Is Trello HIPAA Compliant for Referral Tracking Kanban Boards?

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Is Trello HIPAA Compliant for Referral Tracking Kanban Boards?

Kevin Henry

HIPAA

August 25, 2026

7 minutes read
Share this article
Is Trello HIPAA Compliant for Referral Tracking Kanban Boards?

Short answer: No—Trello is not a HIPAA-eligible app under Atlassian’s Business Associate Agreement (BAA), and Atlassian’s Customer Agreement forbids uploading protected health information (PHI) to any cloud product without a signed BAA. As of August 25, 2026, Atlassian lists Jira, Confluence, Jira Service Management, Jira Product Discovery, and Rovo as HIPAA-supported apps; Trello is not included, so you cannot use it to create, receive, maintain, or transmit PHI. You may only use Trello for referral tracking if you keep PHI completely out of the boards. ([support.atlassian.com](https://support.atlassian.com/organization-administration/docs/understand-hipaa-compliance-for-atlassian-products/))

HIPAA Compliance Requirements

What HIPAA expects from your referral workflow

HIPAA’s Security Rule requires you to conduct a documented Compliance Risk Assessment (risk analysis) and implement risk management measures, technical and non‑technical safeguards, and ongoing evaluations. For software used to coordinate referrals, you must have access controls, audit logging, and appropriate data encryption to protect ePHI. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html?utm_source=openai))

The Security Rule’s technical safeguards include audit controls (45 CFR §164.312(b)), access control (including unique user identification), and transmission security with encryption when appropriate (45 CFR §164.312(a)(2)(iv) and §164.312(e)(2)(ii)). These controls are table‑stakes for any kanban or ticketing system that touches PHI. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/protocol/index.html?utm_source=openai))

Trello Platform Security Features

Encryption and reliability

Atlassian encrypts customer data in Trello and other cloud apps in transit (TLS) and at rest (AES‑256). This protects data confidentiality during storage and transfer but, by itself, does not make a service HIPAA compliant. ([atlassian.com](https://www.atlassian.com/trust/reliability/cloud-architecture-and-operational-practices?utm_source=openai))

Identity, authentication, and Access Controls

Trello supports SAML single sign‑on through Atlassian Guard (formerly Access) and two‑step verification tied to Atlassian accounts. Enterprise admins can centrally manage users, enforce sign‑in policies, and control workspace and board permissions. ([support.atlassian.com](https://support.atlassian.com/trello/docs/configure-sso-for-trello-with-atlassian-guard/?utm_source=openai))

Audit logging and admin governance

Trello Enterprise includes an audit log and admin dashboard to review member activity, workspace/board changes, public board settings, attachment restrictions, and Power‑Ups administration—capabilities you need for audit logging and governance at scale. ([support.atlassian.com](https://support.atlassian.com/trello/docs/enterprise-admin-dashboard/?utm_source=openai))

Why these features don’t equal HIPAA compliance

Despite strong platform security, Trello is not covered by Atlassian’s HIPAA program or BAA. Atlassian’s Implementation Guide and BAA limit HIPAA coverage to specific “eligible” apps, and the Customer Agreement prohibits PHI in any cloud product unless a BAA is in place—conditions Trello does not meet. Third‑party Power‑Ups and beta features are also outside BAA scope. ([support.atlassian.com](https://support.atlassian.com/organization-administration/docs/the-hipaa-implementation-guide/))

Business Associate Agreement Importance

A Business Associate Agreement is the linchpin for using any SaaS tool with PHI. HHS defines business associates and prescribes BAAs to ensure vendors meet HIPAA’s privacy and security obligations. Without a signed BAA, using a tool to process PHI violates HIPAA. Atlassian will sign BAAs for certain cloud apps (Jira, Confluence, Jira Service Management, Jira Product Discovery, and Rovo). Trello is not on this list, so it cannot be used to handle PHI. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

PHI Management Risks

Using Trello for referral details that include identifiers (names, MRNs, phone numbers) risks noncompliance on two fronts: (1) Atlassian’s Customer Agreement bars PHI absent a BAA; and (2) HIPAA’s Security Rule requires audit logging, access controls, and encryption configured under a BAA. Notifications, public board settings, guests, and third‑party Power‑Ups can also leak PHI. If you must coordinate operational tasks in Trello, keep PHI out of titles, comments, attachments, custom fields, and labels. ([atlassian.com](https://www.atlassian.com/legal/atlassian-customer-agreement?utm_source=openai))

Atlassian further instructs customers not to include PHI in metadata (for example, card names) or in support channels, reinforcing the “no‑PHI‑in‑Trello” stance. ([support.atlassian.com](https://support.atlassian.com/organization-administration/docs/the-hipaa-implementation-guide/))

Alternative HIPAA Compliant Tools

If you need a kanban‑style referral pipeline with PHI, choose a platform that offers a BAA and HIPAA configuration guidance:

  • Jira Software Cloud (kanban boards) and Confluence Cloud under Atlassian’s HIPAA program and BAA. ([support.atlassian.com](https://support.atlassian.com/organization-administration/docs/understand-hipaa-compliance-for-atlassian-products/))
  • Asana Enterprise with a Business Associate Addendum and HIPAA configuration adjustments. ([assets.asana.biz](https://assets.asana.biz/m/7162ffe21527c538/original/Asana-HIPAA-Compliance-Datasheet.pdf?utm_source=openai))
  • monday.com HIPAA‑compliant plans with an in‑product BAA acceptance flow. ([support.monday.com](https://support.monday.com/hc/en-us/articles/360006506699-monday-com-and-HIPAA?utm_source=openai))
  • Smartsheet with a HIPAA BAA and PHI‑eligible services. ([smartsheet.com](https://www.smartsheet.com/legal/hipaa-baa?utm_source=openai))
  • Airtable Enterprise Scale with a Health Information Exhibit and BAA. ([support.airtable.com](https://support.airtable.com/articles/5742348809-understanding-hipaa-at-airtable?utm_source=openai))
  • ClickUp Enterprise supports HIPAA with a signed BAA (validate plan scope and AI exclusions). ([clickup.com](https://clickup.com/faqs?utm_source=openai))

Always verify the BAA’s scope (features excluded, such as certain AI tools or connectors) before storing any PHI. ([support.atlassian.com](https://support.atlassian.com/organization-administration/docs/the-hipaa-implementation-guide/))

Best Practices for Referral Tracking

When you must use kanban boards with PHI

  • Sign a Business Associate Agreement with the vendor and complete a formal Compliance Risk Assessment (risk analysis) before onboarding. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))
  • Implement least‑privilege Access Controls: SSO, strong MFA, role‑based permissions, and tight external sharing rules. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.312?utm_source=openai))
  • Enable audit logging and monitor access to referral items; retain logs per policy. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/protocol/index.html?utm_source=openai))
  • Enforce Data Encryption in transit and at rest; document key management and transmission protections. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2001/is-the-use-of-encryption-mandatory-in-the-security-rule/index.html?utm_source=openai))
  • Apply “minimum necessary” data design: store only the data needed to route referrals; avoid PHI in titles, tags, and notifications. ([support.atlassian.com](https://support.atlassian.com/organization-administration/docs/the-hipaa-implementation-guide/))
  • Train staff on PHI handling, breach response, and naming conventions; review safeguards during periodic evaluations. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html?form=MG0AV3&utm_source=openai))

When you use Trello without PHI

  • Use internal referral IDs or pseudonyms instead of names or identifiers, and store the identity key in a HIPAA‑eligible system.
  • Keep boards private, restrict guests, disable risky Power‑Ups, and prevent attachments from non‑approved sources; rely on the Enterprise audit log for oversight. ([support.atlassian.com](https://support.atlassian.com/trello/docs/enterprise-admin-dashboard/?utm_source=openai))
  • Document that Trello contains no PHI and re‑validate during quarterly risk reviews. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html?utm_source=openai))

Data Encryption and Access Controls

Data Encryption

Under the HIPAA Security Rule, encryption of ePHI in transit and at rest is an addressable specification that becomes mandatory if your risk analysis deems it reasonable and appropriate. Atlassian encrypts Trello data at rest (AES‑256) and in transit (TLS), which supports confidentiality but does not substitute for a BAA when PHI is involved. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2001/is-the-use-of-encryption-mandatory-in-the-security-rule/index.html?utm_source=openai))

Access Controls

HIPAA requires technical policies and procedures to ensure only authorized users can access systems with ePHI. In Trello, SAML SSO via Atlassian Guard, enforced MFA, and granular workspace/board permissions strengthen Access Controls—but again, they are not a license to store PHI in a non‑BAA app. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.312?utm_source=openai))

Audit Logging

Audit logging is required for systems that “contain or use” ePHI so you can reconstruct who viewed or changed referral data. Trello Enterprise provides an audit log for governance; if PHI is in scope, use a HIPAA‑eligible platform with BAA‑covered logging and retention. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/protocol/index.html?utm_source=openai))

Bottom line: Trello’s security features are useful for non‑PHI coordination, but HIPAA compliance hinges on a signed Business Associate Agreement and eligible product scope—both of which Trello lacks. For referral tracking with PHI, move to a HIPAA‑eligible tool (with BAA) or rigorously keep PHI out of Trello. ([support.atlassian.com](https://support.atlassian.com/organization-administration/docs/understand-hipaa-compliance-for-atlassian-products/))

FAQs

Why is Trello not HIPAA compliant?

Because Atlassian’s HIPAA program and BAA do not cover Trello. Atlassian signs BAAs only for specific cloud apps (for example, Jira and Confluence). Their Customer Agreement further prohibits uploading PHI to any cloud product without a BAA—making Trello ineligible for PHI processing. ([support.atlassian.com](https://support.atlassian.com/organization-administration/docs/understand-hipaa-compliance-for-atlassian-products/))

Can Trello be used for referral tracking without PHI?

Yes. You can manage tasks, capacity, and timelines in Trello if you exclude PHI entirely. Use coded identifiers (no names or MRNs), keep boards private, restrict guests and Power‑Ups, and avoid PHI in titles, comments, attachments, and labels; Atlassian also advises keeping PHI out of metadata. ([support.atlassian.com](https://support.atlassian.com/organization-administration/docs/the-hipaa-implementation-guide/))

What alternatives exist for HIPAA compliant kanban boards?

Consider HIPAA‑eligible options that sign BAAs and support kanban workflows: Jira Software Cloud (under Atlassian’s BAA), Asana Enterprise, monday.com HIPAA plans, Smartsheet with BAA, Airtable Enterprise Scale with Health Information Exhibit, and ClickUp Enterprise with BAA. Confirm plan tier and excluded features (for example, certain AI or integrations) before adding PHI. ([support.atlassian.com](https://support.atlassian.com/organization-administration/docs/understand-hipaa-compliance-for-atlassian-products/))

How can healthcare organizations ensure referral tracking compliance?

Start with a documented HIPAA Compliance Risk Assessment, select a HIPAA‑eligible platform and execute a BAA, configure Access Controls and encryption, enable audit logging with retention, train your workforce, and re‑evaluate safeguards periodically. These steps align with HIPAA’s Security Rule requirements for risk analysis, access control, transmission security, and audit controls. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html?utm_source=openai))

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles