The PHI compliance boundary is a tenant-wide switch: turn it on when an organization handles protected health information and Kamo acts as its business associate under HIPAA. While it's on, the platform refuses every module that can't legally carry health data, for every member of that organization — not a warning, an actual block.
This is platform-operator functionality, gated behind god-mode, not something any organization's own admin — even a full Administrator role — can reach or control. See How do I turn PHI handling on or off? for the mechanics, if that applies to you.
Two things that don't change once set
- The effective date never moves. Once PHI handling is first recorded as on, that date stays on record permanently — even across a later off/on cycle — because it scopes any future breach or compliance assessment to "since when was this org actually handling PHI."
- The blocked-module list is server-driven, not fixed. Turning the boundary on shows the specific modules blocked for that organization at that moment, based on what it has enabled — it isn't a static list you can look up once and assume applies everywhere.
Where this connects
Every access to protected health information — whether the boundary is on or off — is separately tracked in the PHI Access Audit trail. See The PHI Access Audit
Related articles
Other guides that answer questions close to this one.
How to Turn PHI Handling On or Off
Audience correction: unlike everything else in this Security section, this is not something any organization admin — including a full Administrator role — can reach or perform. The tab itself is only visible to platform…
The PHI Access Audit
Every read of protected health information anywhere in KamoCRM is recorded as a PHI access record: who (actor), what kind of access (view, list, search, download, export, or disclose), on what record (one of 17 tracked…
How to Review the PHI Access Trail
See every read of protected health information in your organization — for periodic review, or to answer someone asking who has accessed their record. Before you start The View Access Logs right to view; the separate…