Questions? Talk to a Real Person via our Live Chat
Is GitHub Copilot HIPAA Compliant? What Microsoft’s Own BAA Excludes (2026)
By Josh Vidals, , HIPAA Blog, HIPAA Compliance, Resources

Is GitHub Copilot HIPAA Compliant? What Microsoft’s Own BAA Excludes (2026)

No. GitHub Copilot is not HIPAA compliant, and — more strikingly — it’s explicitly excluded from Microsoft’s own HIPAA Business Associate Agreement (BAA), even though Microsoft owns GitHub. Microsoft offers a BAA covering Azure, Office 365, Dynamics 365, Microsoft 365 Copilot, and roughly two dozen other in-scope services. GitHub and GitHub Copilot are not on... Continue reading
Is Windsurf HIPAA Compliant? The Vibe-Coding Tool athenahealth Actually Uses (2026)
By Alicia Kelley, , HIPAA Blog, Resources, Vibe Coding

Is Windsurf HIPAA Compliant? The Vibe-Coding Tool athenahealth Actually Uses (2026)

Short answer: Windsurf has the strongest HIPAA story of any AI coding tool examined in this series — and it’s the only one with a named healthcare customer to back it up. Windsurf’s own security documentation states plainly that it will “entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance” for significant implementations. And... Continue reading
Can You Store PHI in SaaS Tools? A HIPAA Framework for Healthcare Organizations
By Josh Vidals, , HIPAA Blog, HIPAA Hosting, Resources

Can You Store PHI in SaaS Tools? A HIPAA Framework for Healthcare Organizations

The short answer: Yes — but only if the vendor covers the exact product, plan, database, file storage, automations, integrations, and logging under a signed Business Associate Agreement (BAA), and only after you have verified every data path where PHI can travel. Most SaaS tools are not HIPAA compliant by default. A platform may look... Continue reading
Is v0 HIPAA Compliant? Why Vercel’s Answer Is Different From the Rest (2026)
By Gil Vidals, , HIPAA Blog, Resources, Vibe Coding

Is v0 HIPAA Compliant? Why Vercel’s Answer Is Different From the Rest (2026)

Short answer: v0 is the one vibe-coding tool in this series backed by a real, third-party-audited HIPAA compliance program — but it’s gated behind a custom-priced Enterprise plan, and it’s not the same thing as a standing offer to sign a Business Associate Agreement. Vercel, the company behind v0, lists HIPAA and HITECH as certified... Continue reading
How to Evaluate a HIPAA-Compliant App Builder: A Framework for Healthcare Founders
By Brenda Medel, , HIPAA Blog, Resources, Vibe Coding

How to Evaluate a HIPAA-Compliant App Builder: A Framework for Healthcare Founders

No AI-powered app builder is HIPAA compliant out of the box — but that doesn’t mean you can’t use them to build healthcare applications. The right question isn’t “is this app builder HIPAA compliant?” It’s “can I build a compliant application with this tool, and can I deploy it to a compliant environment?” The HIPAA... Continue reading
Is DocuSign HIPAA Compliant?
By Josh Vidals, , HIPAA Blog, HIPAA Compliance, Resources

Is DocuSign HIPAA Compliant?

Yes — DocuSign can be HIPAA compliant, but not on all plans. DocuSign lists HIPAA among its supported compliance frameworks and offers a Business Associate Agreement (BAA) on qualifying business plans. DocuSign holds SOC 2 Type 2, ISO 27001:2022, and PCI-DSS certifications — among the strongest security postures of any e-signature provider. However, free and... Continue reading