No. Base44 offers no Business Associate Agreement on any plan, and its Terms of Service have you warrant that no protected health information will be shared with the Platform. Its parent, Wix.com Ltd., does sign BAAs — but Wix scopes that offer to sites built on the Wix Editor or Wix Studio Editor, and names Base44 nowhere in its HIPAA documentation. Moving the patient-data layer off Base44 takes us 6–10 weeks.
| Fact | Value |
|---|---|
| Tool | Base44 |
| Verdict | No |
| Sources checked | August 2026 |
| Typical range | $13,000–$25,000 |
| Typical timeline | 6–10 weeks |
| Last updated | August 2026 |
What the agreements actually reach
"Covered" here means one thing: a published agreement under which the vendor will handle protected health information. Nothing Base44 operates is covered — we read the home, pricing, security, enterprise, Terms of Service, Privacy Policy, Data Processing Agreement and responsible-use pages, and neither "HIPAA" nor "Business Associate" appears on any of them. The two covered rows below belong to products made by the parent company, and are listed only so you can see exactly where the boundary falls.
Your PHI
Your Base44 app
Inside the agreement — PHI may live here
- Wix sites built on the Wix Editor or Wix Studio Editor, on a supported Premium or Studio plan with PHI protection activated
- Apps that Wix lists as HIPAA-compliant apps provided by Wix, installed on one of those Wix sites
Outside it — PHI here is a gap
- The Base44 Platform — the builder and its chat prompt box
- Customer Data and Input Data — anything you type or upload into the builder
- Generated Output — the code and content the model returns
- The Base44 managed backend (Mongo, US by default) and apps served by Render
- Enterprise workspace — Security Center, SSO enforcement, SCIM user provisioning, IP allowlist, audit logs, workspace API keys, training opt-out
- Superagents
- Base44 workspaces on every tier — Free, Elite and Enterprise alike
- Base44 Data Processing Agreement
- A bespoke prior written agreement under Terms of Service §4.3
| Service | Under the BAA | Condition |
|---|---|---|
| The Base44 Platform — the builder and its chat prompt box | Not covered | The Terms define "Platform" as the Company's generative AI application building platform offered under the brand name of Base44. Pasting protected health information into the prompt is therefore inside the §4.3 warranty, not outside it. |
| Customer Data and Input Data — anything you type or upload into the builder | Not covered | Both fall inside the §4.3 PHI warranty and inside the §4.2 licence that permits training on that content. |
| Generated Output — the code and content the model returns | Not covered | Named alongside Customer Data in the §4.2 licence. |
| The Base44 managed backend (Mongo, US by default) and apps served by Render | Not covered | The subprocessor directory names Mongo (US) for data storage and hosting and Render (US) for server services. No BAA exists anywhere in that chain. |
| Enterprise workspace — Security Center, SSO enforcement, SCIM user provisioning, IP allowlist, audit logs, workspace API keys, training opt-out | Not covered | These are the Enterprise controls Base44 publishes, and none of them is described as a HIPAA or PHI mode; the Enterprise page does not mention HIPAA at all. Data residency — choosing an EU, UK or US region for your app data — is a separate control rather than an Enterprise-only one: it is sold on Elite and Enterprise plans, and per the docs it reaches only apps created after April 16, 2026. It changes where records sit, not who is contractually answerable for them. |
| Superagents | Not covered | Part of the same Platform and under the same Terms. The §4.3 warranty is written against the Platform as a whole rather than against one screen of it, so what you hand a Superagent sits under the same warranty as what you type into the chat box. |
| Base44 workspaces on every tier — Free, Elite and Enterprise alike | Not covered | No plan buys a Business Associate Agreement here. We read the pricing page and the enterprise page along with the rest and found neither "HIPAA" nor "Business Associate" on either, and paying more moves the training default and the storage region rather than the contract. |
| Base44 Data Processing Agreement | Not covered | GDPR and CCPA processor terms. No HIPAA language, no BAA, no special-categories clause. |
| A bespoke prior written agreement under Terms of Service §4.3 | Unconfirmed | The Terms allow for one, and nothing published tells you whether Base44 has ever signed one, at what price, or on what tier. Unknown is the honest status: absence of an advertisement is not a refusal, and it is certainly not an offer. |
| Wix sites built on the Wix Editor or Wix Studio Editor, on a supported Premium or Studio plan with PHI protection activated | Covered | Parent company, different product. Wix ships an explicit PHI-protection toggle and an in-dashboard BAA signing flow. None of that exists in Base44, and building an app in Base44 does not put you inside this row. |
| Apps that Wix lists as HIPAA-compliant apps provided by Wix, installed on one of those Wix sites | Covered | Parent company again, and again a different product. Wix's HIPAA documentation names a set of HIPAA-compliant apps it provides for sites built on the Wix Editor or Wix Studio Editor, which is the second and last surface on the covered side of this boundary. Nothing you build in Base44 enters it, and installing one of those apps on a Wix site does nothing for a Base44 app. |
The Terms of Service we read carry the stamp "Last updated: June 22, 2026"; the Privacy Policy still reads "Last updated: September 21, 2025". The security page shows no date at all, which matters because the subprocessor directory on it is the thing most likely to change quietly. Open each page and check its own date before you rely on this table. Verified August 2026.
Wix signs BAAs. That is a true sentence about a different product
What secondary sources say
The reasoning is easy to follow and it is wrong. Wix acquired Base44 in June 2025 — Wix's own newsroom announced it — and the Base44 Terms of Service now name Wix.com Ltd. as the contracting party. Wix sells HIPAA hosting and will sign a Business Associate Agreement with eligible US healthcare customers. So a founder who searches for "Wix HIPAA" finds a real BAA, a real signing flow and a real toggle, and concludes that the app they just built in Base44 sits under it.
- The Base44 enterprise page answers the adjacent procurement question — "Is Base44 secure enough for enterprise? Yes. Base44 runs on Wix's enterprise security infrastructure. SOC 2 Type II, ISO 27001, and GDPR compliant." — which invites the inference about the parent's compliance posture while listing three frameworks that are not HIPAA.
- Base44's Responsible Use Policy gates medical use on licensure rather than on data handling, so a licensed clinician can clear that policy and still breach the separate Terms of Service PHI warranty. Two policies, two different tests.
What the vendor's own documentation says
Wix's own HIPAA article scopes the offer to a named product surface: "Wix sites built on the Wix Editor or Wix Studio Editor can be HIPAA compliant. However, you must have a supported Premium or Studio site plan to activate PHI protection." Its HIPAA hosting page opens by ruling out the default: "Wix is not HIPAA compliant by default. Certain Wix solutions can be configured to support HIPAA compliance only for eligible US healthcare providers and their business associates." Base44 is not among the named solutions. We searched Wix's HIPAA article and its HIPAA hosting page for the string "Base44" and found no occurrence on either.
How we resolve it
Ownership is not coverage. A BAA covers the services it names, and Wix names Editor and Studio sites. Base44 is a separate product with its own Terms, its own subprocessor list and its own managed backend, and those Terms contain a PHI warranty rather than a BAA. The relationship in fact runs the other way round from the assumption: Wix.com Ltd. appears on Base44's subprocessor directory as a recipient of Base44 customer data, in Israel. Data flows from Base44 to Wix; the agreement does not flow back.
Where the patient data actually goes
The chat prompt box in the builder
HighThis is the surface people forget, because it does not look like storage. What you type is Customer Data and Input Data under the Terms, and §4.2 grants Base44 and its third-party service providers an irrevocable, perpetual, sub-licensable licence over it — including to train the company's own AI models. Opting out of training is an Enterprise-only feature, so on the cheaper tiers the default is that a prompt containing a real patient description is licensed for training with no published retention window. One sentence of debugging context is enough: a patient's name, a date of birth and a description of what the screen did wrong.
How to check
Open your workspace and scroll the chat history from the first day of the build. Search it for a real surname you know is in your data, for your clinic's email domain, and for the prefix your record numbers start with. Read what comes back rather than counting the hits.
Files and screenshots dragged into the builder
HighThe normal way to teach a builder your data shape is to attach a real CSV export or paste a screenshot of a live record. That attachment is Input Data on exactly the same terms as the typed prompt, and unlike a prompt it usually carries dozens of rows rather than one.
How to check
Go back through the same chat history and open every attachment, not just the recent ones. Anything exported from a live system on the day you were setting up the schema is the likely one.
The managed backend your app writes to
HighBase44 provisions the database for you — the subprocessor directory names Mongo (US) for data storage and hosting and Render (US) for server services, and the docs state all Base44 servers are currently located in the United States. This is where the Base44 case differs from a tool where you bring your own database: because the backend is managed, you cannot point the primary app store at a database you hold an agreement for. Records written by your live app land under Base44's contracts, and there is no BAA in that chain.
How to check
Open your app's data tables in the Base44 dashboard and read actual rows, not field names. If real people are in there, the storage question is already live and is not fixed by editing a prompt.
The model providers that receive each prompt
HighThe subprocessor directory lists OpenAI (US) and Anthropic (US) for API calls to LLM. The docs page on AI service providers names Anthropic, Google and OpenAI, and pushes the question to you: "We encourage you to read and understand their policies before using Base44's Platform." Base44 makes no claim of a zero-retention arrangement with any of them. Note the inconsistency between its own two pages — Google appears as an AI provider in the docs but not in the formal subprocessor directory, where GCP is listed only for analytics.
How to check
Read the subprocessor table on base44.com/security next to the AI service providers page in the docs and compare the two lists yourself. If they still disagree when you look, that is a question for Base44 support in writing, not a detail to wave through.
LLM logging in three jurisdictions
MediumPrompt traffic is not only sent to a model, it is logged. The directory names Langfuse (DE) specifically for LLM logging, plus Datadog (US) and Logfire (UK) for general logging. LLM logging means prompt and completion content, which is the same text as the surface above, held by a fourth party in Germany. No page anywhere states how long any of it is kept — the Privacy Policy offers only that information is retained for as long as it is necessary based on the purpose it was collected for.
How to check
Read the same subprocessor table, then ask support in writing which fields Langfuse receives and how long they are retained. Keep the answer with your records — a retention period you were told in a chat window is not evidence.
The parent company as a subprocessor
MediumWix.com Ltd. (IL) appears in Base44's own subprocessor directory, for providing and improving the services. So Base44 customer data — including whatever went through the prompt box — reaches the parent in Israel, while the parent's HIPAA agreement stays scoped to Wix Editor and Studio sites.
How to check
Check the same directory for the Wix.com Ltd. entry, then check whether anyone at your company has a Wix BAA on file and assumed it applied here. That assumption is common and it is the one worth writing down and correcting.
Six checks before you talk to anyone, including us
Four of these you can answer from the Base44 dashboard in under a minute. The other two are questions for whoever holds your contracts and for the people already making decisions on them. Run them first, because the answers decide whether there is a project here at all.
01Search your Base44 chat history for a real surname, your clinic's email domain, or a real record-number prefix. Does anything come back?
02Did anyone attach a CSV, a PDF or a screenshot exported from a live system while setting up the app's data model?
03Open your app's data tables in Base44. Are there rows about real patients rather than test records?
04Is your workspace on any plan below Enterprise?
05Can someone at your company produce a prior written agreement from Base44 expressly permitting protected health information on the Platform?
06Is anyone at your company relying on a Wix BAA to cover this Base44 app?
What we do about it
Typical range
$13,000–$25,000
Typical timeline
6–10 weeks
- 01
Disclosure inventory
3–5 daysA written record of what real data reached Base44 and by which route: prompts, attachments, live app tables. Includes the dated subprocessor list showing every third party that received it, so the picture is not just Base44 but Mongo, Render, the model providers and the logging vendors.
- 02
Target architecture
1 weekA design putting the patient-data layer on infrastructure whose vendor will sign a Business Associate Agreement, with a clear line showing which parts of the product stay on Base44 and which cannot. You get the reasoning, not just the diagram, because you will have to defend it.
- 03
Data-layer migration
2–3 weeksRecords moved off the Base44 managed backend onto the covered store, application logic re-pointed and tested, with a written account of what moved, what was copied and what was deleted.
- 04
Workspace and prompt cleanup
1–2 weeksChat histories and attachments containing real data identified, exported for the record and removed where removal is possible; a written note of what could not be removed and why, including the terms that govern it. A team rule that keeps it from happening again.
- 05
Access, logging and agreements
1 weekAccess narrowed to named individuals on the new stack, audit logging switched on, and a signed agreement in hand from each vendor that will touch patient data from now on.
- 06
Handover pack
3–5 daysOne document holding the service map, the checks we ran, the dated source pages behind each decision, and an explicit list of what remains yours to do — the thing your auditor or your lawyer will ask for.
What moves the number
- How much real data reached the prompt box and how far back, since reconstructing what was disclosed takes longer than moving a database.
- How many records are in the Base44 managed backend and how tangled the schema is — the managed backend means a migration, not a connection-string change.
- Whether the app has live users, which turns a cutover into a staged migration with no downtime.
- Which parts of the product genuinely need to touch patient data, because the parts that do not can often stay where they are and stay cheap.
- How many other vendors already touch the same data — a payments provider, an email service, an AI API — since each needs its own agreement and its own review.
When not to hire us
- You have no real patient data yet. A prototype on invented records is exactly what Base44's Terms permit, and doing this work before the product shape settles usually means doing it twice.
- One prompt contained one real name and nothing else ever did. Then you need an hour, a written note of what happened and a rule for the team — not an engagement.
- All you actually need is a signed agreement with a hosting or database vendor. That is a form you request and sign yourself, and paying an agency to do it is paying for an email.
- You are shopping for a compliance certificate. There is no government HIPAA certification, so nobody can sell you one — us included.
Worth knowing either way
There is no government HIPAA certification
No authority certifies software as HIPAA-compliant. What exists is a signed Business Associate Agreement with every vendor that touches protected health information, plus the administrative, physical and technical safeguards you implement and document yourself.
SOC 2 is not a substitute for a BAA
Supabase states it plainly in its own documentation: “SOC 2 does not cover, nor is it a substitute for, compliance with the Health Insurance Portability and Accountability Act (HIPAA).” The same holds for every vendor here.
An absence of documentation is not a vendor promise
Several answers here rest on what vendor documents do not say. We name which documents we read and when. A vendor that has never published a HIPAA position may still decline to sign, and one that publishes nothing today may publish something next quarter.
The same question, for the other fifteen tools
Firebase
NoOnly the Google Cloud equivalents are covered — no Firebase-branded service is
Supabase
Yes, with conditionsBAA plus a paid HIPAA add-on, on the Team plan or above
v0 by Vercel
PartiallyVercel hosting is covered; v0 itself is contractually off-limits for PHI
Lovable
NoIts terms prohibit uploading protected health information
Bubble
NoIts own documentation says apps built on Bubble won't achieve compliance
Replit
NoIts Terms, Commercial Agreement and DPA carry no HIPAA or BAA terms
Bolt.new
NoNo BAA in the StackBlitz and Bolt documents we read; HIPAA is named only for self-hosted
FlutterFlow
NoIts terms bar processing HIPAA-protected data outright
Claude Code
Yes, with conditionsCovered only with zero data retention, on accounts Anthropic qualifies
Codex
Yes, with conditionsCodex Local on a Regulated or Healthcare tier; Codex Cloud is excluded
Cursor
Yes, with conditionsEnterprise only, with Privacy Mode locked organisation-wide
GitHub Copilot
NoNo BAA offered; the Data Protection Agreement tells customers not to send PHI
Devin
NoPHI is Prohibited Data under the acceptable-use policy
Hermes Agent
Not the right questionSelf-hosted — the agreement you need is with your model provider
OpenClaw
Not the right questionSelf-hosted — but the vendor-run router still receives prompts
Base44
NoNo BAA; its terms ask customers to keep PHI off the platform
Sources, quoted as printed
Every quotation above is reproduced below with the page it came from, and every factual claim we make about Base44 or Wix rests either on one of these entries or on a page named in them that we read and then described in our own words rather than quoting. Quotes are reproduced word for word from the source page; where we have left intervening words out, the omission is marked by an ellipsis. Where several entries of one list are cited, each is reproduced on its own line and no ordering or adjacency between them is implied. Where we searched a page for a word and found nothing, we say so in our own words rather than dressing an absence as a quotation.
The Terms of Service do not merely omit HIPAA — they have the customer warrant that protected health information will not be shared with the Platform, with one carve-out for a prior written agreement. "Platform" is defined in the same Terms as the Company's generative AI application building platform offered under the brand name of Base44, which puts the chat prompt inside the warranty.
Customer represents and warrants that ... (iii) no sensitive data that is protected under special legislation and requires unique treatment (such as protected health information or credit, debit or other payment card data) will be shared with the Platform, other than if expressly agreed by the Company in prior writing and the appropriate agreement is in place.
Base44 Terms of Service, §4.3 Responsibility for Customer DataSource dated: Last updated: June 22, 2026Checked: August 2026What you type into the builder is licensed to Base44 and to its third-party service providers on perpetual terms, including for training. This is why the prompt box is a disclosure surface rather than a scratch pad.
Customer hereby grants the Company and Third-Party Service Providers involved in the provision of the Platform or any part of it, an irrevocable, non-exclusive, worldwide, royalty-free, perpetual, fully paid, sub-licensable right and license including to access, use, modify, translate, process, copy, download, store, distribute, display, upload, reproduce, adapt, perform, improve, enhance, disclose to third parties, publish and prepare derivative works of the Customer Data and the Generated Output ... including to: ... (5) train Company software tools (e.g. artificial intelligence and machine learning models)
Base44 Terms of Service, §4.2 License to Customer DataSource dated: Last updated: June 22, 2026Checked: August 2026Opting out of model training exists, and it is gated to one tier. Below Enterprise the §4.2 licence applies by default.
Enterprise workspaces are opted out of model training by default. Your data, your apps, and your prompts stay yours.
The Enterprise tier's published control set is a security and administration package, not a HIPAA package. Nothing in it is described as a PHI mode, and the training opt-out quoted above is the only item that changes how prompt content is treated.
Security Center, IP allowlist, SSO enforcement, Automatic user provisioning (SCIM), Audit logs, and Workspace API keys
Base44 publishes three compliance frameworks and HIPAA is not among them. We searched the home, pricing, security, enterprise, Terms of Service, Privacy Policy, Data Processing Agreement and responsible-use pages for "HIPAA" and for "business associate" without regard to case, and found no occurrence on any of them. The compliance section of the security page lists exactly three entries, quoted here.
SOC 2 Type II — Independent audit of the design and operating effectiveness of our security controls. ISO 27001 — Certified information security management – the international standard. GDPR — EU data protection standards, with a Data Processing Agreement available on request.
The enterprise page answers the adjacent procurement question with three frameworks and leaves HIPAA out. This is the quotation the contradiction section above rests on.
Is Base44 secure enough for enterprise? Yes. Base44 runs on Wix's enterprise security infrastructure. SOC 2 Type II, ISO 27001, and GDPR compliant.
The subprocessor directory names where prompt content and app data actually go: a managed database, a server host, two model providers, three logging vendors and the parent company. Each entry below is a separate row of that directory.
Mongo (US) — Data storage and hosting Render (US) — Server services OpenAI (US) — API calls to LLM Anthropic (US) — API calls to LLM Wix.com Ltd. (IL) — Providing and improving the services Datadog (US) — General logging purposes Langfuse (DE) — LLM logging Logfire (UK) — General logging purposes
Base44 — Security, subprocessor directorySource dated: no date shown on the pageChecked: August 2026This docs page is where Base44 states where the servers sit, and where the regional-storage option is set out: choosing an EU, UK or US region for app data is limited to Elite and Enterprise plans and, per this page, reaches only apps created after April 16, 2026. The two sentences below are separate statements from that page, each reproduced on its own line.
All Base44 servers are currently located in the United States By default, data for all workspaces is stored in the US
Wix does sign Business Associate Agreements, and it scopes them to a named product surface that is not Base44. We searched this article for the string "Base44" and found no occurrence.
Wix sites built on the Wix Editor or Wix Studio Editor can be HIPAA compliant. However, you must have a supported Premium or Studio site plan to activate PHI protection.
Wix Help Center — Enabling HIPAA Compliance for Your Wix SiteSource dated: no date shown on the pageChecked: August 2026Wix's own HIPAA hosting page rules out the default reading and limits coverage to certain configured solutions, while describing Wix as offering a BAA to eligible US healthcare customers. We searched this page for the string "Base44" and found no occurrence.
Wix is not HIPAA compliant by default. Certain Wix solutions can be configured to support HIPAA compliance only for eligible US healthcare providers and their business associates.
The acquisition is real, which is why the inference about the parent's BAA is so easy to make.
Today Wix announced its acquisition of Base44, an AI-powered platform that enables anyone to create fully-functional, custom software solutions and applications using natural language, without the need for traditional coding.
Wix Press Room — Wix expands into vibe coding with acquisition of Base44Source dated: Jun 18, 2025Checked: August 2026Base44 passes the model-provider question back to the customer rather than claiming any retention arrangement of its own.
We encourage you to read and understand their policies before using Base44's Platform.
No page states how long prompts, generated code or app data persist. The Privacy Policy is the only document that addresses retention at all, and it sets no period.
We retain the information that we collect from you for as long as it is necessary based on the purpose it was collected for and taking into account compliance with our legal obligations
The contracting entity named in the Terms is the parent, which is worth establishing before anyone tries to negotiate under the §4.3 carve-out — the Privacy Policy and the Data Processing Agreement still name Base44, Inc.
These Terms of Service, constitute a legally binding agreement between Wix.com Ltd., which operates the Base44-branded services ("us", "our", "we", or "Company")
The Responsible Use Policy tests medical use by licensure and by compliance with applicable law, not by whether patient data is handled — which is why clearing it says nothing about the separate PHI warranty in the Terms. The two restrictions below are separate entries in that policy's list.
To provide medical advice and medical results interpretation, or promote pharmaceutical or medical products and services, without having the qualifications, licenses and permits required by applicable law In connection with any high-risk or regulated product, service or use-case, without fully complying with the applicable laws and regulations
Frequently asked questions
Wix owns Base44 and Wix signs BAAs. Why doesn't that cover us?
Because a BAA covers the services it names, and Wix names a different product. Its HIPAA article says: "Wix sites built on the Wix Editor or Wix Studio Editor can be HIPAA compliant. However, you must have a supported Premium or Studio site plan to activate PHI protection." Base44 does not appear in Wix's HIPAA documentation. Wix also ships a PHI-protection toggle and an in-dashboard BAA signing flow for those sites; Base44 ships no equivalent. And the data relationship runs the opposite way to the assumption — Wix.com Ltd. is listed on Base44's own subprocessor directory as a recipient of Base44 data.
We're on Enterprise with the training opt-out on. Is that enough?
It fixes the training default and nothing else. Base44 states that "Enterprise workspaces are opted out of model training by default", which closes one route, but the Enterprise page mentions no HIPAA and no BAA, and the published Enterprise control set — Security Center, SSO enforcement, SCIM user provisioning, IP allowlist, audit logs, workspace API keys and training opt-out — contains nothing described as a PHI mode. Data residency sits alongside them on Elite and Enterprise plans, for apps created after April 16, 2026, and it moves where records are stored without changing who is answerable for them. The Terms of Service warranty applies on Enterprise the same as on Free, and the prompt still reaches the model providers and the logging vendors listed on the security page.
The terms say PHI is barred "other than if expressly agreed by the Company in prior writing". Can we just ask?
You can ask, and you should treat it as a sales negotiation with an unknown outcome rather than a BAA you can obtain. It is unadvertised, unpriced and tied to no plan tier — nothing published tells you whether such an agreement has ever been signed. If you do pursue it, settle the counterparty first: the Terms name Wix.com Ltd. as the company, while the Privacy Policy and the Data Processing Agreement still name Base44, Inc. Until something is signed, the warranty in §4.3 is what binds you.
Base44 is SOC 2 Type II and ISO 27001 certified. Isn't that the same thing?
No. Those are audits of a security programme; a BAA is a contract in which a vendor accepts business-associate obligations for your patient data. Neither audit obliges a vendor to accept those obligations, and there is no certification that confers HIPAA compliance on a product. The tell is on Base44's own enterprise page, where the answer to "Is Base44 secure enough for enterprise?" lists SOC 2 Type II, ISO 27001 and GDPR — three frameworks, on a page built to clear procurement objections, with HIPAA left out.
We only pasted one real record into the chat to show the model the data shape. Does that matter?
It is the most common way this happens and yes, it counts. Under the Terms that content is Customer Data licensed on terms described as irrevocable and perpetual, extended to third-party service providers, and on tiers below Enterprise it sits under the training licence. The prompt also travels to the model providers on the subprocessor list and to Langfuse in Germany for LLM logging. No retention window is published anywhere. Deleting the message is the right move; knowing what was in it and when is the part you will actually be asked about.
Can we keep the Base44 front end and move only the patient data?
This is where Base44 differs from tools where you bring your own database. The backend is managed — the directory shows Mongo for storage and Render for server services — so there is no documented way to point the primary app store at a database you hold an agreement for. Base44's own positioning is that it removes the need for third-party integrations, and that is exactly what closes this door. Even if the interface stayed, the prompt box remains inside the §4.3 warranty. Our engagement therefore moves the patient-data layer onto covered infrastructure rather than trying to bolt one onto Base44.
How long does moving off take, and what does it cost?
Six to ten weeks at $13,000–$25,000 for the engagement described above. The disclosure inventory comes first and is one of the two shortest stages at three to five days, alongside the handover pack that closes the engagement; the data-layer migration off the managed backend is the longest single one. A live user base is what pushes the calendar to the upper end, because the cutover has to happen without downtime. If your app is still on invented data, none of this applies to you yet.
This page reports what Base44's and Wix's published documents said on the dates shown and is technical information rather than legal advice; HIPAA compliance is a property of your whole system and the processes around it rather than of any single tool, and vendor terms change — open the pages linked above and verify the current terms before relying on anything here.
