Questions? Talk to a Real Person via our Live Chat
Vibe Coding a Healthcare App: HIPAA Compliance Checklist
By Monica Dircio, , HIPAA Blog, Resources, Vibe Coding

Vibe Coding a Healthcare App: HIPAA Compliance Checklist

Quick answer: Vibe coding platforms like Lovable, Replit, Bolt, and Cursor are fine for building a healthcare app — they just aren’t built to hold real patient data. This checklist walks through HIPAA Vault’s own eight-point “AI-to-HIPAA Migration Checklist,” the same one used to take a vibe-coded prototype from sandbox to a genuinely HIPAA-compliant production... Continue reading
Is Zapier HIPAA Compliant?
By Gil Vidals, , HIPAA Blog, HIPAA Compliance, Resources

Is Zapier HIPAA Compliant?

Straight answer: No. Zapier states this plainly in its own documentation — it does not sign a Business Associate Agreement (BAA) and does not support HIPAA compliance. It’s a legitimate, well-secured tool for non-PHI workflows, but it should never be the pipe carrying patient data out of a healthcare app or website. Key Takeaways Ready... Continue reading
Are AI Coding Agents Like Claude Code and Codex HIPAA Compliant?
By Josh Vidals, , HIPAA Blog, Resources, Vibe Coding

Are AI Coding Agents Like Claude Code and Codex HIPAA Compliant?

Direct answer: Claude Code and OpenAI’s Codex can be used in a HIPAA-eligible way — but only under specific enterprise-tier configurations with an executed Business Associate Agreement (BAA), never on their default consumer plans, and never for the local machine or third-party tools the agent touches along the way. Ready to move your AI-coded app... Continue reading
HIPAA Compliant Vibe Coding: How to Build Healthcare Apps Safely With AI
By Alicia Kelley, , HIPAA Blog, Resources, Vibe Coding

HIPAA Compliant Vibe Coding: How to Build Healthcare Apps Safely With AI

AI-assisted “vibe coding” can dramatically lower the barrier to creating a useful healthcare application — but moving from a working prototype to one that actually handles protected health information requires deliberate decisions about vendors, secrets, authentication, database access, and infrastructure. HIPAA follows the data, not the appearance of the app. Something that looks finished can... Continue reading
How Much Does a HIPAA Violation Cost? Fines, Cases, and Prevention
By Monica Dircio, , HIPAA Blog, Resources, Security

How Much Does a HIPAA Violation Cost? Fines, Cases, and Prevention

HIPAA violation fines range from $145 to $73,011 per violation, depending on the level of culpability, with annual caps adjusted periodically for inflation — reaching over $2.1 million for the most serious violations. A single enforcement action in 2024 resulted in a $4.75 million penalty against Montefiore Medical Center, exceeding the HHS Office for Civil... Continue reading
Is Retool HIPAA Compliant? No BAA on Any Cloud Plan — Here’s the Self-Hosted Exception (2026)
By Gil Vidals, , HIPAA Blog, Resources, Vibe Coding

Is Retool HIPAA Compliant? No BAA on Any Cloud Plan — Here’s the Self-Hosted Exception (2026)

No. Retool will not sign a Business Associate Agreement on any cloud plan, and its own contracts say so directly. Retool’s Master Subscription Agreement (Enterprise) and Customer-Specific Supplement (Free, Team, and Business) both state plainly: “Retool is not a Business Associate or subcontractor… and accordingly, Customer is solely responsible for complying with any obligations thereunder.”... Continue reading