No. Retool will not sign a Business Associate Agreement on any cloud plan, and its own contracts say so directly. Retool’s Master Subscription Agreement (Enterprise) and Customer-Specific Supplement (Free, Team, and Business) both state plainly: “Retool is not a Business Associate or subcontractor… and accordingly, Customer is solely responsible for complying with any obligations thereunder.” Both contracts instruct customers not to submit, collect, or use protected health information on “the Retool Cloud Platform.” There’s a real nuance for self-hosted deployments, covered below, but on Retool’s hosted cloud service, the answer is unambiguous.


Building internal healthcare tools in Retool and need a compliant place for the data behind them? HIPAA Vault reviews your Retool-connected architecture, remediates the compliance gaps, and deploys the BAA-covered environment your data actually needs.

Book a Free 15-Minute Consultation →


Key Takeaways

  • Retool explicitly states in its own contracts — not just marketing pages — that it is not a HIPAA Business Associate or subcontractor, on every plan tier from Free through Enterprise.
  • The prohibition on submitting PHI is written directly into the Customer-Specific Supplement and Master Subscription Agreement, and applies to “the Retool Cloud Platform” / “online, cloud-based versions” of the service.
  • Retool’s own support team confirms this directly in its community forum: “Retool does not sign Business Associate Agreements (BAAs).”
  • Retool’s Trust Center lists CCPA, GDPR, ISO/IEC 27001:2022, and SOC 2 Type 2 as its compliance certifications — HIPAA is not among them.
  • Self-hosted Retool changes the analysis, but not by granting permission: when Retool has no access to Customer Data at all, it isn’t acting as a Business Associate in the first place — the entire compliance burden (the hosting environment, encryption, access control, audit logging) still falls on you.
  • Retool markets itself as a professional internal-tools builder for developers, not a “vibe coding” app generator — but its AI-native app builder (AppGen) means the same “the AI wrote it, so it must be handled” assumption risk from the rest of this series still applies to whatever gets built inside it.

Does Building Internal Healthcare Tools in Retool Involve PHI?

Retool is different from most of the tools in this series: it isn’t a consumer-facing app generator, it’s a platform for building internal tools — admin panels, ops dashboards, support consoles, database editors — that connect directly to your production databases and APIs. That makes it common for healthcare organizations to reach for Retool specifically to build the internal tools that let staff view, search, and edit patient records, referrals, billing data, or care coordination workflows.

That’s precisely the use case Retool’s own contract language exists to head off. If your internal tool queries a database containing patient names, diagnoses, treatment notes, or any other protected health information, and that tool runs on Retool’s hosted cloud platform, you are operating exactly the scenario Retool’s Customer-Specific Supplement was written to disclaim.


What Retool’s Own Contracts Actually Say

Retool has two customer agreements that address this directly, and it applies to every plan:

Master Subscription Agreement (Enterprise plan), Section 3.5 — HIPAA Compliance:

“Customer acknowledges that Retool is not a Business Associate or subcontractor (as those terms are defined in the Health Insurance Portability and Accountability Act and related amendments and regulations as updated or replaced ‘HIPAA’) and accordingly, Customer is solely responsible for complying with any obligations thereunder. Customer should not submit, collect or use any ‘protected health information,’ as defined in 45 CFR §160.103, to the Retool Cloud Platform.”

Customer-Specific Supplement (Free, Team, and Business plans), Section III — Healthcare Customers:

“Customer acknowledges that Retool is not a Business Associate or subcontractor… and accordingly, Customer is solely responsible for complying with any obligations thereunder. With respect to any online, cloud-based versions of the Services, Customer should not submit, collect or use any ‘protected health information’ as defined in 45 CFR §160.103 (‘PHI’). Customer agrees that we cannot support and have no liability for PHI received from Customer, notwithstanding anything to the contrary herein.”

That last sentence is worth sitting with: even if PHI ends up flowing through Retool’s cloud platform anyway — because a query returns patient data, or a field displays a diagnosis — Retool has contractually disclaimed liability for it. There’s no ambiguity to negotiate around here; this is the exact language every customer, on every plan, has already agreed to.

Retool’s support team says the same thing in plain language when asked directly in its community forum: “Retool does not sign Business Associate Agreements (BAAs)” — while noting that customers who need HIPAA compliance often turn to self-hosting instead.

It’s worth being clear about what that disclaimer actually costs you. In a HIPAA Vault livestream Q&A on vibe coding, Gil Vidals explained what a BAA is actually for — and, by extension, what its absence leaves you without:

“The BAA is ensuring that both parties, or multiple parties, are aware that there’s patient information and that they’re going to do everything they can to protect it. Lovable and these other companies that are doing the coding platforms — they’re saying the opposite. They’re saying, ‘Hey, don’t come to us, we don’t have anything to do with securing this pipeline or this platform for your medical data.’ They’re actually doing the right thing — they’re declaring it so that people don’t make a mistake.”

Retool’s Master Subscription Agreement and Customer-Specific Supplement are doing exactly what Gil describes there: declaring, in contract language, that you’re on your own for PHI on their cloud platform, precisely so you don’t assume otherwise.


Your AI Prototype Works. Is It Ready for Healthcare?

HIPAA Vault reviews your architecture, addresses compliance gaps, and deploys your application into secure, managed infrastructure.

Book a Free 15-Minute Consultation

Retool’s Certifications vs. What HIPAA Requires

Retool Trust Center CertificationWhat It CoversDoes It Cover HIPAA?
SOC 2 Type 2Security, availability, and confidentiality controls over a period of timeNo — SOC 2 is not a HIPAA substitute, and Retool’s own materials don’t claim otherwise
ISO/IEC 27001:2022Information security management system standardNo — a general security framework, not a healthcare-specific one
GDPREU data protection and privacy regulationNo — different regulatory scope than HIPAA
CCPACalifornia consumer privacy lawNo — different regulatory scope than HIPAA
HIPAA BAARequired to legally handle PHI as a Business AssociateNot offered, on any plan

Verified against trust, master subscription agreement, and customer specific supplement, confirmed July 2026.


The Self-Hosted Exception — and Why It’s Not a Loophole

Retool’s contract language specifically limits the “don’t submit PHI” instruction to “the Retool Cloud Platform” and “online, cloud-based versions of the Services.” That phrasing is deliberate, and it’s why Retool’s own support staff point HIPAA-concerned customers toward self-hosting.

Here’s the mechanism: when you self-host Retool on your own infrastructure — your own VPC, your own VPN, your own servers — Retool’s documentation states plainly that “no Retool systems store Customer Data and no Retool personnel have technical or logical access to Customer Data.” If Retool never touches, stores, or processes your data at all, it isn’t acting as a Business Associate under HIPAA in the first place, because a Business Associate relationship requires the vendor to actually handle PHI on the covered entity’s behalf. No access, no Business Associate relationship, no BAA required — the same way HIPAA doesn’t require a BAA with the company that manufactured your server hardware.

That is meaningfully different from a vendor like Supabase, which affirmatively offers a signed BAA and HIPAA-configured environment as a paid product feature. Retool never says “we’ll sign a BAA if you self-host” — it simply removes itself from the data flow entirely, which changes who’s responsible for what:

  • You become fully responsible for the hosting environment — the server, the network, the encryption at rest and in transit, the access controls, the audit logging, the patching, the physical or cloud-infrastructure security. Retool provides the application; you provide every HIPAA safeguard around it.
  • Retool’s self-hosted contract language still doesn’t affirmatively authorize PHI — it simply doesn’t apply the same explicit “should not submit PHI” language to your own infrastructure, because Retool has no visibility into what you run there.
  • This is a bigger lift than it sounds. Standing up a self-hosted Retool instance is a 15-minute Docker deployment per Retool’s own documentation — but making that Docker deployment and the infrastructure underneath it HIPAA compliant (encryption, logging, access control, a real risk analysis, a BAA with your actual hosting provider) is a substantially larger and ongoing undertaking that Retool’s setup speed doesn’t reflect.

What Gil Vidals Says

Gil Vidals’s core point about where compliance actually lives applies just as directly to an internal-tools platform like Retool as it does to any AI-generated frontend:

“I don’t believe these building platforms offer HIPAA compliance. I don’t think that’s their forte.”

And on the layer that actually has to be compliant, regardless of what tool built the interface on top of it:

“At this juncture, AI is trapped in the virtual world. It does everything inside the computer — it’s digital. To be HIPAA compliant, you have to touch the physical world. The AI doesn’t do that yet. That means you have to have infrastructure that’s HIPAA compliant… and even if that infrastructure is configured, the code itself is probably going to live on a virtual machine, and that virtual machine has to be configured to be HIPAA compliant too. You have to monitor it, scan it, run vulnerability reports, patch it on a weekly or monthly basis.”

(Source: HIPAA Insider Show, Episode 107, “Vibe Coding to HIPAA-Compliant Production: The Steps.”) Retool’s own self-hosted answer proves this point from the vendor’s side: Retool doesn’t claim to make your infrastructure compliant just because you moved off its cloud — it explicitly hands that responsibility back to you.

Joshua Vidals, HIPAA Vault’s cloud engineer, described what actually has to be true of that infrastructure once you take on that responsibility, in the same HIPAA Vault livestream Q&A:

“Once you move on to that private infrastructure — with encryption in transit, audit logging, access controls — you’re very close to having a HIPAA-compliant application.”

That’s the checklist a self-hosted Retool deployment inherits the moment you stand it up: the 15-minute Docker deployment gets you a running app, but encryption in transit, audit logging, and access controls are separate, ongoing work that Retool’s own setup speed doesn’t include.


What to Do If You’re Already Building Healthcare Tools in Retool

  1. Confirm whether PHI is actually flowing through your Retool Cloud apps today. If any query, table view, or workflow surfaces patient names, diagnoses, treatment details, or other PHI, and you’re on Retool’s cloud platform, you’re operating outside what Retool’s own contract permits.
  2. Don’t treat self-hosting as an automatic compliance fix. It removes Retool from the data flow, but it transfers the entire HIPAA technical safeguard burden — encryption, access control, audit logging, infrastructure security — to your team and your hosting environment.
  3. Get a signed BAA with whoever hosts your self-hosted Retool instance, since that hosting provider, not Retool, becomes your Business Associate for infrastructure purposes.
  4. Apply the same database-layer scrutiny covered elsewhere in this series. If Retool connects to a database like Supabase or a Postgres instance, that database’s own HIPAA posture (BAA, encryption, access controls) matters just as much as Retool’s.
  5. Enable Retool’s audit logging (Business/Enterprise plans) and rich permission controls, and treat them as necessary — not sufficient — for a HIPAA technical safeguards program.
  6. If PHI needs to stay out of Retool’s cloud platform entirely, architect around it — de-identify data before it reaches Retool, or restrict Retool’s role to non-PHI operational data while keeping the PHI-handling parts of your workflow inside infrastructure that carries a real BAA.

Your Internal Tools Platform Is Only One Layer

Retool is a genuinely different category from the AI app generators covered elsewhere in this series — it’s built for professional developers extending real systems, not for prompting a consumer app into existence from scratch. But the underlying compliance gap is the same one that runs through this entire series: a tool that’s excellent at what it does isn’t automatically compliant with a regulation it was never built to satisfy, and its own legal team says so in writing.

Whether your team builds internal tools in Retool’s cloud, self-hosts it, or connects it to a dozen different data sources, the infrastructure underneath still needs to be built and maintained like it will actually be audited — because if PHI is involved, it will be.

HIPAA Vault has provided that infrastructure layer since 1997, with certifications including NIST 800-53, SOC 2 (AICPA), HITECH Omnibus, and GSA.

Need a compliant hosting environment for a self-hosted Retool deployment, or for the databases behind your Retool apps? HIPAA Vault handles the review, the remediation, and the deployment to a BAA-covered environment.

Book a Free 15-Minute Consultation →  |  Talk to a specialist →


Questions to Ask Before Building Healthcare Tools in Retool

  1. Does any app, workflow, or query built in Retool surface PHI — even incidentally, like a support console that displays a patient’s name alongside a ticket number?
  2. Are you on Retool’s cloud platform, or self-hosted — and if self-hosted, has your hosting environment itself been assessed for HIPAA technical safeguards?
  3. If self-hosted, who is your actual Business Associate for the infrastructure — do you have a signed BAA with that hosting provider?
  4. Have you enabled audit logging and rich permission controls, and are they actually configured to the minimum-necessary standard for who can view PHI-adjacent records?
  5. Is the database or API Retool connects to itself HIPAA compliant, with its own BAA and safeguards — or does Retool just add a UI on top of a non-compliant data layer?

Frequently Asked Questions


Educational content, not legal advice — consult a qualified HIPAA compliance attorney for your organization. Contract language is quoted directly from Retool’s Master Subscription Agreement and Customer-Specific Supplement as of July 2026; verify current terms before relying on this for a live program.