# Is GitHub Copilot HIPAA compliant? No — GitHub signs no BAA on any tier

- Tool: Compliance
- Last updated: August 2026

## TL;DR

No. GitHub publishes no Business Associate Agreement for GitHub Copilot on any tier, and for the customers its Data Protection Agreement reaches — those buying under a volume licensing agreement, and those buying through Microsoft, whose Product Terms point Copilot Business and Enterprise back at that same GitHub DPA — the agreement forbids sending GitHub protected health information at all, absent GitHub's "prior, written, and specific consent." Personal plans sit outside it, governed by the GitHub Terms of Service, which says nothing about HIPAA in either direction. Microsoft 365 Copilot — now named Microsoft Copilot — is a different product and is named on Microsoft's HIPAA in-scope list; GitHub Copilot is not on that list, and neither is GitHub. Getting real records out of the repositories and prompts a Copilot-assisted team touches takes us 6–10 weeks.

## Frequently asked questions

### Our compliance lead says GitHub Copilot is explicitly excluded from the BAA. Where is that written?

It is not written anywhere, and you should stop repeating it before an auditor asks. We searched GitHub's Data Protection Agreement and its Generative AI Services Terms: neither names Copilot in its contract body at all. What exists instead is broader, not narrower — §12 of the DPA tells the customer not to provide GitHub protected health information at all, absent GitHub's prior, written, and specific consent, and it applies to every service GitHub provides, for every customer whose contract includes that DPA. Add to that GitHub's absence from Microsoft's published in-scope services list and you have the real answer: no BAA is offered, PHI is contractually prohibited by default, and there is no product-specific carve-out to point at.

### We buy GitHub through our Microsoft Enterprise Agreement. Doesn't our Microsoft BAA cover it?

No, and this one has an affirmative answer rather than an absence. GitHub's own terms send Microsoft-channel customers to the Microsoft Product Terms for GitHub Offerings — and that document points GitHub Copilot Business and Enterprise at the GitHub DPA, not the Microsoft DPA. It matters because the Microsoft BAA lives inside the Microsoft DPA, and the GitHub DPA is the one carrying the PHI prohibition. The string GitHub occurs zero times in the Microsoft DPA and zero times on Microsoft's HIPAA in-scope services page.

### Does Copilot Business or Enterprise change the answer?

Not the BAA answer — there is no BAA on any tier. It changes two other things that matter operationally. Business and Enterprise seats are not subject to the training default that applies to Free, Pro, Pro+ and Max as of April 24, 2026, and GitHub deliberately does not show those accounts the training toggle at all. If you are going to use Copilot in a company that touches patient data, being on Business or Enterprise is the floor, not the fix.

### A developer pasted a row from the patients table into Copilot Chat last month. What actually happened to it?

It depends on which surface they used and on which licence that account holds. For Business and Enterprise customers GitHub publishes a window per surface: in the editor — chat, code completions or the CLI — inputs and outputs are not retained by default, with a carve-out for investigating confirmed policy violations; anywhere else, inputs and outputs are retained up to 28 days by default; through the coding agent, session logs are retained for the life of the account. For Free, Pro, Pro+ and Max seats we found no published retention window — GitHub's answer for those subscribers covers what the data is used for, including model training, rather than how long it is kept. In every case the text also went to a model host: OpenAI, Anthropic, AWS Bedrock, Google Cloud or xAI, depending on the model selected. Find out which surface and which licence first; the rest follows from that.

### GitHub has zero data retention agreements with OpenAI and Anthropic. Isn't that as good as a BAA?

It is a genuinely useful property and it is not the same thing. A BAA is a contract in which a vendor accepts business-associate obligations for protected health information. A zero-retention agreement is a commitment about how long prompts are kept. Read GitHub's own wording closely, too: the Anthropic agreement covers generally available features, beta and preview features including tool search via the Messages API are outside it, and GitHub warns that when Claude Fable 5 is used, Anthropic retains prompts and outputs to operate safety classifiers. Good hygiene, no BAA in the chain.

### Is GitHub Copilot HIPAA certified?

Nothing is. There is no government HIPAA certification for a product or a company — the mechanism is a signed Business Associate Agreement with each vendor that touches protected health information, plus the safeguards you implement and document yourself. What GitHub does publish for Copilot Business and Enterprise is SOC 1, SOC 2, SOC 3, ISO 27001, ISO/IEC 42001, CSA STAR Level 2 and TISAX. HIPAA is not among them, and none of those is a substitute for a BAA.

### Could we get GitHub's written consent under that carve-out and use Copilot with PHI anyway?

The clause contemplates it, so we will not tell you it is impossible — but we could find no route to it. Compare it with the FERPA clause sitting immediately beside it in the same contract, which spells out what a customer must obtain: consent expressly reciting GitHub's agreement to accept that data, plus a separate agreement with GitHub. The HIPAA clause names no such process, no contact and no eligible tier; no GitHub document we read offers a BAA or describes how to request one; and neither of GitHub's trust centres lists HIPAA among its published compliance frameworks or answers a question about it. Plan on the answer being no.

---

Source: https://www.rapidevelopers.com/compliance/is-github-copilot-hipaa-compliant
© RapidDev — https://www.rapidevelopers.com/compliance/is-github-copilot-hipaa-compliant
