Skip to main content
RapidDev - Software Development Agency
Cursor

Is Cursor HIPAA compliant? Yes — on Enterprise, with Privacy Mode locked

The verdictVerified August 2026
Yes — Enterprise, Privacy Mode locked

Yes, conditionally. Cursor signs a HIPAA Business Associate Agreement, but only for Enterprise customers and only where Privacy Mode is enabled and locked organization-wide; a signed BAA and an Enterprise agreement have to be in place before any PHI is submitted. Coverage reaches only the Eligible Services and Eligible Models named in Cursor's HIPAA Implementation and Configuration Guide, which is part of the BAA and sits behind the Trust Center, so the model list is not publicly readable. Third-party services, integrations and model providers are not automatically covered.

What would change this

Two things would change the answer for most readers: Cursor extending BAA support below Enterprise, or publishing the Eligible Services and Eligible Models list where anyone can read it. Neither has happened. Until then the scope of your agreement is set by a document you only see after you ask for it, and that document describes itself as carrying the current details — meaning it is expected to change. On your side, the answer also flips back: dropping off Enterprise, unlocking Privacy Mode, or an admin opting the team into a model that requires retention with the provider each moves you outside the configuration the coverage assumes.

Cursor Docs — HIPAA Business Associate Agreements

Yes, conditionally — and most write-ups get this wrong. Cursor does sign a HIPAA Business Associate Agreement, but only for Enterprise customers, only with Privacy Mode enabled and locked organization-wide, and only across a list of Eligible Services and Eligible Models that lives in a guide behind the Trust Center. Third-party model providers, MCP servers and your own API keys sit outside it. Getting an existing team into that configuration and cleaning up what was pasted before takes us 6–10 weeks.

Book a free consultation
4.9Clutch rating
1,000+Happy partners
20+Countries served
200+Team members
CursorYes, with conditionsSources checked August 2026August 2026RapidDev Engineering Team
TL;DR

Yes, conditionally — and most write-ups get this wrong. Cursor does sign a HIPAA Business Associate Agreement, but only for Enterprise customers, only with Privacy Mode enabled and locked organization-wide, and only across a list of Eligible Services and Eligible Models that lives in a guide behind the Trust Center. Third-party model providers, MCP servers and your own API keys sit outside it. Getting an existing team into that configuration and cleaning up what was pasted before takes us 6–10 weeks.

Quick facts about this guide
FactValue
ToolCursor
VerdictYes, with conditions
Sources checkedAugust 2026
Typical range$13,000–$25,000
Typical timeline6–10 weeks
Last updatedAugust 2026

Which Cursor surfaces the BAA reaches

"Covered" here means named as an Eligible Service on Cursor's HIPAA BAA page, which prefaces that list as covered for Enterprise customers with Privacy Mode enabled and locked organization-wide. Two conditions sit above every row: a signed BAA plus an Enterprise agreement, and Privacy Mode locked so members cannot switch it off. A third condition cuts across all of them — the model. Cursor gates PHI on a model basis as well as a surface basis, and the Eligible Models list is only in the gated HIPAA Guide, so a covered surface running a model that is not on that list is not a covered arrangement.

7of 16 services covered by the BAA· 1 conditional

Your PHI

Your Cursor app

Inside the agreement — PHI may live here

  • Desktop IDE — including Agent, Tab, Edit, local agent mode and inline edit
  • CLI
  • Tab
  • Cursor for iOS
  • Cloud Agents
  • BugBot
  • Automations
  • Models that require data retention with the provider· conditional

Outside it — PHI here is a gap

  • Teams plan (any surface)
  • Free, Pro and individual plans
  • Grok Bot
  • MCP servers, @Web and user-configured connectors
  • Third-party model providers and other third-party services
  • Bring your own key (BYOK) and custom models via a base URL override or third-party gateway
  • The Eligible Models list itself
  • Cursor's authoritative sub-processor list
Which Cursor surfaces the BAA reaches
ServiceUnder the BAACondition
Desktop IDE — including Agent, Tab, Edit, local agent mode and inline editCoveredListed as an Eligible Service. The model in the picker still has to be an Eligible Model, and that list is not public.
CLICoveredListed as an Eligible Service.
TabCoveredListed as an Eligible Service, and separately named inside the Desktop IDE entry.
Cursor for iOSCoveredListed as an Eligible Service.
Cloud AgentsCoveredListed as an Eligible Service, and the one surface where Cursor says it has to store your code: encrypted copies of the repositories the agent works on, stored while the agent runs and deleted after it completes. Cursor's own advice is not to enable it if your security policy prohibits code storage.
BugBotCoveredListed as an Eligible Service.
AutomationsCoveredListed as an Eligible Service.
Teams plan (any surface)Not coveredCursor's FAQ answer to whether BAA support is available on Teams points at Enterprise and tells Teams customers to contact sales about moving.
Free, Pro and individual plansNot coveredA BAA comes as part of an Enterprise agreement, and Cursor states that on an individual plan the DPA does not apply.
Grok BotNot coveredCursor describes it as running on a separate product surface with its own data flows, and it is not among the Eligible Services. Privacy Mode in the editor does not govern it.
MCP servers, @Web and user-configured connectorsNot coveredCursor calls these separate services, each with its own region, and says third-party services and integrations are not automatically covered by its BAA.
Third-party model providers and other third-party servicesNot coveredCursor's BAA does not automatically cover them. If PHI reaches a provider through an integration you wired up, that is your agreement to make, not one you inherit.
Bring your own key (BYOK) and custom models via a base URL override or third-party gatewayNot coveredWith your own API keys, Cursor says its zero-retention agreements do not apply and your data handling follows your provider's privacy policy. Cursor also states BYOK has no data-residency support.
Models that require data retention with the providerConditionalSome models fall outside Cursor's zero-retention agreements; Cursor names Claude Fable 5 and says Anthropic stores its inputs and outputs for harm-prevention reviews. Requests fail until an admin approves the retention policy, and that opt-in applies to the whole team. Outside the covered set unless separately approved.
The Eligible Models list itselfUnconfirmedNo model is publicly named as HIPAA-eligible anywhere on cursor.com. The list is in the gated HIPAA Guide. This is the sharpest practical trap on the page: the surface can be right and the model wrong.
Cursor's authoritative sub-processor listUnconfirmedEvery Cursor page that mentions sub-processors points at the Trust Center. When we fetched that URL in August 2026 it returned a JavaScript shell with no names in the served HTML, so we cannot publish a sub-processor roster for Cursor. The only providers we can source are the ones Cursor names illustratively — OpenAI, Anthropic and Google, prefaced by the word "like".

This table reflects Cursor's BAA documentation page as we read it in August 2026; that page carries no last-updated stamp. The authoritative list is not this table and not even that page — it is the HIPAA Implementation and Configuration Guide, which Cursor says is part of the BAA and holds the current details of Eligible Services and Eligible Models. That guide is behind a Trust Center access request, so we could not read it and neither can you until you ask. Treat the rows below as a starting point for the conversation with Cursor, not as the contract.

Why almost everything you have read says Cursor has no BAA

What secondary sources say

The claim in circulation — and the claim our own brief for this page stated as settled fact — is that Cursor does not offer a HIPAA BAA on any plan, and that Privacy Mode is the closest thing on offer. We drafted this page to say exactly that, then went looking for the sentence to quote and could not find one.

  • Our own pre-verification brief for this page, which asserted that Cursor does not offer a BAA on any plan — refuted against the primary source and corrected on 26 August 2026, before publication.
  • Cursor's own Privacy Policy, dated 6 October 2025, which states that Anysphere "does not knowingly collect sensitive or special category personal information" and goes on to name health information among the examples. It predates the BAA documentation by roughly a year and reads, on its face, as a refusal of the very data the BAA contemplates.

What the vendor's own documentation says

Cursor's docs say the opposite in plain terms: "Cursor supports HIPAA Business Associate Agreements (BAAs) for Enterprise customers." The same page states that a signed BAA is required before submitting protected health information to Cursor, lists the covered services, and answers the Teams question directly.

How we resolve it

The reason the wrong version spread is structural. The BAA page exists only at cursor.com/docs/enterprise/baa, and it is not linked from cursor.com/security, cursor.com/privacy or cursor.com/data-use — the three pages anyone doing vendor diligence actually opens. It appears in the docs sidebar as "HIPAA BAA" under Teams & Enterprise, and the obvious guessed URLs return 404. So a reasonable person can check Cursor's security hub end to end, find no mention of HIPAA, and publish that there is none. If you are running diligence on Cursor, go to the docs sidebar, not the security page. And note the flip side: the BAA existing does not mean your setup is inside it.

Where a pasted patient record actually goes

MCP servers, connectors and @Web in the editor

High

This is where PHI leaves the perimeter most plausibly in a coding-agent workflow. An MCP server is a separate service that receives whatever the agent sends it — a ticket body, a log line, a row from a real export used to reproduce a bug. Cursor describes @Web and user-configured MCPs or connectors as separate services, each with its own region, and says third-party services and integrations are not automatically covered by its BAA. The agent can call them without anyone deciding, in that moment, that a call was about to happen.

How to check

Open Cursor's settings on a developer machine that touches patient data and read the MCP list. For each entry, name the company that operates it and say out loud whether you have an agreement with them. Then open the agent history for the last week and look for a request that included a record body.

A developer's own API key or a custom model base URL

High

Cursor is explicit that its zero-retention agreements do not apply when you use your own API keys, and that data handling then follows your provider's privacy policy. The same applies to a custom model pointed at through an OpenAI-compatible base URL override or a third-party gateway. Both are common enterprise setups, both are outside the BAA's list, and neither looks different from the outside: the editor behaves the same, the prompts go somewhere else.

How to check

In Cursor's model settings on each machine, look for an API key entered by the user or a base URL that is not Cursor's. One machine is enough to matter — the prompts from that machine went to a provider you have no agreement with.

Someone signed in on a personal Pro account

High

Privacy Mode being available is not Privacy Mode being on. With it off, Cursor says it may use and store codebase data, prompts, editor actions, code snippets and other code data and actions to improve its AI features and train its models. On Enterprise teams Privacy Mode is on by default and can be locked so members cannot disable it; on an individual plan none of that applies, and the DPA does not apply either. A contractor using their own login on the same repository is outside every control you configured.

How to check

In the Cursor dashboard, list the accounts in your organization and compare it against everyone who has cloned the repository. Anyone on the second list and not the first is working outside your tenancy.

A model that requires retention with the provider

Medium

Cursor keeps zero-retention agreements with providers, but says a few models require data retention with the provider and fall outside those agreements — it names Claude Fable 5, and says Anthropic stores its inputs and outputs to run harm-prevention reviews. Requests to such a model fail until an admin approves the retention policy, and Cursor states that opting in applies to the whole team. So one admin clearing one blocked request can move an entire organization off zero retention for that model, quietly, on a Tuesday.

How to check

In the Cursor dashboard, open the model list and find which models are designated as requiring retention and whether any of them has been opted into for the team. Then ask who approved it and when.

Codebase indexing and the embeddings it leaves behind

Medium

The leak is usually not the database — it is the seed file. A fixture with three real patients, a saved API response checked in to reproduce a bug, an anonymised export that kept the names. Cursor says the plaintext code used to compute embeddings ceases to exist after the life of the request, but that the embeddings and metadata about your codebase may be stored. Deleting the fixture from the repository today does not retract what was derived from it.

How to check

Search the working tree — including test fixtures, seed scripts, notebooks and anything under a directory named samples or examples — for a real surname, a real email domain and a real record-number prefix. Search the git history for the same strings, because the file may already be deleted and still indexed.

Cloud Agents copying the repository

Medium

Cloud Agents are on the Eligible Services list, so this is inside the BAA when the BAA is in place. It is on the map because it is the one Cursor feature that requires Cursor to store code: encrypted copies of the repositories the agent works on, stored while the agent runs, deleted after it completes. If your repository carries PHI in fixtures, those copies carry it too — and Cursor's own guidance is that if your security policy prohibits code storage, do not enable Cloud Agents.

How to check

In the dashboard, list which repositories and branches Cloud Agents have run against in the last month, then cross-reference that list against the fixture search above.

Six checks, each answerable in a minute

All six are answerable by someone with admin access to your Cursor organization, except the first, which is a question for whoever holds your contracts. Run them before you pay anyone — including us. If none of them flags, there is no project here and we will say so.

  1. 01Can someone at your company produce a countersigned BAA with Cursor and an Enterprise agreement today?

  2. 02In the Cursor dashboard, is Privacy Mode both enabled and locked organization-wide, so members cannot turn it off?

  3. 03Can anyone on your team name the Eligible Models from the HIPAA Guide in the Trust Center, and does your model allowlist match that list?

  4. 04Does anyone in your organization use their own API key, a custom base URL, or a third-party gateway in Cursor?

  5. 05Are any MCP servers or connectors configured, or is @Web in use, on machines that touch patient data?

  6. 06Is anyone with a copy of the repository signed into Cursor on a personal Free or Pro account rather than your organization?

What we do about it

Typical range

$13,000–$25,000

Typical timeline

6–10 weeks

  1. 01

    Prompt-surface inventory

    3–5 days

    A written list of every place a prompt can leave your machines: accounts and plan tiers, model settings including any own-key or custom base URL, every configured MCP server and connector with its operator named, and whether Cloud Agents are enabled. Each entry marked against Cursor's Eligible Services list, with the date we read that list printed on it.

  2. 02

    Tenancy and configuration lockdown

    1–2 weeks

    Everyone inside one Enterprise organization, Privacy Mode enabled and locked organization-wide, a model allowlist reconciled against the Eligible Models in the HIPAA Guide once you have Trust Center access, and own-key and custom-endpoint paths closed or documented as out of scope.

  3. 03

    Repository and history sweep

    2–3 weeks

    A search of the working tree and the git history for real identifiers in fixtures, seeds, notebooks and saved API responses, with a written record of what was found, what was removed, what was already indexed, and which Cloud Agent runs touched it.

  4. 04

    Integration perimeter

    1–2 weeks

    Each MCP server, connector and third-party model provider either removed, replaced, or carried into its own written agreement — because Cursor's BAA does not automatically cover them — plus a standing rule for how a new one gets added.

  5. 05

    Handover pack

    3–5 days

    One document holding the surface inventory, the configuration as locked, the checks we ran with their results, the dated source pages behind each decision, and an explicit list of what remains your responsibility — the thing your auditor asks for in writing.

What moves the number

  • How many engineers and machines are involved, and whether contractors on personal accounts have to be brought into the organization.
  • Whether you are on Teams today, because the Enterprise move has to land before the configuration work means anything.
  • Whether anyone uses their own API keys, a custom base URL or a gateway — each one is a separate provider relationship to close out or paper.
  • How many MCP servers and connectors are configured across the team, and how many of them turn out to be operated by someone nobody can name.
  • How much history there is to sweep: a six-month-old repository with two fixtures is a different job from three years of branches, notebooks and support exports.
  • Whether Cloud Agents have run against PHI-bearing repositories, which turns a configuration question into an accounting question.

When not to hire us

  • You have no real PHI in play yet. If your team works against synthetic data, this is a policy to write down, not a project to run, and doing it before the product shape settles usually means doing it twice.
  • All you actually need is the BAA. That is a conversation with Cursor sales as part of an Enterprise agreement. Paying an agency to arrange it is paying an agency to send an email.
  • You are a small team, already on Enterprise with Privacy Mode locked, with no MCP servers, no own keys and no fixtures carrying real records. Then the self-check above is the whole audit, and our free Cursor guides cover the rest.
  • You want a compliance certificate. There is no government HIPAA certification for a product or a company, so nobody can sell you one — us included.
Our free Cursor guides

Worth knowing either way

There is no government HIPAA certification

No authority certifies software as HIPAA-compliant. What exists is a signed Business Associate Agreement with every vendor that touches protected health information, plus the administrative, physical and technical safeguards you implement and document yourself.

SOC 2 is not a substitute for a BAA

Supabase states it plainly in its own documentation: “SOC 2 does not cover, nor is it a substitute for, compliance with the Health Insurance Portability and Accountability Act (HIPAA).” The same holds for every vendor here.

An absence of documentation is not a vendor promise

Several answers here rest on what vendor documents do not say. We name which documents we read and when. A vendor that has never published a HIPAA position may still decline to sign, and one that publishes nothing today may publish something next quarter.

The same question, for the other fifteen tools

Sources, quoted as printed

Every claim above traces to one of these. Quotes are reproduced as printed on the source page, including its own spacing and punctuation. Where an entry cites more than one sentence from the same page, each is reproduced on its own line and no adjacency or ordering between them is implied. Where we describe what a page did not contain, that is our observation of a fetch on the date shown, not a vendor statement — those are written as prose, never inside quotation marks. Cursor's enterprise documentation pages carry no last-updated stamps and Cursor moves material between them, so if a line is not where we cite it, search the enterprise docs section rather than assuming it was withdrawn.

  1. Cursor does sign HIPAA Business Associate Agreements, on the Enterprise plan, and requires the signature before any PHI is submitted. This is the finding that refutes the common claim that no BAA exists.

    Cursor supports HIPAA Business Associate Agreements (BAAs) for Enterprise customers. Organizations that are covered entities or business associates under HIPAA can request a BAA as part of their Enterprise agreement. A signed BAA is required before submitting protected health information (PHI) to Cursor.

    Cursor Docs — HIPAA Business Associate AgreementsSource dated: no date shown on pageChecked: August 2026
  2. BAA support does not extend to the Teams plan; Cursor answers that question directly in its own FAQ.

    BAA support is available on Enterprise. If your organization is currently on a Teams plan, contact sales to discuss moving to Enterprise and requesting a BAA.

  3. Locking Privacy Mode organization-wide is a stated precondition of using Cursor with PHI, and Cursor is explicit that the agreement alone does not make an arbitrary configuration appropriate. The first line below is one item in a four-item checklist headed "Before using Cursor with PHI"; the second appears separately on the same page.

    Enable and lock Privacy Mode organization-wide A BAA does not automatically make every product, configuration, or workflow appropriate for PHI.

    Cursor Docs — HIPAA Business Associate AgreementsSource dated: no date shown on pageChecked: August 2026
  4. The real definition of scope is a gated document, not the public page: the guide that names Eligible Services and Eligible Models is part of the BAA itself. We requested nothing and read none of it — the Trust Center content was not retrievable for us in August 2026.

    The HIPAA Implementation and Configuration Guide is part of the BAA. It includes current details about Eligible Services, Eligible Models, required controls, and customer responsibilities.

    Cursor Docs — HIPAA Business Associate AgreementsSource dated: no date shown on pageChecked: August 2026
  5. Third-party services, integrations and model providers are outside the agreement unless you put something in place yourself — the single most important line on the page for a coding-agent workflow. The page uses the same construction for integrations, describing them as not automatically covered by Cursor's BAA.

    Cursor's BAA does not automatically cover third-party services

    Cursor Docs — HIPAA Business Associate AgreementsSource dated: no date shown on pageChecked: August 2026
  6. What Privacy Mode does and does not guarantee, in Cursor's own words — including the abuse-detection caveat that qualifies every zero-retention claim.

    If you enable “ Privacy Mode ” in Cursor’s settings: Customer Data will not be used for training by Cursor. Cursor maintains zero data retention (ZDR) agreements with all providers, and AI model providers will not store or train on your data. However, please note that subject to their policies, model providers (including Cursor) may run risk classifiers to detect violations of terms and usage policies, and if your prompts or conversations trigger abuse detectors your data may be stored for investigation and deleted in accordance with their retention policies. Non-ZDR models will be designated as such or require an admin to opt-in to enable the model for your workspace.

    Cursor — Data UseSource dated: Last updated July 15, 2026Checked: August 2026
  7. With Privacy Mode off, training on prompts and code is permitted by the terms. This is the default path that matters for anyone on an individual plan.

    If you choose to turn off “Privacy Mode”: we may use and store codebase data, prompts, editor actions, code snippets, and other code data and actions to improve our AI features and train our models. Some of our inference providers may temporarily access and store model inputs and outputs to improve our inference performance; this data is deleted after use.

    Cursor — Data UseSource dated: Last updated July 15, 2026Checked: August 2026
  8. Privacy Mode is available on every tier, but availability is not the same as being switched on — the security page never says it is on by default for individuals.

    Privacy Mode can be enabled in settings or by a team or enterprise admin. Privacy Mode is available to anyone (free or Pro). New team members inherit the team's Privacy Mode settings.

    Cursor — SecuritySource dated: Last updated April 24, 2026Checked: August 2026
  9. For teams it is on by default and can be enforced so members cannot disable it, and for Enterprise it is on by default. The two lines below appear on the same help page.

    For teams, Privacy Mode is enabled by default for all team members. Admins can enforce it organization-wide via cursor.com/dashboard so members cannot disable it. Privacy Mode is on by default for Enterprise teams.

    Cursor Help — Security and privacy, PrivacySource dated: no date shown on pageChecked: August 2026
  10. Zero data retention does not survive bringing your own key, and Cursor says so plainly.

    ZDR doesn't apply when you use your own API keys. In that case, your data handling follows your provider's privacy policy.

    Cursor Docs — Enterprise privacy and data governanceSource dated: no date shown on pageChecked: August 2026
  11. Some models sit outside the zero-retention agreements, and a single admin approval moves the whole team onto that footing for that model.

    A few models require data retention with the provider and fall outside these agreements Opting in applies to the whole team.

    Cursor Docs — Enterprise privacy and data governanceSource dated: no date shown on pageChecked: August 2026
  12. MCP servers, connectors and @Web are separate services outside the editor's perimeter, and Grok Bot is carved out as its own product surface.

    @Web and user-configured MCPs or connectors are separate services, each with its own region. Grok Bot runs on a separate product surface with its own data flows

    Cursor Docs — Enterprise privacy and data governanceSource dated: no date shown on pageChecked: August 2026
  13. Cloud Agents are the only feature where Cursor stores your code, and Cursor gives its own condition for not enabling it.

    Cloud Agents are the only feature that requires Cursor to store code. If your security policy prohibits code storage, don't enable Cloud Agents.

    Cursor Docs — Enterprise privacy and data governanceSource dated: no date shown on pageChecked: August 2026
  14. Indexing does not keep your plaintext, but what it derives from your code persists — which is why deleting a fixture today does not settle the question.

    plaintext code for computing embeddings ceases to exist after the life of the request.

    Cursor Docs — Enterprise privacy and data governanceSource dated: no date shown on pageChecked: August 2026
  15. Cursor names model providers only illustratively. The definitive sub-processor list is on the Trust Center, and when we fetched trust.cursor.com/subprocessors in August 2026 the response was a JavaScript application shell carrying the page title and no sub-processor names in the served HTML — so we cannot publish a roster, and neither the illustrative names nor their absence should be read as complete.

    When you use AI features, we send prompts and code context to language model providers like OpenAI, Anthropic, and Google.

    Cursor Docs — Enterprise privacy and data governanceSource dated: no date shown on pageChecked: August 2026
  16. The only certification Cursor names on its security page is SOC 2 Type II, asserted as a report available on request. We could not retrieve the report itself, so its period, auditor and scope are unverified by us — and an attestation is not a BAA in any case. No ISO 27001 claim appears on that page.

    A SOC 2 Type II attestation report is available on request at trust.cursor.com .

    Cursor — Security, under "Certifications and third-party assessments"Source dated: Last updated April 24, 2026Checked: August 2026
  17. Cursor's Privacy Policy, which predates the BAA documentation by roughly a year, disclaims collecting health information — worth raising with Cursor rather than resolving yourself.

    does not knowingly collect sensitive or special category personal information

    Cursor — Privacy Policy (Anysphere, Inc.)Source dated: October 6, 2025Checked: August 2026

Frequently asked questions

We're on Teams. Can we get a BAA there?

No. Cursor answers this one in its own FAQ: "BAA support is available on Enterprise. If your organization is currently on a Teams plan, contact sales to discuss moving to Enterprise and requesting a BAA." Teams does give you Privacy Mode on by default, which is a real control, but it is not the agreement. Budget for the plan move before you budget for anything else.

Privacy Mode is on. Isn't that the same thing?

No, and the relationship runs the other way from how people usually describe it. Privacy Mode is not a substitute for the BAA — Cursor makes it a precondition of it, and specifically "Enable and lock Privacy Mode organization-wide". Enabled but not locked is not the configuration the Eligible Services list is prefaced with. It is also not absolute: Cursor states that model providers may run risk classifiers and that if your prompts trigger abuse detectors your data may be stored for investigation.

Which models can we actually use with PHI?

We cannot tell you, and no public Cursor page can either. Cursor gates PHI on a model basis as well as a surface basis, and says the HIPAA Guide lists the current Eligible Models. That guide is behind a Trust Center access request. No model is publicly named as HIPAA-eligible anywhere on cursor.com. Practically, this means the trap is not the surface — the Desktop IDE is an Eligible Service — but the model picker inside it. Get the guide, then build an allowlist that matches it, then treat a new model in the picker as a change that needs approval.

One of our engineers uses their own Anthropic key in Cursor. Does the BAA cover that?

No. Cursor says "ZDR doesn't apply when you use your own API keys. In that case, your data handling follows your provider's privacy policy." Bring-your-own-key sits outside the covered set, and Cursor also states it has no data-residency support. Whatever went through that key was governed by that account's terms with that provider, which is unlikely to include a BAA. The same applies to a custom model reached through a base URL override or a third-party gateway.

Can we run Cloud Agents on a repo that has real records in its test fixtures?

Cloud Agents are on the Eligible Services list, so with the BAA in place and Privacy Mode locked, the surface itself is in scope. But it is the one feature where Cursor stores your code — encrypted copies of the repositories the agent works on, kept while the agent runs and deleted after it completes — and Cursor's own line is that if your security policy prohibits code storage, don't enable Cloud Agents. So the honest answer is that the fixtures are the problem, not the agent. Fix the fixtures first.

What about @Web, MCP servers and Grok Bot?

All three are outside the editor's perimeter. Cursor describes @Web and user-configured MCPs or connectors as separate services, each with its own region, and says third-party services and integrations are not automatically covered by its BAA. Grok Bot is described as running on a separate product surface with its own data flows and is not among the Eligible Services, so Privacy Mode in the editor does not govern it. In a coding-agent workflow this is where a leak most plausibly happens, because the agent can call these without anyone deciding in the moment that a call was about to occur.

Is Cursor HIPAA certified?

Nothing is. There is no government HIPAA certification for a product or a company. What exists is a signed Business Associate Agreement with each vendor that touches protected health information, plus the safeguards you implement and document yourself. Cursor names SOC 2 Type II on its security page, as a report available on request — a useful thing to ask for, and not a substitute for the agreement.

This page reports what Cursor's published documents said on the dates shown and is technical information rather than legal advice; HIPAA compliance is a property of your whole system and the processes around it rather than of any single tool, and vendor terms change — verify the current terms with Cursor, including the HIPAA Implementation and Configuration Guide in its Trust Center, before relying on anything here.

Matt Graham

Written by

Matt Graham · CEO & Founder, RapidDev

1,000+ client projects delivered. Columbia University & Harvard Business School alumnus, U.S. Navy veteran. About the author →

Ready when you are

Fixed price, fixed timeline: $13K–$25K, 6–10 weeks, production-grade code you own. Book a call and get a custom quote at no cost.

Get your custom quote

We put the rapid in RapidDev

Need a dedicated strategic tech and growth partner? Discover what RapidDev can do for your business! Book a call with our team to schedule a free, no-obligation consultation. We'll discuss your project and provide a custom quote at no cost.