ModelCharter

Is Midjourney HIPAA compliant?

Unverified

Midjourney, Inc. · Image

Not verified. Check directly with Midjourney, Inc. before using Midjourney with protected health information (PHI).

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

Business Associate Agreement
Not verified
No public BAA was confirmed. Treat PHI use as blocked until Midjourney, Inc. provides written terms.
Enterprise route
Not confirmed
Do not infer a regulated-use tier from consumer product marketing.
Default data training
Yes by default
Midjourney's Terms of Service grant it a broad license to reproduce and prepare derivative works of submitted text/image prompts and generated assets, which it uses to train and improve its models by default.
Business-tier training
Yes by default
Paid Pro/Mega users are also subject to model training; Stealth Mode only keeps generations out of the public gallery and Midjourney still retains the license to use them for service improvement.
Practical risk: All prompts and generated images are public by default and licensed for model training, and Stealth Mode (Pro/Mega only) merely hides outputs from the public gallery without exempting them from training, so confidential work-related content should not be used.

How to make a decision

Check the precise account tier, written contract and intended data before approving Midjourney. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Midjourney

See the full Midjourney risk profile, with every data-handling fact and its source, or browse all rated AI tools.