# Is Base44 HIPAA compliant? No — and the Wix BAA does not reach it

- Tool: Compliance
- Last updated: August 2026

## TL;DR

No. Base44 offers no Business Associate Agreement on any plan, and its Terms of Service have you warrant that no protected health information will be shared with the Platform. Its parent, Wix.com Ltd., does sign BAAs — but Wix scopes that offer to sites built on the Wix Editor or Wix Studio Editor, and names Base44 nowhere in its HIPAA documentation. Moving the patient-data layer off Base44 takes us 6–10 weeks.

## Frequently asked questions

### Wix owns Base44 and Wix signs BAAs. Why doesn't that cover us?

Because a BAA covers the services it names, and Wix names a different product. Its HIPAA article says: "Wix sites built on the Wix Editor or Wix Studio Editor can be HIPAA compliant. However, you must have a supported Premium or Studio site plan to activate PHI protection." Base44 does not appear in Wix's HIPAA documentation. Wix also ships a PHI-protection toggle and an in-dashboard BAA signing flow for those sites; Base44 ships no equivalent. And the data relationship runs the opposite way to the assumption — Wix.com Ltd. is listed on Base44's own subprocessor directory as a recipient of Base44 data.

### We're on Enterprise with the training opt-out on. Is that enough?

It fixes the training default and nothing else. Base44 states that "Enterprise workspaces are opted out of model training by default", which closes one route, but the Enterprise page mentions no HIPAA and no BAA, and the published Enterprise control set — Security Center, SSO enforcement, SCIM user provisioning, IP allowlist, audit logs, workspace API keys and training opt-out — contains nothing described as a PHI mode. Data residency sits alongside them on Elite and Enterprise plans, for apps created after April 16, 2026, and it moves where records are stored without changing who is answerable for them. The Terms of Service warranty applies on Enterprise the same as on Free, and the prompt still reaches the model providers and the logging vendors listed on the security page.

### The terms say PHI is barred "other than if expressly agreed by the Company in prior writing". Can we just ask?

You can ask, and you should treat it as a sales negotiation with an unknown outcome rather than a BAA you can obtain. It is unadvertised, unpriced and tied to no plan tier — nothing published tells you whether such an agreement has ever been signed. If you do pursue it, settle the counterparty first: the Terms name Wix.com Ltd. as the company, while the Privacy Policy and the Data Processing Agreement still name Base44, Inc. Until something is signed, the warranty in §4.3 is what binds you.

### Base44 is SOC 2 Type II and ISO 27001 certified. Isn't that the same thing?

No. Those are audits of a security programme; a BAA is a contract in which a vendor accepts business-associate obligations for your patient data. Neither audit obliges a vendor to accept those obligations, and there is no certification that confers HIPAA compliance on a product. The tell is on Base44's own enterprise page, where the answer to "Is Base44 secure enough for enterprise?" lists SOC 2 Type II, ISO 27001 and GDPR — three frameworks, on a page built to clear procurement objections, with HIPAA left out.

### We only pasted one real record into the chat to show the model the data shape. Does that matter?

It is the most common way this happens and yes, it counts. Under the Terms that content is Customer Data licensed on terms described as irrevocable and perpetual, extended to third-party service providers, and on tiers below Enterprise it sits under the training licence. The prompt also travels to the model providers on the subprocessor list and to Langfuse in Germany for LLM logging. No retention window is published anywhere. Deleting the message is the right move; knowing what was in it and when is the part you will actually be asked about.

### Can we keep the Base44 front end and move only the patient data?

This is where Base44 differs from tools where you bring your own database. The backend is managed — the directory shows Mongo for storage and Render for server services — so there is no documented way to point the primary app store at a database you hold an agreement for. Base44's own positioning is that it removes the need for third-party integrations, and that is exactly what closes this door. Even if the interface stayed, the prompt box remains inside the §4.3 warranty. Our engagement therefore moves the patient-data layer onto covered infrastructure rather than trying to bolt one onto Base44.

### How long does moving off take, and what does it cost?

Six to ten weeks at $13,000–$25,000 for the engagement described above. The disclosure inventory comes first and is one of the two shortest stages at three to five days, alongside the handover pack that closes the engagement; the data-layer migration off the managed backend is the longest single one. A live user base is what pushes the calendar to the upper end, because the cutover has to happen without downtime. If your app is still on invented data, none of this applies to you yet.

---

Source: https://www.rapidevelopers.com/compliance/is-base44-hipaa-compliant
© RapidDev — https://www.rapidevelopers.com/compliance/is-base44-hipaa-compliant
