Every ranking page for "does X sign a BAA" is vendor content, written by a company selling the
compliance layer it is describing. This table is not that. It is dated, sourced against each
vendor's own terms or trust page, and it will be wrong the day a vendor changes its policy, which
is exactly why every row below carries a verified_on date and a watcher that checks for drift.
A Business Associate Agreement (BAA) is the specific US legal instrument HIPAA requires before Protected Health Information (PHI) can touch a vendor. No BAA means no PHI on that vendor, on any plan, at any price, no matter how good its general security posture is. "No BAA" is not a verdict on a tool's quality; Cursor and Replit are both fine editors. It is a verdict on one narrow question: can real patient data touch this thing.
| Platform | BAA | Min tier / price | EU DPA | EU region | Subprocessors | AI training | Zero retention | Verified | Sources | Correction |
|---|---|---|---|---|---|---|---|---|---|---|
| AI app builders | ||||||||||
Lovable AI app builder; generates full-stack apps on a Supabase backend | No Terms (checked 2026-09-02) prohibit uploading PHI unless your plan or a separate written agreement expressly permits it; no public BAA or HIPAA plan. Backend is Supabase (see that row); AI Gateway sends prompts and data to third-party model providers. | not-applicable not-applicable | Not verified | Not verified | List | Not verified | N/A | 2026-09-02 | Suggest a correction | |
Bolt.new (StackBlitz) AI app builder; generates and runs full-stack apps in-browser | No No BAA offered on any plan; privacy wording is GDPR/CCPA-style and does not name HIPAA anywhere in Terms of Service, Privacy Policy, Enterprise or Pricing pages. | not-applicable not-applicable | Not verified | Not verified | List | Not verified | N/A | 2026-09-02 | Suggest a correction | |
Base44 (Wix) AI app builder, acquired by Wix; generates full-stack apps | No No BAA offered, including on Enterprise; standard Terms of Service restrict PHI from entering the platform without a separately negotiated written agreement. Subprocessors include Wix (Israel), Langfuse (Germany), Logfire (UK). | not-applicable not-applicable | Not verified | Not verified | List | Not verified | N/A | 2026-09-02 | Suggest a correction | |
Replit AI app builder and cloud IDE; generates and hosts full-stack apps | No No BAA on any plan; Replit's own documentation states standard hosting is not HIPAA compliant. | not-applicable not-applicable | Not verified | Not verified | List | Not verified | N/A | 2026-09-02 | Suggest a correction | |
v0 (Vercel) Generative UI tool; scaffolds React/Next.js components and pages from prompts | No No BAA for v0 itself; Vercel support has confirmed v0 falls outside the scope of Vercel's HIPAA BAA even where the hosting platform is covered. See the Vercel (hosting) row for the deployed app, which is a separate question from the generator. | not-applicable not-applicable | Not verified | Not verified | List | Not verified | N/A | 2026-09-02 | Suggest a correction | |
| Editors & coding agents | ||||||||||
Cursor AI code editor; used against synthetic data during development, not in production | Not applicable As an editor used on synthetic data during development, no BAA applies to the editor itself. Cursor does offer a BAA on its Enterprise plan (Privacy Mode required, org-wide, limited to a defined list of Eligible Services and Eligible Models) if PHI is ever routed through it; the model API a clinician actually calls governs any PHI in transit. | not-applicable not-applicable | Not verified | Not verified | List | Not verified | Not verified | 2026-09-02 | Suggest a correction | |
Claude Code AI coding agent (terminal/editor); used against synthetic data during development | Not applicable As an editor used on synthetic data, no BAA applies to Claude Code itself. Anthropic's BAA only covers Claude Code when zero data retention (ZDR) is enabled on a qualified HIPAA-ready Enterprise account; the model API a clinician actually calls governs any PHI sent to the model (see Anthropic API row). | not-applicable not-applicable | Not verified | No | List | No | Not verified | 2026-09-02 | Suggest a correction | |
| Hosting | ||||||||||
Vercel Deployment platform for Next.js and other frontends; default host for v0/AI-generated apps | Paid tier Vercel signs a BAA with Enterprise customers on request; Pro customers get a click-through BAA with no Enterprise contract required (per Vercel's 2026 changelog announcement). | Pro (click-through BAA) or Enterprise (negotiated BAA) Pro plan from USD 20/month per member; Enterprise pricing on request | Yes | Yes | List | N/A | N/A | 2026-09-02 | Suggest a correction | |
Netlify Deployment platform for static/JAMstack frontends | Enterprise only Netlify launched a HIPAA-compliant service offering for enterprise customers handling PHI (announced 2024, still current); a BAA is executed as part of that offering. | Enterprise Enterprise pricing on request | Yes | Not verified | List | N/A | N/A | 2026-09-02 | Suggest a correction | |
| Database & backend | ||||||||||
Supabase Postgres, auth and storage; the default backend behind Lovable and v0 | Paid tier Self-hosting is outside the BAA. Free and Pro plans do not support HIPAA at any price; the add-on requires Team or Enterprise. | Team plan plus HIPAA add-on USD 599/month (Team) plus a USD 350/month HIPAA add-on | Yes | Yes | List | N/A | N/A | 2026-09-02 | Suggest a correction | |
Firebase / Google Cloud Backend-as-a-service (Firestore, Auth, Functions) built on Google Cloud | Paid tier Google Cloud's HIPAA BAA covers Cloud Firestore and Cloud Functions; Firebase Analytics, Crashlytics, Cloud Messaging and Remote Config generally fall outside HIPAA-eligible services. Verify the current covered-services list before relying on any Firebase feature. | Google Cloud BAA (Enterprise agreement); only specific Firebase services are covered not-applicable; part of a negotiated Google Cloud agreement | Yes | Yes | List | N/A | N/A | 2026-09-02 | Suggest a correction | |
| Model APIs | ||||||||||
OpenAI API Foundation model API called directly or via other tools for text/vision generation | Paid tier BAA available for the API on eligible endpoints configured for zero data retention; ChatGPT consumer plans (Free/Plus) are not covered. Web Search with live internet access is explicitly not HIPAA-eligible even under ZDR; offline/cache-only web search can be covered. | API on a qualifying zero-data-retention (ZDR) organization, sales-approved usage-based API pricing; BAA approval is a sales process, not a plan tier | Yes | Not verified | List | No | Yes | 2026-09-02 | Suggest a correction | |
Anthropic API Foundation model API (Claude) called directly or via other tools | Paid tier Not automatic: standard Claude Enterprise plans carry no BAA coverage until a Primary Owner turns on HIPAA readiness. Covered Models require 30-day retention and are unavailable with zero data retention enabled; some surfaces (Console, Cowork, beta features) are excluded even under an active BAA. | First-party API or Claude Enterprise, with the org's Primary Owner activating HIPAA compliance and accepting the BAA usage-based API pricing; Enterprise pricing on request | Yes | No | List | No | Not verified | 2026-09-02 | Suggest a correction | |
Azure OpenAI / AWS Bedrock / Google Vertex AI Foundation model access via a hyperscaler's own API surface, often chosen specifically for its BAA | Paid tier All three offer BAAs at enterprise tiers, but coverage varies by endpoint, feature, configuration and sub-processor chain; verify each provider's current eligible-services list before use, not just the top-level claim that the platform 'has a BAA'. | Covered under the hyperscaler's own HIPAA BAA (Microsoft Online Services DPA, AWS HIPAA BAA, Google Cloud BAA respectively); only listed eligible services/models are covered usage-based; BAA is contractual, not a separate line item | Yes | Yes | List | No | Not verified | 2026-09-02 | Suggest a correction | |
| Auth | ||||||||||
Clerk Authentication and user management, commonly paired with Next.js apps | Paid tier Clerk advertises HIPAA compliance and will sign BAAs; onboarding and migration support plus custom security questionnaires are bundled at the same tier. | HIPAA compliance available with BAA on paid plans (Enterprise-style add-on) not-verified exact figure; Clerk's public pricing page lists "HIPAA compliance available with BAA" as a paid-plan feature | Yes | Not verified | List | N/A | N/A | 2026-09-02 | Suggest a correction | |
Resend Transactional and marketing email API; used by this site's own Handover newsletter | Enterprise only Our own stack: disclose this. Resend's GDPR page states plainly that Resend is not HIPAA compliant and cannot sign a BAA; however its Enterprise Terms and Conditions allow submitting PHI under a BAA signed by both parties "if set forth in the Order Form", i.e. only by explicit enterprise negotiation, not as a standard offering. | Enterprise, on request, per an Order Form Enterprise pricing on request | Yes | Not verified | List | N/A | N/A | 2026-09-02 | Suggest a correction | |
| Repo | ||||||||||
GitHub Source control and CI; where the code (never the data) lives | No Teaching row: GitHub's own site-policy pages make no mention of HIPAA or a BAA at any tier; treat GitHub as having no BAA path. PHI must never enter the repository, in code, commit messages, issues or CI logs, regardless of plan. | not-applicable not-applicable | Yes | Not verified | List | N/A | N/A | 2026-09-02 | Suggest a correction | |
Changelog
- Lovable2026-09-02 · Row created; verified against live Terms of Service
- Bolt.new (StackBlitz)2026-09-02 · Row created; secondary-source verified, no primary BAA/HIPAA page exists to check directly
- Base44 (Wix)2026-09-02 · Row created; secondary-source verified
- Replit2026-09-02 · Row created; secondary-source verified
- v0 (Vercel)2026-09-02 · Row created; secondary-source verified
- Cursor2026-09-02 · Row created; verified against Cursor's own BAA docs page
- Claude Code2026-09-02 · Row created; verified against Anthropic's own BAA docs page
- Vercel2026-09-02 · Row created; verified against Vercel's own knowledge base and changelog
- Netlify2026-09-02 · Row created; verified against Netlify's own announcement
- Supabase2026-09-02 · Row created; price figure cross-checked across three independent sources
- Firebase / Google Cloud2026-09-02 · Row created; covered-services caveat verified against Google's own compliance page
- OpenAI API2026-09-02 · Row created; verified against OpenAI's own data-controls documentation
- Anthropic API2026-09-02 · Row created; verified against Anthropic's own BAA documentation, correcting the initial lead of a flat no
- Azure OpenAI / AWS Bedrock / Google Vertex AI2026-09-02 · Row created as a combined teaching row; per-provider eligible-services lists not individually re-verified this pass
- Clerk2026-09-02 · Row created; verified against Clerk's own pricing page; exact BAA add-on price not published, left not-verified
- Resend2026-09-02 · Row created; corrected from an initial "unverified" lead to enterprise-only after finding Resend's own contradicting GDPR FAQ vs Enterprise Terms
- GitHub2026-09-02 · Row created; verified by absence of any HIPAA/BAA mention on GitHub's own site-policy pages
Reading the table
Status is not-applicable for editors and IDEs used against synthetic data during development;
the model API a clinician's code actually calls at runtime is what governs any PHI in transit, not
the editor writing the code. not-verified means exactly that, not "probably no": every unknown
started there and only left not-verified once checked against the vendor's own terms, trust
centre, or docs page.
Prices are quoted exactly as the vendor publishes them, in the vendor's currency, never converted; a USD figure next to a EUR one is not a mistake.
The EU side: BAA is a US construct
HIPAA and its BAA requirement are American law. European clinicians are covered by GDPR instead, and GDPR does not use the term "BAA": the equivalent contract is a Data Processing Agreement under GDPR Article 28, and the questions that matter are different. The table carries five columns for this:
- GDPR Art. 28 DPA: does the vendor offer the data-processing contract GDPR requires between a controller (the clinician or their organisation) and a processor (the vendor)?
- EU data region: can you pin storage and processing to an EU region, not just accept a Standard Contractual Clauses transfer to the US?
- Subprocessor list: the published URL naming which further vendors (model providers, logging, analytics) will also see the data, because GDPR liability follows the whole chain, not just the vendor you signed with.
- AI-training default: does the vendor use submitted data to train its models by default, or is that opt-in only?
- Zero-data-retention: for model APIs specifically, can inputs and outputs be excluded from storage entirely, rather than merely deleted after a retention window?
A DPA plus an EU region gets a European clinician most of the way; a subprocessor chain that routes through a US model provider with no EU region of its own (several rows above) is the detail that undoes it, and it is exactly the detail vendor marketing pages leave out.
What is not on this table
Compliance-backend vendors (companies that sell HIPAA-compliant hosting or compliance tooling as their entire product, such as HIPAA Vault, Knack Health and VertiComply) are deliberately not rows here. This table is about the tools clinicians are already using to build; the compliance-backend category is a different, vendor-driven market this site is not trying to rank.
Corrections
Every row has a "Suggest a correction" link that opens a pre-filled email. A vendor's BAA terms change without much notice; if you hold a contract or screenshot that contradicts a row, that link is the fastest way to get it fixed. See the open data endpoint for the machine-readable version of everything above, CC BY 4.0 licensed.