Hightail claims to be both exempt from HIPAA requirements and appropriate to use for protected health information. It does not appear to facilitate HIPAA compliance.
On its website, Hightail states that because of the nature of its business, the platform isn’t subject to HIPAA compliance. However, it also claims that many customers using both its Enterprise and individual accounts use Hightail to securely deliver protected health information (PHI). Examples of these security measures include SSL/TLS and AES 256-bit encryption, forward secrecy, and dynamically scrambled file names.
There is no mention of Business Associate Agreements on the Hightail website.