Reviewed by Jonathan West · Updated Aug 29, 2026

Is Hermes Agent HIPAA Compliant?

Self-hosting is the only realistic path, and only if you supply every safeguard yourself.

Reviewed by Jonathan West · Updated Aug 29, 2026

Hermes Agent is not HIPAA compliant out of the box, and Nous Research does not document a Business Associate Agreement (BAA) program for it. That is true whether you self-host or use Hermes Agent Cloud.

That does not make Hermes Agent unusable for a business that touches health data. It means the compliance burden sits entirely on you, since there is no vendor-provided BAA to lean on.

This guide covers why the missing BAA matters, the real difference between self-hosting and Hermes Agent Cloud for PHI, and what your organization would need to add before letting Hermes Agent anywhere near patient data.


The Short Answer

Hermes Agent is free and open source, and nothing in its documentation or pricing describes a Business Associate Agreement offering for either hosting mode.

Under HIPAA, a covered entity cannot lawfully hand PHI to a vendor without a signed BAA in place first. No BAA program means Hermes Agent Cloud is not a lawful place to process PHI today.

Self-hosting sidesteps the vendor-BAA question, because Nous Research never touches your data at all in that mode. That only works if you supply every safeguard HIPAA requires yourself.

No vendor BAA means no PHI on Hermes Agent Cloud. Self-hosting can be part of a compliant setup, but only with your own controls layered on top.

Want the whole playbook, not just this page? The Complete Medical Practice AI Implementation Guide (2026) is the full step-by-step rollout for medical & dental practices.

Get the guide — $59 (reg. $89)

Why Hermes Agent Has No HIPAA BAA

HIPAA requires a signed BAA before a covered entity lets any vendor create, receive, store, or transmit protected health information. That rule does not bend for open-source tools or newer vendors.

Hermes Agent Cloud is Nous Research's managed offering. The agent, its memory, and its configuration all run on infrastructure Nous Research operates, so routing any PHI through that service without a BAA is the exact gap HIPAA exists to close.

Being free and open source does not exempt Hermes Agent from this rule. The obligation follows whoever actually processes the data, and that depends entirely on which hosting mode you choose.


Self-Hosting Shifts Who Signs the BAA

Self-hosting Hermes Agent keeps the agent, its persistent memory, and its configuration on infrastructure you control. Nous Research is never a business associate in that deployment, because no vendor is touching the data.

That removes one obstacle. It does not make a self-hosted deployment automatically compliant, since you still need the standard HIPAA technical safeguards: encryption at rest and in transit, access controls, audit logging, and a documented retention policy for whatever the agent stores.

Hermes Agent's persistent memory is the detail most setups miss here. It keeps and searches what it learns across sessions, so if any of that content is PHI, the memory store itself becomes a system that needs the same safeguards, access logging, and retention limits as any other database holding patient data.

Model routing is the other gap to close. Whatever model provider you point a self-hosted agent at, whether a managed service, OpenRouter, OpenAI, or your own private endpoint, receives the content the agent sends it. If PHI reaches that provider, it needs its own BAA too, independent of Hermes Agent's own hosting.

  • Self-hosting removes Nous Research as a business associate, but it hands you the full safeguard burden in exchange.
  • Encrypt the memory store and configuration at rest and in transit.
  • Treat persistent memory as PHI-grade data if any PHI ever reaches it, with access controls and a retention policy.
  • Route model calls only to providers you already have a BAA with. A self-hosted agent does not remove that requirement.
Self-hosting removes the vendor-BAA gap. The safeguard requirements stay, and building them is now entirely your job.

What HIPAA Compliance Requires from Hermes Agent

If your organization is considering Hermes Agent for anything touching PHI, you need a checklist first, because there is no plan to upgrade to here, unlike a vendor with a documented Enterprise-plus-BAA tier.

Start with the same governance work any unattended agent needs, then add the HIPAA-specific layer on top: encryption, access logging, and a named privacy officer accountable for the memory policy.

In the governance work we do for clients handling regulated data, checking the BAA question is always the first step before wiring in any new tool, not the last.

  • Self-host only. Hermes Agent Cloud has no documented BAA path, so it is not an option for PHI today.
  • Encrypt the memory store and any configuration files that could hold PHI.
  • Scope tool, file, and API access to the minimum a job needs, matching the general safety guidance for the agent.
  • Confirm a BAA already exists with whatever model provider processes the content, if PHI reaches the model at all.
  • Assign one accountable owner for the memory-retention policy and periodic review.
  • Document all of it before any PHI touches the system.

The Delivery-Channel Gap Most Setups Miss

A HIPAA-compliant model provider does not make a Hermes Agent deployment compliant on its own, because the model is only one stop on the path PHI travels. Hermes Agent delivers its results to Telegram, Slack, Discord, WhatsApp, or email, and every one of those is a separate place data can land.

Standard consumer Telegram, Discord, and WhatsApp accounts are not channels a covered entity can use for PHI, since none of them offer a BAA for that use case. A message with a patient's name and diagnosis routed to a personal Telegram chat is a violation even if the model that generated it sits behind a signed BAA.

Slack and email can work, but only inside an account tier your organization already covers under its own BAA with Slack or your email provider, not a default free workspace or a personal inbox. Confirm that coverage before pointing any Hermes Agent job at either channel.

The practical fix is to route anything that might touch PHI to a channel you already control and have covered: an internal Slack workspace under an existing BAA, or an email address on infrastructure your organization already secures. Never let a job default to whichever channel is easiest to wire up.

  • Telegram, Discord, and consumer WhatsApp: never route PHI through these, regardless of what generated the message.
  • Slack and email: usable only under your organization's own BAA with that provider, never a default or personal account.
  • A compliant model provider covers one link in the chain. Delivery and memory are separate links that need their own coverage.

When to Choose a HIPAA-Ready Alternative Instead

Skip Hermes Agent for PHI entirely if your team cannot commit to running its own encryption, access controls, and memory-retention policy on an ongoing basis, since that work does not end after setup. Someone has to patch the server, rotate keys, review what the memory has stored, and re-check every delivery channel every time a new job gets added.

A vendor that already documents a BAA program, the way Otter.ai does above its Enterprise tier, shifts that maintenance burden onto the vendor in exchange for a subscription. Weigh that subscription cost against the cost of building and auditing your own safeguards before deciding.

Confirm your model provider's BAA status and lock down encryption and access controls before any PHI reaches Hermes Agent, since HIPAA compliance here depends entirely on what you build around it.

Frequently Asked Questions

  • No. Hermes Agent has no documented Business Associate Agreement (BAA) program, on Hermes Agent Cloud or otherwise, so it is not HIPAA compliant as shipped.
  • No. Without a BAA, routing PHI through Nous Research's managed Hermes Agent Cloud is not a lawful use under HIPAA.
  • Self-hosting removes Nous Research as a business associate, since no vendor touches your data, but it is not automatically compliant. You still need to add encryption, access controls, audit logging, and a memory-retention policy yourself.
  • Yes. Persistent memory keeps and searches what the agent learns across sessions. If any of that is PHI, the memory store itself needs the same safeguards as any other system holding patient data.
  • Yes, if PHI reaches the model. Self-hosting the agent does not cover the model-routing step, so whichever provider processes the content (a managed service, OpenRouter, OpenAI, or your own endpoint) needs its own BAA if PHI is in what it receives.
  • There is no published timeline. As a free, open-source project, a formal BAA program is less certain than it would be for a paid enterprise vendor, so confirm the current status directly with Nous Research before assuming otherwise.
  • No. A model provider's own BAA only covers the model step. Hermes Agent's memory store and its delivery channels, such as Telegram, Slack, Discord, WhatsApp, or email, are separate links in the chain and need their own safeguards or their own BAA coverage.
  • Telegram, Discord, and consumer WhatsApp are never safe for PHI, since none offer a BAA for that use. Slack and email can work, but only under an account tier your organization already covers with its own BAA with that provider, never a default workspace or personal inbox.
  • Deleting the agent does not delete what its memory already stored. Export or purge the memory store yourself before decommissioning, and confirm no copy survives in a backup, a log, or a delivery channel like Slack or email where a message already landed.

The complete AI playbook for medical & dental practices

The Complete Medical Practice AI Implementation Guide (2026): HIPAA-compliant vendor selection, scribes, voice agents, scheduling and intake, front-desk automation, dental-specific plays, and the specialty cuts — for the owner rolling AI into a real practice in 2026.

Get the guide — $59 (reg. $89)