Questions? Talk to a Real Person via our Live Chat
How Much Does a HIPAA Violation Cost? Fines, Cases, and Prevention
By Monica Dircio, , HIPAA Blog, Resources, Security

How Much Does a HIPAA Violation Cost? Fines, Cases, and Prevention

HIPAA violation fines range from $145 to $73,011 per violation, depending on the level of culpability, with annual caps adjusted periodically for inflation — reaching over $2.1 million for the most serious violations. A single enforcement action in 2024 resulted in a $4.75 million penalty against Montefiore Medical Center, exceeding the HHS Office for Civil... Continue reading
Is Retool HIPAA Compliant? No BAA on Any Cloud Plan — Here’s the Self-Hosted Exception (2026)
By Gil Vidals, , HIPAA Blog, Resources, Vibe Coding

Is Retool HIPAA Compliant? No BAA on Any Cloud Plan — Here’s the Self-Hosted Exception (2026)

No. Retool will not sign a Business Associate Agreement on any cloud plan, and its own contracts say so directly. Retool’s Master Subscription Agreement (Enterprise) and Customer-Specific Supplement (Free, Team, and Business) both state plainly: “Retool is not a Business Associate or subcontractor… and accordingly, Customer is solely responsible for complying with any obligations thereunder.”... Continue reading
AI Coding Tools Keep Hardcoding API Keys — Why That’s a HIPAA Breach Risk, Not Just a Bug
By Brenda Medel, , HIPAA Blog, Resources, Vibe Coding

AI Coding Tools Keep Hardcoding API Keys — Why That’s a HIPAA Breach Risk, Not Just a Bug

Hardcoded API keys aren’t a rare mistake in AI-generated code — they’re one of the most common defects it produces, and in a healthcare application they’re a direct path to an impermissible disclosure under the HIPAA Security Rule. Independent research in 2026 found roughly 380,000 publicly accessible applications built on vibe-coding platforms like Lovable, Replit,... Continue reading
Is Supabase HIPAA Compliant? Yes — Here’s What the BAA Actually Requires (2026)
By Alicia Kelley, , HIPAA Blog, Resources, Vibe Coding

Is Supabase HIPAA Compliant? Yes — Here’s What the BAA Actually Requires (2026)

Yes — Supabase is the rare tool in this series where the answer is genuinely “yes,” not “no” or “it depends.” Supabase’s hosted platform is SOC 2 Type II certified, ISO 27001 certified, and offers a signed Business Associate Agreement (BAA) as a paid HIPAA add-on to Team ($599/month) and Enterprise customers. But “yes” comes... Continue reading
Is GitHub Copilot HIPAA Compliant? What Microsoft’s Own BAA Excludes (2026)
By Josh Vidals, , HIPAA Blog, HIPAA Compliance, Resources

Is GitHub Copilot HIPAA Compliant? What Microsoft’s Own BAA Excludes (2026)

No. GitHub Copilot is not HIPAA compliant, and — more strikingly — it’s explicitly excluded from Microsoft’s own HIPAA Business Associate Agreement (BAA), even though Microsoft owns GitHub. Microsoft offers a BAA covering Azure, Office 365, Dynamics 365, Microsoft 365 Copilot, and roughly two dozen other in-scope services. GitHub and GitHub Copilot are not on... Continue reading
Is Windsurf HIPAA Compliant? The Vibe-Coding Tool athenahealth Actually Uses (2026)
By Alicia Kelley, , HIPAA Blog, Resources, Vibe Coding

Is Windsurf HIPAA Compliant? The Vibe-Coding Tool athenahealth Actually Uses (2026)

Short answer: Windsurf has the strongest HIPAA story of any AI coding tool examined in this series — and it’s the only one with a named healthcare customer to back it up. Windsurf’s own security documentation states plainly that it will “entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance” for significant implementations. And... Continue reading