Available on the Asana Enterprise+ tier, as well as legacy tier Legacy Enterprise for existing customers who have already enabled the feature.
Visit our pricing page for more information.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law in the United States that requires the creation of national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. Businesses that are subject to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) can use Asana to support HIPAA-compliant work management.
HIPAA compliance for Asana is governed by Asana’s Business Associate Addendum (BAA). For additional detail on HIPAA and Asana, please refer to the HIPAA Data Sheet.
To enable HIPAA compliance, following steps will facilitate agreement to Asana’s Business Associate Addendum (BAA) and enable HIPAA compliance in your domain. Please note that a super admin must agree to Asana’s BAA in the admin console to activate HIPAA compliance.
Existing Legacy Enterprise customers who have not enabled HIPAA compliance will need to move to the Asana Enterprise+ tier if they wish to enable it.

From the Admin Console, navigate to the Security tab.

Navigate to HIPAA compliance and review the BAA + Use Requirements and Limitations.
.

Upon agreeing to the terms, please allow 24 hours for HIPAA compliance to activate across your domain..
Please review Asana’s Data Sheet for guidance on maintaining HIPAA compliance in your domain.
Activating HIPAA compliance in an Asana domain has broad implications on the product behavior. This includes behavior around Asana AI features, notifications, mobile, and login experiences. For more detail on HIPAA-related changes, please review Asana's HIPAA Data Sheet and Business Associate Addendum (BAA).
Note
PHI (Personal Health Information) should only be entered into project or task descriptions, task titles, custom fields on tasks, comments, and attachments on tasks. See the HIPAA Use Requirements and Limitations for more information.
All integrations and Personal Access Tokens (PATs) within a domain will be disabled by default. Previously enabled apps will remain enabled and a super admin must use our App Management feature to review existing integrations use. New applications will require an Asana super admin’s approval in order to be enabled. If an integration is disabled, this applies to all users in the domain.
Goals will remain unchanged but should not include PHI. PHI should be limited to project or task descriptions, task titles, custom fields on tasks, comments, and attachments on tasks. See our HIPAA Use Requirements and Limitations for more information.
There will be no change to reporting. You’ll still have access to the same tasks, projects and portfolios as before HIPAA compliance was activated.

These cookies are strictly necessary to provide you with certain features. For example, these cookies allow you to access secure areas that require registration and set your privacy preferences. Because these cookies are essential to providing services to you, they cannot be disabled. You can set your browser to block or alert you about these cookies, but it may cause some parts of the site to not work.
Third party trackers collect information used for analytics and to personalize your experience with targeted ads. Under the Virginia Consumer Data Protection Act, you have the right to opt-out of the sale of your personal data to third parties. You also have the right to opt out of targeted advertising related processing. You may exercise your right to opt out of the sale of personal data and targeted advertising by using this toggle. If you opt out, we will not be able to offer you personalized ads and we will stop sharing your personal information with third parties. For more information please see our Privacy Statement.
These cookies allow us or our third-party analytics providers to collect information and statistics on use of our services by you and other visitors. This information helps us to improve our services and products for the benefit of you and others.
These cookies, provided by our third-party advertising partners, collect information about your browsing habits, as well as your preferences for various features and services. They also provide us with auditing, research, and reporting to know when advertising content has been displayed and how successful the content has been. This information allows us and our third-party advertising providers to display relevant advertising content.
These cookies provide enhanced functionality, providing chat support, allowing you to more easily complete forms, personalizing content to your preferences, and selecting your communications preferences. If you do not enable these cookies, or choose to disable them in the future, that could impact your ability to use certain features.