Is Zendesk HIPAA Compliant?
Learn how your organization's use of Zendesk can be brought into full compliance with HIPAA standards
In its standard configuration, Zendesk does not comply with HIPAA standards.
Although Zendesk offers various security features intended to safeguard sensitive data, there are questions around the best way to go about handling Protected Health Information (PHI) in a HIPAA-compliant manner. Healthcare organizations must take steps to bring their use of Zendesk into compliance with HIPAA standards.
First, organizations must be subscribed to a Zendesk Suite plan or have purchased a HIPAA-compliant Zendesk add-on like the Advanced Data Privacy and Protection Add-On.
Second, to bring their use of Zendesk into full compliance with HIPAA standards, covered entities such as organizations involved with healthcare must agree to a Business Associate Agreement (BAA) or equivalent with Zendesk.
Although Zendesk offers various security features intended to safeguard sensitive data, there are questions around the best way to go about handling PHI in a HIPAA-compliant manner.
For a third-party provider to be considered HIPAA compliant, it must agree to the terms of a BAA with any customers classed as HIPAA covered entities that use its service for storing or processing PHI.
Like some other third-party software providers, Zendesk does not offer individual Business Associate Agreements to each of its customers. Instead, Zendesk offers a standardized addendum as part of its Main Services Agreement, that all customers agree to.
Zendesk’s standardized addendum includes all of the essential terms usually covered in a BAA. For example, the addendum outlines the obligations of both parties and specifies which Zendesk services fall under the scope of the addendum.
Zendesk can be configured to support the secure handling of PHI, but storing patient data and PHI in Zendesk carries significant compliance and data security risks.
Whilst Zendesk does offer various security mechanisms, it lacks sensitive data detection protocols. This means that Zendesk’s security settings can’t be configured to automatically identify and redact sensitive comments and attachments within Zendesk help tickets and other communications.
Yes, even with Zendesk’s additional security mechanisms, there will always be a risk of data leaks.
Data leaks can occur due to misconfigured settings, unauthorized access, or accidental sharing. To minimize these risks, healthcare organizations opt to implement additional data security mechanisms such as strong authentication methods, access controls and automated identification and redaction capabilities.
Data security is also dependent on employees who are trained on how to properly handle sensitive data, in line with data privacy and security standards.
The persistent risks of leaks and non-compliance with data security standards highlights the need for robust data loss prevention solutions. Many organizations opt to ensure their customers' sensitive data is effectively protected through the use of a DLP solution.
As standard, Zendesk lacks native data loss prevention functionality. This gap leaves the healthcare organizations that use Zendesk as a multi-purpose CRM vulnerable to unauthorized access of sensitive data, accidental leaks and other employee mishaps.
Strac Zendesk DLP ensures your organization's use of Zendesk remains secure and fully compliant, at all times.
Here's how Strac DLP integration works:
To learn more about how Strac ensures ongoing compliance with HIPAA standards, see our guide to HIPAA Compliance.
Book a free 30-minute demo to learn how Strac can keep your business secure and fully compliant.