**HIPAA-enabled Workspaces**  
HIPAA-enabled workspaces require a Scale or Enterprise plan.  
For details, see the [pricing page](/content/pricing/index.html).

**HIPAA** is a United States federal law that sets standards for protecting individuals' healthcare data. It defines administrative, physical, and technical safeguards for organizations that process or store protected health information (PHI).  
Render provides **HIPAA-enabled workspaces** for organizations subject to HIPAA requirements. These workspaces run services and datastores on access-restricted hosts, helping to secure any PHI processed or stored by your applications. Access to these hosts by Render staff is subject to strict controls.

## Setup  
**Before proceeding, review all [important considerations](/content/docs/hipaa-compliance#important-considerations/index.html) below.**

The following steps must be completed by a workspace admin:

1. In the [Render Dashboard](https://dashboard.render.com/), open your **Workspace Settings** page and scroll down to the **Compliance** section:

2. Click **Get Started**. This opens a confirmation flow to receive Render's Business Associate Agreement (BAA).

3. Review all enablement steps, best practices, and workspace details outlined in the confirmation flow.

4. After you complete the confirmation flow, Render emails you a link to sign the BAA.

5. After you sign the BAA, return to the **Compliance** section of your workspace settings. After about a minute, your HIPAA Compliance status updates to **Pending**:

6. When you're ready, click **Enable HIPAA** to initiate the enablement process.

- Before proceeding, review all details in the confirmation dialog that appears.  
   - If you don't initiate the enablement process manually, Render initiates it automatically 72 hours after you sign the BAA.

As part of enablement, Render redeploys all of your workspace's existing services and datastores to access-restricted hosts. Your services might become unavailable for a few minutes.

Render emails you when the enablement process begins, then a second time after it completes.

7. After the process completes, your HIPAA Compliance status updates to **Enabled**:  
   
     
Your workspace is now ready to host HIPAA-compliant applications.

## Important Considerations  
**Before upgrading to a HIPAA-enabled workspace, note all of the following:**

- Upgrading to a HIPAA-enabled workspace is an irreversible action.  
- An additional 20% fee applies to all usage (compute, storage, etc.) in a HIPAA-enabled workspace.  
- HIPAA-enabled workspaces cannot deploy or run services in Render's Singapore [region](/content/docs/regions/index.html) at this time. All other regions are supported.  
- HIPAA-enabled workspaces cannot deploy or run [free instances](/content/docs/free/index.html).  
  
   - This is because free instances run on hosts that do not support restricted access for HIPAA compliance.  
   - If your workspace has existing free instances, Render migrates them to the smallest paid compute plan as part of the upgrade process.  
   - Render also _suspends_ free web services migrated this way (Postgres and Key Value instances are not suspended). These services are not billed while suspended. You can resume them any time after upgrading.  
- With a **Scale** or **Enterprise** [plan](/content/pricing/index.html), Render upgrades _one_ of your workspaces to a HIPAA-enabled workspace.  
  
   - You specify which workspace to upgrade in your BAA.  
   - Your other workspaces are _not_ HIPAA-enabled. All HIPAA-compliant workflows must run in the HIPAA-enabled workspace.  
- Even in a HIPAA-enabled workspace, you _must not_ include PHI in certain resources.  
  
   - For details, see [Where can I process and store PHI?](/content/docs/hipaa-compliance#where-can-i-process-and-store-phi/index.html)  
- **A HIPAA-enabled workspace does not automatically make your applications HIPAA-compliant.**  
  
   - You are responsible for adhering to HIPAA regulations for all applications in your workspace.  
   - For more information, see Render's [shared responsibility model](/content/docs/shared-responsibility-model/index.html).

## Where can I process and store PHI?  
**Never process or store PHI on Render outside of a HIPAA-enabled workspace.**  
Not all resources in a HIPAA-enabled workspace support HIPAA-compliant processing and storing of PHI. See the following table for details:

| Resource | PHI OK? | Details |
| --- | --- | --- |
| **Live services** | | |
| [Web services](/content/docs/web-services/index.html) | 🟢 |  |
| [Static sites](/content/docs/static-sites/index.html) | ❌ | Static sites consist of static assets hosted at a publicly accessible URL. Those assets _must not_ include any PHI. |
| [Private services](/content/docs/private-services/index.html) | 🟢 |  |
| [Background workers](/content/docs/background-workers/index.html) | 🟢 |  |
| [Pre-deploy commands](/content/docs/deploys#pre-deploy-command/index.html) | 🟢 | Pre-deploy commands can process PHI, such as when running a database migration. However, the pre-deploy command itself must not include PHI. |
| [Cron jobs](/content/docs/cronjobs/index.html) | 🟢 |  |
| [Workflows](/content/docs/workflows/index.html) | ❌ | Workflows are not available in HIPAA-enabled workspaces. |
| **Service-generated [logs](/content/docs/logging/index.html)** | ❌ | Never include PHI in any message logged by any Render service, whether at build time or runtime. |
| [Service previews](/content/docs/service-previews/index.html) and [preview environments](/content/docs/preview-environments/index.html) | 🟢 | Preview instances run on access-restricted hosts, like their production counterparts. |
| **Datastores** | | |
| [Persistent disks](/content/docs/disks/index.html) | 🟢 | All disks and their daily snapshots are encrypted at rest. |
| [Render Postgres](/content/docs/postgresql/index.html) databases | 🟢 | Your primary databases, [read replicas](/content/docs/postgresql-read-replicas/index.html), and [high availability](/content/docs/postgresql-high-availability/index.html) standby databases all support HIPAA-compliant workflows. |
| [Render Key Value](/content/docs/key-value/index.html) instances | 🟢 |  |
| **Builds** | | |
| Build artifacts | ❌ | This is the bundle generated by your service's [build command](/content/docs/deploys#build-command/index.html). It includes application code, dependencies, static assets, and any other files needed to run your service. These generated files must not include PHI. |
| **Service configuration** | | |
| Infrastructure-as-code config | ❌ | This includes `render.yaml` files for [Blueprints](/content/docs/infrastructure-as-code/index.html), along with [Terraform](/content/docs/terraform-provider/index.html) configuration files. |
| Resource names | ❌ | Do not include PHI in the name you assign to _any_ resource, including:<br>- Service names<br>- Environment variable names<br>- Secret file filenames<br>- Table or column names in your database |
