Is DocuSign HIPAA Compliant?
Yes — DocuSign can be HIPAA compliant, but not on all plans. DocuSign lists HIPAA among its supported compliance frameworks and offers a Business Associate Agreement (BAA) on qualifying business plans. DocuSign holds SOC 2 Type 2, ISO 27001:2022, and PCI-DSS certifications — among the strongest security postures of any e-signature provider. However, free and... Continue reading
Is Cursor HIPAA Compliant? Vibe Coding Tools for Healthcare Compared
Short answer: Cursor is not HIPAA compliant, and Anysphere (the company behind it) doesn’t offer a Business Associate Agreement (BAA). Cursor has strong general-purpose security — SOC 2 Type II certification, AES-256 encryption at rest, TLS 1.2+ in transit, SSO/SCIM, and a zero-data-retention Privacy Mode — but none of that satisfies HIPAA, which requires a... Continue reading
Is Bolt.new HIPAA Compliant? What StackBlitz’s Policies Actually Say
Short answer: Bolt.new is not HIPAA compliant, among the vibe-coding tools not built for regulated health data. Bolt (built by StackBlitz) offers no Business Associate Agreement anywhere in its Terms of Service, Privacy Policy, Enterprise page, or Pricing page. What makes Bolt’s paper trail unusual is the split between documents: its Terms of Service haven’t... Continue reading
How to Respond to a HIPAA Breach: A Step-by-Step Guide for Healthcare Organizations
When a HIPAA breach occurs, the clock starts immediately. Covered entities have 60 days from the date of discovery to notify affected individuals, report to HHS, and — for breaches affecting 500 or more individuals in a state — notify prominent media outlets. The response you take in the first hours and days after a... Continue reading
