Is Retool HIPAA Compliant? No BAA on Any Cloud Plan — Here’s the Self-Hosted Exception (2026)
No. Retool will not sign a Business Associate Agreement on any cloud plan, and its own contracts say so directly. Retool’s Master Subscription Agreement (Enterprise) and Customer-Specific Supplement (Free, Team, and Business) both state plainly: “Retool is not a Business Associate or subcontractor… and accordingly, Customer is solely responsible for complying with any obligations thereunder.”... Continue reading
AI Coding Tools Keep Hardcoding API Keys — Why That’s a HIPAA Breach Risk, Not Just a Bug
Hardcoded API keys aren’t a rare mistake in AI-generated code — they’re one of the most common defects it produces, and in a healthcare application they’re a direct path to an impermissible disclosure under the HIPAA Security Rule. Independent research in 2026 found roughly 380,000 publicly accessible applications built on vibe-coding platforms like Lovable, Replit,... Continue reading
Is Supabase HIPAA Compliant? Yes — Here’s What the BAA Actually Requires (2026)
Yes — Supabase is the rare tool in this series where the answer is genuinely “yes,” not “no” or “it depends.” Supabase’s hosted platform is SOC 2 Type II certified, ISO 27001 certified, and offers a signed Business Associate Agreement (BAA) as a paid HIPAA add-on to Team ($599/month) and Enterprise customers. But “yes” comes... Continue reading
Is GitHub Copilot HIPAA Compliant? What Microsoft’s Own BAA Excludes (2026)
No. GitHub Copilot is not HIPAA compliant, and — more strikingly — it’s explicitly excluded from Microsoft’s own HIPAA Business Associate Agreement (BAA), even though Microsoft owns GitHub. Microsoft offers a BAA covering Azure, Office 365, Dynamics 365, Microsoft 365 Copilot, and roughly two dozen other in-scope services. GitHub and GitHub Copilot are not on... Continue reading
