SaaS HIPAA, BAA, and SOC 2 Finder

Search vendors before HIPAA-regulated workflows. Review BAA signals, PHI risk, SOC 2 evidence, and safer alternatives to verify.

Showing high-signal vendor profiles - type to filter the database

QuickBooks

HIPAA: Not HIPAA compliantSOC2: Verify with vendor

QuickBooks offers SOC 2 Type II compliance and can be HIPAA compliant with specific e...

Shopify

HIPAA: Not supported for PHISOC2: Public evidence

Shopify offers a robust security framework and SOC 2 compliance, but HIPAA compliance...

Zelle

HIPAA: Unable to confirmSOC2: Verify with participating bank

Zelle, as a peer-to-peer payment service, is generally not HIPAA compliant and does n...

Salesforce

HIPAA: ConditionalSOC2: Public evidence

Salesforce offers a robust security framework and achieves SOC 2 compliance, but HIPA...

Chime

HIPAA: Unable to confirmSOC2: Verify with vendor

Chime is a neobank primarily focused on consumer banking and does not generally offer...

Outlook

HIPAA: ConditionalSOC2: Yes

Outlook.live.com offers features and configurations that can support HIPAA compliance...

Google Calendar

HIPAA: ConditionalSOC2: Public evidence

Google Calendar, as part of Google Workspace, offers a strong security foundation and...

HubSpot

HIPAA: ConditionalSOC2: Public evidence

HubSpot offers robust security features and SOC 2 Type II compliance, but HIPAA compl...

Wix

HIPAA: ConditionalSOC2: Verify with vendor

Wix offers SOC 2 Type II compliance and can be made HIPAA compliant through specific ...

ChatGPT

HIPAA: ConditionalSOC2: Public evidence

ChatGPT demonstrates a strong commitment to security with SOC 2 Type II certification...

Pro Tools

HIPAA: ConditionalSOC2: Unknown

Pro Tools, while not inherently HIPAA compliant out-of-the-box, can be used in HIPAA-...

QuickBooks Desktop

HIPAA: Unable to confirmSOC2: Verify with vendor

QuickBooks Desktop offers features and Intuit provides a BAA for eligible enterprise ...

Educational compliance research database

ComplySaaS maps SaaS vendors to HIPAA, BAA, PHI, and SOC 2 review questions.

The database currently covers 271 SaaS vendor records and organizes them into vendor compliance profiles, HIPAA-compliant category hubs, and buyer guides. Each core profile is written for cautious vendor review: BAA availability, PHI workflow risk, SOC 2 evidence, source notes, last-checked dates, confidence level, and safer alternatives where appropriate.

ComplySaaS provides educational software compliance research only. We are not a law firm, compliance auditor, healthcare provider, or certification body. Vendor compliance status can change and may depend on plan, configuration, signed agreements, and intended use. Always verify directly with the vendor and consult qualified legal or compliance counsel before storing, transmitting, or processing PHI or regulated data.

Explore HIPAA, BAA, and SOC 2 Research

Vendor profiles

  • HubSpot

    HIPAA: Conditional | SOC 2: Public evidence

  • Shopify

    HIPAA: Not supported for PHI | SOC 2: Public evidence

  • ChatGPT

    HIPAA: Conditional | SOC 2: Public evidence

  • Wix

    HIPAA: Conditional | SOC 2: Verify with vendor

  • QuickBooks Desktop

    HIPAA: Unable to confirm | SOC 2: Verify with vendor

  • Klaviyo

    HIPAA: Unable to confirm | SOC 2: Public trust signal

  • Google Calendar

    HIPAA: Conditional | SOC 2: Public evidence

  • Chime

    HIPAA: Unable to confirm | SOC 2: Verify with vendor

  • QuickBooks

    HIPAA: Not HIPAA compliant | SOC 2: Verify with vendor

  • Zelle

    HIPAA: Unable to confirm | SOC 2: Verify with participating bank

  • Airtable

    HIPAA: Conditional | SOC 2: Public evidence

  • AWS

    HIPAA: Conditional | SOC 2: Public evidence

Compliance categories