Is HeyGen HIPAA compliant?
UnverifiedHeyGen · Video
Not verified. Check directly with HeyGen before using HeyGen with protected health information (PHI).
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Business Associate Agreement
- Not verified
- No public BAA was confirmed. Treat PHI use as blocked until HeyGen provides written terms.
- Enterprise route
- Enterprise (excluded from training, DPA, SSO and SCIM, contractual deletion terms)
- For regulated use, validate the BAA, configured service and users under the Enterprise (excluded from training, DPA, SSO and SCIM, contractual deletion terms) contract.
- Default data training
- Opt-out required
- Non-enterprise inputs and outputs may be used to train and improve HeyGen's avatar models; consumer users can request opt-out by emailing [email protected].
- Business-tier training
- No by default
- Enterprise customer data is excluded from training by default under the Master SaaS Agreement.
Practical risk: HeyGen holds SOC 2 Type II and stays US only. On consumer plans HeyGen may use your inputs to improve its models unless you email to opt out, and there is no BAA, so keep PHI out of it.
How to make a decision
Check the precise account tier, written contract and intended data before approving HeyGen. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on HeyGen
Is HeyGen GDPR compliant?Is HeyGen SOC 2 compliant?Is HeyGen ISO 27001 certified?Does HeyGen train on your data?
See the full HeyGen risk profile, with every data-handling fact and its source, or browse all rated AI tools.