Is Sana HIPAA compliant?
UnverifiedSana Labs · Productivity
Not verified. Check directly with Sana Labs before using Sana with protected health information (PHI).
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Business Associate Agreement
- Not verified
- No public BAA was confirmed. Treat PHI use as blocked until Sana Labs provides written terms.
- Enterprise route
- Enterprise (single-tenant deployment, SAML and SCIM, DPA)
- For regulated use, validate the BAA, configured service and users under the Enterprise (single-tenant deployment, SAML and SCIM, DPA) contract.
- Default data training
- No by default
- Sana states no customer data is used to train its or third-party LLMs, and AI subprocessors are contractually barred from training on it.
- Business-tier training
- No by default
- Enterprise (single-tenant deployment, SAML and SCIM, DPA) is the business tier recorded for this profile.
Practical risk: Sana states it does not train models on customer data, holds SOC 2 and ISO 27001, and publishes a subprocessor list and DPA. HIPAA BAA availability and a firm EU data-residency guarantee are not documented publicly, so confirm both before handling PHI or EU-restricted data.
How to make a decision
Check the precise account tier, written contract and intended data before approving Sana. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Sana
Is Sana GDPR compliant?Is Sana SOC 2 compliant?Is Sana ISO 27001 certified?Does Sana train on your data?
See the full Sana risk profile, with every data-handling fact and its source, or browse all rated AI tools.