Skip to main content
RapidDev - Software Development Agency
Base44

Is Base44 HIPAA compliant? No — and the Wix BAA does not reach it

The verdictVerified August 2026
No — no BAA offered, and its terms bar PHI

No. Base44 does not offer a Business Associate Agreement on any plan, and its Terms of Service go further than silence: the customer warrants that no sensitive data protected under special legislation — protected health information is one of the two named examples — will be shared with the Platform, unless the Company has expressly agreed otherwise in prior writing. "Platform" is defined in those Terms as the Base44-branded generative AI application building platform, which means the chat prompt box is inside the warranty, not just the database. Base44's parent Wix.com Ltd. does sign BAAs, but Wix scopes them to sites built on the Wix Editor or Wix Studio Editor on a supported Premium or Studio plan, and Base44 is named nowhere in Wix's HIPAA documentation.

What would change this

Base44 publishing a Business Associate Agreement and naming the surfaces it covers — or Wix adding Base44 to the list of solutions its HIPAA documentation covers. The only door in the current text is the Terms of Service carve-out for a prior written agreement with the Company: it is unadvertised, unpriced and attached to no plan tier, so treat it as a sales conversation rather than an available BAA. If you have one of those conversations, establish which entity would sign first — the Terms name Wix.com Ltd. while the Privacy Policy and the Data Processing Agreement still name Base44, Inc.

Base44 Terms of Service, §4.3 Responsibility for Customer Data

No. Base44 offers no Business Associate Agreement on any plan, and its Terms of Service have you warrant that no protected health information will be shared with the Platform. Its parent, Wix.com Ltd., does sign BAAs — but Wix scopes that offer to sites built on the Wix Editor or Wix Studio Editor, and names Base44 nowhere in its HIPAA documentation. Moving the patient-data layer off Base44 takes us 6–10 weeks.

Book a free consultation
4.9Clutch rating
1,000+Happy partners
20+Countries served
200+Team members
Base44NoSources checked August 2026August 2026RapidDev Engineering Team
TL;DR

No. Base44 offers no Business Associate Agreement on any plan, and its Terms of Service have you warrant that no protected health information will be shared with the Platform. Its parent, Wix.com Ltd., does sign BAAs — but Wix scopes that offer to sites built on the Wix Editor or Wix Studio Editor, and names Base44 nowhere in its HIPAA documentation. Moving the patient-data layer off Base44 takes us 6–10 weeks.

Quick facts about this guide
FactValue
ToolBase44
VerdictNo
Sources checkedAugust 2026
Typical range$13,000–$25,000
Typical timeline6–10 weeks
Last updatedAugust 2026

What the agreements actually reach

"Covered" here means one thing: a published agreement under which the vendor will handle protected health information. Nothing Base44 operates is covered — we read the home, pricing, security, enterprise, Terms of Service, Privacy Policy, Data Processing Agreement and responsible-use pages, and neither "HIPAA" nor "Business Associate" appears on any of them. The two covered rows below belong to products made by the parent company, and are listed only so you can see exactly where the boundary falls.

2of 11 services covered by the BAA

Your PHI

Your Base44 app

Inside the agreement — PHI may live here

  • Wix sites built on the Wix Editor or Wix Studio Editor, on a supported Premium or Studio plan with PHI protection activated
  • Apps that Wix lists as HIPAA-compliant apps provided by Wix, installed on one of those Wix sites

Outside it — PHI here is a gap

  • The Base44 Platform — the builder and its chat prompt box
  • Customer Data and Input Data — anything you type or upload into the builder
  • Generated Output — the code and content the model returns
  • The Base44 managed backend (Mongo, US by default) and apps served by Render
  • Enterprise workspace — Security Center, SSO enforcement, SCIM user provisioning, IP allowlist, audit logs, workspace API keys, training opt-out
  • Superagents
  • Base44 workspaces on every tier — Free, Elite and Enterprise alike
  • Base44 Data Processing Agreement
  • A bespoke prior written agreement under Terms of Service §4.3
What the agreements actually reach
ServiceUnder the BAACondition
The Base44 Platform — the builder and its chat prompt boxNot coveredThe Terms define "Platform" as the Company's generative AI application building platform offered under the brand name of Base44. Pasting protected health information into the prompt is therefore inside the §4.3 warranty, not outside it.
Customer Data and Input Data — anything you type or upload into the builderNot coveredBoth fall inside the §4.3 PHI warranty and inside the §4.2 licence that permits training on that content.
Generated Output — the code and content the model returnsNot coveredNamed alongside Customer Data in the §4.2 licence.
The Base44 managed backend (Mongo, US by default) and apps served by RenderNot coveredThe subprocessor directory names Mongo (US) for data storage and hosting and Render (US) for server services. No BAA exists anywhere in that chain.
Enterprise workspace — Security Center, SSO enforcement, SCIM user provisioning, IP allowlist, audit logs, workspace API keys, training opt-outNot coveredThese are the Enterprise controls Base44 publishes, and none of them is described as a HIPAA or PHI mode; the Enterprise page does not mention HIPAA at all. Data residency — choosing an EU, UK or US region for your app data — is a separate control rather than an Enterprise-only one: it is sold on Elite and Enterprise plans, and per the docs it reaches only apps created after April 16, 2026. It changes where records sit, not who is contractually answerable for them.
SuperagentsNot coveredPart of the same Platform and under the same Terms. The §4.3 warranty is written against the Platform as a whole rather than against one screen of it, so what you hand a Superagent sits under the same warranty as what you type into the chat box.
Base44 workspaces on every tier — Free, Elite and Enterprise alikeNot coveredNo plan buys a Business Associate Agreement here. We read the pricing page and the enterprise page along with the rest and found neither "HIPAA" nor "Business Associate" on either, and paying more moves the training default and the storage region rather than the contract.
Base44 Data Processing AgreementNot coveredGDPR and CCPA processor terms. No HIPAA language, no BAA, no special-categories clause.
A bespoke prior written agreement under Terms of Service §4.3UnconfirmedThe Terms allow for one, and nothing published tells you whether Base44 has ever signed one, at what price, or on what tier. Unknown is the honest status: absence of an advertisement is not a refusal, and it is certainly not an offer.
Wix sites built on the Wix Editor or Wix Studio Editor, on a supported Premium or Studio plan with PHI protection activatedCoveredParent company, different product. Wix ships an explicit PHI-protection toggle and an in-dashboard BAA signing flow. None of that exists in Base44, and building an app in Base44 does not put you inside this row.
Apps that Wix lists as HIPAA-compliant apps provided by Wix, installed on one of those Wix sitesCoveredParent company again, and again a different product. Wix's HIPAA documentation names a set of HIPAA-compliant apps it provides for sites built on the Wix Editor or Wix Studio Editor, which is the second and last surface on the covered side of this boundary. Nothing you build in Base44 enters it, and installing one of those apps on a Wix site does nothing for a Base44 app.

The Terms of Service we read carry the stamp "Last updated: June 22, 2026"; the Privacy Policy still reads "Last updated: September 21, 2025". The security page shows no date at all, which matters because the subprocessor directory on it is the thing most likely to change quietly. Open each page and check its own date before you rely on this table. Verified August 2026.

Wix signs BAAs. That is a true sentence about a different product

What secondary sources say

The reasoning is easy to follow and it is wrong. Wix acquired Base44 in June 2025 — Wix's own newsroom announced it — and the Base44 Terms of Service now name Wix.com Ltd. as the contracting party. Wix sells HIPAA hosting and will sign a Business Associate Agreement with eligible US healthcare customers. So a founder who searches for "Wix HIPAA" finds a real BAA, a real signing flow and a real toggle, and concludes that the app they just built in Base44 sits under it.

  • The Base44 enterprise page answers the adjacent procurement question — "Is Base44 secure enough for enterprise? Yes. Base44 runs on Wix's enterprise security infrastructure. SOC 2 Type II, ISO 27001, and GDPR compliant." — which invites the inference about the parent's compliance posture while listing three frameworks that are not HIPAA.
  • Base44's Responsible Use Policy gates medical use on licensure rather than on data handling, so a licensed clinician can clear that policy and still breach the separate Terms of Service PHI warranty. Two policies, two different tests.

What the vendor's own documentation says

Wix's own HIPAA article scopes the offer to a named product surface: "Wix sites built on the Wix Editor or Wix Studio Editor can be HIPAA compliant. However, you must have a supported Premium or Studio site plan to activate PHI protection." Its HIPAA hosting page opens by ruling out the default: "Wix is not HIPAA compliant by default. Certain Wix solutions can be configured to support HIPAA compliance only for eligible US healthcare providers and their business associates." Base44 is not among the named solutions. We searched Wix's HIPAA article and its HIPAA hosting page for the string "Base44" and found no occurrence on either.

How we resolve it

Ownership is not coverage. A BAA covers the services it names, and Wix names Editor and Studio sites. Base44 is a separate product with its own Terms, its own subprocessor list and its own managed backend, and those Terms contain a PHI warranty rather than a BAA. The relationship in fact runs the other way round from the assumption: Wix.com Ltd. appears on Base44's subprocessor directory as a recipient of Base44 customer data, in Israel. Data flows from Base44 to Wix; the agreement does not flow back.

Where the patient data actually goes

The chat prompt box in the builder

High

This is the surface people forget, because it does not look like storage. What you type is Customer Data and Input Data under the Terms, and §4.2 grants Base44 and its third-party service providers an irrevocable, perpetual, sub-licensable licence over it — including to train the company's own AI models. Opting out of training is an Enterprise-only feature, so on the cheaper tiers the default is that a prompt containing a real patient description is licensed for training with no published retention window. One sentence of debugging context is enough: a patient's name, a date of birth and a description of what the screen did wrong.

How to check

Open your workspace and scroll the chat history from the first day of the build. Search it for a real surname you know is in your data, for your clinic's email domain, and for the prefix your record numbers start with. Read what comes back rather than counting the hits.

Files and screenshots dragged into the builder

High

The normal way to teach a builder your data shape is to attach a real CSV export or paste a screenshot of a live record. That attachment is Input Data on exactly the same terms as the typed prompt, and unlike a prompt it usually carries dozens of rows rather than one.

How to check

Go back through the same chat history and open every attachment, not just the recent ones. Anything exported from a live system on the day you were setting up the schema is the likely one.

The managed backend your app writes to

High

Base44 provisions the database for you — the subprocessor directory names Mongo (US) for data storage and hosting and Render (US) for server services, and the docs state all Base44 servers are currently located in the United States. This is where the Base44 case differs from a tool where you bring your own database: because the backend is managed, you cannot point the primary app store at a database you hold an agreement for. Records written by your live app land under Base44's contracts, and there is no BAA in that chain.

How to check

Open your app's data tables in the Base44 dashboard and read actual rows, not field names. If real people are in there, the storage question is already live and is not fixed by editing a prompt.

The model providers that receive each prompt

High

The subprocessor directory lists OpenAI (US) and Anthropic (US) for API calls to LLM. The docs page on AI service providers names Anthropic, Google and OpenAI, and pushes the question to you: "We encourage you to read and understand their policies before using Base44's Platform." Base44 makes no claim of a zero-retention arrangement with any of them. Note the inconsistency between its own two pages — Google appears as an AI provider in the docs but not in the formal subprocessor directory, where GCP is listed only for analytics.

How to check

Read the subprocessor table on base44.com/security next to the AI service providers page in the docs and compare the two lists yourself. If they still disagree when you look, that is a question for Base44 support in writing, not a detail to wave through.

LLM logging in three jurisdictions

Medium

Prompt traffic is not only sent to a model, it is logged. The directory names Langfuse (DE) specifically for LLM logging, plus Datadog (US) and Logfire (UK) for general logging. LLM logging means prompt and completion content, which is the same text as the surface above, held by a fourth party in Germany. No page anywhere states how long any of it is kept — the Privacy Policy offers only that information is retained for as long as it is necessary based on the purpose it was collected for.

How to check

Read the same subprocessor table, then ask support in writing which fields Langfuse receives and how long they are retained. Keep the answer with your records — a retention period you were told in a chat window is not evidence.

The parent company as a subprocessor

Medium

Wix.com Ltd. (IL) appears in Base44's own subprocessor directory, for providing and improving the services. So Base44 customer data — including whatever went through the prompt box — reaches the parent in Israel, while the parent's HIPAA agreement stays scoped to Wix Editor and Studio sites.

How to check

Check the same directory for the Wix.com Ltd. entry, then check whether anyone at your company has a Wix BAA on file and assumed it applied here. That assumption is common and it is the one worth writing down and correcting.

Six checks before you talk to anyone, including us

Four of these you can answer from the Base44 dashboard in under a minute. The other two are questions for whoever holds your contracts and for the people already making decisions on them. Run them first, because the answers decide whether there is a project here at all.

  1. 01Search your Base44 chat history for a real surname, your clinic's email domain, or a real record-number prefix. Does anything come back?

  2. 02Did anyone attach a CSV, a PDF or a screenshot exported from a live system while setting up the app's data model?

  3. 03Open your app's data tables in Base44. Are there rows about real patients rather than test records?

  4. 04Is your workspace on any plan below Enterprise?

  5. 05Can someone at your company produce a prior written agreement from Base44 expressly permitting protected health information on the Platform?

  6. 06Is anyone at your company relying on a Wix BAA to cover this Base44 app?

What we do about it

Typical range

$13,000–$25,000

Typical timeline

6–10 weeks

  1. 01

    Disclosure inventory

    3–5 days

    A written record of what real data reached Base44 and by which route: prompts, attachments, live app tables. Includes the dated subprocessor list showing every third party that received it, so the picture is not just Base44 but Mongo, Render, the model providers and the logging vendors.

  2. 02

    Target architecture

    1 week

    A design putting the patient-data layer on infrastructure whose vendor will sign a Business Associate Agreement, with a clear line showing which parts of the product stay on Base44 and which cannot. You get the reasoning, not just the diagram, because you will have to defend it.

  3. 03

    Data-layer migration

    2–3 weeks

    Records moved off the Base44 managed backend onto the covered store, application logic re-pointed and tested, with a written account of what moved, what was copied and what was deleted.

  4. 04

    Workspace and prompt cleanup

    1–2 weeks

    Chat histories and attachments containing real data identified, exported for the record and removed where removal is possible; a written note of what could not be removed and why, including the terms that govern it. A team rule that keeps it from happening again.

  5. 05

    Access, logging and agreements

    1 week

    Access narrowed to named individuals on the new stack, audit logging switched on, and a signed agreement in hand from each vendor that will touch patient data from now on.

  6. 06

    Handover pack

    3–5 days

    One document holding the service map, the checks we ran, the dated source pages behind each decision, and an explicit list of what remains yours to do — the thing your auditor or your lawyer will ask for.

What moves the number

  • How much real data reached the prompt box and how far back, since reconstructing what was disclosed takes longer than moving a database.
  • How many records are in the Base44 managed backend and how tangled the schema is — the managed backend means a migration, not a connection-string change.
  • Whether the app has live users, which turns a cutover into a staged migration with no downtime.
  • Which parts of the product genuinely need to touch patient data, because the parts that do not can often stay where they are and stay cheap.
  • How many other vendors already touch the same data — a payments provider, an email service, an AI API — since each needs its own agreement and its own review.

When not to hire us

  • You have no real patient data yet. A prototype on invented records is exactly what Base44's Terms permit, and doing this work before the product shape settles usually means doing it twice.
  • One prompt contained one real name and nothing else ever did. Then you need an hour, a written note of what happened and a rule for the team — not an engagement.
  • All you actually need is a signed agreement with a hosting or database vendor. That is a form you request and sign yourself, and paying an agency to do it is paying for an email.
  • You are shopping for a compliance certificate. There is no government HIPAA certification, so nobody can sell you one — us included.
Our free Supabase guides — the covered-backend route, including row-level security setup

Worth knowing either way

There is no government HIPAA certification

No authority certifies software as HIPAA-compliant. What exists is a signed Business Associate Agreement with every vendor that touches protected health information, plus the administrative, physical and technical safeguards you implement and document yourself.

SOC 2 is not a substitute for a BAA

Supabase states it plainly in its own documentation: “SOC 2 does not cover, nor is it a substitute for, compliance with the Health Insurance Portability and Accountability Act (HIPAA).” The same holds for every vendor here.

An absence of documentation is not a vendor promise

Several answers here rest on what vendor documents do not say. We name which documents we read and when. A vendor that has never published a HIPAA position may still decline to sign, and one that publishes nothing today may publish something next quarter.

The same question, for the other fifteen tools

Sources, quoted as printed

Every quotation above is reproduced below with the page it came from, and every factual claim we make about Base44 or Wix rests either on one of these entries or on a page named in them that we read and then described in our own words rather than quoting. Quotes are reproduced word for word from the source page; where we have left intervening words out, the omission is marked by an ellipsis. Where several entries of one list are cited, each is reproduced on its own line and no ordering or adjacency between them is implied. Where we searched a page for a word and found nothing, we say so in our own words rather than dressing an absence as a quotation.

  1. The Terms of Service do not merely omit HIPAA — they have the customer warrant that protected health information will not be shared with the Platform, with one carve-out for a prior written agreement. "Platform" is defined in the same Terms as the Company's generative AI application building platform offered under the brand name of Base44, which puts the chat prompt inside the warranty.

    Customer represents and warrants that ... (iii) no sensitive data that is protected under special legislation and requires unique treatment (such as protected health information or credit, debit or other payment card data) will be shared with the Platform, other than if expressly agreed by the Company in prior writing and the appropriate agreement is in place.

    Base44 Terms of Service, §4.3 Responsibility for Customer DataSource dated: Last updated: June 22, 2026Checked: August 2026
  2. What you type into the builder is licensed to Base44 and to its third-party service providers on perpetual terms, including for training. This is why the prompt box is a disclosure surface rather than a scratch pad.

    Customer hereby grants the Company and Third-Party Service Providers involved in the provision of the Platform or any part of it, an irrevocable, non-exclusive, worldwide, royalty-free, perpetual, fully paid, sub-licensable right and license including to access, use, modify, translate, process, copy, download, store, distribute, display, upload, reproduce, adapt, perform, improve, enhance, disclose to third parties, publish and prepare derivative works of the Customer Data and the Generated Output ... including to: ... (5) train Company software tools (e.g. artificial intelligence and machine learning models)

    Base44 Terms of Service, §4.2 License to Customer DataSource dated: Last updated: June 22, 2026Checked: August 2026
  3. Opting out of model training exists, and it is gated to one tier. Below Enterprise the §4.2 licence applies by default.

    Enterprise workspaces are opted out of model training by default. Your data, your apps, and your prompts stay yours.

    Base44 — EnterpriseSource dated: no date shown on the pageChecked: August 2026
  4. The Enterprise tier's published control set is a security and administration package, not a HIPAA package. Nothing in it is described as a PHI mode, and the training opt-out quoted above is the only item that changes how prompt content is treated.

    Security Center, IP allowlist, SSO enforcement, Automatic user provisioning (SCIM), Audit logs, and Workspace API keys

    Base44 docs — Security overviewSource dated: no date shown on the pageChecked: August 2026
  5. Base44 publishes three compliance frameworks and HIPAA is not among them. We searched the home, pricing, security, enterprise, Terms of Service, Privacy Policy, Data Processing Agreement and responsible-use pages for "HIPAA" and for "business associate" without regard to case, and found no occurrence on any of them. The compliance section of the security page lists exactly three entries, quoted here.

    SOC 2 Type II — Independent audit of the design and operating effectiveness of our security controls. ISO 27001 — Certified information security management – the international standard. GDPR — EU data protection standards, with a Data Processing Agreement available on request.

    Base44 — SecuritySource dated: no date shown on the pageChecked: August 2026
  6. The enterprise page answers the adjacent procurement question with three frameworks and leaves HIPAA out. This is the quotation the contradiction section above rests on.

    Is Base44 secure enough for enterprise? Yes. Base44 runs on Wix's enterprise security infrastructure. SOC 2 Type II, ISO 27001, and GDPR compliant.

    Base44 — Enterprise, FAQSource dated: no date shown on the pageChecked: August 2026
  7. The subprocessor directory names where prompt content and app data actually go: a managed database, a server host, two model providers, three logging vendors and the parent company. Each entry below is a separate row of that directory.

    Mongo (US) — Data storage and hosting Render (US) — Server services OpenAI (US) — API calls to LLM Anthropic (US) — API calls to LLM Wix.com Ltd. (IL) — Providing and improving the services Datadog (US) — General logging purposes Langfuse (DE) — LLM logging Logfire (UK) — General logging purposes

    Base44 — Security, subprocessor directorySource dated: no date shown on the pageChecked: August 2026
  8. This docs page is where Base44 states where the servers sit, and where the regional-storage option is set out: choosing an EU, UK or US region for app data is limited to Elite and Enterprise plans and, per this page, reaches only apps created after April 16, 2026. The two sentences below are separate statements from that page, each reproduced on its own line.

    All Base44 servers are currently located in the United States By default, data for all workspaces is stored in the US

    Base44 docs — Privacy and securitySource dated: no date shown on the pageChecked: August 2026
  9. Wix does sign Business Associate Agreements, and it scopes them to a named product surface that is not Base44. We searched this article for the string "Base44" and found no occurrence.

    Wix sites built on the Wix Editor or Wix Studio Editor can be HIPAA compliant. However, you must have a supported Premium or Studio site plan to activate PHI protection.

    Wix Help Center — Enabling HIPAA Compliance for Your Wix SiteSource dated: no date shown on the pageChecked: August 2026
  10. Wix's own HIPAA hosting page rules out the default reading and limits coverage to certain configured solutions, while describing Wix as offering a BAA to eligible US healthcare customers. We searched this page for the string "Base44" and found no occurrence.

    Wix is not HIPAA compliant by default. Certain Wix solutions can be configured to support HIPAA compliance only for eligible US healthcare providers and their business associates.

    Wix — HIPAA compliant hostingSource dated: no date shown on the pageChecked: August 2026
  11. The acquisition is real, which is why the inference about the parent's BAA is so easy to make.

    Today Wix announced its acquisition of Base44, an AI-powered platform that enables anyone to create fully-functional, custom software solutions and applications using natural language, without the need for traditional coding.

  12. Base44 passes the model-provider question back to the customer rather than claiming any retention arrangement of its own.

    We encourage you to read and understand their policies before using Base44's Platform.

    Base44 docs — AI service providersSource dated: no date shown on the pageChecked: August 2026
  13. No page states how long prompts, generated code or app data persist. The Privacy Policy is the only document that addresses retention at all, and it sets no period.

    We retain the information that we collect from you for as long as it is necessary based on the purpose it was collected for and taking into account compliance with our legal obligations

    Base44 Privacy PolicySource dated: Last updated: September 21, 2025Checked: August 2026
  14. The contracting entity named in the Terms is the parent, which is worth establishing before anyone tries to negotiate under the §4.3 carve-out — the Privacy Policy and the Data Processing Agreement still name Base44, Inc.

    These Terms of Service, constitute a legally binding agreement between Wix.com Ltd., which operates the Base44-branded services ("us", "our", "we", or "Company")

    Base44 Terms of Service, openingSource dated: Last updated: June 22, 2026Checked: August 2026
  15. The Responsible Use Policy tests medical use by licensure and by compliance with applicable law, not by whether patient data is handled — which is why clearing it says nothing about the separate PHI warranty in the Terms. The two restrictions below are separate entries in that policy's list.

    To provide medical advice and medical results interpretation, or promote pharmaceutical or medical products and services, without having the qualifications, licenses and permits required by applicable law In connection with any high-risk or regulated product, service or use-case, without fully complying with the applicable laws and regulations

    Base44 — Responsible Use PolicySource dated: no date shown on the pageChecked: August 2026

Frequently asked questions

Wix owns Base44 and Wix signs BAAs. Why doesn't that cover us?

Because a BAA covers the services it names, and Wix names a different product. Its HIPAA article says: "Wix sites built on the Wix Editor or Wix Studio Editor can be HIPAA compliant. However, you must have a supported Premium or Studio site plan to activate PHI protection." Base44 does not appear in Wix's HIPAA documentation. Wix also ships a PHI-protection toggle and an in-dashboard BAA signing flow for those sites; Base44 ships no equivalent. And the data relationship runs the opposite way to the assumption — Wix.com Ltd. is listed on Base44's own subprocessor directory as a recipient of Base44 data.

We're on Enterprise with the training opt-out on. Is that enough?

It fixes the training default and nothing else. Base44 states that "Enterprise workspaces are opted out of model training by default", which closes one route, but the Enterprise page mentions no HIPAA and no BAA, and the published Enterprise control set — Security Center, SSO enforcement, SCIM user provisioning, IP allowlist, audit logs, workspace API keys and training opt-out — contains nothing described as a PHI mode. Data residency sits alongside them on Elite and Enterprise plans, for apps created after April 16, 2026, and it moves where records are stored without changing who is answerable for them. The Terms of Service warranty applies on Enterprise the same as on Free, and the prompt still reaches the model providers and the logging vendors listed on the security page.

The terms say PHI is barred "other than if expressly agreed by the Company in prior writing". Can we just ask?

You can ask, and you should treat it as a sales negotiation with an unknown outcome rather than a BAA you can obtain. It is unadvertised, unpriced and tied to no plan tier — nothing published tells you whether such an agreement has ever been signed. If you do pursue it, settle the counterparty first: the Terms name Wix.com Ltd. as the company, while the Privacy Policy and the Data Processing Agreement still name Base44, Inc. Until something is signed, the warranty in §4.3 is what binds you.

Base44 is SOC 2 Type II and ISO 27001 certified. Isn't that the same thing?

No. Those are audits of a security programme; a BAA is a contract in which a vendor accepts business-associate obligations for your patient data. Neither audit obliges a vendor to accept those obligations, and there is no certification that confers HIPAA compliance on a product. The tell is on Base44's own enterprise page, where the answer to "Is Base44 secure enough for enterprise?" lists SOC 2 Type II, ISO 27001 and GDPR — three frameworks, on a page built to clear procurement objections, with HIPAA left out.

We only pasted one real record into the chat to show the model the data shape. Does that matter?

It is the most common way this happens and yes, it counts. Under the Terms that content is Customer Data licensed on terms described as irrevocable and perpetual, extended to third-party service providers, and on tiers below Enterprise it sits under the training licence. The prompt also travels to the model providers on the subprocessor list and to Langfuse in Germany for LLM logging. No retention window is published anywhere. Deleting the message is the right move; knowing what was in it and when is the part you will actually be asked about.

Can we keep the Base44 front end and move only the patient data?

This is where Base44 differs from tools where you bring your own database. The backend is managed — the directory shows Mongo for storage and Render for server services — so there is no documented way to point the primary app store at a database you hold an agreement for. Base44's own positioning is that it removes the need for third-party integrations, and that is exactly what closes this door. Even if the interface stayed, the prompt box remains inside the §4.3 warranty. Our engagement therefore moves the patient-data layer onto covered infrastructure rather than trying to bolt one onto Base44.

How long does moving off take, and what does it cost?

Six to ten weeks at $13,000–$25,000 for the engagement described above. The disclosure inventory comes first and is one of the two shortest stages at three to five days, alongside the handover pack that closes the engagement; the data-layer migration off the managed backend is the longest single one. A live user base is what pushes the calendar to the upper end, because the cutover has to happen without downtime. If your app is still on invented data, none of this applies to you yet.

This page reports what Base44's and Wix's published documents said on the dates shown and is technical information rather than legal advice; HIPAA compliance is a property of your whole system and the processes around it rather than of any single tool, and vendor terms change — open the pages linked above and verify the current terms before relying on anything here.

Matt Graham

Written by

Matt Graham · CEO & Founder, RapidDev

1,000+ client projects delivered. Columbia University & Harvard Business School alumnus, U.S. Navy veteran. About the author →

Ready when you are

Fixed price, fixed timeline: $13K–$25K, 6–10 weeks, production-grade code you own. Book a call and get a custom quote at no cost.

Get your custom quote

We put the rapid in RapidDev

Need a dedicated strategic tech and growth partner? Discover what RapidDev can do for your business! Book a call with our team to schedule a free, no-obligation consultation. We'll discuss your project and provide a custom quote at no cost.