Questions? Talk to a Real Person via our Live Chat
Are AI Coding Agents Like Claude Code and Codex HIPAA Compliant?
By Josh Vidals, , HIPAA Blog, Resources, Vibe Coding

Are AI Coding Agents Like Claude Code and Codex HIPAA Compliant?

Direct answer: Claude Code and OpenAI’s Codex can be used in a HIPAA-eligible way — but only under specific enterprise-tier configurations with an executed Business Associate Agreement (BAA), never on their default consumer plans, and never for the local machine or third-party tools the agent touches along the way. Ready to move your AI-coded app... Continue reading
Is GitHub Copilot HIPAA Compliant? What Microsoft’s Own BAA Excludes (2026)
By Josh Vidals, , HIPAA Blog, HIPAA Compliance, Resources

Is GitHub Copilot HIPAA Compliant? What Microsoft’s Own BAA Excludes (2026)

No. GitHub Copilot is not HIPAA compliant, and — more strikingly — it’s explicitly excluded from Microsoft’s own HIPAA Business Associate Agreement (BAA), even though Microsoft owns GitHub. Microsoft offers a BAA covering Azure, Office 365, Dynamics 365, Microsoft 365 Copilot, and roughly two dozen other in-scope services. GitHub and GitHub Copilot are not on... Continue reading
Can You Store PHI in SaaS Tools? A HIPAA Framework for Healthcare Organizations
By Josh Vidals, , HIPAA Blog, HIPAA Hosting, Resources

Can You Store PHI in SaaS Tools? A HIPAA Framework for Healthcare Organizations

The short answer: Yes — but only if the vendor covers the exact product, plan, database, file storage, automations, integrations, and logging under a signed Business Associate Agreement (BAA), and only after you have verified every data path where PHI can travel. Most SaaS tools are not HIPAA compliant by default. A platform may look... Continue reading
Is DocuSign HIPAA Compliant?
By Josh Vidals, , HIPAA Blog, HIPAA Compliance, Resources

Is DocuSign HIPAA Compliant?

Yes — DocuSign can be HIPAA compliant, but not on all plans. DocuSign lists HIPAA among its supported compliance frameworks and offers a Business Associate Agreement (BAA) on qualifying business plans. DocuSign holds SOC 2 Type 2, ISO 27001:2022, and PCI-DSS certifications — among the strongest security postures of any e-signature provider. However, free and... Continue reading
Is Lovable HIPAA Compliant? What Its Terms of Service Actually Say
By Josh Vidals, , HIPAA Blog, Resources, Vibe Coding

Is Lovable HIPAA Compliant? What Its Terms of Service Actually Say

Short answer: Lovable is not HIPAA compliant, and unlike most vibe-coding tools, its Terms of Service say so directly. As of the January 2026 update, Lovable’s ToS states in plain language: “You agree not to upload, input, or otherwise provide any protected health information under HIPAA, or any other sensitive categories of data… Our Services... Continue reading
HIPAA Compliant Hosting Providers Compared: HIPAA Vault vs Atlantic.Net vs Liquid Web vs AWS vs Azure (2026)
By Josh Vidals, , HIPAA Blog, HIPAA Hosting, Resources

HIPAA Compliant Hosting Providers Compared: HIPAA Vault vs Atlantic.Net vs Liquid Web vs AWS vs Azure (2026)

The verdict: All five providers can support HIPAA-compliant hosting — but they serve very different audiences and come with very different levels of compliance management. HIPAA Vault and Atlantic.Net offer purpose-built HIPAA hosting with dedicated compliance support. Liquid Web provides managed hosting with HIPAA-audited infrastructure. AWS offers the most flexibility but places full compliance responsibility... Continue reading