ModelCharter

Is HeyGen HIPAA compliant?

Unverified

HeyGen · Video

Not verified. Check directly with HeyGen before using HeyGen with protected health information (PHI).

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

Business Associate Agreement
Not verified
No public BAA was confirmed. Treat PHI use as blocked until HeyGen provides written terms.
Enterprise route
Enterprise (excluded from training, DPA, SSO and SCIM, contractual deletion terms)
For regulated use, validate the BAA, configured service and users under the Enterprise (excluded from training, DPA, SSO and SCIM, contractual deletion terms) contract.
Default data training
Opt-out required
Non-enterprise inputs and outputs may be used to train and improve HeyGen's avatar models; consumer users can request opt-out by emailing [email protected].
Business-tier training
No by default
Enterprise customer data is excluded from training by default under the Master SaaS Agreement.
Practical risk: HeyGen holds SOC 2 Type II and stays US only. On consumer plans HeyGen may use your inputs to improve its models unless you email to opt out, and there is no BAA, so keep PHI out of it.

How to make a decision

Check the precise account tier, written contract and intended data before approving HeyGen. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on HeyGen

See the full HeyGen risk profile, with every data-handling fact and its source, or browse all rated AI tools.