Questions? Talk to a Real Person via our Live Chat
Are AI Coding Agents Like Claude Code and Codex HIPAA Compliant?
By Josh Vidals, , HIPAA Blog, Resources, Vibe Coding

Are AI Coding Agents Like Claude Code and Codex HIPAA Compliant?

Direct answer: Claude Code and OpenAI’s Codex can be used in a HIPAA-eligible way — but only under specific enterprise-tier configurations with an executed Business Associate Agreement (BAA), never on their default consumer plans, and never for the local machine or third-party tools the agent touches along the way. Ready to move your AI-coded app... Continue reading
HIPAA Compliant Vibe Coding: How to Build Healthcare Apps Safely With AI
By Alicia Kelley, , HIPAA Blog, Resources, Vibe Coding

HIPAA Compliant Vibe Coding: How to Build Healthcare Apps Safely With AI

AI-assisted “vibe coding” can dramatically lower the barrier to creating a useful healthcare application — but moving from a working prototype to one that actually handles protected health information requires deliberate decisions about vendors, secrets, authentication, database access, and infrastructure. HIPAA follows the data, not the appearance of the app. Something that looks finished can... Continue reading
How Much Does a HIPAA Violation Cost? Fines, Cases, and Prevention
By Monica Dircio, , HIPAA Blog, Resources, Security

How Much Does a HIPAA Violation Cost? Fines, Cases, and Prevention

HIPAA violation fines range from $145 to $73,011 per violation, depending on the level of culpability, with annual caps adjusted periodically for inflation — reaching over $2.1 million for the most serious violations. A single enforcement action in 2024 resulted in a $4.75 million penalty against Montefiore Medical Center, exceeding the HHS Office for Civil... Continue reading
Is Retool HIPAA Compliant? No BAA on Any Cloud Plan — Here’s the Self-Hosted Exception (2026)
By Gil Vidals, , HIPAA Blog, Resources, Vibe Coding

Is Retool HIPAA Compliant? No BAA on Any Cloud Plan — Here’s the Self-Hosted Exception (2026)

No. Retool will not sign a Business Associate Agreement on any cloud plan, and its own contracts say so directly. Retool’s Master Subscription Agreement (Enterprise) and Customer-Specific Supplement (Free, Team, and Business) both state plainly: “Retool is not a Business Associate or subcontractor… and accordingly, Customer is solely responsible for complying with any obligations thereunder.”... Continue reading
AI Coding Tools Keep Hardcoding API Keys — Why That’s a HIPAA Breach Risk, Not Just a Bug
By Brenda Medel, , HIPAA Blog, Resources, Vibe Coding

AI Coding Tools Keep Hardcoding API Keys — Why That’s a HIPAA Breach Risk, Not Just a Bug

Hardcoded API keys aren’t a rare mistake in AI-generated code — they’re one of the most common defects it produces, and in a healthcare application they’re a direct path to an impermissible disclosure under the HIPAA Security Rule. Independent research in 2026 found roughly 380,000 publicly accessible applications built on vibe-coding platforms like Lovable, Replit,... Continue reading
Is Supabase HIPAA Compliant? Yes — Here’s What the BAA Actually Requires (2026)
By Alicia Kelley, , HIPAA Blog, Resources, Vibe Coding

Is Supabase HIPAA Compliant? Yes — Here’s What the BAA Actually Requires (2026)

Yes — Supabase is the rare tool in this series where the answer is genuinely “yes,” not “no” or “it depends.” Supabase’s hosted platform is SOC 2 Type II certified, ISO 27001 certified, and offers a signed Business Associate Agreement (BAA) as a paid HIPAA add-on to Team ($599/month) and Enterprise customers. But “yes” comes... Continue reading