Which AI builders can hold patient data?16 tools, checked against the vendors' own documents
One answer per tool, each traced to the vendor's own terms with the date we last read them. Most answers are no — and for several the terms prohibit protected health information outright.
Get your build reviewedEvery answer in one table
There is no government HIPAA certification, so “compliant” always means a signed Business Associate Agreement plus the safeguards you run yourself. This table says whether each vendor will sign one at all.
| Tool | Can it hold PHI? | In short | Checked |
|---|---|---|---|
| Is Base44 HIPAA Compliant? No BAA, Terms Bar PHI | No | No. Base44 offers no BAA, and its terms make you warrant that no protected health information reaches the platform. Wix's BAA covers Wix sites only. | — |
| Is Bolt.new HIPAA Compliant? No — Here's the Proof | No | Bolt.new publishes no BAA, and its own trust profile lists only SOC 2 Type 2, GDPR and CCPA. HIPAA appears only for self-hosted deploys. Verified Aug 2026. | — |
| Is Bubble HIPAA Compliant? No (August 2026) | RapidDev | No | No. Bubble's own docs say apps built on Bubble don't achieve HIPAA compliance, and no BAA is offered on any plan. Bubble targets HIPAA by end of 2026. | — |
| Is Claude Code HIPAA Compliant? Only With ZDR Enabled | No | Anthropic signs a BAA, but Claude Code is covered only with zero data retention on qualified accounts. Six Claude Code surfaces never can be. | — |
| Is Codex HIPAA Compliant? Local Yes on Regulated, Cloud No | No | OpenAI's BAA covers Codex Local — CLI and IDE extension — on a HIPAA-eligible ChatGPT workspace an Account Director switched on. Codex Cloud is excluded. | — |
| Is Cursor HIPAA Compliant? Yes on Enterprise, With a BAA | No | Cursor signs a HIPAA BAA on Enterprise with Privacy Mode locked org-wide. Coverage reaches only Eligible Services and Eligible Models in a gated guide. | — |
| Is Devin HIPAA Compliant? No BAA From Cognition | No | No. Cognition offers no BAA for Devin, Devin CLI or Devin Desktop. Its Acceptable Use Policy makes PHI prohibited data and the Enterprise MSA bans it. | — |
| Is Firebase HIPAA Compliant? What Google's BAA Covers | No | No Firebase-branded service is on Google Cloud's HIPAA Covered Products list. Firestore, Cloud Storage, Cloud Run functions and Identity Platform are. | — |
| Is FlutterFlow HIPAA Compliant? No — ToS Prohibit PHI | No | No. FlutterFlow's Terms state the Service is not intended for processing HIPAA-protected health data. No public BAA commitment; SOC 2 Type 1 only. | — |
| Is GitHub Copilot HIPAA Compliant? No BAA Exists | No | No. GitHub signs no BAA for Copilot on any tier, and the Data Protection Agreement its volume-licence customers agree to bars sending it PHI. | — |
| Is Hermes Agent HIPAA Compliant? Nobody to Sign With | No | Hermes Agent is self-hosted, so no vendor receives data from it — but Nous Portal, the Tool Gateway and Hermes Cloud do, and none offers a BAA. | — |
| Is Lovable HIPAA Compliant? No — Terms Ban PHI | No | No. Lovable offers no BAA and its Terms tell you not to upload PHI. The DPA repeats the ban on Business and Enterprise plans. Verified August 2026. | — |
| Is OpenClaw HIPAA Compliant? No Vendor to Sign a BAA | No | OpenClaw is MIT-licensed software you run yourself, so no entity signs a BAA. The bundled ClawRouter proxy and your model provider still see prompts. | — |
| Is Replit HIPAA Compliant? No BAA | RapidDev | No | No. Replit's Terms, Commercial Agreement and DPA never mention HIPAA or a BAA. What that means for your app, with quotes and dates. | — |
| Is Supabase HIPAA Compliant? Yes, With Conditions | No | Supabase allows PHI only with a signed BAA, the paid HIPAA add-on enabled, and a Team plan or above. Checked against Supabase's own docs, August 2026. | — |
| Is v0 HIPAA Compliant? Hosting Yes, v0 Itself No | No | Vercel signs a HIPAA BAA for hosting (at $350/month on Pro), but its API Terms prohibit PHI in v0 itself. What the primary sources say, Aug 2026. | — |
All answers
16 tools, grouped by verdict
Not for protected health information
16No BAA on any plan — in several cases the terms prohibit PHI outright.
Is Base44 HIPAA compliant? No — and the Wix BAA does not reach it
Read the full answerIs Bolt.new HIPAA compliant? No — its HIPAA mentions describe a different setup
Read the full answerIs Bubble HIPAA compliant? No — and Bubble's own docs say so
Read the full answerIs Claude Code HIPAA compliant? Only in a zero-data-retention org
Read the full answerIs Codex HIPAA compliant? Codex Local only on a Regulated or Healthcare tier
Read the full answerIs Cursor HIPAA compliant? Yes — on Enterprise, with Privacy Mode locked
Read the full answerIs Devin HIPAA compliant? No — Cognition's terms prohibit PHI outright
Read the full answerIs Firebase HIPAA compliant? Only the Google Cloud equivalents are
Read the full answerIs FlutterFlow HIPAA compliant? No — its Terms prohibit HIPAA data
Read the full answerIs GitHub Copilot HIPAA compliant? No — GitHub signs no BAA on any tier
Read the full answerIs Hermes Agent HIPAA compliant? It is self-hosted, so the question moves
Read the full answerIs Lovable HIPAA compliant? No — and the exception does not apply
Read the full answerIs OpenClaw HIPAA compliant? There is no vendor to sign a BAA with
Read the full answerIs Replit HIPAA compliant? No — and here is what the documents say
Read the full answerIs Supabase HIPAA Compliant? Yes, Under Three Conditions
Read the full answerIs v0 HIPAA Compliant? The Answer Splits in Two
Read the full answerThere is no government HIPAA certification
No authority certifies software as HIPAA-compliant. What exists is a signed Business Associate Agreement with every vendor that touches protected health information, plus the safeguards you implement and document yourself.
SOC 2 is not a substitute for a BAA
Supabase states it plainly in its own documentation: “SOC 2 does not cover, nor is it a substitute for, compliance with the Health Insurance Portability and Accountability Act (HIPAA).” The same holds for every vendor here.
This directory is technical information, not legal advice. HIPAA compliance is a property of your entire system and operating processes, never of a single tool. Vendor terms change — verify current terms with the vendor before relying on any answer here.