Questions? Talk to a Real Person via our Live Chat
Is Firebase HIPAA Compliant?
By Brenda Medel, , HIPAA Blog, HIPAA Compliance, Resources

Is Firebase HIPAA Compliant?

Short answer: It depends entirely on which piece of Firebase you mean. Firebase isn’t one product for compliance purposes — it’s split into two legal buckets. Firestore, Cloud Storage, and Identity Platform can be covered under a signed Google Cloud BAA. But Firebase Authentication, Realtime Database, Hosting, Cloud Messaging, Crashlytics, and several other Firebase-branded services... Continue reading
Is Zapier HIPAA Compliant?
By Gil Vidals, , HIPAA Blog, HIPAA Compliance, Resources

Is Zapier HIPAA Compliant?

Straight answer: No. Zapier states this plainly in its own documentation — it does not sign a Business Associate Agreement (BAA) and does not support HIPAA compliance. It’s a legitimate, well-secured tool for non-PHI workflows, but it should never be the pipe carrying patient data out of a healthcare app or website. Key Takeaways Ready... Continue reading
Is GitHub Copilot HIPAA Compliant? What Microsoft’s Own BAA Excludes (2026)
By Josh Vidals, , HIPAA Blog, HIPAA Compliance, Resources

Is GitHub Copilot HIPAA Compliant? What Microsoft’s Own BAA Excludes (2026)

No. GitHub Copilot is not HIPAA compliant, and — more strikingly — it’s explicitly excluded from Microsoft’s own HIPAA Business Associate Agreement (BAA), even though Microsoft owns GitHub. Microsoft offers a BAA covering Azure, Office 365, Dynamics 365, Microsoft 365 Copilot, and roughly two dozen other in-scope services. GitHub and GitHub Copilot are not on... Continue reading
Is DocuSign HIPAA Compliant?
By Josh Vidals, , HIPAA Blog, HIPAA Compliance, Resources

Is DocuSign HIPAA Compliant?

Yes — DocuSign can be HIPAA compliant, but not on all plans. DocuSign lists HIPAA among its supported compliance frameworks and offers a Business Associate Agreement (BAA) on qualifying business plans. DocuSign holds SOC 2 Type 2, ISO 27001:2022, and PCI-DSS certifications — among the strongest security postures of any e-signature provider. However, free and... Continue reading
Is Slack HIPAA Compliant?
By Alicia Kelley, , HIPAA Blog, HIPAA Compliance, Resources

Is Slack HIPAA Compliant?

Slack can support HIPAA compliance — but only on Business+ and Enterprise+ plans, and only when properly configured. Free and Pro plans do not support HIPAA compliance, as confirmed on Slack’s own pricing page. Even on qualifying plans, HIPAA compliance is not automatic — it requires enabling specific security controls, executing a Business Associate Agreement... Continue reading
Is WhatsApp HIPAA Compliant?
By Monica Dircio, , HIPAA Blog, HIPAA Compliance, Resources

Is WhatsApp HIPAA Compliant?

No — WhatsApp is not HIPAA compliant. WhatsApp uses end-to-end encryption, which sounds secure — but encryption alone does not make a platform HIPAA compliant. WhatsApp is owned by Meta and does not offer a Business Associate Agreement (BAA) under any plan, including WhatsApp Business and WhatsApp Business API. Without a BAA, no healthcare organization... Continue reading