Audience correction: unlike everything else in this Security section, this is not something any organization admin — including a full Administrator role — can reach or perform. The tab itself is only visible to platform operators who are god-eligible, and even then the switch stays disabled unless god mode is actively turned on for that session. If you're an org admin, this isn't reachable from your account; skip this article.
(Platform-operator only.) Mark an organization as handling protected health information, which blocks every module that can't legally carry it — or reverse that.
Before you start
God-eligible platform operator status, with god mode actively switched on for the current session (eligibility alone isn't enough — the switch stays disabled with an explanatory alert until god mode is on).
Steps
- Go to Settings → System Security → Health Data (PHI).
- Review the current status: Handles PHI or Not a PHI tenant. If it was ever turned on before, the effective start date is shown — this date is never re-stamped, even if toggled off and back on.
- Toggle the switch:
- Turning it ON shows exactly which modules will be blocked for everyone in the organization (the list comes from the server, so it's specific to this org's enabled features) — nothing works around this list; you'll lose those modules immediately.
- Turning it OFF restores every module. The original start date stays on record regardless.
- Check the acknowledgement box — its wording changes depending on direction (confirming a BAA is in place when enabling; confirming the org no longer handles PHI when disabling). Changing the switch again after checking the box un-checks it — you must re-acknowledge whatever the current intended change is.
- Click Apply change.
What you'll see
Every change — and every refused attempt — is written to the organization's HIPAA access log with your identity attached. See What Turning On PHI Handling Does for what "blocked module" actually means underneath.
Related articles
Other guides that answer questions close to this one.
What Turning On PHI Handling Does
The PHI compliance boundary is a tenant-wide switch: turn it on when an organization handles protected health information and Kamo acts as its business associate under HIPAA. While it's on, the platform refuses every…
How to Review the PHI Access Trail
See every read of protected health information in your organization — for periodic review, or to answer someone asking who has accessed their record. Before you start The View Access Logs right to view; the separate…
The PHI Access Audit
Every read of protected health information anywhere in KamoCRM is recorded as a PHI access record: who (actor), what kind of access (view, list, search, download, export, or disclose), on what record (one of 17 tracked…