Is Signal HIPAA Compliant?

Signal's encryption is genuinely strong. But "encrypted" and "HIPAA compliant" are different claims, and the gap — a signed BAA, admin controls, audit trails — is everything a healthcare organization actually needs.

Get started for freeSchedule a demo →
No

No. Signal does not offer a Business Associate Agreement and has no healthcare compliance program. Signal is a consumer messaging app operated by a nonprofit with no enterprise tier, no organizational admin controls, and no audit trail. Using Signal for protected health information puts a healthcare organization outside HIPAA regardless of Signal's end-to-end encryption.

Why?

Signal does not offer a BAA

Signal's terms of service and privacy policy make no mention of HIPAA, Business Associate Agreements, healthcare, or covered entities. Without a signed BAA, any third-party service that handles PHI on behalf of a covered entity is operating outside HIPAA.

Source: Signal Terms of Service and Privacy Policy

No enterprise or business tier

Signal is a free consumer messaging app with no paid tier, no enterprise plan, and no mechanism for a healthcare organization to contract with Signal for compliant use. Platforms like Slack and Microsoft Teams offer BAAs on specific plans. Signal has no such path — there is no plan to upgrade to and no sales team to contact.

Source: Signal Terms of Service and Privacy Policy

No organizational admin controls

Signal accounts are tied to individual phone numbers and personal devices. There is no admin console, no centralized user management, and no ability to remove a departing staff member's access to conversations or reassign message history. Messages belong to the individual, not the organization. When a staff member leaves, the practice has no way to recover or revoke access to the PHI in those conversations.

Source: Signal Terms of Service and Privacy Policy

No audit trail or organizational data retention

Signal is architected to retain minimal data. In response to government subpoenas, Signal has stated it can produce only the date a user registered and the date of their last connection. HIPAA requires covered entities to maintain records of who accessed PHI and when. Signal's design makes organizational audit logging impossible.

Source: Signal Government Requests

Encryption alone does not satisfy HIPAA

Signal uses the Signal Protocol for end-to-end encryption, and that encryption is genuinely strong — it is the same protocol used by WhatsApp and Google Messages. But HHS has clarified that encryption does not remove the obligation to enter into a BAA. The HIPAA Security Rule requires administrative safeguards, access controls, audit logging, and breach notification procedures in addition to encryption.

Source: HHS FAQ: encrypted ePHI and BAA requirements

What Signal says

Signal's terms of service and privacy policy make no reference to HIPAA, healthcare, or Business Associate Agreements. Signal describes itself as "an independent nonprofit" focused on private communication for individuals. The service is provided without warranties of fitness for any particular purpose.
Source: Signal Terms of Service and Privacy Policy

HIPAA-compliant alternatives

BloomText

Purpose-built HIPAA messaging with a signed BAA on every plan, including the free plan. Patients reply via SMS without downloading an app.

TigerConnect

Enterprise clinical messaging platform used by hospitals and health systems. Includes role-based routing and EHR integrations.

Spruce Health

HIPAA-compliant communication platform for medical practices with secure messaging, phone, fax, and telehealth in one system.

Frequently Asked Questions

Is Signal HIPAA compliant?

No. Signal does not offer a BAA, has no enterprise tier, and provides no admin controls or audit trail. Its end-to-end encryption is strong, but encryption is one requirement among many. HIPAA also requires a signed BAA, organizational access controls, audit logging, and breach notification procedures — none of which Signal provides.

Does Signal offer a BAA?

No. Signal does not offer a BAA and there is no tier, plan, or configuration that makes one available. Signal is a free consumer app operated by a nonprofit. A signed BAA is required under HIPAA before transmitting PHI through any third-party service.

Signal is end-to-end encrypted — isn't that enough for HIPAA?

No. Signal's encryption is genuinely strong, but HIPAA requires more than message confidentiality. A signed BAA, administrative safeguards, organizational access controls, audit logging, and breach notification procedures are all separate HIPAA obligations. HHS has confirmed that encryption alone does not remove the requirement to enter into a BAA.

What happens to messages when a staff member leaves?

Signal messages live on the individual's personal devices. There is no admin console to revoke access, no way to transfer conversation history to another staff member, and no organizational backup. When someone leaves, the PHI in those conversations may remain on their personal phone indefinitely, outside the organization's control. A HIPAA-compliant messaging platform lets the organization deactivate a departing member's access and keep conversation history under its control.

Can a practice use Signal if no patient names are used?

Protected health information includes any information that could identify a patient, not just names. Appointment times, treatment details, phone numbers, and other identifiers can constitute PHI. In practice, PHI tends to enter any channel that staff use for clinical discussion, making it difficult to keep a non-compliant app safely separated from patient information. Avoiding names does not eliminate the HIPAA requirements for a BAA, access controls, and audit logging.

What should a practice use instead of Signal?

If your practice is already using Signal for clinical communication, the priority is moving those conversations to a platform that can sign a BAA and give the organization control over its messages. Look for a signed BAA, organizational admin controls, conversation auditing, and the ability to manage staff access centrally. BloomText provides all of these on every plan, including the free plan, and patients reply via standard SMS without downloading an app.

Sources

Last verified August 25, 2026.

  1. BloomText pricing
  2. Signal Terms of Service and Privacy Policy
  3. Signal Government Requests
  4. HHS HIPAA Security Rule
  5. HHS FAQ: encrypted ePHI and BAA requirements

Need HIPAA-compliant messaging?

Get started for freeSchedule a demo →

Trusted by today's leading healthcare professionals

Streamlined appointment schedulingWith BloomText Broadcast SMS Messaging, I literally took the job of 20 employees and I can do it by myself in three and a half hours.Chief Administrative Officer, Radiology
Best HIPAA app on the marketBloomText has brought our clinic into the modern age, and our patients love being able to communicate with us via text or through our website.Office Administrator, Family Medicine
Excellent for acute careBloomText is the nervous system for my business. It helps us differentiate ourselves in terms of our communication and our quality of care.Clinical Director, Acute Care