Why "the file gets deleted after an hour" isn't HIPAA-safe
Many online PDF tools advertise that uploaded files are auto-deleted after a set time, positioning that as privacy-friendly. Under HIPAA, though, the moment a file containing protected health information (PHI) is uploaded to a third-party server at all, that server operator becomes a business associate requiring a signed BAA — regardless of how quickly the file is later deleted.
PrivaPDF sidesteps the question entirely: because PHI never leaves the browser tab it's opened in, there's no third party receiving the data and therefore no business associate relationship to establish in the first place.