The question has no yes or no answer. OpenClaw is MIT-licensed software from the non-profit OpenClaw Foundation that you run on your own machine, so there is no hosted service to buy and nobody to sign a Business Associate Agreement with — and no OpenClaw document we could find mentions HIPAA, PHI or a BAA. The obligation moves to whoever you wire in: the configured model provider, the ClawRouter proxy that ships bundled and enabled by default, the chat app you message the gateway from, and any ClawHub skills installed on it.
| Fact | Value |
|---|---|
| Tool | Openclaw |
| Verdict | Not the right question |
| Sources checked | August 2026 |
| Typical range | $13,000–$25,000 |
| Typical timeline | 6–10 weeks |
| Last updated | August 2026 |
Who is in the prompt path, and who could sign anything
There is no OpenClaw BAA, so no row below can read "covered" on OpenClaw's own paperwork. What this table sorts is something more useful: which parties actually receive prompt text, and which of them is a counterparty you could hold an agreement with. "Conditional" means the party can be governed by an agreement — but by their agreement, signed by you, not by anything OpenClaw publishes.
Your PHI
Your Openclaw app
Inside the agreement — PHI may live here
- Configured model providers (OpenAI, Anthropic, Google Gemini, Mistral, Cohere, xAI, DeepSeek, Groq, OpenRouter and around forty more)· conditional
- Local model runtimes (Ollama, llama.cpp, LM Studio, vLLM, SGLang)· conditional
- Channel plugins (Discord, Google Chat, iMessage, Matrix, Microsoft Teams, Signal, Slack, Telegram, WhatsApp, Zalo and others)· conditional
Outside it — PHI here is a gap
- OpenClaw Gateway (the self-hosted process on your machine or server)
- ClawRouter (clawrouter.openclaw.ai) — vendor-operated model proxy
- ClawHub registry (clawhub.ai) and its install telemetry
- OpenClaw mobile apps for iOS and Android, and the Chrome extension
- HealthKit day summary (the health.summary node command)
- ElevenLabs talk mode and platform speech recognition
| Service | Under the BAA | Condition |
|---|---|---|
| OpenClaw Gateway (the self-hosted process on your machine or server) | Not covered | Nothing to cover and nobody to sign. The docs describe a single Gateway process you run on your own machine or a server, and the homepage says state lives on your machine rather than a vendor cloud. Absence of a vendor is not the same as coverage — the host itself is now your responsibility. |
| ClawRouter (clawrouter.openclaw.ai) — vendor-operated model proxy | Not covered | The plugin ships bundled with OpenClaw and is enabled by default; it carries traffic once a ClawRouter credential is configured, and then prompts and completions pass through infrastructure on an openclaw.ai subdomain. Its documentation refers to a content-retention state without publishing what that state is. No BAA, no DPA, no privacy policy. |
| Configured model providers (OpenAI, Anthropic, Google Gemini, Mistral, Cohere, xAI, DeepSeek, Groq, OpenRouter and around forty more) | Conditional | This is where a BAA can genuinely exist. Each provider is governed by its own terms and its own agreement with you, not by anything OpenClaw publishes. OpenClaw's privacy policy states that services your gateway forwards data to handle it under their own policies. |
| Local model runtimes (Ollama, llama.cpp, LM Studio, vLLM, SGLang) | Conditional | If inference runs on hardware you control, no third party receives the prompt for that step, so there is no counterparty to sign with. Conditional on the gateway actually being pointed at the local runtime for the agents that see sensitive text — not at ClawRouter or a hosted provider for some of them. |
| Channel plugins (Discord, Google Chat, iMessage, Matrix, Microsoft Teams, Signal, Slack, Telegram, WhatsApp, Zalo and others) | Conditional | Whatever you type reaches the channel operator before the gateway ever sees it, and it stays in that thread afterwards. Each operator is governed by its own agreement with you. For anyone pasting sensitive text into a chat thread, this matters more than the model provider. |
| ClawHub registry (clawhub.ai) and its install telemetry | Not covered | The install event carries the skill slug and version and explicitly not prompts, file contents or per-run logs, it is only sent when you are signed in, and it can be switched off with an environment variable. No prompt path here — but the registry publishes no legal, privacy or terms page, and the skills it distributes run inside an agent with filesystem and messaging access. |
| OpenClaw mobile apps for iOS and Android, and the Chrome extension | Not covered | Governed by the Apps & Browser Extension Privacy Policy, effective 2 August 2026, which contains no HIPAA or BAA terms and states in its own words that it does not cover the gateway, server or AI provider you connect to. |
| HealthKit day summary (the health.summary node command) | Not covered | Off by default and gated behind both an iOS consent step and an explicit gateway authorization. When enabled, the device computes an aggregate on-device, and the docs concede the aggregate reaches the configured AI provider and may remain in chat history. Consumer fitness data, and the vendor disclaims medical use — but it is an outbound health data path in the product. |
| ElevenLabs talk mode and platform speech recognition | Not covered | The privacy policy states that enabling talk mode with ElevenLabs may send text and voice configuration to ElevenLabs. Optional, off unless you turn it on, and governed by ElevenLabs rather than by OpenClaw. |
Almost nothing here is dated. The only OpenClaw document carrying an effective date is the Apps & Browser Extension Privacy Policy — 2 August 2026. The documentation pages behind every other row show no effective or last-updated stamp, so the only anchor is the date we read them: 26 August 2026. Defaults in an open-source project also move with releases; ClawRouter being bundled and enabled by default is a shipping decision, not a contract term, so re-read the ClawRouter page after any upgrade rather than trusting this table.
Why "it's self-hosted, so nothing leaves the machine" is only half the answer
What secondary sources say
The self-hosted framing gets repeated until it becomes an absolute: the software runs locally, therefore no third party is in the path, therefore compliance is entirely an on-premise question. Our own pre-verification draft of this page carried a version of it too, describing OpenClaw as an open-source AI coding tool with roughly 342,000 stars.
- Our own pre-verification draft of this page, corrected on 26 August 2026 before publication.
- Copies of the OpenClaw documentation served from addresses other than the project's own. The canonical properties are openclaw.ai, docs.openclaw.ai, openclaw.org and clawhub.ai; anything published elsewhere is not a primary source and nothing on this page rests on one.
What the vendor's own documentation says
The docs describe a self-hosted gateway whose job is to connect chat apps to AI coding agents and dispatch prompts to a configured model provider — around fifty of them are named, most of them hosted. The ClawRouter page documents a proxy at a default URL of https://clawrouter.openclaw.ai, states that the plugin ships bundled and enabled by default, and describes upstream credentials and forwarding staying inside ClawRouter. The GitHub repository describes the product as a personal AI assistant, not a coding tool, and reports more than 380,000 stars.
How we resolve it
Self-hosted describes where the process runs, not where the text goes. The gateway is a router: it receives your message from a chat app that already stored it, and it forwards your prompt to a model that is usually somebody else's. Read the framing as a relocation of the question rather than an answer to it — the correct list of parties to check is your channel operator, your model provider, and whether ClawRouter is sitting between them.
Where a pasted patient detail actually travels
The chat thread you message the gateway from
HighThis is the first and most-missed hop. You describe the bug to your assistant in Slack, Telegram, WhatsApp or Discord, and that message is stored by the channel operator before the gateway process ever reads it. The gateway being local changes nothing about it, and the thread keeps the text long after the agent has answered.
How to check
Open the thread you use to talk to your bot and search it for a real surname, a real record number prefix, or an email domain you know belongs to a patient. Read what comes back rather than counting hits.
ClawRouter, if a credential for it is configured
HighThe ClawRouter plugin ships bundled with OpenClaw and is enabled by default, and it carries traffic as soon as a ClawRouter credential exists. From that point every prompt and completion for the agents using it passes through a proxy on an openclaw.ai subdomain, run by the project rather than by you. Its own docs mention a content-retention state; no retention window, privacy policy or agreement is published anywhere.
How to check
Open your gateway configuration and read which provider each agent is pointed at, then look for a ClawRouter credential. Any model reference naming clawrouter, or a stored ClawRouter key, means the proxy is in the path.
The configured model provider's own retention
HighWhatever survives the first two hops lands with OpenAI, Anthropic, Google or whichever of the roughly fifty providers is configured — under that provider's terms and that provider's retention, not under anything OpenClaw publishes. OpenClaw's own privacy policy says as much: services your gateway forwards data to handle it according to their own policies.
How to check
Read your gateway configuration for which provider API key is set, then find out whose account that key belongs to. Then ask that account owner one question: is there a signed BAA on that account, and does it cover the API you are calling?
Conversation state on the gateway host
MediumThe project's selling point is that state lives on your machine rather than a vendor cloud. That is a real privacy gain and a real custody problem: the transcript of everything anyone pasted now sits on a machine whose access control, disk encryption and backups are entirely yours to answer for.
How to check
Find out who can log into the machine or server running the gateway, whether its disk is encrypted, and where it backs up to. A laptop syncing to a consumer cloud backup is the case that catches people out.
Skills and plugins installed from ClawHub
MediumClawHub distributes third-party skills that run inside an agent with filesystem and messaging access, and what any given skill does with the text it is handed is that skill's business. The registry itself publishes no legal, privacy or terms page. Separately, the install telemetry is metadata only — slug and version, explicitly not prompts, file contents or per-run logs — so the telemetry is not the risk here; the installed code is.
How to check
List every skill and plugin installed on the gateway and, for each, find the network endpoints it calls. Anything you cannot account for is something that has been handed your prompts.
The HealthKit day summary, if it was ever switched on
LowThe health.summary node command is off by default and needs both consent on the iOS device and an explicit gateway authorization. When it is on, the phone computes an aggregate — steps, sleep duration, average resting heart rate, workout count and duration — and the docs state that the aggregate reaches the configured AI provider and may remain in chat history. Raw samples stay on the device.
How to check
Check whether health.summary appears in your gateway's allowed node commands, and whether any connected iPhone or iPad has granted Health access. If both are true, health aggregates have been flowing to your model provider.
Six checks for whoever has admin on the gateway
Five of these are answerable in a minute by someone with access to the gateway configuration and the chat thread; the sixth is a question for whoever holds your vendor contracts. Run them before paying anyone, us included — the answers decide whether there is a project here at all.
01Is a ClawRouter credential configured on the gateway, or is any agent pointed at a provider entry naming clawrouter?
02Can someone at your company produce a signed BAA with the provider whose API key is in that configuration, covering the API the gateway calls?
03Search the chat thread you use to talk to the bot for a real patient surname or record number — does anything come back?
04Is the machine running the gateway one that only a known, named set of people can log into, with disk encryption on and no consumer cloud backup?
05Do you have a written list of every ClawHub skill and plugin installed on the gateway, and what each one sends outbound?
06Is health.summary present in the gateway's allowed node commands with a connected iPhone or iPad that has granted Health access?
What we do about it
Typical range
$13,000–$25,000
Typical timeline
6–10 weeks
- 01
Prompt path map
3–5 daysA one-page diagram of every hop a message takes — which channel, which gateway, which proxy, which model provider — with each party marked as holding an agreement with you or not, and the date we read each vendor page printed on it.
- 02
Provider re-point
2–3 weeksClawRouter removed from the path, and every agent that touches sensitive text pointed at either a local runtime or a provider account your company holds a BAA with, tested end to end and documented.
- 03
Channel and history cleanup
1–2 weeksThe chat channels searched for identifying content, a written record of what was found, what was deleted and what the operator still retains, and the sensitive channels either retired or moved behind an internal one.
- 04
Skill and plugin inventory
1–2 weeksEvery installed ClawHub skill listed with its outbound endpoints, anything unjustified removed, install telemetry switched off where you want it off, and a written rule for what may be installed in future.
- 05
Host hardening and audit trail
1 weekGateway host access narrowed to named individuals, disk encryption and backup destinations verified, conversation state retention set deliberately rather than by default, and logging in place that shows who ran what.
- 06
Handover pack
3–5 daysA written document with the prompt path map, the checks we ran, the dated source pages behind each decision, and an explicit list of what stays your responsibility — the thing your auditor will ask for.
What moves the number
- How many agents and channels the gateway serves, since every channel is a separate operator and a separate thread of history to account for.
- Whether the model provider can simply be re-pointed, or whether the work means standing up a local runtime with enough capacity to replace a hosted model.
- How much conversation history already exists on the host and in the chat threads, because tracing what is in it takes far longer than stopping new text from arriving.
- How many ClawHub skills and plugins are installed, and how many of them call endpoints nobody can currently account for.
- Whether the gateway host is a personal laptop or a server someone already administers — moving it is a week of work that a well-run server makes unnecessary.
When not to hire us
- You are running a local model runtime already and nothing identifying a patient has ever gone into a chat channel. Then there is no third party in the path and no project here — the self-check above is the whole audit.
- What you actually need is a BAA with your model provider. That is signed with the provider directly, and paying an agency to arrange it is paying an agency to fill in a form.
- You are still experimenting on synthetic data. Do this once the workflow settles, or you will do it twice.
- You are shopping for a compliance certificate. There is no government HIPAA certification, so nobody can sell you one — and an MIT-licensed project run by a non-profit has nothing to certify in the first place.
Worth knowing either way
There is no government HIPAA certification
No authority certifies software as HIPAA-compliant. What exists is a signed Business Associate Agreement with every vendor that touches protected health information, plus the administrative, physical and technical safeguards you implement and document yourself.
SOC 2 is not a substitute for a BAA
Supabase states it plainly in its own documentation: “SOC 2 does not cover, nor is it a substitute for, compliance with the Health Insurance Portability and Accountability Act (HIPAA).” The same holds for every vendor here.
An absence of documentation is not a vendor promise
Several answers here rest on what vendor documents do not say. We name which documents we read and when. A vendor that has never published a HIPAA position may still decline to sign, and one that publishes nothing today may publish something next quarter.
The same question, for the other fifteen tools
Firebase
NoOnly the Google Cloud equivalents are covered — no Firebase-branded service is
Supabase
Yes, with conditionsBAA plus a paid HIPAA add-on, on the Team plan or above
v0 by Vercel
PartiallyVercel hosting is covered; v0 itself is contractually off-limits for PHI
Lovable
NoIts terms prohibit uploading protected health information
Bubble
NoIts own documentation says apps built on Bubble won't achieve compliance
Replit
NoIts Terms, Commercial Agreement and DPA carry no HIPAA or BAA terms
Bolt.new
NoNo BAA in the StackBlitz and Bolt documents we read; HIPAA is named only for self-hosted
FlutterFlow
NoIts terms bar processing HIPAA-protected data outright
Claude Code
Yes, with conditionsCovered only with zero data retention, on accounts Anthropic qualifies
Codex
Yes, with conditionsCodex Local on a Regulated or Healthcare tier; Codex Cloud is excluded
Cursor
Yes, with conditionsEnterprise only, with Privacy Mode locked organisation-wide
GitHub Copilot
NoNo BAA offered; the Data Protection Agreement tells customers not to send PHI
Devin
NoPHI is Prohibited Data under the acceptable-use policy
Hermes Agent
Not the right questionSelf-hosted — the agreement you need is with your model provider
OpenClaw
Not the right questionSelf-hosted — but the vendor-run router still receives prompts
Base44
NoNo BAA; its terms ask customers to keep PHI off the platform
Sources, quoted as printed
Every vendor claim above traces to one of these, quoted as printed on the source page and never spliced together. Two findings on this page are absences rather than statements, so they are described here in our own words instead: first, a case-insensitive search for hipaa, phi, protected health, business associate and baa across https://openclaw.ai/, https://docs.openclaw.ai/, https://openclaw.ai/privacy and https://github.com/openclaw/openclaw returned no matches, and the documentation sitemap at https://docs.openclaw.ai/sitemap.xml — 15,692 URLs — contains no occurrence of hipaa; second, https://clawhub.ai/legal, https://clawhub.ai/privacy and https://clawhub.ai/terms each returned 404, so the registry publishes no legal or privacy document at all. Both are our own observations from fetching those addresses on 26 August 2026, not vendor statements — there is no vendor sentence to quote, which is itself the finding.
OpenClaw is a self-hosted gateway that you run yourself — it connects chat apps to AI coding agents rather than being a service you buy.
OpenClaw is a self-hosted gateway that connects your favorite chat apps — Discord, Google Chat, iMessage, Matrix, Microsoft Teams, Signal, Slack, Telegram, WhatsApp, Zalo, and more via channel plugins — to AI coding agents. You run a single Gateway process on your own machine (or a server)
The software is MIT-licensed and the copyright sits with a foundation rather than a company, which is why there is no commercial counterparty to sign an agreement with.
MIT License Copyright (c) 2026 OpenClaw Foundation
A vendor-operated proxy ships with OpenClaw and is enabled by default, so the self-hosted architecture has a hosted component in the prompt path unless you take it out.
The plugin ships bundled with OpenClaw ( enabledByDefault: true ); you only need an issued ClawRouter credential.
ClawRouter's documentation acknowledges a content-retention state without publishing a retention window, a privacy policy or an agreement.
ClawRouter's own audit event provides the selected upstream provider and content-retention state.
OpenClaw states plainly that anything the gateway forwards is governed by the receiving service, not by OpenClaw — which is exactly why the BAA question moves to your model provider.
If your configured gateway forwards data to AI models or other third-party services, those services will handle data according to their own policies.
OpenClaw — Apps & Browser Extension Privacy PolicySource dated: Effective date: August 2, 2026Checked: August 2026The only OpenClaw document carrying an effective date covers the mobile apps and the browser extension only, and disclaims the gateway, the server and the AI provider.
It does not cover the privacy practices of the gateway, server, AI provider, or other services you choose to connect to through OpenClaw.
OpenClaw — Apps & Browser Extension Privacy PolicySource dated: Effective date: August 2, 2026Checked: August 2026ClawHub install telemetry carries metadata only — no prompt content — so the registry is a supply-chain question rather than a data-leak one.
No folder paths or folder-derived identifiers. No file contents. No per-run logs, prompts, or other CLI output.
The one health data path in the product sends an on-device aggregate outbound to whichever model provider is configured, and it may persist in chat history.
Aggregation happens on the iOS device. Raw samples do not leave the device. The requested aggregate leaves the device through your Gateway. When an agent requests it, the aggregate reaches the configured AI provider and may remain in chat history.
There is no hosted OpenClaw product to buy, which is the structural reason no BAA is on offer.
Personal AI that runs on your hardware, knows your context, and works for you. Not a product you rent from a platform. A tool you own, and a foundation that protects your right to own it.
OpenClaw FoundationSource dated: not shown on the page; latest Foundation blog entry dated 30 July 2026Checked: August 2026
Frequently asked questions
It runs on our own hardware. Doesn't that settle it?
It settles where the process runs, not where the text goes. The gateway is a router: your message reaches a chat operator before the gateway reads it, and your prompt reaches a model provider after. OpenClaw says this itself — "If your configured gateway forwards data to AI models or other third-party services, those services will handle data according to their own policies." Self-hosting removes one vendor from the middle. It does not remove the ones at either end.
What is ClawRouter, and why do you keep bringing it up?
It is a model proxy the project operates at clawrouter.openclaw.ai, and it is the one place the "nothing leaves your machine" story breaks. Its documentation states: "The plugin ships bundled with OpenClaw ( enabledByDefault: true ); you only need an issued ClawRouter credential." So it is on by default and starts carrying traffic the moment a credential exists. It publishes no privacy policy, no data processing agreement and no BAA, and its own docs mention a content-retention state without saying what that state is. If you need a BAA, take it out of the path and point the gateway at a provider you hold an agreement with directly.
Who do we actually sign a BAA with, then?
Whoever receives the data. In practice that is the model provider whose API key is in your gateway configuration, and the operator of any chat channel the gateway is attached to. Neither agreement is arranged through OpenClaw, and neither is affected by anything OpenClaw publishes. The alternative is to have no hosted model in the path at all: the docs list local runtimes including Ollama, llama.cpp, LM Studio, vLLM and SGLang, and inference on hardware you control has no third party to sign with.
Does ClawHub see what our team types?
Not according to its telemetry documentation, which lists what is not collected: "No folder paths or folder-derived identifiers. No file contents. No per-run logs, prompts, or other CLI output." The install event carries the skill slug and version, it is only sent when you are signed in, and it can be switched off with an environment variable. The real ClawHub question is a different one: the registry publishes no legal, privacy or terms page — those addresses return 404 — while the skills it distributes run inside an agent with filesystem and messaging access. Treat it as a supply-chain risk, not a telemetry risk.
We talk to the bot from Slack. Is that a problem?
It is the first hop and the one people forget, because it happens before any of the software you audited is involved. The message sits with the channel operator whether or not the gateway ever processes it, and it stays in the thread afterwards. Open the thread you use, search it for a real surname, and decide based on what comes back. If sensitive text is in there, that is a conversation with the channel operator about their agreement with you — not with OpenClaw.
One of our engineers connected an iPhone. Is Health data flowing somewhere?
Only if someone deliberately switched it on: the health.summary command is off by default and needs both consent on the device and an explicit gateway authorization. If it is on, the phone computes an aggregate — steps, sleep, average resting heart rate, workout count and duration — and the docs are direct about where it goes: "When an agent requests it, the aggregate reaches the configured AI provider and may remain in chat history." Raw samples stay on the device. This is consumer fitness data and the docs disclaim medical use, but it is a real outbound health path and worth checking before someone else does.
Is OpenClaw HIPAA certified?
Nothing is. There is no government HIPAA certification for a product or a company — the mechanism is a signed Business Associate Agreement with every vendor that touches protected health information, plus the safeguards you implement and document yourself. In OpenClaw's case there is an additional reason the question does not land: it is MIT-licensed software from a non-profit foundation, with no hosted service and no commercial counterparty. There is nobody to certify anything, and no OpenClaw document we could find mentions HIPAA.
This page reports what OpenClaw's published documents said on the dates shown and is technical information rather than legal advice; HIPAA compliance is a property of your whole system and the processes around it rather than of any single tool, and both vendor terms and open-source defaults change — verify the current documents and the current configuration before relying on anything here.
