Questions? Talk to a Real Person via our Live Chat
HIPAA Compliant Vibe Coding: How to Build Healthcare Apps Safely With AI
By Alicia Kelley, , HIPAA Blog, Resources, Vibe Coding

HIPAA Compliant Vibe Coding: How to Build Healthcare Apps Safely With AI

AI-assisted “vibe coding” can dramatically lower the barrier to creating a useful healthcare application — but moving from a working prototype to one that actually handles protected health information requires deliberate decisions about vendors, secrets, authentication, database access, and infrastructure. HIPAA follows the data, not the appearance of the app. Something that looks finished can... Continue reading
Is Supabase HIPAA Compliant? Yes — Here’s What the BAA Actually Requires (2026)
By Alicia Kelley, , HIPAA Blog, Resources, Vibe Coding

Is Supabase HIPAA Compliant? Yes — Here’s What the BAA Actually Requires (2026)

Yes — Supabase is the rare tool in this series where the answer is genuinely “yes,” not “no” or “it depends.” Supabase’s hosted platform is SOC 2 Type II certified, ISO 27001 certified, and offers a signed Business Associate Agreement (BAA) as a paid HIPAA add-on to Team ($599/month) and Enterprise customers. But “yes” comes... Continue reading
Is Windsurf HIPAA Compliant? The Vibe-Coding Tool athenahealth Actually Uses (2026)
By Alicia Kelley, , HIPAA Blog, Resources, Vibe Coding

Is Windsurf HIPAA Compliant? The Vibe-Coding Tool athenahealth Actually Uses (2026)

Short answer: Windsurf has the strongest HIPAA story of any AI coding tool examined in this series — and it’s the only one with a named healthcare customer to back it up. Windsurf’s own security documentation states plainly that it will “entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance” for significant implementations. And... Continue reading
Is Slack HIPAA Compliant?
By Alicia Kelley, , HIPAA Blog, HIPAA Compliance, Resources

Is Slack HIPAA Compliant?

Slack can support HIPAA compliance — but only on Business+ and Enterprise+ plans, and only when properly configured. Free and Pro plans do not support HIPAA compliance, as confirmed on Slack’s own pricing page. Even on qualifying plans, HIPAA compliance is not automatic — it requires enabling specific security controls, executing a Business Associate Agreement... Continue reading
HIPAA Compliant File Sharing: What Healthcare Organizations Need to Know in 2026
By Alicia Kelley, , HIPAA Blog, Resources, sFTP

HIPAA Compliant File Sharing: What Healthcare Organizations Need to Know in 2026

In plain terms:: File sharing can be HIPAA compliant — but only when it uses a solution that encrypts data in transit and at rest, provides audit logging, enforces access controls, and is backed by a signed Business Associate Agreement (BAA). Standard file sharing tools like email attachments, consumer Dropbox, Google Drive through a personal... Continue reading
HIPAA Compliant Fax: What Healthcare Providers Need to Know in 2026
By Alicia Kelley, , HIPAA Blog, HIPAA Fax, Resources

HIPAA Compliant Fax: What Healthcare Providers Need to Know in 2026

Faxing can be HIPAA compliant — but only when done through a secure cloud fax service that signs a Business Associate Agreement (BAA) and encrypts transmissions. Traditional analog fax machines, consumer internet fax services, and free online fax tools are not HIPAA compliant. Using a non-compliant fax method to transmit protected health information (PHI) is... Continue reading