ModelCharter

Is Intercom Fin HIPAA compliant?

Yes

Intercom · Customer support

Yes. Intercom will sign a Business Associate Agreement (BAA) for Intercom Fin, usually on an enterprise plan, which is the baseline requirement for handling PHI.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

Business Associate Agreement
Confirmed
Intercom publishes a BAA option. Confirm the exact plan and service are covered before sending PHI.
Enterprise route
Expert plan plus Regional Data Hosting addendum plus signed BAA (the config that gates HIPAA, SSO and auto-exclusion from AI training)
For regulated use, validate the BAA, configured service and users under the Expert plan plus Regional Data Hosting addendum plus signed BAA (the config that gates HIPAA, SSO and auto-exclusion from AI training) contract.
Default data training
Opt-out required
Intercom's own fin-cx models are trained on anonymized Customer Data from active workspaces; workspaces with a HIPAA BAA, on EU or AU regional hosting, or on trial are auto-excluded, and you can self-serve opt out in Settings.
Business-tier training
No by default
Third-party LLMs (OpenAI, Anthropic, Google) are contractually barred from training.
Practical risk: On the top Expert plan with Regional Data Hosting and a signed BAA, Fin holds SOC 2 Type II and ISO 27001, keeps third-party LLMs out of training, and offers EU residency. Lower plans train Intercom's own models on anonymized data unless you opt out.

How to make a decision

Check the precise account tier, written contract and intended data before approving Intercom Fin. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Intercom Fin

See the full Intercom Fin risk profile, with every data-handling fact and its source, or browse all rated AI tools.