Questions? Talk to a Real Person via our Live Chat
Is Windsurf HIPAA Compliant? The Vibe-Coding Tool athenahealth Actually Uses (2026)
By Alicia Kelley, , HIPAA Blog, Resources, Vibe Coding

Is Windsurf HIPAA Compliant? The Vibe-Coding Tool athenahealth Actually Uses (2026)

Short answer: Windsurf has the strongest HIPAA story of any AI coding tool examined in this series — and it’s the only one with a named healthcare customer to back it up. Windsurf’s own security documentation states plainly that it will “entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance” for significant implementations. And... Continue reading
Is v0 HIPAA Compliant? Why Vercel’s Answer Is Different From the Rest (2026)
By Gil Vidals, , HIPAA Blog, Resources, Vibe Coding

Is v0 HIPAA Compliant? Why Vercel’s Answer Is Different From the Rest (2026)

Short answer: v0 is the one vibe-coding tool in this series backed by a real, third-party-audited HIPAA compliance program — but it’s gated behind a custom-priced Enterprise plan, and it’s not the same thing as a standing offer to sign a Business Associate Agreement. Vercel, the company behind v0, lists HIPAA and HITECH as certified... Continue reading
How to Evaluate a HIPAA-Compliant App Builder: A Framework for Healthcare Founders
By Brenda Medel, , HIPAA Blog, Resources, Vibe Coding

How to Evaluate a HIPAA-Compliant App Builder: A Framework for Healthcare Founders

No AI-powered app builder is HIPAA compliant out of the box — but that doesn’t mean you can’t use them to build healthcare applications. The right question isn’t “is this app builder HIPAA compliant?” It’s “can I build a compliant application with this tool, and can I deploy it to a compliant environment?” The HIPAA... Continue reading
Is Cursor HIPAA Compliant? Vibe Coding Tools for Healthcare Compared
By Monica Dircio, , HIPAA Blog, Resources, Vibe Coding

Is Cursor HIPAA Compliant? Vibe Coding Tools for Healthcare Compared

Short answer: Cursor is not HIPAA compliant, and Anysphere (the company behind it) doesn’t offer a Business Associate Agreement (BAA). Cursor has strong general-purpose security — SOC 2 Type II certification, AES-256 encryption at rest, TLS 1.2+ in transit, SSO/SCIM, and a zero-data-retention Privacy Mode — but none of that satisfies HIPAA, which requires a... Continue reading
Is Bolt.new HIPAA Compliant? What StackBlitz’s Policies Actually Say
By Gil Vidals, , HIPAA Blog, Resources, Vibe Coding

Is Bolt.new HIPAA Compliant? What StackBlitz’s Policies Actually Say

Short answer: Bolt.new is not HIPAA compliant, among the vibe-coding tools not built for regulated health data. Bolt (built by StackBlitz) offers no Business Associate Agreement anywhere in its Terms of Service, Privacy Policy, Enterprise page, or Pricing page. What makes Bolt’s paper trail unusual is the split between documents: its Terms of Service haven’t... Continue reading
Is Lovable HIPAA Compliant? What Its Terms of Service Actually Say
By Josh Vidals, , HIPAA Blog, Resources, Vibe Coding

Is Lovable HIPAA Compliant? What Its Terms of Service Actually Say

Short answer: Lovable is not HIPAA compliant, and unlike most vibe-coding tools, its Terms of Service say so directly. As of the January 2026 update, Lovable’s ToS states in plain language: “You agree not to upload, input, or otherwise provide any protected health information under HIPAA, or any other sensitive categories of data… Our Services... Continue reading