Is DocuSign HIPAA Compliant?
Is DocuSign HIPAA compliant? Yes — DocuSign signs a BAA, so it can be used for PHI when configured correctly. See BAA status, where PHI ends up, the AI/MCP gap, and how Strac protects it.
Yes — DocuSign signs a BAA, so it can be used for PHI when configured correctly. HIPAA compliance is never automatic — it depends on a signed Business Associate Agreement (BAA) with the vendor plus how you configure and use the tool. Below is where DocuSign stands, where PHI ends up, and the AI/MCP gap most teams miss.

DocuSign will sign a Business Associate Agreement and publishes HIPAA guidance, which makes it one of the few e-signature platforms you can legitimately use for PHI — patient consent forms, HIPAA authorizations, and release-of-information documents — provided the BAA is active on your plan and you lock down access and audit logging.
Even teams that "don’t use DocuSign for health data" accumulate PHI in it: signed consent forms, HIPAA authorizations, intake paperwork, and the envelope fields that carry patient identifiers. Under HIPAA, a single identifier tied to health information is enough to trigger the rules — so the question isn’t whether PHI could land in DocuSign, it’s what protects it when it does.
Here is the gap even a BAA doesn’t close. The moment someone connects DocuSign to an AI assistant over the Model Context Protocol (MCP), an agent can query it and pull PHI straight into the model’s context. If that model is Claude Cowork — which Anthropic will not sign a BAA for — the PHI now sits outside your BAA perimeter, a reportable exposure even though DocuSign itself is configured correctly.

Strac MCP DLP sits on the MCP path, detects PHI in every request and response, and redacts, masks, or blocks it before it reaches the assistant — so an AI that won’t sign a BAA never sees regulated data. And Strac browser and endpoint DLP catch PHI before it is pasted or typed into DocuSign in the first place. Every action is audit-logged for HIPAA. See MCP integrations and DocuSign MCP server.

Is DocuSign HIPAA compliant in 2026? Yes — DocuSign signs a BAA, so it can be used for PHI when configured correctly.
Can I use DocuSign with Claude or ChatGPT and stay HIPAA compliant? Only if PHI never reaches a model that isn’t under a BAA. Claude Cowork does not sign one, so connecting DocuSign over MCP can expose PHI. Strac MCP DLP redacts PHI on the MCP path before it reaches the assistant.
Does DocuSign store PHI? It can — signed consent forms, HIPAA authorizations, intake paperwork, and the envelope fields that carry patient identifiers. Whether or not that’s intended, it needs to be protected.
.avif)
.avif)
.avif)
.avif)
.avif)


.gif)

