{"licence":"CC BY 4.0","attribution":"Clinicians That Code","generated":"2026-09-02","source":"https://cliniciansthatcode.com/guides/which-platforms-sign-a-baa/","rows":[{"id":"lovable","vendor":"Lovable","layer":"builder","role_in_stack":"AI app builder; generates full-stack apps on a Supabase backend","baa":{"status":"no","min_tier":"not-applicable","price_as_published":"not-applicable","note":"Terms (checked 2026-09-02) prohibit uploading PHI unless your plan or a separate written agreement expressly permits it; no public BAA or HIPAA plan. Backend is Supabase (see that row); AI Gateway sends prompts and data to third-party model providers."},"eu":{"dpa":"not-verified","eu_region":"not-verified","subprocessors_url":"https://lovable.dev/terms","ai_training_default":"not-verified","zero_data_retention":"n-a"},"sources":[{"label":"Lovable Terms of Service, \"No Sensitive Data\" clause","url":"https://lovable.dev/terms"}],"verified_on":"2026-09-02","watch":{"url":"https://lovable.dev/terms","hint":"protected health information","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; verified against live Terms of Service"}]},{"id":"bolt-new","vendor":"Bolt.new (StackBlitz)","layer":"builder","role_in_stack":"AI app builder; generates and runs full-stack apps in-browser","baa":{"status":"no","min_tier":"not-applicable","price_as_published":"not-applicable","note":"No BAA offered on any plan; privacy wording is GDPR/CCPA-style and does not name HIPAA anywhere in Terms of Service, Privacy Policy, Enterprise or Pricing pages."},"eu":{"dpa":"not-verified","eu_region":"not-verified","subprocessors_url":"https://stackblitz.com/privacy-policy","ai_training_default":"not-verified","zero_data_retention":"n-a"},"sources":[{"label":"HIPAA Vault: Is Bolt.new HIPAA Compliant?","url":"https://www.hipaavault.com/resources/is-bolt-new-hipaa-compliant/"}],"verified_on":"2026-09-02","watch":{"url":"https://stackblitz.com/privacy-policy","hint":"HIPAA","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; secondary-source verified, no primary BAA/HIPAA page exists to check directly"}]},{"id":"base44","vendor":"Base44 (Wix)","layer":"builder","role_in_stack":"AI app builder, acquired by Wix; generates full-stack apps","baa":{"status":"no","min_tier":"not-applicable","price_as_published":"not-applicable","note":"No BAA offered, including on Enterprise; standard Terms of Service restrict PHI from entering the platform without a separately negotiated written agreement. Subprocessors include Wix (Israel), Langfuse (Germany), Logfire (UK)."},"eu":{"dpa":"not-verified","eu_region":"not-verified","subprocessors_url":"https://base44.com/privacy-policy","ai_training_default":"not-verified","zero_data_retention":"n-a"},"sources":[{"label":"Knack: Is Base44 HIPAA Compliant? A Healthcare Builder Guide","url":"https://www.knack.com/blog/is-base44-hipaa-compliant/"}],"verified_on":"2026-09-02","watch":{"url":"https://base44.com/privacy-policy","hint":"HIPAA","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; secondary-source verified"}]},{"id":"replit","vendor":"Replit","layer":"builder","role_in_stack":"AI app builder and cloud IDE; generates and hosts full-stack apps","baa":{"status":"no","min_tier":"not-applicable","price_as_published":"not-applicable","note":"No BAA on any plan; Replit's own documentation states standard hosting is not HIPAA compliant."},"eu":{"dpa":"not-verified","eu_region":"not-verified","subprocessors_url":"https://replit.com/site/privacy","ai_training_default":"not-verified","zero_data_retention":"n-a"},"sources":[{"label":"Paubox: Is Replit.com HIPAA compliant? (2026 update)","url":"https://www.paubox.com/blog/is-replit.com-hipaa-compliant-2025-update"}],"verified_on":"2026-09-02","watch":{"url":"https://replit.com/site/privacy","hint":"HIPAA","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; secondary-source verified"}]},{"id":"v0","vendor":"v0 (Vercel)","layer":"builder","role_in_stack":"Generative UI tool; scaffolds React/Next.js components and pages from prompts","baa":{"status":"no","min_tier":"not-applicable","price_as_published":"not-applicable","note":"No BAA for v0 itself; Vercel support has confirmed v0 falls outside the scope of Vercel's HIPAA BAA even where the hosting platform is covered. See the Vercel (hosting) row for the deployed app, which is a separate question from the generator."},"eu":{"dpa":"not-verified","eu_region":"not-verified","subprocessors_url":"https://vercel.com/legal/dpa","ai_training_default":"not-verified","zero_data_retention":"n-a"},"sources":[{"label":"Vercel HIPAA compliance guide (v0 scoped out)","url":"https://vercel.com/kb/guide/hipaa-compliance-guide-vercel"}],"verified_on":"2026-09-02","watch":{"url":"https://vercel.com/kb/guide/hipaa-compliance-guide-vercel","hint":"v0","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; secondary-source verified"}]},{"id":"cursor","vendor":"Cursor","layer":"ide","role_in_stack":"AI code editor; used against synthetic data during development, not in production","baa":{"status":"not-applicable","min_tier":"not-applicable","price_as_published":"not-applicable","note":"As an editor used on synthetic data during development, no BAA applies to the editor itself. Cursor does offer a BAA on its Enterprise plan (Privacy Mode required, org-wide, limited to a defined list of Eligible Services and Eligible Models) if PHI is ever routed through it; the model API a clinician actually calls governs any PHI in transit."},"eu":{"dpa":"not-verified","eu_region":"not-verified","subprocessors_url":"https://cursor.com/docs/enterprise/baa","ai_training_default":"not-verified","zero_data_retention":"not-verified"},"sources":[{"label":"Cursor Docs: HIPAA Business Associate Agreements","url":"https://cursor.com/docs/enterprise/baa"}],"verified_on":"2026-09-02","watch":{"url":"https://cursor.com/docs/enterprise/baa","hint":"Eligible Services","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; verified against Cursor's own BAA docs page"}]},{"id":"claude-code","vendor":"Claude Code","layer":"ide","role_in_stack":"AI coding agent (terminal/editor); used against synthetic data during development","baa":{"status":"not-applicable","min_tier":"not-applicable","price_as_published":"not-applicable","note":"As an editor used on synthetic data, no BAA applies to Claude Code itself. Anthropic's BAA only covers Claude Code when zero data retention (ZDR) is enabled on a qualified HIPAA-ready Enterprise account; the model API a clinician actually calls governs any PHI sent to the model (see Anthropic API row)."},"eu":{"dpa":"not-verified","eu_region":"no","subprocessors_url":"https://privacy.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customers","ai_training_default":"no","zero_data_retention":"not-verified"},"sources":[{"label":"Anthropic: Business Associate Agreements (BAA) for Commercial Customers","url":"https://privacy.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customers"},{"label":"Anthropic: HIPAA-ready Enterprise plans","url":"https://support.claude.com/en/articles/13296973-hipaa-ready-enterprise-plans"}],"verified_on":"2026-09-02","watch":{"url":"https://privacy.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customers","hint":"Claude Code","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; verified against Anthropic's own BAA docs page"}]},{"id":"vercel","vendor":"Vercel","layer":"hosting","role_in_stack":"Deployment platform for Next.js and other frontends; default host for v0/AI-generated apps","baa":{"status":"paid-tier","min_tier":"Pro (click-through BAA) or Enterprise (negotiated BAA)","price_as_published":"Pro plan from USD 20/month per member; Enterprise pricing on request","note":"Vercel signs a BAA with Enterprise customers on request; Pro customers get a click-through BAA with no Enterprise contract required (per Vercel's 2026 changelog announcement)."},"eu":{"dpa":"yes","eu_region":"yes","subprocessors_url":"https://vercel.com/legal/dpa","ai_training_default":"n-a","zero_data_retention":"n-a"},"sources":[{"label":"Vercel: Does Vercel support HIPAA compliance?","url":"https://vercel.com/kb/guide/is-vercel-hipaa-compliant"},{"label":"Vercel changelog: HIPAA BAAs are now available to Pro teams","url":"https://vercel.com/changelog/hipaa-baas-are-now-available-to-pro-teams"},{"label":"Vercel Data Processing Addendum","url":"https://vercel.com/legal/dpa"}],"verified_on":"2026-09-02","watch":{"url":"https://vercel.com/kb/guide/is-vercel-hipaa-compliant","hint":"BAA","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; verified against Vercel's own knowledge base and changelog"}]},{"id":"netlify","vendor":"Netlify","layer":"hosting","role_in_stack":"Deployment platform for static/JAMstack frontends","baa":{"status":"enterprise-only","min_tier":"Enterprise","price_as_published":"Enterprise pricing on request","note":"Netlify launched a HIPAA-compliant service offering for enterprise customers handling PHI (announced 2024, still current); a BAA is executed as part of that offering."},"eu":{"dpa":"yes","eu_region":"not-verified","subprocessors_url":"https://www.netlify.com/gdpr-ccpa/","ai_training_default":"n-a","zero_data_retention":"n-a"},"sources":[{"label":"Netlify: Netlify launches a HIPAA-compliant service offering","url":"https://www.netlify.com/blog/netlify-launches-a-hipaa-compliant-service-offering/"}],"verified_on":"2026-09-02","watch":{"url":"https://www.netlify.com/blog/netlify-launches-a-hipaa-compliant-service-offering/","hint":"HIPAA","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; verified against Netlify's own announcement"}]},{"id":"supabase","vendor":"Supabase","layer":"database","role_in_stack":"Postgres, auth and storage; the default backend behind Lovable and v0","baa":{"status":"paid-tier","min_tier":"Team plan plus HIPAA add-on","price_as_published":"USD 599/month (Team) plus a USD 350/month HIPAA add-on","note":"Self-hosting is outside the BAA. Free and Pro plans do not support HIPAA at any price; the add-on requires Team or Enterprise."},"eu":{"dpa":"yes","eu_region":"yes","subprocessors_url":"https://supabase.com/legal/customer-resources/subprocessor-list","ai_training_default":"n-a","zero_data_retention":"n-a"},"sources":[{"label":"HIPAA Vault: Is Supabase HIPAA Compliant? Yes, With Conditions (2026)","url":"https://www.hipaavault.com/resources/is-supabase-hipaa-compliant/"},{"label":"Supabase Data Processing Addendum","url":"https://supabase.com/legal/dpa"},{"label":"Supabase: GDPR compliance and Supabase","url":"https://supabase.com/docs/guides/security/gdpr-compliance"}],"verified_on":"2026-09-02","watch":{"url":"https://supabase.com/legal/dpa","hint":"HIPAA","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; price figure cross-checked across three independent sources"}]},{"id":"firebase","vendor":"Firebase / Google Cloud","layer":"database","role_in_stack":"Backend-as-a-service (Firestore, Auth, Functions) built on Google Cloud","baa":{"status":"paid-tier","min_tier":"Google Cloud BAA (Enterprise agreement); only specific Firebase services are covered","price_as_published":"not-applicable; part of a negotiated Google Cloud agreement","note":"Google Cloud's HIPAA BAA covers Cloud Firestore and Cloud Functions; Firebase Analytics, Crashlytics, Cloud Messaging and Remote Config generally fall outside HIPAA-eligible services. Verify the current covered-services list before relying on any Firebase feature."},"eu":{"dpa":"yes","eu_region":"yes","subprocessors_url":"https://cloud.google.com/terms/subprocessors","ai_training_default":"n-a","zero_data_retention":"n-a"},"sources":[{"label":"Google Cloud: HIPAA Compliance on Google Cloud","url":"https://cloud.google.com/security/compliance/hipaa"},{"label":"Accountable: Is Firebase HIPAA Compliant? BAA, Covered Services","url":"https://www.accountablehq.com/post/is-firebase-hipaa-compliant-baa-covered-services-and-how-to-use-it-safely"}],"verified_on":"2026-09-02","watch":{"url":"https://cloud.google.com/security/compliance/hipaa","hint":"Firebase","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; covered-services caveat verified against Google's own compliance page"}]},{"id":"openai-api","vendor":"OpenAI API","layer":"model API","role_in_stack":"Foundation model API called directly or via other tools for text/vision generation","baa":{"status":"paid-tier","min_tier":"API on a qualifying zero-data-retention (ZDR) organization, sales-approved","price_as_published":"usage-based API pricing; BAA approval is a sales process, not a plan tier","note":"BAA available for the API on eligible endpoints configured for zero data retention; ChatGPT consumer plans (Free/Plus) are not covered. Web Search with live internet access is explicitly not HIPAA-eligible even under ZDR; offline/cache-only web search can be covered."},"eu":{"dpa":"yes","eu_region":"not-verified","subprocessors_url":"https://openai.com/policies/data-processing-addendum/","ai_training_default":"no","zero_data_retention":"yes"},"sources":[{"label":"OpenAI: Data controls in the OpenAI platform","url":"https://developers.openai.com/api/docs/guides/your-data"},{"label":"OpenAI: Enterprise privacy at OpenAI","url":"https://openai.com/enterprise-privacy/"}],"verified_on":"2026-09-02","watch":{"url":"https://developers.openai.com/api/docs/guides/your-data","hint":"HIPAA","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; verified against OpenAI's own data-controls documentation"}]},{"id":"anthropic-api","vendor":"Anthropic API","layer":"model API","role_in_stack":"Foundation model API (Claude) called directly or via other tools","baa":{"status":"paid-tier","min_tier":"First-party API or Claude Enterprise, with the org's Primary Owner activating HIPAA compliance and accepting the BAA","price_as_published":"usage-based API pricing; Enterprise pricing on request","note":"Not automatic: standard Claude Enterprise plans carry no BAA coverage until a Primary Owner turns on HIPAA readiness. Covered Models require 30-day retention and are unavailable with zero data retention enabled; some surfaces (Console, Cowork, beta features) are excluded even under an active BAA."},"eu":{"dpa":"yes","eu_region":"no","subprocessors_url":"https://privacy.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customers","ai_training_default":"no","zero_data_retention":"not-verified"},"sources":[{"label":"Anthropic: Business Associate Agreements (BAA) for Commercial Customers","url":"https://privacy.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customers"},{"label":"Anthropic: Covered Models under a Business Associate Agreement (BAA)","url":"https://support.claude.com/en/articles/15455031-covered-models-under-a-business-associate-agreement-baa"}],"verified_on":"2026-09-02","watch":{"url":"https://privacy.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customers","hint":"BAA","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; verified against Anthropic's own BAA documentation, correcting the initial lead of a flat no"}]},{"id":"cloud-model-apis","vendor":"Azure OpenAI / AWS Bedrock / Google Vertex AI","layer":"model API","role_in_stack":"Foundation model access via a hyperscaler's own API surface, often chosen specifically for its BAA","baa":{"status":"paid-tier","min_tier":"Covered under the hyperscaler's own HIPAA BAA (Microsoft Online Services DPA, AWS HIPAA BAA, Google Cloud BAA respectively); only listed eligible services/models are covered","price_as_published":"usage-based; BAA is contractual, not a separate line item","note":"All three offer BAAs at enterprise tiers, but coverage varies by endpoint, feature, configuration and sub-processor chain; verify each provider's current eligible-services list before use, not just the top-level claim that the platform 'has a BAA'."},"eu":{"dpa":"yes","eu_region":"yes","subprocessors_url":"https://cloud.google.com/terms/subprocessors","ai_training_default":"no","zero_data_retention":"not-verified"},"sources":[{"label":"The AI Career Lab: AI Business Associate Agreements (BAAs) in 2026","url":"https://theaicareerlab.com/blog/ai-business-associate-agreements-baa-vendor-guide-2026"},{"label":"AI Provider Trust Registry: Which AI providers offer a HIPAA BAA?","url":"https://aiprovidertrust.com/questions/hipaa-baa/"}],"verified_on":"2026-09-02","watch":{"url":"https://cloud.google.com/security/compliance/hipaa","hint":"Vertex AI","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created as a combined teaching row; per-provider eligible-services lists not individually re-verified this pass"}]},{"id":"clerk","vendor":"Clerk","layer":"auth","role_in_stack":"Authentication and user management, commonly paired with Next.js apps","baa":{"status":"paid-tier","min_tier":"HIPAA compliance available with BAA on paid plans (Enterprise-style add-on)","price_as_published":"not-verified exact figure; Clerk's public pricing page lists \"HIPAA compliance available with BAA\" as a paid-plan feature","note":"Clerk advertises HIPAA compliance and will sign BAAs; onboarding and migration support plus custom security questionnaires are bundled at the same tier."},"eu":{"dpa":"yes","eu_region":"not-verified","subprocessors_url":"https://clerk.com/legal/dpa","ai_training_default":"n-a","zero_data_retention":"n-a"},"sources":[{"label":"Clerk Pricing","url":"https://clerk.com/pricing"},{"label":"Clerk Data Processing Addendum","url":"https://clerk.com/legal/dpa"}],"verified_on":"2026-09-02","watch":{"url":"https://clerk.com/pricing","hint":"HIPAA","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; verified against Clerk's own pricing page; exact BAA add-on price not published, left not-verified"}]},{"id":"resend","vendor":"Resend","layer":"email","role_in_stack":"Transactional and marketing email API; used by this site's own Handover newsletter","baa":{"status":"enterprise-only","min_tier":"Enterprise, on request, per an Order Form","price_as_published":"Enterprise pricing on request","note":"Our own stack: disclose this. Resend's GDPR page states plainly that Resend is not HIPAA compliant and cannot sign a BAA; however its Enterprise Terms and Conditions allow submitting PHI under a BAA signed by both parties \"if set forth in the Order Form\", i.e. only by explicit enterprise negotiation, not as a standard offering."},"eu":{"dpa":"yes","eu_region":"not-verified","subprocessors_url":"https://resend.com/legal/dpa","ai_training_default":"n-a","zero_data_retention":"n-a"},"sources":[{"label":"Resend: GDPR","url":"https://resend.com/security/gdpr"},{"label":"Resend: Enterprise Terms and Conditions","url":"https://resend.com/legal/enterprise-terms"}],"verified_on":"2026-09-02","watch":{"url":"https://resend.com/security/gdpr","hint":"HIPAA","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; corrected from an initial \"unverified\" lead to enterprise-only after finding Resend's own contradicting GDPR FAQ vs Enterprise Terms"}]},{"id":"github","vendor":"GitHub","layer":"repo","role_in_stack":"Source control and CI; where the code (never the data) lives","baa":{"status":"no","min_tier":"not-applicable","price_as_published":"not-applicable","note":"Teaching row: GitHub's own site-policy pages make no mention of HIPAA or a BAA at any tier; treat GitHub as having no BAA path. PHI must never enter the repository, in code, commit messages, issues or CI logs, regardless of plan."},"eu":{"dpa":"yes","eu_region":"not-verified","subprocessors_url":"https://docs.github.com/en/site-policy/privacy-policies/github-subprocessors-list","ai_training_default":"n-a","zero_data_retention":"n-a"},"sources":[{"label":"GitHub Data Protection Agreement (site policy)","url":"https://docs.github.com/en/site-policy/privacy-policies/github-data-protection-agreement"}],"verified_on":"2026-09-02","watch":{"url":"https://docs.github.com/en/site-policy/privacy-policies/github-data-protection-agreement","hint":"HIPAA","mode":"auto"},"changelog":[{"date":"2026-09-02","note":"Row created; verified by absence of any HIPAA/BAA mention on GitHub's own site-policy pages"}]}]}