Not currently, based on public evidence. Perplexity claims "HIPAA-aligned safeguards" but publishes no business associate agreement, and its enterprise terms reportedly prohibit PHI without one. Until a BAA is signed and verified, no Perplexity tier should touch PHI.
"HIPAA-aligned" is a phrase doing a lot of work, and this post takes it apart. A note on method: several Perplexity help-center and legal pages blocked automated access during our review, so where we rely on secondary summaries we say so explicitly. Compliance statuses change — re-check Perplexity's security page and trust center before relying on any status here. Last verified: September 5, 2026.
What does Perplexity actually claim about HIPAA?
Perplexity's own enterprise security page claims "GDPR-compliant and HIPAA-aligned safeguards." Notice the asymmetry inside that one sentence: GDPR gets "compliant," HIPAA gets "aligned." The word choice matters. For a vendor handling protected health information, HIPAA compliance runs through a business associate agreement — a contract carrying safeguard obligations, breach-notification duties, and liability. "Aligned" describes security engineering that resembles what HIPAA expects; it creates no contractual obligation to you and gives regulators nothing to hold the vendor to.
Perplexity's API documentation reinforces that reading. Its compliance list includes a SOC 2 Type II report, a CAIQlite, and a "2025 HIPAA Gap Assessment." A gap assessment is an internal readiness exercise — it tells Perplexity how far it stands from HIPAA's requirements. It is not a certification, not an attestation, and not a BAA.
Does Perplexity offer a BAA?
Not publicly — and that is the central finding of this review. On the Perplexity pages we could access (the enterprise security page and the API privacy and security docs), there is no BAA offer, no HIPAA-ready plan, and no PHI guidance.
The sharpest evidence comes from Perplexity's own Enterprise Terms, as quoted by Paubox in its review of the terms (the terms page itself blocked automated access during our check): customers "may not use Perplexity Enterprise Pro or Perplexity Enterprise Max to create, receive, maintain, transmit, or otherwise process PHI unless a business associate agreement is in place." Paubox adds that it "did not find a publicly posted standalone BAA" and concluded that availability appears to depend on enterprise contracting. Claims that Perplexity will sign a BAA through sales appear only in third-party blogs, not on any Perplexity property we could reach — treat them as unconfirmed until your own contract says otherwise.
The contrast with peers is stark. Anthropic publishes its entire BAA process — eligible products, activation flow, exclusions — in its help center (see our sibling post, Is Claude HIPAA Compliant?). When a vendor's compliance story requires a sales call just to confirm a BAA exists, your compliance team, not the vendor, owns the risk.
Is Perplexity ISO 27001 certified?
We found no ISO 27001 claim on any Perplexity page accessible during this review — a notable absence when competing AI vendors advertise ISO/IEC 27001 prominently. What Perplexity does claim, on its enterprise security page, is being "SOC 2 Type 2 certified by independent auditors," GDPR compliance, and payment security meeting PCI standards.
To be fair, the disclosed security stack is substantial: MFA and SSO, AWS IAM with just-in-time access, Cloudflare WAF and DDoS protection, Wiz, Panther SIEM, EDR and MDM on the fleet, an annual third-party penetration test, a private bug bounty plus a public disclosure program, twice-yearly access reviews, and a rule that customer data is "prohibited from storage on company workstations, laptops, or removable media." A trust center exists at trust.perplexity.ai; it did not render for automated review, so check the current report list there yourself. None of this substitutes for a BAA — SOC 2 audits security controls, not HIPAA obligations.
What happens to data you send Perplexity?
It depends heavily on the surface:
- Sonar API: the strongest story, and stated officially in the API docs: "We do not retain data sent through the Chat Completions API, and we do not use customer data to train our models." Only billing metadata — tokens, model, timestamps, key ID — is kept.
- Enterprise workspaces: per Strac's summary of Perplexity's help-center article (blocked to automated fetchers), retention is admin-configurable under Organization Settings, and custom retention periods require 50 or more seats.
- File uploads: per third-party summaries of Perplexity's help-center articles, files attached to threads are automatically deleted after seven days, while files uploaded to Spaces do not auto-expire.
Read that last line as a healthcare team. An uploaded discharge summary sits on Perplexity infrastructure for seven days — and indefinitely if someone put it in a Space. Without a BAA, the impermissible disclosure happens at upload, not at breach. And in a search product the query itself is a disclosure: "treatment options for [name]'s [condition]" is PHI before any file is attached.
Which Perplexity tiers can handle PHI?
| Tier | Public BAA evidence | PHI verdict |
|---|---|---|
| Free / Pro (consumer) | None | Never |
| Sonar API | None (zero retention, but retention is not the issue) | Not without an executed BAA |
| Enterprise Pro / Max | None published; terms reportedly prohibit PHI absent a BAA | Only if you negotiate, execute, and scope-check a BAA through sales |
| Comet browser | None | Treat as uncovered; govern it separately (see our Comet enterprise guide) |
How can healthcare teams use Perplexity safely?
- Write the query-box rule first. Perplexity is excellent for literature, guidelines, coding references, and payer-policy research — none of which needs patient identifiers. Policy should say what may go in the prompt, not just which tool is approved.
- If you want Enterprise for clinical workflows, get the BAA in writing and verify its scope: does it cover file uploads, Spaces, Comet, and connected data sources? Then configure retention (50+ seats for custom periods) and restrict uploads and Spaces for PHI-adjacent teams.
- Apply minimum necessary anyway. 45 CFR 164.502(b) applies to prompts exactly as it applies to faxes, and your risk analysis must cover the deployment.
- Enforce at the endpoint, not on trust. Perplexity is one of the most common tools in shadow-AI inventories, and personal accounts bypass every contract you sign (how employee shadow AI leaks sensitive data). AccuroAI's workforce AI governance classifies prompts inline with 40+ classifiers, including PHI, before they leave the browser — customers have cut shadow-AI usage 94% within 30 days of deploying it.
For the broader program this slots into, see the healthcare AI security playbook and our sibling review, Is ChatGPT HIPAA Compliant?.
FAQ
Is Perplexity HIPAA compliant?
Not currently, based on public evidence. Perplexity claims "HIPAA-aligned safeguards," lists only a HIPAA gap assessment in its API docs, and publishes no BAA. Its enterprise terms, per Paubox's review, prohibit processing PHI unless a BAA is in place.
Will Perplexity sign a BAA?
Unknown from public sources. Some third-party blogs say a BAA is available through enterprise sales, but no Perplexity page we could access confirms it. Ask sales directly, get the agreement in writing, and verify what surfaces it covers before any PHI moves.
Is Perplexity SOC 2 or ISO 27001 certified?
Perplexity's enterprise security page claims SOC 2 Type II. We found no ISO 27001 claim on any accessible Perplexity page as of this review — check trust.perplexity.ai for the current list.
Is the Perplexity Sonar API safe for patient data?
Its docs state zero retention and no training on customer data, which is good engineering — but zero retention is not a BAA, and HIPAA requires the contract. Without one, PHI through the API is still an impermissible disclosure.
What does "HIPAA-aligned" actually mean?
It is a marketing term, not a legal status. It signals that a vendor's safeguards resemble HIPAA's expectations, without the business associate agreement that creates enforceable obligations. Treat any "aligned," "ready," or "friendly" claim as a prompt to ask one question: will you sign a BAA?
Related reading: Workforce AI Governance · Perplexity Comet in the Enterprise: Sanction, Restrict, or Block · Is Claude HIPAA Compliant? · Shadow AI Data Leakage: The Employee Risk