Skip to main content
BAA Directory

Is Signal HIPAA compliant? Does it sign a BAA?

The answer

No public statement

No public statement. We found no statement about a BAA or HIPAA on Signal's own terms, privacy policy or support pages.

Messaging and payments. Checked on the vendor's own pages on .

Using Signal on a healthcare site? Curve Compliance keeps your ad tracking HIPAA-compliant around it, under a BAA on every plan. Book a call

On this page

What we checked

We looked for a statement about a BAA on Signal's own pages and could not find one we could quote. These are the pages we checked:

Until Signal puts a BAA in writing for you, treat it as a tool that has not agreed to protect patient data.

What this means for ad tracking

Staff sometimes move patient questions to Signal because it is end-to-end encrypted, and Signal's privacy policy says it cannot decrypt or access the content of messages or calls. Encryption is not a BAA, though, and we found no BAA offered on Signal's own pages.

Without a BAA, patient conversations should not run through Signal, and a reply or booking you count as a conversion should reach your ad platforms with nothing from the thread.

Curve Compliance closes that gap: it sends the conversion itself server-side, under a BAA it signs on every plan, so your campaigns keep a conversion signal without a pixel carrying patient data. Book a call to see it on your own funnel.

A business associate agreement binds only the vendor that signs it, so each vendor that handles patient information for you needs its own.

How Curve helps

  • Curve gives you a conversion signal that does not depend on Signal or a browser pixel carrying patient details.
  • Server-side conversion tracking in place of pixels: conversions reach your ad platforms from Curve's server, not from the patient's browser.
  • A fixed field list per platform, so each ad platform receives only the fields set for it.
  • PHI-like pattern detection checks every event before it goes out, and neutral event names keep conditions and treatments out of what the platforms see.
  • When identifiers are enabled, Curve hashes them with SHA-256.
  • Consent management for your site, alongside the tracking.
  • A HIPAA-compliant setup done by Curve's team, with a BAA signed on every plan.

Book a call with Curve and Curve's team will walk through your tracking setup with you.

Frequently asked questions

Is Signal HIPAA compliant?

No public statement. We found no statement about a BAA or HIPAA on Signal's own terms, privacy policy or support pages. Ask Signal directly before sending it patient information.

Does Signal sign a BAA?

No public statement. We found no statement about a BAA or HIPAA on Signal's own terms, privacy policy or support pages. We checked Signal's own pages on October 5, 2026.

Can I use Signal with patient data?

Not until Signal signs a BAA with you. We could not find a statement from Signal offering one on its own pages, so ask Signal directly and keep Protected Health Information out of Signal until a BAA is in place.

Can I still track ad conversions that come through Signal?

Yes, when the conversion reaches your ad platforms without health information. Curve sends conversions server-side under a BAA it signs on every plan, with neutral event names and SHA-256 hashed identifiers.

Does Curve Compliance sign a BAA?

Yes. Curve Compliance signs a BAA on every plan, and Curve's team does the HIPAA-compliant setup for you. Book a call to get started.

Sources

Last checked . Vendors change their plans and terms, so confirm the current terms with Signal before you send it patient data.

See every tool in the BAA Directory.

Track ad conversions under a BAA

Curve signs a BAA on every plan. Curve's team sets up HIPAA-compliant conversion tracking for you in about a week, sending conversions server-side in place of pixels.

Book a call