Missed Team ’24? Catch up on announcements here.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Expand what’s possible with HIPAA

37 comments

Comment

Log in or Sign up to comment
Filiberto Selvas
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 22, 2023

Hello @Rob Horan , @Rebecca Dean and @Slavisha Karach 

We are already 50% deployed for expansion of eligibility, aim to be 100% by the end of next week. The capability is a self service processes handled by Org Admins through the products administrative interfaces.  You can license the products through the normal channels, and then self service. More information coming soon in an update I will make to this post, hopefully later today. 

Like Rebecca Dean likes this
Rebecca Dean September 22, 2023

@Filiberto Selvas This is great news! I attempted to sign the BAA and unfortunately hit a snag. Support ticket is filed - just thought I'd give you a heads up. 

Filiberto Selvas
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 22, 2023

@Rebecca Dean : can you email me the ticket number to FSelvas at Atlassian dot Com? 

Like Rebecca Dean likes this
Filiberto Selvas
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 26, 2023

For anyone reading the thread of comments above ^^^. Issues have been resolved, BAA signing is flowing now! 

Brent Lee November 20, 2023

@Filiberto Selvas How does an existing customer needing HIPAA compliance migrate to the cloud if Atlassian does not sign BAA's for trial instances?

Like Filiberto Selvas likes this
Filiberto Selvas
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
November 20, 2023

Hello @Brent Lee , 

Atlassian HIPAA offerings are only available for active subscriptions of eligible cloud products.  Because of the inherent risks and costs that Atlassian incurs when offering HIPAA we decided to not make it available for free offerings, such as trials.

You can test the functionality and capabilities of the Atlassian Cloud offerings through trials without entering any PHI. You can also establish an active subscription of an eligible product, establish a BAA to ensure protection of data, and then migrate the PHI data into it. 

Hope this helps 

Filiberto Selvas 

Like Brent Lee likes this
Andy Levesque
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 21, 2023

We are running into challenges because the Atlassian BAA language requires a BAA with all 'relevant' third-party plugins. We've asked Atlassian for guidance on their definition of relevant but haven't heard back. This is critical as (1) this language was not in the BAA of our previous hosting provider and (2) most plugin vendors are small shops and not comfortable signing a BAA. 

Can we get some clarity or guidance to help us reach HIPAA compliance? This is a showstopper for us. 

Filiberto Selvas
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
November 21, 2023

Hello @Andy Levesque , 

The term “relevant” is not one that is defined by Atlassian.  This is because it is up to our customers to decide which third-party plugins and apps they will use, how they will use them, and what data they share with them.  Which third-party vendors are considered relevant will be specific to each of our customers and is not a decision that Atlassian can make on behalf of our customers.  You are completely right in stating that not all third party vendors in our marketplace will offer a HIPAA compliant solution, but it will be up to you to determine how your use of these plugins/apps will impact your obligations under HIPAA, if at all.

I hope this helps,

Filiberto 

Robert Adler January 18, 2024

Any updates on expanding HIPAA compliance with Jira Work Management? It just seems like a logical next step, as more teams use JWM for their daily work.

Like Filiberto Selvas likes this
Filiberto Selvas
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 6, 2024

No solid timeline for that @Robert Adler , we will share an update in community when that changes 

Like Robert Adler likes this
Rebecca Dean March 8, 2024

@Filiberto Selvas and community - do you have any guidance for people who managed their Jira interactions primarily through email notifications? While we're very happy to see that the sensitive fields like comments are no longer sent in email notifications - the notifications page in the Jira web application is a bit lacking according to feedback I'm getting. So we don't have a great alternate apart from opening every jira ticket. This can be challenging for folks who are managing multiple projects, releases etc. 

Like Jared Pittman likes this
Filiberto Selvas
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
March 8, 2024

Hi @Rebecca Dean , 

I agree that it is very inconvenient, unfortunately it is a binary decision as we can't sign a BAA with the vendor that Atlassian uses for notifications (they don't offer it), so we simply can not pass sensitive data to that vendor.  

We have customers that have implemented integrations with Microsoft Teams, and they report it works well for them.  Please be aware that for any 3rd party integrations it will be for you to ensure HIPAA compliance. 

I hope this helps 

Like Rebecca Dean likes this
TAGS
AUG Leaders

Atlassian Community Events