ModelCharter

Is Sana HIPAA compliant?

Unverified

Sana Labs · Productivity

Not verified. Check directly with Sana Labs before using Sana with protected health information (PHI).

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

Business Associate Agreement
Not verified
No public BAA was confirmed. Treat PHI use as blocked until Sana Labs provides written terms.
Enterprise route
Enterprise (single-tenant deployment, SAML and SCIM, DPA)
For regulated use, validate the BAA, configured service and users under the Enterprise (single-tenant deployment, SAML and SCIM, DPA) contract.
Default data training
No by default
Sana states no customer data is used to train its or third-party LLMs, and AI subprocessors are contractually barred from training on it.
Business-tier training
No by default
Enterprise (single-tenant deployment, SAML and SCIM, DPA) is the business tier recorded for this profile.
Practical risk: Sana states it does not train models on customer data, holds SOC 2 and ISO 27001, and publishes a subprocessor list and DPA. HIPAA BAA availability and a firm EU data-residency guarantee are not documented publicly, so confirm both before handling PHI or EU-restricted data.

How to make a decision

Check the precise account tier, written contract and intended data before approving Sana. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Sana

See the full Sana risk profile, with every data-handling fact and its source, or browse all rated AI tools.