Questions? Talk to a Real Person via our Live Chat
How to Evaluate a HIPAA-Compliant App Builder: A Framework for Healthcare Founders
By Brenda Medel, , HIPAA Blog, Resources, Vibe Coding

How to Evaluate a HIPAA-Compliant App Builder: A Framework for Healthcare Founders

No AI-powered app builder is HIPAA compliant out of the box — but that doesn’t mean you can’t use them to build healthcare applications. The right question isn’t “is this app builder HIPAA compliant?” It’s “can I build a compliant application with this tool, and can I deploy it to a compliant environment?” The HIPAA... Continue reading
Is DocuSign HIPAA Compliant?
By Josh Vidals, , HIPAA Blog, HIPAA Compliance, Resources

Is DocuSign HIPAA Compliant?

Yes — DocuSign can be HIPAA compliant, but not on all plans. DocuSign lists HIPAA among its supported compliance frameworks and offers a Business Associate Agreement (BAA) on qualifying business plans. DocuSign holds SOC 2 Type 2, ISO 27001:2022, and PCI-DSS certifications — among the strongest security postures of any e-signature provider. However, free and... Continue reading
Is Cursor HIPAA Compliant? Vibe Coding Tools for Healthcare Compared
By Monica Dircio, , HIPAA Blog, Resources, Vibe Coding

Is Cursor HIPAA Compliant? Vibe Coding Tools for Healthcare Compared

Short answer: Cursor is not HIPAA compliant, and Anysphere (the company behind it) doesn’t offer a Business Associate Agreement (BAA). Cursor has strong general-purpose security — SOC 2 Type II certification, AES-256 encryption at rest, TLS 1.2+ in transit, SSO/SCIM, and a zero-data-retention Privacy Mode — but none of that satisfies HIPAA, which requires a... Continue reading
Is Bolt.new HIPAA Compliant? What StackBlitz’s Policies Actually Say
By Gil Vidals, , HIPAA Blog, Resources, Vibe Coding

Is Bolt.new HIPAA Compliant? What StackBlitz’s Policies Actually Say

Short answer: Bolt.new is not HIPAA compliant, among the vibe-coding tools not built for regulated health data. Bolt (built by StackBlitz) offers no Business Associate Agreement anywhere in its Terms of Service, Privacy Policy, Enterprise page, or Pricing page. What makes Bolt’s paper trail unusual is the split between documents: its Terms of Service haven’t... Continue reading
Is Slack HIPAA Compliant?
By Alicia Kelley, , HIPAA Blog, HIPAA Compliance, Resources

Is Slack HIPAA Compliant?

Slack can support HIPAA compliance — but only on Business+ and Enterprise+ plans, and only when properly configured. Free and Pro plans do not support HIPAA compliance, as confirmed on Slack’s own pricing page. Even on qualifying plans, HIPAA compliance is not automatic — it requires enabling specific security controls, executing a Business Associate Agreement... Continue reading