Is Salesforce Einstein / Agentforce HIPAA compliant?
YesSalesforce · Sales & CRM
Yes. Salesforce will sign a Business Associate Agreement (BAA) for Salesforce Einstein / Agentforce, usually on an enterprise plan, which is the baseline requirement for handling PHI.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Business Associate Agreement
- Confirmed
- Salesforce publishes a BAA option. Confirm the exact plan and service are covered before sending PHI.
- Enterprise route
- Salesforce Shield add-on (Platform Encryption, Event Monitoring) on a HIPAA-eligible edition, paired with the Einstein Trust Layer
- For regulated use, validate the BAA, configured service and users under the Salesforce Shield add-on (Platform Encryption, Event Monitoring) on a HIPAA-eligible edition, paired with the Einstein Trust Layer contract.
- Default data training
- No by default
- The Einstein Trust Layer enforces zero data retention with LLM providers: prompts and responses are not persisted by the model provider or used to train the models.
- Business-tier training
- No by default
- Salesforce Shield add-on (Platform Encryption, Event Monitoring) on a HIPAA-eligible edition, paired with the Einstein Trust Layer is the business tier recorded for this profile.
How to make a decision
Check the precise account tier, written contract and intended data before approving Salesforce Einstein / Agentforce. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Salesforce Einstein / Agentforce
See the full Salesforce Einstein / Agentforce risk profile, with every data-handling fact and its source, or browse all rated AI tools.