Skip to content
Help Center
TopicsSecurity and privacy

Is Mindstamp HIPAA compliant?

Updated · 1 min read

Short answer

No. Mindstamp is not HIPAA compliant and does not sign business associate agreements (BAAs). Do not use Mindstamp to collect or store protected health information (PHI). If you have specific needs, contact the team to discuss them.

Lead Capture page in Mindstamp with the timing options At start, First interaction, At time and On interaction, the Custom field button and the Required column highlighted
Lead Capture: choose when to ask, pick the fields, add a custom field, and mark fields as required.

What this means in practice

Copy link to What this means in practice

Healthcare organizations can use Mindstamp for content that contains no PHI, such as staff training, product education and patient information that does not ask for health details. The risk comes from what your video asks viewers to enter.

Settings to check in healthcare videos

Copy link to Settings to check in healthcare videos
  • Lead Capture: collect only a work email or an employee ID, not patient details.
  • Questions: do not ask for symptoms, diagnoses, treatments or other health details, in text, voice, video or drawing answers.
  • Variables and personalized links: do not pass patient data in link parameters.
  • Integrations: check what each integration sends before you connect it.
  • Genie AI: viewers type or speak questions to Genie, so do not enable it where viewers might share health details.

Mindstamp has no current plan to become HIPAA compliant, but the team is open to discussing specific needs. Use the contact form and describe the data you need to handle.