ClinicOps  /  Briefings  /  Tools Guide

Tools Guide · Published Aug 20, 2026

HIPAA, ClickUp, Monday and Asana: The PHI-Safe Setup (Chart Numbers Only)

The tool roundups all ask which project app is HIPAA-compliant. That is the wrong question. The right one is how to use any of them safely, and the answer is to keep patient data out entirely. Here is the chart-numbers-only method.

You can run a practice on ClickUp, Monday, or Asana in a HIPAA-safe way, on standard tiers, by keeping protected health information out of the tool completely. Track work by chart number, status, and owner; keep the PHI in the EHR. No PHI in the tool means no BAA required and nothing to breach, which is safer than protecting PHI you chose to put in.

Key takeaways

  • The safe question is not which tool is compliant, but how to use any tool without putting PHI in it.
  • Track by chart number, status, owner, and date. Never by name, diagnosis, or any patient identifier.
  • No PHI in the tool means no Business Associate Agreement is needed, so standard tiers work.
  • A BAA is generally an Enterprise-tier feature; the chart-numbers-only method avoids needing one.
  • This is safer, not just cheaper: the data that was never in the tool cannot leak from it.

Search "HIPAA-compliant project management" and you get roundups ranking tools by whether they offer a Business Associate Agreement. Useful, but it answers the wrong question. The safest way to use any of these tools is to never put patient data in them in the first place. Do that, and the whole compliance question dissolves.

The question the roundups skip

A BAA is a legal agreement about how a vendor will handle your protected health information. It matters only if PHI is going to live in the vendor's tool. The roundups assume it will, and then rank tools by how well they protect it. But that assumption is a choice, not a requirement. If you decide that no PHI ever enters the project tool, there is no PHI for a BAA to cover, and the entire ranking becomes irrelevant. The question worth asking is not "which tool is compliant," it is "how do I run operations without putting patient data in a project tool at all." That reframing is the whole guide.

What each tool actually requires

For completeness, here is where a BAA sits on the major tools as of 2026, so you can see what the chart-numbers-only method lets you skip.

Where a BAA lives, by tool (2026)
ToolBAA available onWhat chart-numbers-only lets you use
ClickUpEnterprise tierFree or a low paid tier, since no PHI is stored
AsanaEnterprise or Enterprise+Standard tiers, since no PHI is stored
MondayEnterprise tierStandard tiers, since no PHI is stored

The pattern is the same everywhere: a BAA is a top-tier feature, and you only need it if you put PHI in the tool. Keep PHI out and any tier is safe on this axis, which is what makes the method both safer and dramatically cheaper.

The chart-numbers-only method

The method is one rule with a clean split behind it. The project tool holds workflow. The EHR holds patients. In the tool, a task is identified by a chart number, a status, an owner, and a date, never by a name, a date of birth, a diagnosis, or any identifier that ties the record to a person. The chart number is a pointer: when a staff member needs the patient, they open that chart in the EHR, where the PHI properly lives and is properly protected. The tool answers "what needs doing and by whom." The EHR answers "who is this and what is their information." Because the two never mix, the project tool contains only operational data, which is not PHI, and the compliance surface shrinks to nothing. Any demonstration or template uses sample data for the same reason. This is exactly the boundary the systems in the Zero-Slip build and every tracker are designed around.

Get the free Rescue Kit

Trackers and SOPs built chart-numbers-only from the start, so PHI never enters the tool.

Get the free Rescue Kit

Setting it up, and the mistakes to avoid

Putting the method in place is mostly discipline, plus a few guardrails. Set the convention explicitly: every task references a chart number, full stop, and staff are trained that names and diagnoses never go in a title, description, comment, or attachment. Watch the fields that leak. The common PHI mistakes in project tools are not the obvious ones; they hide in a task title with a patient's name, a comment adding "the diabetic patient," an uploaded document with a face sheet, or a custom field for date of birth. Each of those quietly turns an operational tool into one holding PHI. Name a reviewer who spot-checks that the convention is holding, especially in the first weeks and after onboarding a new hire, since new staff are the most likely to paste in a name out of habit. Bake the rule into onboarding from day one, as in the onboarding checklist, and it becomes second nature rather than a policy people forget.

Why this is safer, not just cheaper

The cost savings are real, standard tiers instead of Enterprise, but the security argument is the stronger one. When you put PHI in a tool and protect it with settings and a BAA, you are managing a risk: a misconfiguration, an over-shared board, a departing employee with access, any of them can expose data that is genuinely there. When you keep PHI out entirely, there is no risk to manage, because the data that was never in the tool cannot leak from it. A BAA is a promise about how a breach will be handled; the chart-numbers-only method is a design where the breach has nothing to take. That is a categorically stronger position, and it is available to any practice willing to hold one simple line. It is the same principle behind running operations remotely without ever touching patient data, described in how I run US operations from 8,000 miles away. To put it into practice, see the ClickUp setup and Monday setup guides.

Where to go next

Find the leak before you fix it

Two ways to start, both free.

Run the free Rescue Kit and its tools yourself, or book a 20-minute Leak Audit where we put a real number on what this is costing, using your own volume. A diagnosis, not a pitch.

Frequently asked questions

Can you use ClickUp, Monday, or Asana in a HIPAA-compliant way?

Yes, and without paying for an Enterprise tier, if you keep protected health information out of the tool entirely. The tools reference work by chart number and status; the actual PHI stays in your EHR. No PHI in the tool means no need for a Business Associate Agreement.

Do you need a BAA to use a project management tool in a practice?

Only if PHI will live in the tool. A BAA is a legal agreement covering how a vendor handles your PHI. If you never put PHI in the tool, there is no PHI for a BAA to cover, so you can use the standard tiers safely.

Which tiers offer a BAA?

As of 2026, a BAA is generally available only on the top tiers: ClickUp on Enterprise, Asana on Enterprise or Enterprise+, and Monday on Enterprise. The chart-numbers-only method avoids needing any of them, because it keeps PHI out of the tool.

What is the chart-numbers-only method?

You track tasks by chart number, status, owner, and date, never by patient name, diagnosis, or any identifier. The chart number is a pointer your staff resolves inside the EHR, so the project tool holds workflow, not patient data.

Is chart-numbers-only actually HIPAA-safe?

It removes the risk at the source: there is no PHI in the tool to breach, misconfigure, or leak. That is safer than putting PHI in a tool and protecting it with settings, because the safest data is the data that was never there.

What counts as PHI I must keep out of the tool?

Names, dates of birth, addresses, phone numbers, diagnoses, and any of the HIPAA identifiers that tie a record to a person. If a field could identify a patient, it does not go in the tool. Chart number and status are safe; the rest stays in the EHR.

Can staff still do their work with only chart numbers?

Yes. The chart number tells them exactly which record to open in the EHR, where the PHI lives. The project tool answers what needs doing and by whom; the EHR answers who the patient is. Splitting those two is the whole method.