# Is Devin HIPAA compliant? No — Cognition's terms prohibit PHI outright

- Tool: Compliance
- Last updated: August 2026

## TL;DR

No. Cognition publishes no HIPAA Business Associate Agreement for Devin, Devin CLI or Devin Desktop on any plan, and its Acceptable Use Policy places protected health information in the Prohibited Data category. The Enterprise Master Services Agreement goes further and tells customers not to submit PHI to the Services at all. If your team has already pasted patient data into a Devin session, the work is finding out where that text went and rebuilding the workflow without it — six to ten weeks.

## Frequently asked questions

### We're on Enterprise. Doesn't that come with a BAA?

No, and Enterprise is actually the stricter document. The Master Services Agreement says "Customer agrees not to share with Licensor or otherwise submit to the Services any protected health information", and unlike the Acceptable Use Policy it attaches no separate-agreement exception to that sentence. The strings HIPAA and Business Associate do not appear in it at all. Buying the top tier did not buy permission.

### Our security review last quarter said Windsurf offers BAAs. Was that wrong?

It was right when it was written and it is wrong now. Windsurf's own security page, captured on 17 May 2026, said "our platform is maintained as HIPAA compliant and for significant implementations, we will entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance." Cognition renamed Windsurf to Devin Desktop on 2 June 2026 and nothing equivalent exists under the new brand — we searched the whole current documentation corpus for HIPAA and business associate and got zero hits. If your review cites a windsurf.com/security URL, follow it: it now redirects to a Devin page with no HIPAA text on it.

### If we run Outposts on our own hardware, does the prompt still leave?

Yes. Cognition's documentation is explicit that "Devin's agent loop (inference and planning) continues to run in Devin's cloud, while all command execution, file edits, and repository access happen on machines you operate." Outposts relocates execution, not inference. The component that reads your prompt is the one that stays remote, so Outposts changes nothing about the question on this page. Customer Dedicated Deployment has the same shape — single-tenant, still Cognition-hosted.

### We turned off training. Are we clear?

You have stopped the flow forward, which is the right first move and takes ten minutes. Two things it does not do. It does not address sessions already sent, and Cognition's published retention is "for the duration of the relationship with a given Customer" with no fixed window. And it does not lift the prohibition — PHI is Prohibited Data whether or not it is used for training. Also confirm an administrator actually exercised it; on the Teams plan nobody else can.

### Is code with patient identifiers in it PHI?

Code by itself generally is not the issue, and Windsurf made that argument reasonably when it wrote that code "does not carry any PHI itself." What carries PHI is what developers paste beside the code: the failing row, the log line with a name in it, the CSV fixture built from a real export, the error message quoting a record. Those go into the same prompt box and travel the same path. That is why the check we recommend is searching your own session history for a real surname rather than auditing your repository.

### SOC 2 Type II, ISO 27001, FedRAMP High — none of that helps?

Those are real and they are Cognition's own published claims; they tell you something genuine about how the company operates. None of them is a Business Associate Agreement, and none of them makes PHI permissible under terms that prohibit it. Worth knowing too that the federal accreditations split by surface in a way most buyers get backwards: on Cognition's own federal compliance table — which describes its federal deployment running on AWS GovCloud rather than the commercial editor or CLI you install — FedRAMP High, IL4 and IL5 read "In Process" for Devin itself, while Devin CLI and Devin Desktop carry checkmarks. The autonomous cloud agent is the least accredited surface.

### Could we negotiate the separate written agreement the Acceptable Use Policy mentions?

You can ask, and some enterprises will get a conversation. Go in with clear eyes about what that clause is. It is a generic provision covering every Prohibited Data category, it names no plan and no tier, and it never uses the words Business Associate Agreement. So you would be asking Cognition to write something that does not currently exist in published form, and the Enterprise MSA you may already have signed points the other way. Ask in writing, be specific that you need a BAA, and keep the reply whatever it says.

---

Source: https://www.rapidevelopers.com/compliance/is-devin-hipaa-compliant
© RapidDev — https://www.rapidevelopers.com/compliance/is-devin-hipaa-compliant
