Skip to main content
RapidDev - Software Development Agency
Compliance

Which AI builders can hold patient data?16 tools, checked against the vendors' own documents

One answer per tool, each traced to the vendor's own terms with the date we last read them. Most answers are no — and for several the terms prohibit protected health information outright.

Get your build reviewed
16
No
4.9Clutch rating
1,000+Happy partners
20+Countries served
200+Team members

Every answer in one table

There is no government HIPAA certification, so “compliant” always means a signed Business Associate Agreement plus the safeguards you run yourself. This table says whether each vendor will sign one at all.

HIPAA and BAA status by AI development tool
ToolCan it hold PHI?In shortChecked
Is Base44 HIPAA Compliant? No BAA, Terms Bar PHINoNo. Base44 offers no BAA, and its terms make you warrant that no protected health information reaches the platform. Wix's BAA covers Wix sites only.
Is Bolt.new HIPAA Compliant? No — Here's the ProofNoBolt.new publishes no BAA, and its own trust profile lists only SOC 2 Type 2, GDPR and CCPA. HIPAA appears only for self-hosted deploys. Verified Aug 2026.
Is Bubble HIPAA Compliant? No (August 2026) | RapidDevNoNo. Bubble's own docs say apps built on Bubble don't achieve HIPAA compliance, and no BAA is offered on any plan. Bubble targets HIPAA by end of 2026.
Is Claude Code HIPAA Compliant? Only With ZDR EnabledNoAnthropic signs a BAA, but Claude Code is covered only with zero data retention on qualified accounts. Six Claude Code surfaces never can be.
Is Codex HIPAA Compliant? Local Yes on Regulated, Cloud NoNoOpenAI's BAA covers Codex Local — CLI and IDE extension — on a HIPAA-eligible ChatGPT workspace an Account Director switched on. Codex Cloud is excluded.
Is Cursor HIPAA Compliant? Yes on Enterprise, With a BAANoCursor signs a HIPAA BAA on Enterprise with Privacy Mode locked org-wide. Coverage reaches only Eligible Services and Eligible Models in a gated guide.
Is Devin HIPAA Compliant? No BAA From CognitionNoNo. Cognition offers no BAA for Devin, Devin CLI or Devin Desktop. Its Acceptable Use Policy makes PHI prohibited data and the Enterprise MSA bans it.
Is Firebase HIPAA Compliant? What Google's BAA CoversNoNo Firebase-branded service is on Google Cloud's HIPAA Covered Products list. Firestore, Cloud Storage, Cloud Run functions and Identity Platform are.
Is FlutterFlow HIPAA Compliant? No — ToS Prohibit PHINoNo. FlutterFlow's Terms state the Service is not intended for processing HIPAA-protected health data. No public BAA commitment; SOC 2 Type 1 only.
Is GitHub Copilot HIPAA Compliant? No BAA ExistsNoNo. GitHub signs no BAA for Copilot on any tier, and the Data Protection Agreement its volume-licence customers agree to bars sending it PHI.
Is Hermes Agent HIPAA Compliant? Nobody to Sign WithNoHermes Agent is self-hosted, so no vendor receives data from it — but Nous Portal, the Tool Gateway and Hermes Cloud do, and none offers a BAA.
Is Lovable HIPAA Compliant? No — Terms Ban PHINoNo. Lovable offers no BAA and its Terms tell you not to upload PHI. The DPA repeats the ban on Business and Enterprise plans. Verified August 2026.
Is OpenClaw HIPAA Compliant? No Vendor to Sign a BAANoOpenClaw is MIT-licensed software you run yourself, so no entity signs a BAA. The bundled ClawRouter proxy and your model provider still see prompts.
Is Replit HIPAA Compliant? No BAA | RapidDevNoNo. Replit's Terms, Commercial Agreement and DPA never mention HIPAA or a BAA. What that means for your app, with quotes and dates.
Is Supabase HIPAA Compliant? Yes, With ConditionsNoSupabase allows PHI only with a signed BAA, the paid HIPAA add-on enabled, and a Team plan or above. Checked against Supabase's own docs, August 2026.
Is v0 HIPAA Compliant? Hosting Yes, v0 Itself NoNoVercel signs a HIPAA BAA for hosting (at $350/month on Pro), but its API Terms prohibit PHI in v0 itself. What the primary sources say, Aug 2026.

All answers

16 tools, grouped by verdict

Not for protected health information

16

No BAA on any plan — in several cases the terms prohibit PHI outright.

NoIs Base44 HIPAA Compliant? No BAA, Terms Bar PHI

Is Base44 HIPAA compliant? No — and the Wix BAA does not reach it

Read the full answer
NoIs Bolt.new HIPAA Compliant? No — Here's the Proof

Is Bolt.new HIPAA compliant? No — its HIPAA mentions describe a different setup

Read the full answer
NoIs Bubble HIPAA Compliant? No (August 2026) | RapidDev

Is Bubble HIPAA compliant? No — and Bubble's own docs say so

Read the full answer
NoIs Claude Code HIPAA Compliant? Only With ZDR Enabled

Is Claude Code HIPAA compliant? Only in a zero-data-retention org

Read the full answer
NoIs Codex HIPAA Compliant? Local Yes on Regulated, Cloud No

Is Codex HIPAA compliant? Codex Local only on a Regulated or Healthcare tier

Read the full answer
NoIs Cursor HIPAA Compliant? Yes on Enterprise, With a BAA

Is Cursor HIPAA compliant? Yes — on Enterprise, with Privacy Mode locked

Read the full answer
NoIs Devin HIPAA Compliant? No BAA From Cognition

Is Devin HIPAA compliant? No — Cognition's terms prohibit PHI outright

Read the full answer
NoIs Firebase HIPAA Compliant? What Google's BAA Covers

Is Firebase HIPAA compliant? Only the Google Cloud equivalents are

Read the full answer
NoIs FlutterFlow HIPAA Compliant? No — ToS Prohibit PHI

Is FlutterFlow HIPAA compliant? No — its Terms prohibit HIPAA data

Read the full answer
NoIs GitHub Copilot HIPAA Compliant? No BAA Exists

Is GitHub Copilot HIPAA compliant? No — GitHub signs no BAA on any tier

Read the full answer
NoIs Hermes Agent HIPAA Compliant? Nobody to Sign With

Is Hermes Agent HIPAA compliant? It is self-hosted, so the question moves

Read the full answer
NoIs Lovable HIPAA Compliant? No — Terms Ban PHI

Is Lovable HIPAA compliant? No — and the exception does not apply

Read the full answer
NoIs OpenClaw HIPAA Compliant? No Vendor to Sign a BAA

Is OpenClaw HIPAA compliant? There is no vendor to sign a BAA with

Read the full answer
NoIs Replit HIPAA Compliant? No BAA | RapidDev

Is Replit HIPAA compliant? No — and here is what the documents say

Read the full answer
NoIs Supabase HIPAA Compliant? Yes, With Conditions

Is Supabase HIPAA Compliant? Yes, Under Three Conditions

Read the full answer
NoIs v0 HIPAA Compliant? Hosting Yes, v0 Itself No

Is v0 HIPAA Compliant? The Answer Splits in Two

Read the full answer

There is no government HIPAA certification

No authority certifies software as HIPAA-compliant. What exists is a signed Business Associate Agreement with every vendor that touches protected health information, plus the safeguards you implement and document yourself.

SOC 2 is not a substitute for a BAA

Supabase states it plainly in its own documentation: “SOC 2 does not cover, nor is it a substitute for, compliance with the Health Insurance Portability and Accountability Act (HIPAA).” The same holds for every vendor here.

This directory is technical information, not legal advice. HIPAA compliance is a property of your entire system and operating processes, never of a single tool. Vendor terms change — verify current terms with the vendor before relying on any answer here.

We put the rapid in RapidDev

Need a dedicated strategic tech and growth partner? Discover what RapidDev can do for your business! Book a call with our team to schedule a free, no-obligation consultation. We'll discuss your project and provide a custom quote at no cost.