MiniFiles.io
All articles
Business7 min30 September 2026

Is Your PDF Compressor HIPAA Compliant? What to Check

Clinics, billing teams and health-tech companies shrink PDFs every day — referral letters, scanned lab results, insurance forms — usually to get them under an email or portal size limit. The quickest route is a free online compressor. But if that PDF contains protected health information (PHI), uploading it hands PHI to a company you probably have no agreement with. This guide explains when a file tool becomes a HIPAA business associate, why "we encrypt uploads" is not enough, what "HIPAA compliant" can and can't mean for software, and a checklist for choosing a tool. It is general information, not legal advice — confirm your own setup with your privacy or compliance officer.

When does a file tool become a business associate?

Under HIPAA, a business associate is a person or company that creates, receives, maintains or transmits PHI on behalf of a covered entity (a provider, health plan or clearinghouse) or of another business associate. Before a covered entity shares PHI with a business associate, the two must sign a Business Associate Agreement (BAA) that commits the vendor to safeguard the data.

An online PDF compressor that receives your file on its servers — even for a few minutes — is receiving PHI. That makes the vendor a business associate for that file, and using it without a BAA is a HIPAA compliance problem, regardless of how briefly the file is kept. Free and consumer tiers of online file converters generally don't offer BAAs, so check the vendor's terms before sending anything that contains PHI.

Why "we encrypt your files" isn't enough

Many upload-based tools advertise TLS encryption in transit and automatic deletion after an hour. Those are good practices, but they don't remove the vendor from HIPAA's scope. HHS guidance on cloud services is clear that a provider which stores or processes ePHI is a business associate even if the data is encrypted and the provider doesn't hold the key. Deletion policies also rely entirely on the vendor's word and on its own subcontractors (hosting, storage, logging) behaving the same way.

The question to ask is not "how well is my upload protected?" but "does this tool need to receive my file at all?"

There is no official "HIPAA certified" software

HHS does not certify, approve or endorse software as HIPAA compliant. When a product says "HIPAA compliant", it can only mean that the vendor's practices support its customers' compliance — for example, it signs BAAs, has administrative, physical and technical safeguards, and handles breaches properly. Compliance is a property of how an organisation uses a tool, not of the tool alone. Be wary of badges and seals that imply a government certification.

Local processing: keeping PHI out of third-party hands

Browser-based tools that process files on your own device change the picture. If the file is read, compressed and saved by code running in your browser tab, the vendor never creates, receives, maintains or transmits the PHI — so, for that processing, there is generally nothing to put under a BAA. The data stays inside the environment your organisation already secures: your workstation, your network, your storage.

You can verify this yourself: open the browser's developer tools, switch to the Network tab and process a file. An upload-based tool shows a request carrying your whole file; a local tool shows no request containing it. Our guide on whether it is safe to compress PDFs online walks through the check step by step.

How MiniFiles handles files

MiniFiles runs its PDF and image tools in the browser: PDF compression uses Ghostscript compiled to WebAssembly, password protection uses qpdf, and merging, splitting and PDF-to-image conversion use pdf-lib and pdf.js. File contents and file names are never sent to MiniFiles servers.

What the servers do receive is limited: anonymous usage counters (file format, size before and after, and which tool was used), account data if you sign in, and — for visitors without an account — a hashed IP address used for the daily usage limit, which expires after about a day. The full list, including analytics and sub-processors, is on the Security page. Your organisation should still review these points against its own policies before adopting any tool.

Local processing doesn't remove your own obligations

Keeping PHI off third-party servers solves one problem, not all of them. Your HIPAA Security Rule duties still apply to the devices and channels involved:

  • Workstations: the computer processing the file needs access controls, updates and disk encryption.
  • Storage: the compressed copy is PHI too — save it where your policies allow, and delete temporary copies.
  • Sharing: emailing a PDF with PHI requires appropriate safeguards. Protecting it with a strong password and AES-256 encryption (for example with Protect PDF) and sending the password through a separate channel reduces exposure if the email goes astray.
  • Minimum necessary: remove pages that aren't needed before sharing — Split PDF can extract just the relevant pages.
  • Training and documentation: record which tools staff may use for PHI and how.

Checklist: choosing a file tool for documents with PHI

  1. Does the tool upload the file? If yes, the vendor is a business associate — you need a signed BAA before using it with PHI.
  2. Can you verify local processing? Check the Network tab yourself rather than relying on marketing copy.
  3. What else does the tool send? Look for a clear list of analytics, logs and metadata it collects.
  4. Is there a clear security and privacy page? It should name sub-processors and data locations.
  5. Does it support your workflow safely? Compression, password protection and page extraction without extra tools reduce the number of places PHI travels.
  6. Is its use documented in your policies? Approve tools explicitly so staff don't fall back on whatever search results suggest.

Key takeaways

  • An online PDF compressor that receives a file containing PHI acts as a HIPAA business associate and needs a signed BAA.
  • Encryption in transit and automatic deletion do not remove an upload-based vendor from HIPAA scope.
  • HHS does not certify software as HIPAA compliant; compliance depends on the vendor's practices and how the tool is used.
  • Browser-based tools that process files locally never receive the PHI, which generally avoids the business-associate relationship for that processing.
  • MiniFiles compresses, protects, splits and converts PDFs in the browser; file contents and names are never sent to its servers.

Frequently asked questions

Is it a HIPAA violation to use a free online PDF compressor?

Uploading a PDF that contains PHI to a vendor without a Business Associate Agreement is generally not permitted under HIPAA, because the vendor receives PHI on your behalf. Using a tool that processes the file locally, without uploading it, avoids that disclosure.

Is there such a thing as a HIPAA certified PDF tool?

No. HHS does not certify software. "HIPAA compliant" claims describe a vendor's practices, such as signing BAAs and maintaining safeguards; compliance depends on how your organisation uses the tool.

Do I need a BAA for a browser-based PDF compressor?

If the tool genuinely processes files on your device and the vendor never receives the file, there is generally no PHI disclosure to cover with a BAA for that processing. Confirm the behaviour yourself and with your compliance officer.

How can I check whether a tool uploads my file?

Open your browser's developer tools, go to the Network tab and process a test file. An upload-based tool shows a request carrying the file; a local tool does not.

Does MiniFiles see my patient documents?

No. MiniFiles processes PDFs and images in your browser, and file contents and names are never sent to its servers. It records only anonymous counters such as file format, size and tool used.

Try it now — free

Compress PNG, JPEG, and PDF files in your browser. No upload, no installation.

Compress PDF