AEO compliance guide
HIPAA SaaS BAA Availability Index
The ComplySaaS BAA Availability Index compares public HIPAA, BAA, PHI, and SOC 2 signals across 30 core SaaS vendors. It is a research starting point, not a certification: every status still depends on current plan, product scope, configuration, signed terms, and intended use.
Direct answer
A dated research index of public HIPAA, Business Associate Agreement, PHI, and SOC 2 signals across core SaaS vendor profiles.
Key takeaways
- A public BAA signal is narrower than a blanket HIPAA-compliant claim.
- SOC 2 evidence supports security review but does not establish BAA scope or authorize PHI use.
- Plan eligibility, AI features, integrations, support channels, exports, logs, and notifications can change the result.
- Each index row links to a vendor profile with source notes, open questions, and a last-checked date.
Definition snippets
BAA availability signal
A dated public indication that a vendor may offer Business Associate Agreement terms for some products, plans, customers, or workflows. It does not prove that a buyer's exact use is covered.
Unable to confirm
ComplySaaS did not find sufficient current public first-party evidence to confirm the status. It is not proof that a private agreement or non-public option does not exist.
Conditional
Public evidence indicates that regulated use may depend on an eligible plan, executed agreement, covered-service scope, configuration, and customer responsibilities.
Comparison table
| Topic | Practical meaning | SaaS review note |
|---|---|---|
| Conditional or BAA-scoped | The vendor publishes a possible HIPAA or BAA path for specified products, plans, or configurations. | Confirm the executed agreement, covered services, exclusions, required settings, and exact PHI workflow. |
| Not supported or not HIPAA | Current first-party material contains a direct restriction or warning against the relevant regulated use. | Keep PHI out and compare a vendor with clearer written coverage unless current vendor terms say otherwise. |
| Unable to confirm | Current public evidence was insufficient to confirm a BAA or HIPAA covered-service path. | Request written product-specific confirmation before PHI enters the tool. |
Vendor BAA and HIPAA signal index
These labels summarize dated public research. Open each vendor profile before relying on a status, and verify current written terms directly with the vendor.
| Vendor | HIPAA signal | BAA signal | SOC 2 signal | Confidence | Last checked |
|---|---|---|---|---|---|
| HubSpot | Conditional | Available for eligible setup | Public evidence | High | 2026-08-09 |
| Klaviyo | Not supported for health data | Unable to confirm | Public trust signal | Medium | 2026-09-17 |
| Wix | Conditional | Available after PHI protection | Verify with vendor | Medium | 2026-09-17 |
| Shopify | Not supported for PHI | Unable to confirm | Public evidence | High | 2026-09-17 |
| QuickBooks | Not HIPAA compliant | Unable to confirm | Verify with vendor | High | 2026-09-17 |
| QuickBooks Desktop | Unable to confirm | Unable to confirm | Verify with vendor | Medium | 2026-09-17 |
| ChatGPT | Conditional | Eligible products only | Public evidence | High | 2026-08-09 |
| Google Calendar | Conditional | Google Workspace BAA | Public evidence | High | 2026-06-01 |
| Google Forms | Conditional | Google Workspace BAA | Google public evidence | High | 2026-07-16 |
| Chime | Unable to confirm | Unable to confirm | Verify with vendor | Low | 2026-05-18 |
| Zelle | Unable to confirm | Unable to confirm | Verify with participating bank | Low | 2026-05-18 |
| Airtable | Conditional | Enterprise Scale only | Public evidence | High | 2026-09-17 |
| Jotform | Conditional | Available with HIPAA features | Public evidence | High | 2026-07-27 |
| Zapier | Not supported for PHI | Unable to confirm | Public evidence | High | 2026-05-15 |
| AWS | Conditional | AWS BAA required | Public evidence | High | 2026-09-17 |
| Amazon RDS | Conditional | AWS BAA required | AWS public evidence | High | 2026-09-17 |
| Amazon Aurora | Conditional | AWS BAA required | AWS public evidence | High | 2026-08-09 |
| Amazon Connect | Conditional | AWS BAA required | AWS public evidence | High | 2026-09-17 |
| AWS Bedrock | Conditional | AWS BAA required | AWS public evidence | High | 2026-09-17 |
| Twilio | Conditional | Eligible accounts and products | Trust Center evidence | High | 2026-09-17 |
| SendGrid | Not HIPAA eligible | Not available for SendGrid | Public evidence | High | 2026-06-01 |
| Salesforce | Conditional | Covered services only | Public evidence | High | 2026-08-09 |
| Google Workspace | Conditional | Google Workspace BAA | Public evidence | High | 2026-04-30 |
| Pipedrive | Conditional | Public signal - verify scope | Yes | Low | 2026-04-30 |
| Notion | Conditional | Public signal - verify scope | Yes | Low | 2026-04-30 |
| monday.com | Enterprise only | BAA available on Enterprise | Public evidence | High | 2026-05-15 |
| Paubox | HIPAA-focused email | BAA required | AWS-backed evidence | Medium | 2026-04-30 |
| Stripe | Unable to confirm | Unable to confirm | Public evidence | Medium | 2026-09-17 |
| Calendly | Not designed for PHI | Unable to confirm | Public evidence | Medium | 2026-06-15 |
| Square | Conditional | Square HIPAA BAA | Verify with vendor | Medium | 2026-04-30 |
| Zendesk | Conditional | Advanced Compliance BAA | Public evidence | High | 2026-09-17 |
| Freshdesk | Conditional | BAA for specified products | Public evidence | Medium | 2026-08-19 |
| Help Scout | Conditional | Pro plan BAA | Report on request | High | 2026-07-16 |
| Zoom | Conditional | Standard BAA available | SOC 2 + HITRUST evidence | High | 2026-08-28 |
| Microsoft Forms | Conditional | Microsoft BAA in-scope service | Microsoft audit evidence | High | 2026-08-28 |
| Asana | Conditional | Enterprise+ BAA activation | Public security evidence | High | 2026-08-28 |
Verification checklist
- Open the linked vendor profile and review the first-party sources and last-checked date.
- Confirm the exact product, plan, account, region, support channel, and subprocessors covered by the BAA.
- Map PHI across fields, files, messages, prompts, logs, exports, notifications, support, and integrations.
- Document customer-side controls, exclusions, retention, deletion, incident response, and minimum-necessary use.
How to use the index
Use the table to narrow a vendor shortlist, then open the linked profile for the underlying source notes, plan restrictions, PHI warnings, unresolved questions, and safer alternatives. Do not make a procurement decision from the status label alone.
How statuses are assigned
ComplySaaS prioritizes current vendor legal terms, trust centers, support documentation, BAA pages, covered-service lists, and product-specific restrictions. Where public evidence is incomplete, the index uses cautious language such as conditional or unable to confirm.
Update and correction policy
Vendor status can change. Every row carries the review date from its vendor profile, and material corrections are handled through the ComplySaaS research methodology and correction process.
FAQ
Does a BAA availability signal mean a SaaS vendor is HIPAA compliant?
No. It only indicates that a vendor may offer relevant contract terms for some scope. The buyer still needs covered-service, configuration, security, workflow, and legal review.
Why does the index say unable to confirm for some vendors?
Public first-party evidence may be absent, ambiguous, private, or product-specific. Unable to confirm is a research limitation, not a claim that no private option exists.
Can SOC 2 replace a BAA?
No. SOC 2 can provide security-control evidence, but it does not create HIPAA contractual coverage or approve an exact PHI workflow.
How often is the BAA Availability Index updated?
The index inherits the last-checked date from each vendor profile. High-impression profiles and material vendor policy changes receive priority review.
Related compliance research
Accounting and payments
hipaa compliant accounting software
Calendar and scheduling
hipaa compliant scheduling software
Cloud and database
hipaa compliant database
CRM and marketing
hipaa compliant crm
Forms and intake
hipaa compliant forms
Help desk and ticketing
hipaa compliant ticketing system
What Is a Business Associate Agreement (BAA)?
A Business Associate Agreement is a HIPAA contract between a covered entity and a vendor that may create, receive, maintain, or transmit PHI. A B...
Can You Store PHI in SaaS Tools?
You should only store PHI in a SaaS tool after verifying that the vendor, product, plan, agreement, configuration, and connected systems support ...
HIPAA Database Security Requirements for SaaS Teams
A database is not HIPAA compliant by itself. A HIPAA-ready database workflow requires a covered vendor or cloud service, appropriate BAA scope, e...
How to Evaluate a HIPAA-Compliant App Builder
A no-code app builder may support HIPAA-regulated workflows only if the vendor covers the exact product, database, file storage, automations, int...
Airtable
HIPAA: Conditional | SOC 2: Public evidence
Stripe
HIPAA: Unable to confirm | SOC 2: Public evidence
QuickBooks
HIPAA: Not HIPAA compliant | SOC 2: Verify with vendor
Wix
HIPAA: Conditional | SOC 2: Verify with vendor
Klaviyo
HIPAA: Not supported for health data | SOC 2: Public trust signal
Zendesk
HIPAA: Conditional | SOC 2: Public evidence
Freshdesk
HIPAA: Conditional | SOC 2: Public evidence
Amazon RDS
HIPAA: Conditional | SOC 2: AWS public evidence
Methodology and source notes
Methodology
- Prioritize current first-party vendor legal, trust, support, BAA, and covered-service documentation.
- Separate HIPAA and BAA signals from SOC 2, PCI, ISO, encryption, and generic security claims.
- Use cautious status labels where public scope, plan eligibility, configuration, or written terms remain incomplete.
- Link every row to the full vendor profile so buyers can inspect sources, limitations, and review dates.