HIPAA compliance is addressed on the ServiceNow website in a 17-page white paper titled “ServiceNow security & HIPAA.” The document can be found under the Industry Resources section in the Trust and Compliance Center.
In the white paper, ServiceNow claims to include features that enable healthcare customers to comply with HIPAA privacy and security requirements. As far as Business Associate Agreements are concerned, ServiceNow says it will enter into a BAA “if the covered entity chooses to store ePHI in their instance.”
There’s a long list of exceptions outlined in the white paper, and ServiceNow cautions that it “is not a typical business associate.” ServiceNow states that it will not enter into a BAA that requires it to carry out the customer’s obligations under HIPAA.