SaaS compliance finder

SaaS HIPAA compliance vendor finder

Review SaaS vendors for HIPAA, BAA, PHI, and SOC 2 signals before regulated data enters a tool. Each profile is educational, source-backed where possible, date-stamped, and written to avoid absolute compliance claims.

Core vendor profiles

36

High-confidence source reviews

24

Conditional HIPAA signals

24

Short answer

No SaaS vendor should be treated as automatically HIPAA compliant. Start with public HIPAA, BAA, PHI, and SOC 2 signals, then verify the exact product, plan, covered services, configuration, integrations, and intended use directly with the vendor.

Core vendor profiles

VendorCategoryHIPAA signalBAA signalConfidence
HubSpot

HubSpot may support some HIPAA-regulated workflows only under specific plan, configuration, and Business Associate Agreement conditions. Do not s...

CRM and marketingConditionalAvailable for eligible setupHigh
Klaviyo

Klaviyo should not be used to manage or store sensitive health data. Klaviyo's current Privacy FAQs say its Acceptable Use Policy prohibits sensi...

CRM and marketingNot supported for health dataUnable to confirmMedium
Wix

Wix may support HIPAA-regulated site workflows only after PHI protection is activated, a supported plan is used, and the BAA process is completed...

Forms and intakeConditionalAvailable after PHI protectionMedium
Shopify

Shopify should not be treated as a PHI-handling platform. Shopify's Acceptable Use Policy lists uploading Protected Health Information subject to...

CRM and marketingNot supported for PHIUnable to confirmHigh
QuickBooks

QuickBooks Online should not be used to store individually identifiable health information. Intuit's public QuickBooks guidance says QuickBooks O...

Accounting and paymentsNot HIPAA compliantUnable to confirmHigh
QuickBooks Desktop

QuickBooks Desktop requires separate review because compliance depends on local deployment, hosted access, backups, support, payments, payroll, a...

Accounting and paymentsUnable to confirmUnable to confirmMedium
ChatGPT

ChatGPT should only be used with PHI through an OpenAI product that is explicitly HIPAA eligible, covered by an executed BAA, and configured for ...

AI chatbotsConditionalEligible products onlyHigh
Google Calendar

Google Calendar may support HIPAA-regulated scheduling only as part of eligible Google Workspace or Cloud Identity services after a Google BAA is...

Calendar and schedulingConditionalGoogle Workspace BAAHigh
Google Forms

Google Forms may support a HIPAA-regulated collection workflow only inside an eligible, managed Google Workspace environment after the applicable...

Forms and intakeConditionalGoogle Workspace BAAHigh
Chime

Chime should be treated as a consumer banking product, not a HIPAA workflow platform. ComplySaaS did not confirm public BAA or HIPAA documentatio...

Accounting and paymentsUnable to confirmUnable to confirmLow
Zelle

Zelle should not be used as a PHI-handling system. It is a payment network accessed through participating financial institutions, and ComplySaaS ...

Accounting and paymentsUnable to confirmUnable to confirmLow
Airtable

Airtable may support some HIPAA-regulated workflows only for Enterprise Scale customers that execute Airtable's Health Information Exhibit or app...

Forms and intakeConditionalEnterprise Scale onlyHigh
Jotform

Jotform may support HIPAA-regulated forms only when HIPAA features are enabled, the account is on an eligible plan, and a Business Associate Agre...

Forms and intakeConditionalAvailable with HIPAA featuresHigh
Zapier

Zapier should not be used to automate workflows involving PHI. Zapier's own HIPAA guidance says it is not HIPAA compliant and should not be used ...

Forms and intakeNot supported for PHIUnable to confirmHigh
AWS

AWS can support HIPAA-regulated workloads only under the AWS Business Associate Addendum, HIPAA-eligible services, and correct customer configura...

Cloud and databaseConditionalAWS BAA requiredHigh
Amazon RDS

Amazon RDS may support HIPAA-regulated database workloads only when used as an AWS HIPAA-eligible service under an accepted AWS BAA and correctly...

Cloud and databaseConditionalAWS BAA requiredHigh
Amazon Aurora

Amazon Aurora may support HIPAA-regulated database workloads only when used as an AWS HIPAA-eligible service under an accepted AWS BAA and correc...

Cloud and databaseConditionalAWS BAA requiredHigh
Amazon Connect

Amazon Connect may support HIPAA-regulated contact-center workflows because AWS lists it as HIPAA eligible. PHI use still requires the AWS BAA an...

Email and messagingConditionalAWS BAA requiredHigh
AWS Bedrock

Amazon Bedrock may support HIPAA-regulated AI workloads because AWS lists it as HIPAA eligible, with stated exclusions for Fable and Mythos model...

AI chatbotsConditionalAWS BAA requiredHigh
Twilio

Twilio may support some HIPAA-regulated communications only when the customer has an eligible Security or Enterprise Edition account, signs Twili...

Email and messagingConditionalEligible accounts and productsHigh
SendGrid

Twilio SendGrid should not be used to send or process PHI. SendGrid's own documentation says it is not a HIPAA Eligible Service, does not nativel...

Email and messagingNot HIPAA eligibleNot available for SendGridHigh
Salesforce

Salesforce may support HIPAA-regulated workflows only for covered Salesforce services, configured features, and contract scope. Verify the curren...

CRM and marketingConditionalCovered services onlyHigh
Google Workspace

Google Workspace may support HIPAA-regulated workflows only for included Workspace or Cloud Identity functionality after the Google BAA is accept...

Email and messagingConditionalGoogle Workspace BAAHigh
Pipedrive

Pipedrive should be treated as a conditional SaaS option for HIPAA-regulated workflows until BAA availability, covered services, security evidenc...

CRM and marketingConditionalPublic signal - verify scopeLow
Notion

Notion should be treated as a conditional SaaS option for HIPAA-regulated workflows until BAA availability, covered services, security evidence, ...

CRM and marketingConditionalPublic signal - verify scopeLow
monday.com

monday.com may support HIPAA-regulated workflows only on eligible Enterprise accounts after HIPAA compliance is activated and the BAA is accepted...

Project managementEnterprise onlyBAA available on EnterpriseHigh
Paubox

Paubox is purpose-built for HIPAA-focused email workflows and may be a safer option for healthcare email than general marketing or transactional ...

Email and messagingHIPAA-focused emailBAA requiredMedium
Stripe

Stripe has strong payment security and SOC evidence, but ComplySaaS did not confirm public HIPAA or BAA support for PHI workflows in this pass. H...

Accounting and paymentsUnable to confirmUnable to confirmMedium
Calendly

Calendly should not be treated as a PHI collection tool. Calendly's Notetaker FAQ says Calendly is not designed to collect Protected Health Infor...

Calendar and schedulingNot designed for PHIUnable to confirmMedium
Square

Square may support some HIPAA-regulated workflows only under Square's HIPAA Business Associate Agreement and the applicable Square services. Heal...

Accounting and paymentsConditionalSquare HIPAA BAAMedium
Zendesk

Zendesk may support some HIPAA-regulated support workflows when an eligible customer purchases Advanced Compliance or an included plan, executes ...

Help desk and ticketingConditionalAdvanced Compliance BAAHigh
Freshdesk

Freshdesk may support some HIPAA-regulated ticketing workflows only when Freshworks and the customer execute a BAA for the specified Freshdesk su...

Help desk and ticketingConditionalBAA for specified productsMedium
Help Scout

Help Scout may support HIPAA-regulated support workflows for eligible Pro accounts after the appropriate BAA is signed and HIPAA support is enabl...

Help desk and ticketingConditionalPro plan BAAHigh
Zoom

Zoom may support HIPAA-regulated meetings and communications only after the customer enters Zoom's BAA and verifies that the selected plan, produ...

Calendar and schedulingConditionalStandard BAA availableHigh
Microsoft Forms

Microsoft Forms appears in Microsoft's current Office 365 HIPAA/HITECH in-scope services list, but a Forms workflow is not automatically HIPAA co...

Forms and intakeConditionalMicrosoft BAA in-scope serviceHigh
Asana

Asana may support HIPAA-regulated work management only on an eligible Enterprise+ domain after a super admin accepts Asana's Business Associate A...

Project managementConditionalEnterprise+ BAA activationHigh

Browse HIPAA software categories

Email and messaging

HIPAA-regulated email and messaging workflows usually require more than encryption. Verify BAA availability, covered services, admin controls, retention, audit logs, user access, and whether PHI can appear in message bodies, subject lines, attachments, or notifications.

CRM and marketing

Healthcare CRM and marketing tools are often conditional. A vendor's security program does not automatically make campaigns, forms, lead records, chat, or integrations appropriate for PHI. Verify BAA scope, eligible plans, field handling, consent, and connected apps.

Forms and intake

Forms and intake tools are high-risk because they intentionally collect sensitive information. Before using any form builder for PHI, verify BAA coverage, storage location, email notifications, file uploads, integrations, access controls, and deletion workflows.

Calendar and scheduling

Scheduling tools can expose PHI through appointment titles, notes, guest lists, reminders, video links, and integrations. Verify BAA coverage and configure calendars so appointment metadata does not disclose diagnosis, treatment, or patient status.

Accounting and payments

Accounting and payment systems may not need PHI to do their job. Healthcare teams should avoid diagnosis, treatment, or patient details in invoices, memos, receipts, payment notes, attachments, and support tickets unless BAA coverage is verified.

AI chatbots

AI tools require strict review before any PHI use. Verify eligible product tier, BAA terms, data retention, training controls, logging, connected apps, human review workflows, and whether prompts, uploads, transcripts, or outputs contain regulated data.

View all category hubs

Verification guides

HIPAA SaaS BAA Availability Index

The ComplySaaS BAA Availability Index compares public HIPAA, BAA, PHI, and SOC 2 signals across 30 core SaaS vendors. It is a research starting point, not a certification: every status still depends on current plan, product scope, configuration, signed terms, and intended use.

What Is a Business Associate Agreement (BAA)?

A Business Associate Agreement is a HIPAA contract between a covered entity and a vendor that may create, receive, maintain, or transmit PHI. A BAA does not automatically make a workflow compliant; plan scope, product configuration, and intended use still matter.

Can You Store PHI in SaaS Tools?

You should only store PHI in a SaaS tool after verifying that the vendor, product, plan, agreement, configuration, and connected systems support that specific regulated workflow. Public security claims or SOC 2 evidence alone are not enough.

HIPAA Database Security Requirements for SaaS Teams

A database is not HIPAA compliant by itself. A HIPAA-ready database workflow requires a covered vendor or cloud service, appropriate BAA scope, encryption, identity controls, audit logging, backup governance, retention, deletion, and policies for every application, export, support, and analytics path that touches PHI.

What Makes a Phone Number or Texting App HIPAA Compliant?

A phone number is not HIPAA compliant by itself. The calling, texting, voicemail, storage, staff access, vendor agreement, and message content all matter. Verify BAA availability and avoid including PHI in SMS or voicemail unless the workflow is approved.

View all guides

Methodology

  • Prioritize vendor official documentation, trust pages, legal terms, BAA materials, and regulator guidance.
  • Separate HIPAA, BAA, PHI, SOC 2, PCI, and general security signals instead of collapsing them into one status.
  • Use confidence levels and source notes where public documentation is incomplete or plan-dependent.
  • Recommend direct vendor verification before PHI is stored, transmitted, processed, or entered into connected tools.