body or subject line
❌ Support tickets & patient-portal usePHI barred from screenshots/tickets; Airtable may not be used as a patient portal
❌ Integrations & the MCP serverData leaving the Airtable boundary is the customer’s responsibility

Source: Airtable HIPAA docs. Vendor terms change — reconfirm your plan’s eligibility in writing before sending PHI.

Where PHI Ends Up in Airtable

Even teams that never intend to handle PHI accumulate it in Airtable. The common places it lands:

  • Patient tracking records: name, DOB, MRN, and contact info stored as structured fields
  • Care-coordination, referral, and intake-tracking data
  • Clinical-trial or research-participant records
  • Patient status, condition notes, and appointment or treatment logs

✨ The New Risk: Airtable + AI Agents via MCP

Airtable ships an official MCP Server that lets Claude, ChatGPT, Cursor, and other models list bases and read, filter, and create records in natural language, and Airtable AI generates and summarizes at the field level. Both move base records — including any PHI — to an LLM, and Airtable AI is explicitly outside the BAA unless separate AI Terms are signed.

The BAA is Enterprise-Scale-only and narrow: PHI may live only in records, and is prohibited in automations, emails, support tickets, patient-portal use, and Airtable AI or MCP unless separately covered. This is the leak path traditional HIPAA controls were never designed to see: the data does not breach outward, it is pulled inward by an AI agent on a legitimate, authenticated tool call. Read more on MCP data loss prevention and MCP DLP.

Strac browser and GenAI DLP redacting sensitive data before it reaches an AI model
Strac inspects and redacts sensitive data in real time as it moves toward an AI tool.

🎥 Why a Signed BAA Still Leaves a Gap

A BAA is a contract — it makes the vendor liable for the data it holds. It does not inspect your data, and it does not follow PHI into the AI features, integrations, or exports that sit outside its scope. Whether or not Airtable signs one, three gaps remain: PHI a user pastes or uploads where it should not go; PHI an AI agent pulls out over MCP; and PHI already sitting in Airtable that no one has found. Closing them needs data-layer DLP, not just paperwork.

Strac detects and redacts PII/PHI in real time across the browser and GenAI tools.

✨ How Strac Protects PHI in Airtable

Strac closes the exact gaps a Airtable BAA leaves open, across every surface PHI can move:

  • MCP DLP: Strac inspects every MCP tool call to and from Airtable and redacts PHI before it reaches Claude, ChatGPT, or any agent — so an AI assistant with no BAA never sees a patient identifier.
  • Browser / GenAI DLP: Strac’s browser extension detects PHI as it is typed, pasted, or uploaded into Airtable or a GenAI tool and blocks, warns, or redacts it in real time.
  • Endpoint DLP: When PHI is exported, downloaded, or copied from Airtable to a device, Strac’s Mac and Windows agent enforces at the file, USB, print, and upload channels.
  • DSPM: Strac scans Airtable and connected stores to find PHI already sitting at rest, classifies it, and flags oversharing so you can remediate it.
Strac automatically redacting sensitive data in real time
Strac redacts sensitive data automatically — the same detection and redaction engine runs across every surface.

✨ Remediation in Action: Redact, Block, Warn, Revoke

Detection alone does not stop a HIPAA violation — remediation does. Strac does not just alert; it acts the moment PHI appears:

  • Redact: strip PHI from the message, ticket, record, or MCP response and vault the original for authorized access.
  • Block: stop a PHI-bearing prompt, upload, or export before it leaves — in the browser and on the endpoint.
  • Warn & coach: tell the employee in the moment why an action was risky, turning policy into training.
  • Revoke access: when PHI is found oversharing in a connected store, Strac removes public and external access so no agent or person can reach it.
Strac warning and blocking a sensitive file upload in real time
Strac warns and blocks sensitive uploads in real time, then coaches the user — content-aware, not a blunt lock.

✨ One Platform Across Every Surface Airtable Touches

PHI does not stay inside Airtable. It flows into email, chat, cloud storage, GenAI tools, and AI agents — so point fixes leave gaps. Strac is one agentless-plus-endpoint platform covering SaaS, cloud, browser, GenAI, endpoint, and MCP under a single policy and classifier, live in minutes.

Strac data-security coverage across SaaS, cloud, endpoint, browser, GenAI and MCP
Strac covers SaaS, cloud, browser, endpoint, GenAI, and MCP from one platform — one policy for every place PHI moves.

A Practical Airtable HIPAA Deployment Checklist

  1. Contract: Execute Airtable’s BAA on an eligible plan before any PHI, and confirm which services are in scope in writing.
  2. Scope the AI/MCP layer: inventory whether Airtable’s MCP server and AI features are enabled, and confirm they are excluded from — or explicitly added to — your coverage.
  3. Deploy Strac MCP DLP: put redaction in front of every Airtable MCP tool call so no agent receives raw PHI.
  4. Deploy Browser + Endpoint DLP: block and redact PHI at entry and export across the web app and devices.
  5. Run DSPM: scan Airtable for PHI already stored, classify it, and remediate oversharing.
  6. Prove it: keep the audit log of every detection and remediation as HIPAA evidence.

Airtable HIPAA Compliance: Quick Reference

QuestionAnswer
Does Airtable sign a BAA?Yes — eligible plans, executed BAA required
Is the AI / MCP layer covered?No — outside the BAA; the main leak path
Can PHI be used safely?Yes, on an eligible plan with a BAA plus data-layer controls
What closes the gap?Strac MCP + Browser + Endpoint DLP and DSPM

🌶️ Spicy FAQs for Is Airtable HIPAA Compliant

Is Airtable HIPAA compliant out of the box?

No tool is. You must be on an eligible plan, execute the BAA, and configure controls before PHI.

Does Airtable’s BAA cover its AI and MCP features?

No. That is the single most common misread — the AI/MCP layer sits outside the core BAA and is the most likely place PHI leaks to a model.

Can an AI agent pull PHI out of Airtable?

Yes. Airtable’s official MCP server lets an agent read data on an authenticated tool call. Strac redacts PHI on that path before the agent sees it.

Is a BAA enough for HIPAA?

No. A BAA assigns liability; it does not inspect your data or follow PHI into AI, integrations, or exports. You still need data-layer DLP.

How does Strac help if we already use Airtable?

Strac layers on without slowing Airtable down — redacting PHI at the MCP layer, blocking it in the browser and on the endpoint, and finding PHI already stored via DSPM.

Related reading:

The Bottom Line

Airtable can be used with PHI on an eligible plan with a signed BAA — but the BAA stops at the core workflow, while the AI/MCP layer keeps moving PHI. Strac closes the gap on every surface — redacting PHI at the MCP layer, blocking it in the browser and on the endpoint, and finding what is already stored. Book a demo to see it on Airtable.

Is Airtable HIPAA compliant in 2026?
Can I use Airtable with Claude or ChatGPT and stay HIPAA compliant?
Does Airtable store PHI?
Discover & Protect Data on SaaS, AI, MCP, Endpoints & Cloud
Strac provides end-to-end data loss prevention for all SaaS and Cloud apps. Integrate in under 10 minutes and experience the benefits of live DLP scanning, live redaction, and a fortified SaaS environment.
Trusted by enterprises
Data Security + Compliance Automation

Latest articles

Browse all

Get Your Datasheet

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Close Icon