Short answer: Windsurf has the strongest HIPAA story of any AI coding tool examined in this series — and it’s the only one with a named healthcare customer to back it up. Windsurf’s own security documentation states plainly that it will “entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance” for significant implementations. And athenahealth, a technology company serving over 160,000 healthcare providers, is a named Windsurf enterprise customer that specifically credited the platform’s “full alignment with zero data retention (ZDR) policies and HIPAA requirements” as a reason it was selected. That’s a real, substantive starting point — not marketing language borrowed from a compliance badge. But “we will entertain a BAA for significant implementations” is an invitation to negotiate, not an automatic guarantee. The Free, Pro, and Max individual plans include none of this, and a real BAA still has to be executed directly with Windsurf before any actual PHI touches the product.
Vibe-coded a healthcare app in Windsurf and need to make it HIPAA compliant? HIPAA Vault audits your Windsurf-built architecture, remediates the compliance gaps, and deploys your app to a BAA-covered production environment — before it touches real patient data.
Book a Free Architecture Consultation →
Key Takeaways
- Windsurf’s security documentation states directly: “our platform is maintained as HIPAA compliant and for significant implementations, we will entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance” — the most direct BAA-willingness language of any tool in this series.
- athenahealth, a health tech company serving 160,000+ providers, is a named Windsurf enterprise customer. Their Director of R&D Productivity, Jeremy Luallen, said: “We work with highly critical systems and sensitive information that must be protected to safeguard the lives of patients being treated by physicians… With Windsurf, we uphold our standards and empower our teams to build quickly.”
- Windsurf holds FedRAMP High accreditation (via Palantir’s FedStart program, serving federal and DoW IL4/IL5/IL6/ITAR customers) and SOC 2 Type II certification, with three deployment tiers — Cloud, Enterprise Hybrid, and Enterprise Self-hosted — that let regulated customers keep data retention entirely inside their own infrastructure.
- Zero-data-retention mode is the default for Teams and Enterprise plans; individual Free ($0), Pro ($20/month), and Max ($200/month) users must opt in manually — and none of those individual tiers include a BAA. That requires an Enterprise conversation.
- Windsurf’s own security page is dated March 11, 2025 — over a year old as of this writing, and predating Cognition AI’s July 2025 acquisition of Windsurf and its integration of the Devin autonomous coding agent. Confirm current terms directly before relying on anything here for a live HIPAA program.
Does Building in Windsurf Involve PHI?
Windsurf’s own security documentation is unusually detailed about exactly what data leaves a developer’s machine and when — which makes it possible to be precise about where PHI risk actually shows up:
- Passive suggestions (Autocomplete, Tab) — a request is sent to Windsurf’s servers on every keystroke.
- Instructive prompts (Command, Chat) — a request is sent on every manually written prompt.
- Agentic steps (Cascade) — requests are sent on every triggering instruction, every reasoning step, and most tool calls.
- Remote codebase indexing, if enabled — retains code snippets and embeddings server-side (Cloud deployments only; not an issue on Hybrid or Self-hosted, where this data stays in the customer’s own tenant).
- The web search tool — an explicit Team/Enterprise opt-in that sends a query “derived from the user’s inputs, past conversation history, and potentially code data” to the Bing API, which Windsurf states plainly has no zero-data-retention agreement in place.
- Devin, the cloud agent — unlike Cascade (a “collaborative agent” that stays visible in the IDE and requires human approval for risky actions), Devin can work autonomously on a remote machine, a different data-handling profile worth accounting for separately.
If none of the above touches real patient data, Windsurf’s default zero-data-retention posture for Team/Enterprise plans is a genuinely strong starting point. The moment real PHI enters any of those surfaces, whether it’s covered depends on your specific deployment tier and whether a BAA has actually been executed — not on the general compliance language on the website.
Windsurf’s Security Posture vs. What HIPAA Requires
| Security control | Windsurf's current posture | Does this satisfy HIPAA? |
|---|---|---|
| HIPAA/BAA language | "We will entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance" for significant implementations | Most direct BAA-willingness statement in this series — but negotiated, not automatic |
| Named healthcare customer | athenahealth (160,000+ providers) publicly credits Windsurf's "HIPAA requirements" alignment | Real-world precedent, not just marketing copy |
| Compliance certifications | SOC 2 Type II certified; FedRAMP High accredited via Palantir FedStart; DoD IL4/IL5/IL6 and ITAR compliant | Strongest formal certification set of any tool covered so far |
| Zero data retention | Default for Team/Enterprise plans; opt-in for individual Free/Pro/Max plans | Strong for Teams+, not automatic below that |
| Deployment options | Cloud (Windsurf-managed), Enterprise Hybrid (data retention in customer's own tenant via Docker Compose + Cloudflare Tunnel), Enterprise Self-hosted (fully within customer's private cloud, connects to customer's own trusted LLM endpoint) | Most architecturally flexible data-residency story in this series |
| AI subprocessor transparency | Explicitly lists OpenAI, Anthropic, Google Vertex, xAI, and Fireworks, each with a stated zero-data-retention agreement | More granular disclosure than peer tools |
| Undisclosed-ZDR exception | Bing API (web search) has no ZDR agreement; must be explicitly enabled by a Team/Enterprise admin | A real, disclosed gap — worth checking is disabled for any PHI-adjacent workflow |
| Documentation currency | Security page last updated March 11, 2025 — predates the Cognition AI acquisition (July 2025) and Devin integration | Confirm current terms; this page may not reflect the latest org/product changes |
| BAA available? | Explicitly offered "for significant implementations" — requires direct negotiation, not automatic on any listed plan tier | The most promising answer in this series, still unconfirmed until executed |
Verified against Security (last updated March 11, 2025), Enterprise, Pricing, and the athenahealth case study as of July 2026. Vendor terms and posture change — confirm current BAA availability directly with Windsurf’s sales team before relying on this for a live HIPAA program.
Your AI Prototype Works. Is It Ready for Healthcare?
HIPAA Vault reviews your architecture, addresses compliance gaps, and deploys your application into secure, managed infrastructure.
Book a Free 15-Minute ConsultationA Named Healthcare Customer, Not Just a Compliance Checkbox
Every other tool in this series has been evaluated on its written policies alone, because none of them have a public healthcare customer story to point to. Windsurf does. athenahealth — a major electronic health records, practice management, and revenue cycle technology company serving more than 160,000 providers — is a named, on-the-record Windsurf enterprise customer, and their own account of why they chose it is specific to compliance, not just productivity:
“We work with highly critical systems and sensitive information that must be protected to safeguard the lives of patients being treated by physicians. At athenahealth, we take a rigorous approach to every technology decision. With Windsurf, we uphold our standards and empower our teams to build quickly.” — Jeremy Luallen, Director of R&D Productivity, athenahealth
Windsurf’s own case study lists “Enterprise-Grade Security & Compliance” as one of the deciding factors, stating the Windsurf Editor “demonstrated full alignment with zero data retention (ZDR) policies and HIPAA requirements.” This is meaningfully different from a vendor simply saying “we support HIPAA” in a FAQ — it’s a named healthcare technology company’s own account of their evaluation. That said, it’s worth being precise about what this shows: athenahealth adopted Windsurf as a developer tool within their engineering organization, evaluated against their own compliance program. It’s evidence Windsurf’s architecture can satisfy a serious healthcare technology company’s security review — not a substitute for your own organization confirming and executing its own BAA before real PHI enters the picture.
What Windsurf’s Security Page Actually Promises on HIPAA
Windsurf’s security documentation states, verbatim:
“HIPAA compliance: In most cases, the data that a customer provides to us is not Personal Health Information (PHI) and does not need special compliance considerations in order to use our platform, even if you are a healthcare organization. This is particularly true for code, which does not carry any PHI itself. That said, our platform is maintained as HIPAA compliant and for significant implementations, we will entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance.”
Read that carefully: the first half makes a fair, defensible point — code by itself usually isn’t PHI. The operative commitment is the second half: “our platform is maintained as HIPAA compliant” and BAAs are entertained “for significant implementations.” That phrase is doing a lot of work. It’s not “every customer gets a BAA on request” — it reads as reserved for meaningful Enterprise engagements, evaluated case by case. Given this page is dated March 11, 2025, more than a year before this writing and before Windsurf’s acquisition by Cognition AI, treat it as a strong starting signal rather than a current, standing offer — confirm the specifics directly with Windsurf’s team before assuming it applies to your deployment.
Deployment Options: The Most Flexible Data-Residency Story in This Series
Unlike Cursor, Lovable, Bolt.new, or v0 — all of which are effectively single-deployment cloud products — Windsurf offers three distinct deployment tiers, each with a different data-handling profile:
- Cloud (individual, Teams, and Enterprise Cloud plans): AI requests are processed on Windsurf-managed servers, with zero-data-retention as the default for Teams/Enterprise.
- Enterprise Hybrid: any functionality requiring data retention runs on a CPU-and-storage-only tenant that the customer manages — deployed via Docker Compose on the customer’s own AWS/GCP/Azure instance or on-prem, connected to Windsurf’s compute layer only through an outbound Cloudflare Tunnel. This is Windsurf’s most popular enterprise deployment method.
- Enterprise Self-hosted: all compute and data retention happens within a GPU-enabled tenant fully managed by the customer, connecting to the customer’s own trusted LLM endpoint (AWS Bedrock, Azure OpenAI, Google Vertex AI). Windsurf states plainly that “no traffic is ever routed past the customer’s firewalls except to this trusted endpoint.” The tradeoff: this tier doesn’t support the Windsurf Editor or Cascade, Windsurf’s flagship agentic experience.
For a healthcare organization with the scale to justify Enterprise Hybrid or Self-hosted, this architecture genuinely changes the compliance conversation — data retention can live entirely inside infrastructure you already control. For most vibe-coders building a first healthcare MVP, though, this level of deployment sophistication is well beyond what a Free, Pro, or Max plan offers.
What Gil Vidals Says About Vibe Coding Platforms and HIPAA
Windsurf wasn’t one of the four platforms Gil Vidals named directly in HIS Episode 107 — that list was Cursor, Replit, Bolt.new, and v0. But the underlying reasoning he gives for treating AI coding tools as sandboxes, not compliance destinations, applies just as much here as anywhere else in this series:
“I don’t believe these building platforms offer HIPAA compliance. I don’t think that’s their forte.”
On why the AI layer itself can’t close that gap:
“At this juncture, AI is trapped in the virtual world. It does everything inside the computer — it’s digital. To be HIPAA compliant, you have to touch the physical world. The AI doesn’t do that yet. That means you have to have infrastructure that’s HIPAA compliant… and even if that infrastructure is configured, the code itself is probably going to live on a virtual machine, and that virtual machine has to be configured to be HIPAA compliant too. You have to monitor it, scan it, run vulnerability reports, patch it on a weekly or monthly basis.”
(Source: HIPAA Insider Show, Episode 107, “Vibe Coding to HIPAA-Compliant Production: The Steps.”) Windsurf is the one platform in this series where that general skepticism deserves a real asterisk — a named healthcare customer and an explicit BAA offer are not nothing. But absent your own confirmed, executed agreement, the same default caution still applies.
From Windsurf to Production: The Migration Steps
- Confirm your deployment tier and BAA status first. If you’re on Enterprise Hybrid or Self-hosted with an executed BAA, PHI-handling may already be architecturally supported — but confirm this in writing rather than assuming it from the athenahealth case study or the security page’s general language.
- If you’re on Free, Pro, Max, or Teams without a confirmed BAA, treat this like every other tool in this series. Test thoroughly with a second reviewer — Gil’s guidance applies universally: “Don’t just make it and then try to ship it out. Make sure you review it.”
- Check whether the web search tool or remote indexing were ever enabled on a Cloud deployment. Both involve data paths (Bing API with no ZDR agreement, and server-side embeddings) that a Hybrid or Self-hosted deployment wouldn’t have exposed.
- Export or migrate your codebase to your intended production environment, treating any component that may have touched real PHI as PHI in transit.
- Confirm your new host — or Windsurf’s own Enterprise team, if staying on their infrastructure — will execute a signed BAA before go-live. As Gil puts it: “One of the first questions you want to investigate is: do they support signing a BAA? If they say yes, then at least you got past that point.”
- Re-verify the security posture is current. Windsurf’s public documentation on this specific topic is over a year old — confirm nothing material has changed before relying on it.
Your AI Coding Tool Is Only One Layer
Windsurf’s architecture — zero data retention by default for Teams/Enterprise, FedRAMP High accreditation, Hybrid and Self-hosted deployment options, and a real named healthcare customer — is the most serious compliance posture of any AI coding tool in this series. None of that changes what still has to be true before real patient data touches a production application: hosting infrastructure with its own signed BAA, encrypted storage and transmission under that agreement, access controls, audit logging, and a documented risk analysis. As Gil Vidals puts it, HIPAA compliance “is not a one and done” — it’s an ongoing commitment, and even Windsurf’s strongest deployment tier is only one part of that picture.
HIPAA Vault has provided that infrastructure layer since 1997, with certifications including NIST 800-53, SOC 2 (AICPA), HITECH Omnibus, and GSA. Whatever tool built the app, it still needs a compliant home to run in — with a BAA that’s actually signed, not just entertained.
Ready to move your Windsurf-built app to a compliant environment? HIPAA Vault handles the architecture audit, the remediation work, and the deployment to a BAA-covered environment.
Book a Free Architecture Consultation → | Talk to a specialist →
Questions to Ask Before Moving a Windsurf-Built App to Production
- Do you have an actual, executed BAA with Windsurf, or just the general security-page language? Those are very different things — confirm which one you have.
- Which deployment tier were you actually using — Cloud, Hybrid, or Self-hosted? This determines whether any data retention happened outside your own infrastructure.
- Was the web search tool or remote indexing ever enabled? Both carry data-handling profiles that need a second look if any real PHI was involved.
- If you used Devin (the autonomous cloud agent) at any point, what did it have access to? Its autonomous, remote-machine model is a different risk surface than Cascade’s collaborative, human-in-the-loop design.
- Will your eventual production host sign a BAA? That remains the deciding question if you’re moving off Windsurf’s infrastructure entirely.
Frequently Asked Questions
This article is educational and does not constitute legal advice. Consult a qualified HIPAA compliance attorney for guidance specific to your organization. Vendor terms and security posture reflect Windsurf’s Security page (dated March 11, 2025), Enterprise/Government page, Pricing page, and published athenahealth case study as of July 2026 — verify current BAA availability and terms directly with Windsurf before relying on this for a live HIPAA program.

