When does a file tool become a business associate?
Under HIPAA, a business associate is a person or company that creates, receives, maintains or transmits PHI on behalf of a covered entity (a provider, health plan or clearinghouse) or of another business associate. Before a covered entity shares PHI with a business associate, the two must sign a Business Associate Agreement (BAA) that commits the vendor to safeguard the data.
An online PDF compressor that receives your file on its servers — even for a few minutes — is receiving PHI. That makes the vendor a business associate for that file, and using it without a BAA is a HIPAA compliance problem, regardless of how briefly the file is kept. Free and consumer tiers of online file converters generally don't offer BAAs, so check the vendor's terms before sending anything that contains PHI.
Why "we encrypt your files" isn't enough
Many upload-based tools advertise TLS encryption in transit and automatic deletion after an hour. Those are good practices, but they don't remove the vendor from HIPAA's scope. HHS guidance on cloud services is clear that a provider which stores or processes ePHI is a business associate even if the data is encrypted and the provider doesn't hold the key. Deletion policies also rely entirely on the vendor's word and on its own subcontractors (hosting, storage, logging) behaving the same way.
The question to ask is not "how well is my upload protected?" but "does this tool need to receive my file at all?"
There is no official "HIPAA certified" software
HHS does not certify, approve or endorse software as HIPAA compliant. When a product says "HIPAA compliant", it can only mean that the vendor's practices support its customers' compliance — for example, it signs BAAs, has administrative, physical and technical safeguards, and handles breaches properly. Compliance is a property of how an organisation uses a tool, not of the tool alone. Be wary of badges and seals that imply a government certification.
Local processing: keeping PHI out of third-party hands
Browser-based tools that process files on your own device change the picture. If the file is read, compressed and saved by code running in your browser tab, the vendor never creates, receives, maintains or transmits the PHI — so, for that processing, there is generally nothing to put under a BAA. The data stays inside the environment your organisation already secures: your workstation, your network, your storage.
You can verify this yourself: open the browser's developer tools, switch to the Network tab and process a file. An upload-based tool shows a request carrying your whole file; a local tool shows no request containing it. Our guide on whether it is safe to compress PDFs online walks through the check step by step.
How MiniFiles handles files
MiniFiles runs its PDF and image tools in the browser: PDF compression uses Ghostscript compiled to WebAssembly, password protection uses qpdf, and merging, splitting and PDF-to-image conversion use pdf-lib and pdf.js. File contents and file names are never sent to MiniFiles servers.
What the servers do receive is limited: anonymous usage counters (file format, size before and after, and which tool was used), account data if you sign in, and — for visitors without an account — a hashed IP address used for the daily usage limit, which expires after about a day. The full list, including analytics and sub-processors, is on the Security page. Your organisation should still review these points against its own policies before adopting any tool.
Local processing doesn't remove your own obligations
Keeping PHI off third-party servers solves one problem, not all of them. Your HIPAA Security Rule duties still apply to the devices and channels involved:
- Workstations: the computer processing the file needs access controls, updates and disk encryption.
- Storage: the compressed copy is PHI too — save it where your policies allow, and delete temporary copies.
- Sharing: emailing a PDF with PHI requires appropriate safeguards. Protecting it with a strong password and AES-256 encryption (for example with Protect PDF) and sending the password through a separate channel reduces exposure if the email goes astray.
- Minimum necessary: remove pages that aren't needed before sharing — Split PDF can extract just the relevant pages.
- Training and documentation: record which tools staff may use for PHI and how.
Checklist: choosing a file tool for documents with PHI
- Does the tool upload the file? If yes, the vendor is a business associate — you need a signed BAA before using it with PHI.
- Can you verify local processing? Check the Network tab yourself rather than relying on marketing copy.
- What else does the tool send? Look for a clear list of analytics, logs and metadata it collects.
- Is there a clear security and privacy page? It should name sub-processors and data locations.
- Does it support your workflow safely? Compression, password protection and page extraction without extra tools reduce the number of places PHI travels.
- Is its use documented in your policies? Approve tools explicitly so staff don't fall back on whatever search results suggest.