Skip to main content
RapidDev - Software Development Agency
Github

Is GitHub Copilot HIPAA compliant? No — GitHub signs no BAA on any tier

The verdictVerified August 2026
No — no BAA on any tier

No. There is no Business Associate Agreement to sign for GitHub Copilot on any tier — not Free, Pro, Pro+, Max, Business or Enterprise. What the contract adds on top of that absence depends on how you bought. Buy under a volume licensing agreement and GitHub's Generative AI Services Terms bind you to GitHub's Data Protection Agreement, which tells the customer not to provide GitHub protected health information at all except with GitHub's prior, written, and specific consent. Buy through Microsoft and the Microsoft Product Terms for GitHub Offerings route Copilot Business and Enterprise back to that same GitHub DPA. Buy a personal plan and the Generative AI Services Terms say the document does not apply to you: your use is governed by the GitHub Terms of Service, in which HIPAA, business associate and protected health information do not appear at all — no prohibition there, and no BAA either. Be precise about what that is and is not: no Microsoft or GitHub document names GitHub Copilot in a HIPAA exclusion. What exists is a product-agnostic prohibition that covers everything GitHub sells to the customers the DPA reaches, plus GitHub's absence from Microsoft's published list of services the Microsoft BAA covers — a list on which Azure DevOps Services, Microsoft's other developer platform, does appear.

What would change this

GitHub would have to publish a BAA programme, or Microsoft would have to add GitHub Copilot to its HIPAA in-scope services list. The DPA already contemplates one narrower route — the clause opens "Except with GitHub's prior, written, and specific consent" — but unlike the parallel FERPA clause beside it, it names no process, no contact and no eligible tier, so today it is a theoretical exception rather than an available one.

GitHub Data Protection Agreement — §12

No. GitHub publishes no Business Associate Agreement for GitHub Copilot on any tier, and for the customers its Data Protection Agreement reaches — those buying under a volume licensing agreement, and those buying through Microsoft, whose Product Terms point Copilot Business and Enterprise back at that same GitHub DPA — the agreement forbids sending GitHub protected health information at all, absent GitHub's "prior, written, and specific consent." Personal plans sit outside it, governed by the GitHub Terms of Service, which says nothing about HIPAA in either direction. Microsoft 365 Copilot — now named Microsoft Copilot — is a different product and is named on Microsoft's HIPAA in-scope list; GitHub Copilot is not on that list, and neither is GitHub. Getting real records out of the repositories and prompts a Copilot-assisted team touches takes us 6–10 weeks.

Book a free consultation
4.9Clutch rating
1,000+Happy partners
20+Countries served
200+Team members
GithubNoSources checked August 2026August 2026RapidDev Engineering Team
TL;DR

No. GitHub publishes no Business Associate Agreement for GitHub Copilot on any tier, and for the customers its Data Protection Agreement reaches — those buying under a volume licensing agreement, and those buying through Microsoft, whose Product Terms point Copilot Business and Enterprise back at that same GitHub DPA — the agreement forbids sending GitHub protected health information at all, absent GitHub's "prior, written, and specific consent." Personal plans sit outside it, governed by the GitHub Terms of Service, which says nothing about HIPAA in either direction. Microsoft 365 Copilot — now named Microsoft Copilot — is a different product and is named on Microsoft's HIPAA in-scope list; GitHub Copilot is not on that list, and neither is GitHub. Getting real records out of the repositories and prompts a Copilot-assisted team touches takes us 6–10 weeks.

Quick facts about this guide
FactValue
ToolGithub
VerdictNo
Sources checkedAugust 2026
Typical range$13,000–$25,000
Typical timeline6–10 weeks
Last updatedAugust 2026

Which product carries the agreement, and which one you are actually using

"Covered" here means named on Microsoft's published HIPAA/HITECH in-scope cloud services list — the list Microsoft's own FAQ points at to say what the Microsoft BAA covers. It is the only publicly readable BAA scope list either company maintains. "Not covered" means the service is absent from that list and GitHub offers no BAA of its own; it does not mean a vendor document names the service in a HIPAA exclusion, because none does. Note also that the two Copilots below share a word and nothing else: one is Microsoft's Office assistant, the other is GitHub's coding assistant, and they are governed by different contracts.

7of 17 services covered by the BAA

Your PHI

Your Github app

Inside the agreement — PHI may live here

  • Microsoft 365 Copilot (Office 365 Commercial) — now named Microsoft Copilot
  • Microsoft 365 Copilot Chat (Office 365 Commercial) — now named Microsoft Copilot Chat
  • Microsoft 365 Copilot and Microsoft 365 Copilot Chat (Office 365 GCC)
  • Azure DevOps Services
  • Microsoft Copilot Search (as part of Microsoft Copilot)
  • Microsoft Copilot for Security
  • Azure and Azure Government

Outside it — PHI here is a gap

  • GitHub Copilot in your code editor (IDE extension)
  • GitHub Copilot Chat and GitHub Copilot Memory
  • Copilot for the Command Line Interface (Copilot CLI)
  • GitHub Copilot coding agent
  • GitHub Copilot on web browser and mobile device
  • Copilot Business and Copilot Enterprise
  • Copilot Free, Copilot Pro, Copilot Pro+, Copilot Max
  • GitHub Marketplace third-party products and partner agents
  • GitHub.com, GitHub Enterprise Cloud, GitHub Enterprise Server, GitHub Codespaces, GitHub Spark
  • The full text of the Microsoft BAA at aka.ms/BAA
Which product carries the agreement, and which one you are actually using
ServiceUnder the BAACondition
Microsoft 365 Copilot (Office 365 Commercial) — now named Microsoft CopilotCoveredNamed in the Office 365 Commercial row of Microsoft's in-scope services table. This is the Office assistant, not the coding assistant.
Microsoft 365 Copilot Chat (Office 365 Commercial) — now named Microsoft Copilot ChatCovered
Microsoft 365 Copilot and Microsoft 365 Copilot Chat (Office 365 GCC)CoveredListed for Commercial and GCC. Microsoft's page describes GCC High and DoD environments separately, and Copilot is not listed in those rows.
Azure DevOps ServicesCoveredMicrosoft's other developer platform is on the in-scope list. That is the contrast worth holding on to: the omission of GitHub from the same list is not an oversight of the category.
Microsoft Copilot Search (as part of Microsoft Copilot)Covered
Microsoft Copilot for SecurityCovered
Azure and Azure GovernmentCovered
GitHub Copilot in your code editor (IDE extension)Not coveredNo GitHub Copilot surface appears on Microsoft's in-scope list, and GitHub publishes no BAA of its own.
GitHub Copilot Chat and GitHub Copilot MemoryNot covered
Copilot for the Command Line Interface (Copilot CLI)Not covered
GitHub Copilot coding agentNot coveredGitHub's Trust Center, in a retention answer scoped by its own question header to Business and Enterprise customers, states that Copilot Coding Agent session logs are retained for the life of the account in order to provide the service.
GitHub Copilot on web browser and mobile deviceNot coveredFalls under "Other GitHub Copilot access and use" in that same Business and Enterprise retention answer, where inputs and outputs are retained for up to 28 days by default. We found no equivalent published window for the individual plans.
Copilot Business and Copilot EnterpriseNot coveredThe Microsoft Product Terms for GitHub Offerings route both to the GitHub DPA — the document containing the PHI prohibition — rather than to the Microsoft DPA that carries the Microsoft BAA.
Copilot Free, Copilot Pro, Copilot Pro+, Copilot MaxNot coveredBought as personal plans rather than under a volume licensing agreement, these fall outside the Generative AI Services Terms and the DPA and sit under the GitHub Terms of Service, which contains no HIPAA text of any kind — that removes the contractual prohibition, not the missing BAA. Additionally the training default flipped on these tiers on April 24, 2026, opt-out only. GitHub's legacy SKU name Copilot Individual also turns up in older material; no GitHub Copilot SKU, under any name, appears on Microsoft's in-scope list.
GitHub Marketplace third-party products and partner agentsNot coveredNothing on Microsoft's in-scope list covers them and GitHub offers no BAA for them. They are also a data path the leak map below does not cover: what a third-party product or partner agent does with what it reads is governed by that vendor's own terms, which you have to read separately.
GitHub.com, GitHub Enterprise Cloud, GitHub Enterprise Server, GitHub Codespaces, GitHub SparkNot coveredThe DPA defines its scope as "any service or software that GitHub provides You under a written and executed agreement," so the PHI prohibition is not Copilot-specific. It reaches the whole platform.
The full text of the Microsoft BAA at aka.ms/BAAUnconfirmedMicrosoft's DPA says the BAA's own full text — not the summary page — identifies the services it applies to. That text sits behind a JavaScript-only Service Trust Portal that returned no readable document when we tried in August 2026, so we cannot tell you what the controlling annex says either way.

These are the documents as we read them in August 2026. Two of them moved recently: GitHub's Copilot Product Specific Terms were deprecated effective 5 March 2026 and replaced by the Generative AI Services Terms (Version: March 2026), and the individual-tier training default changed on April 24, 2026. GitHub has also retired its static Copilot privacy statements — the Copilot Privacy Statement URL now returns a 404, and the Copilot Business Privacy Statement redirects to GitHub's Copilot Trust Center at copilot.github.trust.page, which is where the retention windows quoted on this page come from. Re-read all three — the DPA, the Generative AI Services Terms and the Trust Center — before relying on this table.

Why "explicitly excluded" is the wrong phrase

What secondary sources say

Two claims circulate widely. The first is that GitHub Copilot is explicitly excluded from BAA coverage — phrased as though Microsoft or GitHub had written the product's name into a HIPAA carve-out. The second runs the opposite way: that buying GitHub Enterprise through a Microsoft Enterprise Agreement pulls it under the Microsoft BAA. A third, softer error is quoting the line "Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated" as GitHub's current position.

  • Blog posts claiming GitHub Enterprise is BAA-covered through a Microsoft Enterprise Agreement — baagenerator.com is one — a claim contradicted by Microsoft's own in-scope list, which omits GitHub entirely.
  • Articles that quote the retention promise from the GitHub Copilot Product Specific Terms without noting the page is now marked [Archive] and was deprecated on 5 March 2026.
  • The framing "GitHub Copilot is explicitly excluded from HIPAA coverage," repeated across compliance-tool blogs, which no GitHub or Microsoft document supports.

What the vendor's own documentation says

We searched GitHub's Data Protection Agreement and its Generative AI Services Terms for the word Copilot. Neither contract names it in its body at all — the only hits on either page are site navigation and a footer link. The §12 clause that mentions HIPAA never names a product; it applies to "Online Services," defined as any service or software GitHub provides under a written and executed agreement. On the Microsoft side, the string GitHub occurs zero times on Microsoft's HIPAA/HITECH in-scope services page and zero times in the Microsoft Product and Services DPA. The Microsoft Product Terms for GitHub Offerings — the exact document the Generative AI Services Terms route Microsoft-channel customers to — points GitHub Copilot Business and Enterprise at the GitHub DPA, not the Microsoft DPA. And the "deleted once Suggestions are generated" sentence comes from the Copilot Product Specific Terms, a page now flagged [Archive] and deprecated effective 5 March 2026; the sentence does not appear in the replacement.

How we resolve it

The honest form of the answer is absence plus a general prohibition, and it lands harder than the exaggeration. Nobody at GitHub or Microsoft wrote "GitHub Copilot is excluded from the BAA." What they wrote is a customer-side ban on sending GitHub any PHI, covering every product GitHub sells, and a closed list of Microsoft services the BAA covers with GitHub nowhere on it. If you tell your auditor there is a named exclusion, they will go looking for it, fail to find it, and start doubting the rest of your file. Say instead: no BAA is offered, the DPA prohibits PHI by default, and the service is absent from the only published scope list. All three are checkable in a browser.

Where a pasted patient record actually goes

Copilot Chat in the editor, and the file you had open when you asked

High

The prompt is not only what you typed. GitHub's own Trust Center describes a prompt as covering the context sent along with your chat or code input for Copilot's AI to generate suggestions. So the failing test fixture on your screen, the seed file with three real names in it, the error string containing a medical record number — that context travels with the question. In the retention answer it publishes for Business and Enterprise customers, GitHub states that for IDE chat, code completions and Copilot CLI, inputs and outputs are not retained by default, with a carve-out for investigating confirmed policy violations. Not retained is not the same as never sent, none of it is under a BAA, and for a personal seat we found no matching published window — the Trust Center answer for Free, Pro, Pro+ and Max subscribers covers what the data is used for, not how long it is kept.

How to check

Open your editor's Copilot Chat history and search it for a real surname, a record-number prefix, or your clinic's email domain. Do this on the machine of whoever debugs production data, not your own.

The Copilot coding agent working in the cloud

High

This is the surface with the longest memory. In its retention answer for Business and Enterprise customers, GitHub states that Copilot Coding Agent session logs are retained for the life of the account in order to provide the service. An agent that reads your repository, runs the test suite and opens a pull request will pull whatever is in those files into its session — and if your fixtures carry real records, that text sits in a log with no stated deletion date.

How to check

On GitHub.com, list the pull requests Copilot opened on any repository that touches patient data, and read the session record attached to one of them. Then ask whether the branch it worked from contained real fixtures.

Copilot on the web, on mobile, and anywhere outside the editor

High

GitHub splits its retention answer — the one scoped to Business and Enterprise customers — in two. Editor chat, completions and CLI are not retained by default; everything the answer calls "Other GitHub Copilot access and use" defaults to inputs and outputs retained for up to 28 days. For the individual plans there is no matching window published anywhere we could find: the Trust Center answer for Free, Pro, Pro+ and Max subscribers covers what the data is used for, including model training, not how long it is kept. This is precisely the surface a founder or a product manager reaches for — asking Copilot on the website to explain a query result that they pasted in with the rows still attached — and precisely the kind of seat those people tend to be on.

How to check

Ask who on the team uses Copilot outside an editor, then open the Copilot conversation history on GitHub.com for those accounts and read the last month of prompts.

Individual seats where training is the default

High

GitHub documents that from April 24, 2026, on Copilot Free, Pro, Pro+ or Max plans it may use interactions with GitHub features and services — including inputs, outputs, code snippets, and associated context — to train and improve AI models. It is opt-out, not opt-in. Business and Enterprise seats do not carry this default, and GitHub deliberately hides the toggle on them. One contractor on a personal Pro seat is enough to put pasted context into a training pipeline.

How to check

For each individual account, open personal settings for GitHub Copilot and look for the dropdown "Allow GitHub to use my data for AI model training." If the dropdown is visible and not set to Disabled, training is on. If it is not visible at all, that account is on a Business or Enterprise licence.

The model providers behind the prompt

Medium

Prompts leave GitHub. GitHub names OpenAI, Anthropic PBC, Amazon Web Services (Bedrock), Google Cloud Platform, xAI and its own Azure infrastructure as the hosts behind Copilot models, and states it maintains zero data retention agreements with OpenAI and with Anthropic for generally available Anthropic features. The exceptions are documented and narrow: Anthropic features in beta or public preview — including tool search via the Messages API — are not covered by that agreement, and GitHub warns that when Claude Fable 5 is used, Anthropic retains data, including prompts and outputs, to operate safety classifiers. Zero retention is a good engineering property. It is not a business associate agreement, and there is no BAA anywhere in this chain.

How to check

Open the model picker in Copilot Chat and note which model your team actually has selected, and whether anyone has enabled a preview feature. Then ask what was pasted while that model was selected.

Screenshots handed to Copilot Vision

Medium

The fastest way to describe a broken screen is to screenshot it — and a screenshot of a live dashboard carries names, dates of birth and diagnoses that no code review would ever have let through. In the same Business and Enterprise retention answer, GitHub states that images submitted to Copilot Vision are processed for content-safety screening, deleted from active processing systems within 48 hours of submission unless flagged for further review, and within 30 days if flagged.

How to check

Search your team chat for the phrase "here's a screenshot" alongside anything about Copilot, and ask whether the screen shown was staging data or production.

Six checks, each answerable in about a minute

One of these is a question for whoever holds your contracts, two are questions you put to your teammates about what they actually use, and the rest you can answer from a settings page or a repository if you have admin access. Run them before you pay anybody — us included — because the answers decide whether there is a project here at all.

  1. 01Can anyone in your company produce a signed BAA that names GitHub or GitHub Copilot?

  2. 02Is anyone touching your codebase on a Copilot Free, Pro, Pro+ or Max plan rather than a Business or Enterprise seat?

  3. 03Do any of your repositories contain real records — a seed file, a test fixture, an exported CSV, a committed log — rather than synthetic data?

  4. 04Has the Copilot coding agent run on any repository whose files contain real patient data?

  5. 05Does anyone use Copilot on the GitHub website or on mobile — not inside an editor?

  6. 06Is anyone using Claude Fable 5 in Copilot, or an Anthropic feature marked beta or public preview?

What we do about it

Typical range

$13,000–$25,000

Typical timeline

6–10 weeks

  1. 01

    Prompt exposure map

    3–5 days

    A one-page map of every Copilot surface your team touches — editor chat, CLI, web, mobile, coding agent, Vision — each marked with the retention GitHub publishes for it or with the fact that it publishes none for that licence, which seats are individual versus Business or Enterprise, and which repositories the agent has run on. Dated, with the source page beside each line.

  2. 02

    Real records out of the repositories

    2–3 weeks

    Every seed file, test fixture, sample export and committed log carrying real data replaced with synthetic equivalents that keep the same shape, so the tests still mean something. A written list of what was found, what replaced it, and what remains in history.

  3. 03

    Seat, policy and model lockdown

    1–2 weeks

    Individual seats consolidated onto Business or Enterprise licences or opted out of training; the coding agent disabled on repositories that touch patient systems; a model policy that keeps the team off surfaces GitHub documents as retaining data. Each change shown as a before-and-after screenshot.

  4. 04

    Separating the data plane from the assisted workflow

    1–2 weeks

    The paths where a developer currently needs live records to debug — support tooling, admin screens, error reporting — rebuilt so the same work can be done against masked data, with the systems that genuinely hold PHI kept on vendors that do sign a BAA.

  5. 05

    Access and audit trail

    1 week

    Repository and organisation access narrowed to named individuals, logging switched on where the platform offers it, and an exported sample showing who could reach production data and who actually did.

  6. 06

    Handover pack

    1 week

    A written document with the exposure map, the checks we ran, the dated vendor pages behind each decision, the rule your team now follows about what may be pasted, and an explicit list of what remains your responsibility — the thing your auditor asks for.

What moves the number

  • How many people hold Copilot seats, and how many of those are individual plans bought on expenses rather than issued by your organisation.
  • Whether real records reached the repositories only in fixtures, or also in committed logs and exports — history is slower to account for than a working tree.
  • Whether the coding agent has run on repositories holding real data, since life-of-the-account session logs cannot be aged out by waiting.
  • How much of your debugging genuinely requires live records today, because building the masked path is the difference between a policy and a habit that survives.
  • Whether other vendors touch the same data — a payments provider, an email service, a separate AI API — because each one needs its own agreement and its own review.

When not to hire us

  • You have no real PHI yet. A prototype on synthetic data needs none of this, and doing it before the product shape settles usually means doing it twice.
  • Your team is three people on Business seats with synthetic fixtures. Then this is a rule written on a wiki page, not a project — the self-check above is the whole audit.
  • What you actually need is a BAA for the systems that hold the data. That is signed with those vendors directly, and no amount of consulting produces one for GitHub, because GitHub does not offer one.
  • You are shopping for a compliance certificate. There is no government HIPAA certification, so nobody can sell you one — us included.
Our free GitHub guides

Worth knowing either way

There is no government HIPAA certification

No authority certifies software as HIPAA-compliant. What exists is a signed Business Associate Agreement with every vendor that touches protected health information, plus the administrative, physical and technical safeguards you implement and document yourself.

SOC 2 is not a substitute for a BAA

Supabase states it plainly in its own documentation: “SOC 2 does not cover, nor is it a substitute for, compliance with the Health Insurance Portability and Accountability Act (HIPAA).” The same holds for every vendor here.

An absence of documentation is not a vendor promise

Several answers here rest on what vendor documents do not say. We name which documents we read and when. A vendor that has never published a HIPAA position may still decline to sign, and one that publishes nothing today may publish something next quarter.

The same question, for the other fifteen tools

Sources, quoted as printed

Every claim above traces to one of these entries. Quotes are reproduced as printed on the source page, and each entry carries one contiguous passage — where a document says something in two separate places, each place gets its own entry, and no ordering or adjacency between entries is implied. Where an entry rests on something not being present in a document, the quote column reads "no such statement found" and records which pages we searched and for which strings, rather than dressing our own search result up as a sentence the vendor never wrote.

  1. GitHub's Data Protection Agreement carries a section headed for HIPAA, and what sits under that heading is a prohibition on the customer rather than an offer of an agreement. It opens with a general ban on providing GitHub certain categories of personal data, then lists those categories in lettered subclauses. The clause never names a product: we searched the contract body for the word Copilot and found it only in the site navigation and a footer link.

    12. CJIS Customer Agreement, HIPAA Business Associate, Biometric Data. Except with GitHub's prior, written, and specific consent, You shall not provide GitHub any Personal Data:

    GitHub Data Protection Agreement — §12 heading and opening clauseSource dated: Version: October 2025Checked: August 2026
  2. Protected health information is subclause B of that list — the item that decides this page. It is quoted here on its own, apart from the other lettered subclauses in the same list.

    B. constituting protected health information governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191) or by state health or medical privacy laws;

    GitHub Data Protection Agreement — §12.BSource dated: Version: October 2025Checked: August 2026
  3. That prohibition reaches Copilot through the current governing terms for customers on a volume licence: using a Generative AI Service is agreeing to the Data Protection Agreement.

    By using Generative AI Services, you agree to the General Terms unless you and GitHub already have another Agreement in place, and you agree to the Data Protection Agreement unless your Agreement with GitHub includes a different data protection agreement.

    GitHub Generative AI Services TermsSource dated: Version: March 2026Checked: August 2026
  4. And the same document says, in its definitions, which agreement that is — by name and by URL.

    "Data Protection Agreement" means the GitHub Data Protection Agreement at gh.io/dpa.

    GitHub Generative AI Services Terms — definitionsSource dated: Version: March 2026Checked: August 2026
  5. Which GitHub contract you are under depends on how you bought Copilot, and the terms name three paths. A volume licensing agreement puts you under the Generative AI Services Terms and through them the DPA, with its PHI prohibition. Buying through Microsoft routes you to the Microsoft Product Terms for GitHub Offerings, which point Copilot Business and Enterprise back at the GitHub DPA. A personal plan is governed by the GitHub Terms of Service instead — and we cloned GitHub's public site-policy repository, 63 policy documents including that Terms of Service and the General Privacy Statement, and searched every one: HIPAA, business associate and protected health information appear in none of them.

    B. Personal Customers. If you do not purchase GitHub under a volume licensing agreement, this document does not apply to you. Your use of GitHub is instead governed by the GitHub Terms of Service, including the GitHub Terms for Additional Products and Features. C. Microsoft Customers. If you purchase GitHub through Microsoft, this document does not apply to you. Your use of Generative AI Services is instead governed by your Microsoft agreement's Product Terms, including its Microsoft Product Terms for GitHub Offerings.

    GitHub Generative AI Services Terms — §1.B–1.CSource dated: Version: March 2026Checked: August 2026
  6. GitHub's public policy corpus offers no BAA and says nothing about HIPAA. We cloned the github/site-policy repository — 63 Markdown policy documents, including the GitHub Terms of Service that governs personal plans, the Corporate Terms of Service, the General Privacy Statement and the Subprocessors list — and searched every one of them. This row records an absence, so the quote column marks that absence rather than quoting wording. It does not mean GitHub never writes the word: the Data Protection Agreement quoted above is hosted at github.com/customer-terms, outside this repository, and it does contain the HIPAA clause.

    no such statement found — searched all 63 policy documents in the github/site-policy repository for "HIPAA", "business associate" and "protected health": zero occurrences of each. RapidDev search, August 2026 — this is our search result, not a GitHub statement.

    GitHub site-policy repository — 63 published policy documentsSource dated: GitHub General Privacy Statement — effective date: April 27, 2026Checked: August 2026
  7. The same terms state in their own words that they replaced the older Product Specific Terms most competing articles still quote.

    D. Earlier Terms Replaced. This document replaces the Product Specific Terms for all Generative AI Services that were in effect before 5 March 2026.

    GitHub Generative AI Services Terms — §1.DSource dated: Version: March 2026Checked: August 2026
  8. The document most competing articles still quote for Copilot's retention promise has been retired. GitHub prints the deprecation notice on the page itself.

    NOTE: These terms have been deprecated effective 5 March 2026. New subscriptions and renewals that occur on 5 March 2026 and later are not governed by this document, and are instead governed by the GitHub Generative AI Services Terms available at gh.io/terms.

    GitHub Copilot Product Specific Terms [Archive]Source dated: Version: October 2024, deprecated effective 5 March 2026Checked: August 2026
  9. Microsoft's HIPAA BAA arrives through its Data Protection Addendum and is scoped by a published list of in-scope services. We searched that page for the string GitHub and found zero occurrences, while Azure DevOps Services — Microsoft's other developer platform — is on the list.

    The Microsoft HIPAA Business Associate Agreement is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA. See 'Microsoft in-scope cloud services' on this webpage for the list of cloud services covered by this BAA.

    Microsoft Learn — HIPAA and the HITECH ActSource dated: Last updated on 2025-07-29; updated_at 2026-06-02Checked: August 2026
  10. The other Copilot — Microsoft's Office assistant — is named on that same in-scope list, in the Office 365 Commercial row. Same compliance page, same word in the product name, opposite answer.

    Access Online, Azure Communications Service, Compliance Manager, Customer Lockbox, Delve, Exchange Online, Forms, Griffin, Identity Manager, Lockbox (Torus), Microsoft 365 Copilot, Microsoft 365 Copilot Chat, Microsoft Defender for Office 365…

    Microsoft Learn — HIPAA and the HITECH Act, Office 365 in-scope servicesSource dated: Last updated on 2025-07-29; updated_at 2026-06-02Checked: August 2026
  11. Microsoft has renamed the covered product, and the HIPAA compliance page still uses the older names — which is why searching for either name matters when you check this yourself.

    Microsoft 365 Copilot is now named Microsoft Copilot, and Microsoft 365 Copilot Chat is now named Microsoft Copilot Chat.

    Microsoft Learn — Microsoft 365 Copilot data privacySource dated: ms.date 2026-07-09; updated_at 2026-08-18Checked: August 2026
  12. Buying GitHub through Microsoft does not move Copilot under the Microsoft BAA. The Microsoft Product Terms for GitHub Offerings — the document GitHub's own terms route Microsoft-channel customers to — point GitHub Copilot Business and Enterprise at the GitHub DPA. The strings HIPAA, Business Associate and protected health each occur zero times in it.

    GitHub Core Online Services The term "GitHub Core Online Services" applies only to the services in the table below, excluding any Previews. Online Services | GitHub Copilot Business | GitHub Copilot Enterprise | GitHub Enterprise (with data residency enabled) Security Practices and Policies for GitHub Core Online Services In addition to the security practices and policies for Online Services in the GitHub DPA, each GitHub Core Online Service also complies with the control standards and frameworks shown in the table below and implements and maintains the security measures set forth in Attachment 2 of the GitHub DPA for the protection of Customer Data.

    Microsoft Product Terms for GitHub Offerings (EA/EAS)Source dated: Effective date selector lists 8/10/2026 as the most recent versionChecked: August 2026
  13. The Microsoft BAA lives inside the Microsoft DPA, and that DPA says the BAA's own full text is what identifies the services covered. We downloaded and searched the May 2026 DPA: the string GitHub occurs zero times in it. The full BAA text at aka.ms/BAA redirects to a Service Trust Portal page that served no readable document when we tried, so we cannot report what the controlling annex says.

    HIPAA Business Associate If Customer is a "covered entity" or a "business associate" and includes "protected health information" in Customer Data or Professional Services Data, as those terms are defined under the Health Insurance Portability and Accountability Act of 1996, as amended, and the regulations promulgated thereunder (collectively, "HIPAA"), execution of Customer's agreement includes execution of the HIPAA Business Associate Agreement ("BAA").The full text of the BAA identifies the Online Services or Professional Services to which it applies and is available at http://aka.ms/BAA.

    Microsoft Product and Services Data Protection AddendumSource dated: Summary of Changes: 05/22/2026Checked: August 2026
  14. GitHub publishes concrete retention windows in its Copilot Trust Center, and the answer carries its own scope: the question above it reads "How long does GitHub retain Copilot data for Business and Enterprise customers?" Within that scope the editor surfaces are the least exposed, though the same answer adds that GitHub may retain inputs and outputs for a limited period where it needs to investigate confirmed violations of its Acceptable Use Policies or Terms of Service. We also searched the Trust Center's published answers for a matching window for the Free, Pro, Pro+ and Max plans and found none; the answer for those subscribers describes what the data is used for, not how long it is kept. This Trust Center is what replaced GitHub's static Copilot privacy statements: the Copilot Privacy Statement URL now returns 404 and the Copilot Business Privacy Statement redirects here.

    Access through IDE for Chat, Code Completions, and Copilot CLI: - Inputs and Outputs: Not retained by default.

    GitHub Copilot Trust Center — data retention FAQ, editor surfacesSource dated: Not dated on the page; retrieved August 2026Checked: August 2026
  15. Everywhere outside the editor, the same answer sets a default window instead of no retention. This is the bucket the web, mobile and browser surfaces fall into.

    Other GitHub Copilot access and use: - Inputs and Outputs: Retained for up to 28 days by default.

    GitHub Copilot Trust Center — data retention FAQ, surfaces outside the editorSource dated: Not dated on the page; retrieved August 2026Checked: August 2026
  16. The coding agent is the surface with no end date at all. Same answer, same Business and Enterprise scope.

    - Copilot Coding Agent: Session logs are retained for the life of the account in order to provide the service.

    GitHub Copilot Trust Center — data retention FAQ, coding agentSource dated: Not dated on the page; retrieved August 2026Checked: August 2026
  17. Screenshots go through a separate path. GitHub says in the same answer that it deletes images from active processing systems within 48 hours of submission unless they are flagged for further review, and within 30 days if they are.

    - Copilot Vision: We process images submitted to Copilot Vision for content-safety screening.

    GitHub Copilot Trust Center — data retention FAQ, Copilot VisionSource dated: Not dated on the page; retrieved August 2026Checked: August 2026
  18. Neither of GitHub's trust centres publishes a HIPAA position — the one place a vendor advertises this if it has one. We read the published FAQ answers and the framework lists on both the GitHub Copilot Trust Center (39 answers) and the GitHub Enterprise Trust Center (28 answers). The frameworks they do list are SOC 1, SOC 2, SOC 3, ISO 27001, ISO/IEC 42001, CSA STAR Level 2 and TISAX. Both pages render only in a browser, so open them and search their own FAQs if you want to repeat this.

    no such statement found — searched the published FAQ answers on copilot.github.trust.page and ghec.github.trust.page for "HIPAA", "business associate" and "protected health": zero occurrences of each, and HIPAA appears on neither site's list of compliance frameworks. RapidDev search, August 2026 — this is our search result, not a GitHub statement.

    GitHub Enterprise Trust Center (and the GitHub Copilot Trust Center)Source dated: Not dated on the page; retrieved August 2026Checked: August 2026
  19. Prompts leave GitHub for named model hosts — OpenAI, Anthropic PBC, Amazon Web Services (Bedrock), Google Cloud Platform, xAI and GitHub's own Azure infrastructure. GitHub states its retention position for each. For OpenAI it is one sentence.

    GitHub maintains a zero data retention agreement with OpenAI.

    GitHub Docs — Copilot AI model hosting, OpenAISource dated: Not dated on the page; retrieved August 2026Checked: August 2026
  20. The Anthropic agreement is scoped, and GitHub prints the scope on the same page.

    Anthropic PBC: GitHub maintains a zero data retention agreement with Anthropic for generally available Anthropic features in GitHub Copilot. Some Anthropic features in beta or public preview—including tool search via the Messages API—are not covered by this agreement.

    GitHub Docs — Copilot AI model hosting, AnthropicSource dated: Not dated on the page; retrieved August 2026Checked: August 2026
  21. And one model carries a warning of its own, in GitHub's own words.

    Warning: When Claude Fable 5 is used, Anthropic retains data, including prompts and outputs, to operate safety classifiers that detect harmful use.

    GitHub Docs — Copilot AI model hosting, model-specific warningSource dated: Not dated on the page; retrieved August 2026Checked: August 2026
  22. On the individual tiers, training on what you paste became the default in April 2026, and it is opt-out.

    Starting on April 24, 2026, if you have a Copilot Free, Copilot Pro, Copilot Pro+, or Copilot Max plan, GitHub may use your interactions with GitHub features and services—including inputs, outputs, code snippets, and associated context—to train and improve AI models.

    GitHub Docs — Managing Copilot policies as an individual subscriberSource dated: Not dated on the page; change effective April 24, 2026Checked: August 2026
  23. GitHub sells into healthcare without ever claiming HIPAA support. On its healthcare solutions page the words HIPAA, business associate and protected health each occur zero times, and the words compliance and regulatory do not appear in the page body — while the page does invite you to build patient-facing software.

    Healthcare solutions Empower healthcare development with a secure, AI-powered platform. By incorporating AI into developer workflows, you can build secure patient care solutions at scale.

    GitHub — Healthcare solutionsSource dated: Not dated on the page; retrieved August 2026Checked: August 2026

Frequently asked questions

Our compliance lead says GitHub Copilot is explicitly excluded from the BAA. Where is that written?

It is not written anywhere, and you should stop repeating it before an auditor asks. We searched GitHub's Data Protection Agreement and its Generative AI Services Terms: neither names Copilot in its contract body at all. What exists instead is broader, not narrower — §12 of the DPA tells the customer not to provide GitHub protected health information at all, absent GitHub's prior, written, and specific consent, and it applies to every service GitHub provides, for every customer whose contract includes that DPA. Add to that GitHub's absence from Microsoft's published in-scope services list and you have the real answer: no BAA is offered, PHI is contractually prohibited by default, and there is no product-specific carve-out to point at.

We buy GitHub through our Microsoft Enterprise Agreement. Doesn't our Microsoft BAA cover it?

No, and this one has an affirmative answer rather than an absence. GitHub's own terms send Microsoft-channel customers to the Microsoft Product Terms for GitHub Offerings — and that document points GitHub Copilot Business and Enterprise at the GitHub DPA, not the Microsoft DPA. It matters because the Microsoft BAA lives inside the Microsoft DPA, and the GitHub DPA is the one carrying the PHI prohibition. The string GitHub occurs zero times in the Microsoft DPA and zero times on Microsoft's HIPAA in-scope services page.

Does Copilot Business or Enterprise change the answer?

Not the BAA answer — there is no BAA on any tier. It changes two other things that matter operationally. Business and Enterprise seats are not subject to the training default that applies to Free, Pro, Pro+ and Max as of April 24, 2026, and GitHub deliberately does not show those accounts the training toggle at all. If you are going to use Copilot in a company that touches patient data, being on Business or Enterprise is the floor, not the fix.

A developer pasted a row from the patients table into Copilot Chat last month. What actually happened to it?

It depends on which surface they used and on which licence that account holds. For Business and Enterprise customers GitHub publishes a window per surface: in the editor — chat, code completions or the CLI — inputs and outputs are not retained by default, with a carve-out for investigating confirmed policy violations; anywhere else, inputs and outputs are retained up to 28 days by default; through the coding agent, session logs are retained for the life of the account. For Free, Pro, Pro+ and Max seats we found no published retention window — GitHub's answer for those subscribers covers what the data is used for, including model training, rather than how long it is kept. In every case the text also went to a model host: OpenAI, Anthropic, AWS Bedrock, Google Cloud or xAI, depending on the model selected. Find out which surface and which licence first; the rest follows from that.

GitHub has zero data retention agreements with OpenAI and Anthropic. Isn't that as good as a BAA?

It is a genuinely useful property and it is not the same thing. A BAA is a contract in which a vendor accepts business-associate obligations for protected health information. A zero-retention agreement is a commitment about how long prompts are kept. Read GitHub's own wording closely, too: the Anthropic agreement covers generally available features, beta and preview features including tool search via the Messages API are outside it, and GitHub warns that when Claude Fable 5 is used, Anthropic retains prompts and outputs to operate safety classifiers. Good hygiene, no BAA in the chain.

Is GitHub Copilot HIPAA certified?

Nothing is. There is no government HIPAA certification for a product or a company — the mechanism is a signed Business Associate Agreement with each vendor that touches protected health information, plus the safeguards you implement and document yourself. What GitHub does publish for Copilot Business and Enterprise is SOC 1, SOC 2, SOC 3, ISO 27001, ISO/IEC 42001, CSA STAR Level 2 and TISAX. HIPAA is not among them, and none of those is a substitute for a BAA.

Could we get GitHub's written consent under that carve-out and use Copilot with PHI anyway?

The clause contemplates it, so we will not tell you it is impossible — but we could find no route to it. Compare it with the FERPA clause sitting immediately beside it in the same contract, which spells out what a customer must obtain: consent expressly reciting GitHub's agreement to accept that data, plus a separate agreement with GitHub. The HIPAA clause names no such process, no contact and no eligible tier; no GitHub document we read offers a BAA or describes how to request one; and neither of GitHub's trust centres lists HIPAA among its published compliance frameworks or answers a question about it. Plan on the answer being no.

This page reports what GitHub's and Microsoft's published documents said on the dates shown and is technical information rather than legal advice; HIPAA compliance is a property of your whole system and the processes around it, not of any single tool, and vendor terms change — GitHub replaced its Copilot terms in March 2026 and changed its individual-tier training default in April 2026, so verify the current documents before relying on anything here.

Matt Graham

Written by

Matt Graham · CEO & Founder, RapidDev

1,000+ client projects delivered. Columbia University & Harvard Business School alumnus, U.S. Navy veteran. About the author →

Ready when you are

Fixed price, fixed timeline: $13K–$25K, 6–10 weeks, production-grade code you own. Book a call and get a custom quote at no cost.

Get your custom quote

We put the rapid in RapidDev

Need a dedicated strategic tech and growth partner? Discover what RapidDev can do for your business! Book a call with our team to schedule a free, no-obligation consultation. We'll discuss your project and provide a custom quote at no cost.