An illustrative consultation on setting up Intercom for HIPAA compliance, between Naveed Ali Qureshi of Vortex Digital AI and an Australia-based healthcare business.
We're a healthcare business in Australia. Can we even use Intercom for patient chat?
Yes, with the right setup. Intercom offers a Business Associate Agreement (BAA) for customers on their Expert plan — that's the tier with the administrative and technical controls HIPAA setups actually need. Lower plans don't include this, so the first step is confirming you're on the right plan.
What exactly do we need to do to get compliant?
Four things: upgrade to the Expert plan, execute Intercom's BAA through their sales team, enable Identity Verification in your security settings so patients can't be impersonated, and train your staff on handling protected health information inside the workspace. We help set up and verify each of these.
Does the BAA cover all our messaging — SMS, email, WhatsApp?
No, and this trips people up. Intercom's core BAA does not cover standard SMS, email, or WhatsApp channels by default — those need separate handling or explicit patient consent before any PHI goes through them. We map out which channels are safe to use for health data and which need to be restricted or replaced.
Can you help us configure the actual security settings?
Yes — turning on Identity Verification, reviewing channel settings, and setting up your workspace structure so PHI stays inside compliant channels is exactly the kind of setup work we do.
What about our other tools, like Zendesk or Salesforce?
If PHI flows through those too, they need their own compliance review — a HIPAA setup isn't just about Intercom in isolation, it's about every system that touches patient data. We can review those integrations as part of the same project.
Intercom can be used in a HIPAA-compliant way for customers on their Expert plan who sign Intercom's Business Associate Agreement — it's not automatic on lower plans.
No. Standard SMS, email, and WhatsApp channels are excluded from Intercom's core BAA by default and need separate handling for PHI.
It's a security setting that authenticates users so one patient can't impersonate another inside the Messenger — an important safeguard when protected health information is involved.
Yes — HIPAA setup isn't just technical configuration; staff handling PHI inside the workspace need training on safe handling practices.
Talk to Naveed Ali Qureshi directly on WhatsApp for a scoped answer.
Send us a message directly — no signup needed.