Hi Asana Community! ![]()
Weโre excited to share that HIPAA compliance is now available for AsanaGov customers, giving organizations working with health information the ability to keep permitted protected health information in Asana Gov with safeguards designed for HIPAA-regulated workflows.
HIPAA-enabled domains include controls designed to help protect sensitive information. Notifications omit task, comment, and project content, embedded third-party media does not render, and AI-powered features may use only approved services with a signed BAA. Third-party integrations and Personal Access Tokens are disabled by default and require explicit super-admin approval. Project privacy controls are limited to super admins, and domain users must use passwords of at least 12 characters.
A super admin must accept the HIPAA Use Requirements and BAA in the Admin Console to enable it, and activation may take up to 24 hours. Please note if you have signed a BAA previously in a commercial account, you will still need to sign a new one in the Asana Gov domain.
If your team is ready to get started with HIPAA-enabled AsanaGov, review the HIPAA Compliance Help Center and connect with your super admin.
Weโd love to hear how your team plans to use AsanaGov for regulated work, so share your questions or feedback in the comments!