Straight answer: No. Zapier states this plainly in its own documentation — it does not sign a Business Associate Agreement (BAA) and does not support HIPAA compliance. It’s a legitimate, well-secured tool for non-PHI workflows, but it should never be the pipe carrying patient data out of a healthcare app or website.

Key Takeaways

  • Zapier’s own published guidance is unambiguous: “No, Zapier isn’t HIPAA compliant. That means you shouldn’t use it to store, send, or automate anything involving protected health information (PHI).”
  • The gap isn’t general security — Zapier holds SOC 2 Type II and SOC 3 audits, GDPR and CCPA compliance, AES-256 encryption at rest, and TLS in transit. The specific thing missing is a BAA and HIPAA support.
  • This is easy to overlook because automations get added incrementally — a form submission routed to an email service, a text alert through an SMS provider — often without anyone stopping to check whether the tool handling that step is actually covered.
  • HIPAA Vault’s own migration checklist calls this out directly: every place patient contact info, appointment data, or symptoms flow to a third party needs to be mapped, and each of those services needs to be on a BAA-covered tier.
  • Zapier remains genuinely useful in a healthcare business for anything that doesn’t touch PHI — non-clinical intake routing, marketing automation, billing and scheduling triage.

Ready to make sure your healthcare app or integrations are actually HIPAA compliant?
Book a Free 15-Minute Consultation →

Zapier’s Compliance Posture at a Glance

Zapier
HIPAA compliantNo
Signs a BAANo
SOC 2 Type IIYes
SOC 3 (public report)Yes
GDPR / CCPA compliantYes
Encryption at restYes (AES-256)
Encryption in transitYes (TLS)
Safe for workflows touching real PHINo
Safe for non-PHI, healthcare-adjacent workflowsYes

Why Doesn’t “Just Passing Data Through” Count as Safe?

It’s a fair question — Zapier isn’t storing patient records the way a database or an EHR would. It just routes data from one app to another. So why does that still require a BAA?

Because under HIPAA, the legal category that matters isn’t “stores data” versus “passes data through.” It’s whether a vendor creates, receives, maintains, or transmits protected health information on behalf of a covered entity or another business associate. Transmission alone is enough to make a vendor a “business associate” under the law — and business associates are required to sign a BAA, full stop, regardless of how briefly the data sits in their system or whether they retain a copy afterward.

That’s the actual reason Zapier draws the line where it does. Signing a BAA isn’t just paperwork — it means accepting direct legal liability for how that data is handled while it’s in transit through their platform, plus the audit, breach-notification, and security obligations that come with it. Zapier has made a business decision not to take on that liability, which is exactly what its own documentation states outright rather than leaving ambiguous.

Is There Any Way to Make Zapier HIPAA Compliant Yourself?

No — and this is where Zapier is different from some of the AI coding tools covered elsewhere in this series. Tools like Claude Code or Codex offer a specific enterprise tier or configuration (zero data retention, a signed BAA) that makes them HIPAA-eligible. Zapier doesn’t have an equivalent path. There’s no plan, add-on, enterprise upgrade, or configuration setting that unlocks BAA coverage — Zapier’s own documentation states it doesn’t support HIPAA at all, on any tier, including Enterprise.

This isn’t a technical gap you can work around with the right settings. It’s a business decision: signing a BAA means accepting legal liability for how PHI is handled while it passes through the platform, and Zapier has chosen not to take that on. That makes the fix a routing decision, not a configuration one — move anything touching PHI to a different, BAA-covered service rather than looking for a Zapier setting that solves it.

Ready for the 2026 HIPAA Rules

See the fully managed solutions that meet MFA, encryption, and recovery requirements out of the box

See HIPAA Solutions

Common Misconceptions Worth Correcting

“We have encryption, so we’re covered.” Encryption protects data from unauthorized access, but it doesn’t replace HIPAA’s legal and administrative requirements — a signed BAA, risk analysis, workforce training, audit controls, and incident response procedures are all still required regardless of how well the data in transit is encrypted.

“We only send patient names, not medical details.” A name by itself isn’t automatically PHI. But once it’s linked to an appointment, a treatment, a payment, or any other health-related context — “John Smith, appointment reminder” — it becomes identifiable health information, and the same rule applies.

“We’re only using it for testing.” Real patient data in a test automation is still PHI, even if the workflow never reaches production. Use synthetic or de-identified data for testing, and save real data for environments that are actually built to handle it.

Where This Actually Shows Up

Zapier tends to enter the picture quietly, regardless of how the underlying site or app was built. A WordPress form plugin (Gravity Forms, WPForms) or a WooCommerce store often has a built-in “connect to Zapier” option a practice manager can switch on directly. A custom or AI-built application might have a webhook wired up to Zapier so that a form submission triggers an email or an SMS follow-up. Either way, the automation gets added incrementally, and it’s easy for it to end up carrying patient contact info, appointment details, or symptoms without anyone stopping to confirm the tool on the other end is BAA-covered.

HIPAA Vault’s own AI-to-HIPAA Migration Checklist addresses this directly under “Third-Party Routing”:

Mapped every place patient contact info, appointment data, or symptoms flow to a third party. Confirmed each service is on a BAA-covered tier — not the free/consumer default AI tools suggest. Confirmed TLS encryption in transit for all of these integrations.

That’s the same principle whether the site is a WordPress practice site, a custom application, or something built with an AI coding tool — the rule doesn’t change based on how the app was built, only based on what data is flowing through it.

What This Looks Like in Practice

The simplest test: would this automation reveal anything about a person’s health if it were intercepted or disclosed? If yes — or even maybe — it needs a BAA-covered path.

Generally fine without a BAA: Notifying IT when a server goes down, creating a project task from a general website inquiry, internal purchasing or HR onboarding notifications, updating an inventory spreadsheet, tracking software license renewals.

Needs a BAA-covered path instead of Zapier: Patient intake forms, appointment requests with a patient’s name attached, syncing EHR data, routing lab results, automating referrals, sending insurance claims, transferring billing records that include PHI.

What Gil Vidals Says

Gil Vidals made a related point directly, on the risk of assuming a tool is automatically safe just because it works:

“Unless you have a very expensive plan with Claude or OpenAI where they have signed a BAA and they have zero retention policies, you need to be really careful on what you’re putting into that prompt box.”

The same logic applies one layer over: it’s not enough that an automation works and the test email arrives. What matters is whether the specific tool handling that data — Zapier included — has a signed BAA for the account tier you’re actually using. HIPAA Vault also provides managed, HIPAA-compliant WordPress hosting — with a BAA included — for practices connecting Zapier to a WordPress site rather than a custom app.

What to Do Instead

  1. Audit every Zap already running. Don’t assume you know what’s connected — check, especially if the integration was set up quickly to ship a feature.
  2. Keep Zapier for what it’s actually good at. Non-clinical intake routing, marketing sequences, internal task handoffs, and billing/scheduling triage that never touches PHI are all reasonable uses.
  3. Route anything touching PHI through a BAA-covered service instead. That might mean a direct integration with a compliant email or SMS provider, or a workflow automation platform built specifically for healthcare that does sign a BAA.
  4. Don’t assume “enterprise” solves this. Zapier’s enterprise tier adds governance and model-training opt-outs, but it does not add HIPAA support or a BAA. Enterprise pricing is not the same as compliance.
  5. Re-map your automations any time the app or site changes. A new feature can introduce a new Zap or third-party call without anyone deciding to add PHI risk — it just happens as a side effect of solving the immediate problem.

Not sure what your app or WordPress site is actually connected to? HIPAA Vault can review your architecture, scope out exactly what needs to change, and deploy it to a BAA-covered production environment or explore HIPAA-compliant WordPress hosting → if your integrations run through a WordPress site.

How to Audit the Zaps You’re Already Running

If Zapier is already wired into your app or site, work through these five questions before deciding whether anything needs to change:

  1. Does the workflow involve patient information? Review every trigger and action in the Zap, not just the ones that seem obviously clinical.
  2. Could any field contain PHI? Don’t stop at diagnoses — appointment details, insurance information, referral notes, and even a name paired with a service can qualify.
  3. Which systems receive the data? Document every destination. A single Zap can quietly fan out to two or three downstream services.
  4. Does every service in that chain support HIPAA? One non-compliant link in an otherwise careful workflow still creates real exposure.
  5. Should the workflow be redesigned? Sometimes the simplest fix is moving the automation to a platform built for HIPAA-regulated data rather than patching around Zapier.

Are we treating “it works” and “it’s compliant” as the same thing? That’s the question underneath all five of these — and it’s worth asking explicitly, not just assuming the answer.

FAQ


For informational purposes only, not legal advice — consult qualified counsel for your specific HIPAA obligations. Reflects Zapier’s published documentation as of the publish date and the perspective of Gil Vidals, CTO and Co-Founder of HIPAA Vault.