GuidesThe honest fact table nobody selling something wrote

Which platforms sign a BAA? The clinician's vibe-coding stack

Every ranking page for "does X sign a BAA" is vendor content, written by a company selling the compliance layer it is describing. This table is not that. It is dated, sourced against each vendor's own terms or trust page, and it will be wrong the day a vendor changes its policy, which is exactly why every row below carries a verified_on date and a watcher that checks for drift.

A Business Associate Agreement (BAA) is the specific US legal instrument HIPAA requires before Protected Health Information (PHI) can touch a vendor. No BAA means no PHI on that vendor, on any plan, at any price, no matter how good its general security posture is. "No BAA" is not a verdict on a tool's quality; Cursor and Replit are both fine editors. It is a verdict on one narrow question: can real patient data touch this thing.

17 platforms checked against their own terms, trust centre or docs page. Newest row verified 2026-09-02.
PlatformBAAMin tier / priceEU DPAEU regionSubprocessorsAI trainingZero retentionVerifiedSourcesCorrection
AI app builders
Lovable
AI app builder; generates full-stack apps on a Supabase backend
No

Terms (checked 2026-09-02) prohibit uploading PHI unless your plan or a separate written agreement expressly permits it; no public BAA or HIPAA plan. Backend is Supabase (see that row); AI Gateway sends prompts and data to third-party model providers.

not-applicable
not-applicable
Not verifiedNot verifiedListNot verifiedN/A2026-09-02Suggest a correction
Bolt.new (StackBlitz)
AI app builder; generates and runs full-stack apps in-browser
No

No BAA offered on any plan; privacy wording is GDPR/CCPA-style and does not name HIPAA anywhere in Terms of Service, Privacy Policy, Enterprise or Pricing pages.

not-applicable
not-applicable
Not verifiedNot verifiedListNot verifiedN/A2026-09-02Suggest a correction
Base44 (Wix)
AI app builder, acquired by Wix; generates full-stack apps
No

No BAA offered, including on Enterprise; standard Terms of Service restrict PHI from entering the platform without a separately negotiated written agreement. Subprocessors include Wix (Israel), Langfuse (Germany), Logfire (UK).

not-applicable
not-applicable
Not verifiedNot verifiedListNot verifiedN/A2026-09-02Suggest a correction
Replit
AI app builder and cloud IDE; generates and hosts full-stack apps
No

No BAA on any plan; Replit's own documentation states standard hosting is not HIPAA compliant.

not-applicable
not-applicable
Not verifiedNot verifiedListNot verifiedN/A2026-09-02Suggest a correction
v0 (Vercel)
Generative UI tool; scaffolds React/Next.js components and pages from prompts
No

No BAA for v0 itself; Vercel support has confirmed v0 falls outside the scope of Vercel's HIPAA BAA even where the hosting platform is covered. See the Vercel (hosting) row for the deployed app, which is a separate question from the generator.

not-applicable
not-applicable
Not verifiedNot verifiedListNot verifiedN/A2026-09-02Suggest a correction
Editors & coding agents
Cursor
AI code editor; used against synthetic data during development, not in production
Not applicable

As an editor used on synthetic data during development, no BAA applies to the editor itself. Cursor does offer a BAA on its Enterprise plan (Privacy Mode required, org-wide, limited to a defined list of Eligible Services and Eligible Models) if PHI is ever routed through it; the model API a clinician actually calls governs any PHI in transit.

not-applicable
not-applicable
Not verifiedNot verifiedListNot verifiedNot verified2026-09-02Suggest a correction
Claude Code
AI coding agent (terminal/editor); used against synthetic data during development
Not applicable

As an editor used on synthetic data, no BAA applies to Claude Code itself. Anthropic's BAA only covers Claude Code when zero data retention (ZDR) is enabled on a qualified HIPAA-ready Enterprise account; the model API a clinician actually calls governs any PHI sent to the model (see Anthropic API row).

not-applicable
not-applicable
Not verifiedNoListNoNot verified2026-09-02Suggest a correction
Hosting
Vercel
Deployment platform for Next.js and other frontends; default host for v0/AI-generated apps
Paid tier

Vercel signs a BAA with Enterprise customers on request; Pro customers get a click-through BAA with no Enterprise contract required (per Vercel's 2026 changelog announcement).

Pro (click-through BAA) or Enterprise (negotiated BAA)
Pro plan from USD 20/month per member; Enterprise pricing on request
YesYesListN/AN/A2026-09-02Suggest a correction
Netlify
Deployment platform for static/JAMstack frontends
Enterprise only

Netlify launched a HIPAA-compliant service offering for enterprise customers handling PHI (announced 2024, still current); a BAA is executed as part of that offering.

Enterprise
Enterprise pricing on request
YesNot verifiedListN/AN/A2026-09-02Suggest a correction
Database & backend
Supabase
Postgres, auth and storage; the default backend behind Lovable and v0
Paid tier

Self-hosting is outside the BAA. Free and Pro plans do not support HIPAA at any price; the add-on requires Team or Enterprise.

Team plan plus HIPAA add-on
USD 599/month (Team) plus a USD 350/month HIPAA add-on
YesYesListN/AN/A2026-09-02Suggest a correction
Firebase / Google Cloud
Backend-as-a-service (Firestore, Auth, Functions) built on Google Cloud
Paid tier

Google Cloud's HIPAA BAA covers Cloud Firestore and Cloud Functions; Firebase Analytics, Crashlytics, Cloud Messaging and Remote Config generally fall outside HIPAA-eligible services. Verify the current covered-services list before relying on any Firebase feature.

Google Cloud BAA (Enterprise agreement); only specific Firebase services are covered
not-applicable; part of a negotiated Google Cloud agreement
YesYesListN/AN/A2026-09-02Suggest a correction
Model APIs
OpenAI API
Foundation model API called directly or via other tools for text/vision generation
Paid tier

BAA available for the API on eligible endpoints configured for zero data retention; ChatGPT consumer plans (Free/Plus) are not covered. Web Search with live internet access is explicitly not HIPAA-eligible even under ZDR; offline/cache-only web search can be covered.

API on a qualifying zero-data-retention (ZDR) organization, sales-approved
usage-based API pricing; BAA approval is a sales process, not a plan tier
YesNot verifiedListNoYes2026-09-02Suggest a correction
Anthropic API
Foundation model API (Claude) called directly or via other tools
Paid tier

Not automatic: standard Claude Enterprise plans carry no BAA coverage until a Primary Owner turns on HIPAA readiness. Covered Models require 30-day retention and are unavailable with zero data retention enabled; some surfaces (Console, Cowork, beta features) are excluded even under an active BAA.

First-party API or Claude Enterprise, with the org's Primary Owner activating HIPAA compliance and accepting the BAA
usage-based API pricing; Enterprise pricing on request
YesNoListNoNot verified2026-09-02Suggest a correction
Azure OpenAI / AWS Bedrock / Google Vertex AI
Foundation model access via a hyperscaler's own API surface, often chosen specifically for its BAA
Paid tier

All three offer BAAs at enterprise tiers, but coverage varies by endpoint, feature, configuration and sub-processor chain; verify each provider's current eligible-services list before use, not just the top-level claim that the platform 'has a BAA'.

Covered under the hyperscaler's own HIPAA BAA (Microsoft Online Services DPA, AWS HIPAA BAA, Google Cloud BAA respectively); only listed eligible services/models are covered
usage-based; BAA is contractual, not a separate line item
YesYesListNoNot verified2026-09-02Suggest a correction
Auth
Clerk
Authentication and user management, commonly paired with Next.js apps
Paid tier

Clerk advertises HIPAA compliance and will sign BAAs; onboarding and migration support plus custom security questionnaires are bundled at the same tier.

HIPAA compliance available with BAA on paid plans (Enterprise-style add-on)
not-verified exact figure; Clerk's public pricing page lists "HIPAA compliance available with BAA" as a paid-plan feature
YesNot verifiedListN/AN/A2026-09-02Suggest a correction
Email
Resend
Transactional and marketing email API; used by this site's own Handover newsletter
Enterprise only

Our own stack: disclose this. Resend's GDPR page states plainly that Resend is not HIPAA compliant and cannot sign a BAA; however its Enterprise Terms and Conditions allow submitting PHI under a BAA signed by both parties "if set forth in the Order Form", i.e. only by explicit enterprise negotiation, not as a standard offering.

Enterprise, on request, per an Order Form
Enterprise pricing on request
YesNot verifiedListN/AN/A2026-09-02Suggest a correction
Repo
GitHub
Source control and CI; where the code (never the data) lives
No

Teaching row: GitHub's own site-policy pages make no mention of HIPAA or a BAA at any tier; treat GitHub as having no BAA path. PHI must never enter the repository, in code, commit messages, issues or CI logs, regardless of plan.

not-applicable
not-applicable
YesNot verifiedListN/AN/A2026-09-02Suggest a correction

Changelog

  • Lovable2026-09-02 · Row created; verified against live Terms of Service
  • Bolt.new (StackBlitz)2026-09-02 · Row created; secondary-source verified, no primary BAA/HIPAA page exists to check directly
  • Base44 (Wix)2026-09-02 · Row created; secondary-source verified
  • Replit2026-09-02 · Row created; secondary-source verified
  • v0 (Vercel)2026-09-02 · Row created; secondary-source verified
  • Cursor2026-09-02 · Row created; verified against Cursor's own BAA docs page
  • Claude Code2026-09-02 · Row created; verified against Anthropic's own BAA docs page
  • Vercel2026-09-02 · Row created; verified against Vercel's own knowledge base and changelog
  • Netlify2026-09-02 · Row created; verified against Netlify's own announcement
  • Supabase2026-09-02 · Row created; price figure cross-checked across three independent sources
  • Firebase / Google Cloud2026-09-02 · Row created; covered-services caveat verified against Google's own compliance page
  • OpenAI API2026-09-02 · Row created; verified against OpenAI's own data-controls documentation
  • Anthropic API2026-09-02 · Row created; verified against Anthropic's own BAA documentation, correcting the initial lead of a flat no
  • Azure OpenAI / AWS Bedrock / Google Vertex AI2026-09-02 · Row created as a combined teaching row; per-provider eligible-services lists not individually re-verified this pass
  • Clerk2026-09-02 · Row created; verified against Clerk's own pricing page; exact BAA add-on price not published, left not-verified
  • Resend2026-09-02 · Row created; corrected from an initial "unverified" lead to enterprise-only after finding Resend's own contradicting GDPR FAQ vs Enterprise Terms
  • GitHub2026-09-02 · Row created; verified by absence of any HIPAA/BAA mention on GitHub's own site-policy pages

Reading the table

Status is not-applicable for editors and IDEs used against synthetic data during development; the model API a clinician's code actually calls at runtime is what governs any PHI in transit, not the editor writing the code. not-verified means exactly that, not "probably no": every unknown started there and only left not-verified once checked against the vendor's own terms, trust centre, or docs page.

Prices are quoted exactly as the vendor publishes them, in the vendor's currency, never converted; a USD figure next to a EUR one is not a mistake.

The EU side: BAA is a US construct

HIPAA and its BAA requirement are American law. European clinicians are covered by GDPR instead, and GDPR does not use the term "BAA": the equivalent contract is a Data Processing Agreement under GDPR Article 28, and the questions that matter are different. The table carries five columns for this:

  • GDPR Art. 28 DPA: does the vendor offer the data-processing contract GDPR requires between a controller (the clinician or their organisation) and a processor (the vendor)?
  • EU data region: can you pin storage and processing to an EU region, not just accept a Standard Contractual Clauses transfer to the US?
  • Subprocessor list: the published URL naming which further vendors (model providers, logging, analytics) will also see the data, because GDPR liability follows the whole chain, not just the vendor you signed with.
  • AI-training default: does the vendor use submitted data to train its models by default, or is that opt-in only?
  • Zero-data-retention: for model APIs specifically, can inputs and outputs be excluded from storage entirely, rather than merely deleted after a retention window?

A DPA plus an EU region gets a European clinician most of the way; a subprocessor chain that routes through a US model provider with no EU region of its own (several rows above) is the detail that undoes it, and it is exactly the detail vendor marketing pages leave out.

What is not on this table

Compliance-backend vendors (companies that sell HIPAA-compliant hosting or compliance tooling as their entire product, such as HIPAA Vault, Knack Health and VertiComply) are deliberately not rows here. This table is about the tools clinicians are already using to build; the compliance-backend category is a different, vendor-driven market this site is not trying to rank.

Corrections

Every row has a "Suggest a correction" link that opens a pre-filled email. A vendor's BAA terms change without much notice; if you hold a contract or screenshot that contradicts a row, that link is the fastest way to get it fixed. See the open data endpoint for the machine-readable version of everything above, CC BY 4.0 licensed.

The Handover

One email a week. Five minutes.

What happened at the crossroads of medicine, code and regulation, every Friday. No vendor marketing, no filler; the archive lives here.