Is Zapier HIPAA Compliant?
Straight answer: No. Zapier states this plainly in its own documentation — it does not sign a Business Associate Agreement (BAA) and does not support HIPAA compliance. It’s a legitimate, well-secured tool for non-PHI workflows, but it should never be the pipe carrying patient data out of a healthcare app or website. Key Takeaways Ready... Continue reading
Is GitHub Copilot HIPAA Compliant? What Microsoft’s Own BAA Excludes (2026)
No. GitHub Copilot is not HIPAA compliant, and — more strikingly — it’s explicitly excluded from Microsoft’s own HIPAA Business Associate Agreement (BAA), even though Microsoft owns GitHub. Microsoft offers a BAA covering Azure, Office 365, Dynamics 365, Microsoft 365 Copilot, and roughly two dozen other in-scope services. GitHub and GitHub Copilot are not on... Continue reading
Is DocuSign HIPAA Compliant?
Yes — DocuSign can be HIPAA compliant, but not on all plans. DocuSign lists HIPAA among its supported compliance frameworks and offers a Business Associate Agreement (BAA) on qualifying business plans. DocuSign holds SOC 2 Type 2, ISO 27001:2022, and PCI-DSS certifications — among the strongest security postures of any e-signature provider. However, free and... Continue reading
Is Slack HIPAA Compliant?
Slack can support HIPAA compliance — but only on Business+ and Enterprise+ plans, and only when properly configured. Free and Pro plans do not support HIPAA compliance, as confirmed on Slack’s own pricing page. Even on qualifying plans, HIPAA compliance is not automatic — it requires enabling specific security controls, executing a Business Associate Agreement... Continue reading
