AEO compliance guide

HIPAA SaaS BAA Availability Index

The ComplySaaS BAA Availability Index compares public HIPAA, BAA, PHI, and SOC 2 signals across 30 core SaaS vendors. It is a research starting point, not a certification: every status still depends on current plan, product scope, configuration, signed terms, and intended use.

Reviewed by Evidence: Public first-party sources

Direct answer

A dated research index of public HIPAA, Business Associate Agreement, PHI, and SOC 2 signals across core SaaS vendor profiles.

Key takeaways

  • A public BAA signal is narrower than a blanket HIPAA-compliant claim.
  • SOC 2 evidence supports security review but does not establish BAA scope or authorize PHI use.
  • Plan eligibility, AI features, integrations, support channels, exports, logs, and notifications can change the result.
  • Each index row links to a vendor profile with source notes, open questions, and a last-checked date.

Definition snippets

BAA availability signal

A dated public indication that a vendor may offer Business Associate Agreement terms for some products, plans, customers, or workflows. It does not prove that a buyer's exact use is covered.

Unable to confirm

ComplySaaS did not find sufficient current public first-party evidence to confirm the status. It is not proof that a private agreement or non-public option does not exist.

Conditional

Public evidence indicates that regulated use may depend on an eligible plan, executed agreement, covered-service scope, configuration, and customer responsibilities.

Comparison table

TopicPractical meaningSaaS review note
Conditional or BAA-scopedThe vendor publishes a possible HIPAA or BAA path for specified products, plans, or configurations.Confirm the executed agreement, covered services, exclusions, required settings, and exact PHI workflow.
Not supported or not HIPAACurrent first-party material contains a direct restriction or warning against the relevant regulated use.Keep PHI out and compare a vendor with clearer written coverage unless current vendor terms say otherwise.
Unable to confirmCurrent public evidence was insufficient to confirm a BAA or HIPAA covered-service path.Request written product-specific confirmation before PHI enters the tool.

Vendor BAA and HIPAA signal index

These labels summarize dated public research. Open each vendor profile before relying on a status, and verify current written terms directly with the vendor.

VendorHIPAA signalBAA signalSOC 2 signalConfidenceLast checked
HubSpotConditionalAvailable for eligible setupPublic evidenceHigh2026-08-09
KlaviyoNot supported for health dataUnable to confirmPublic trust signalMedium2026-09-17
WixConditionalAvailable after PHI protectionVerify with vendorMedium2026-09-17
ShopifyNot supported for PHIUnable to confirmPublic evidenceHigh2026-09-17
QuickBooksNot HIPAA compliantUnable to confirmVerify with vendorHigh2026-09-17
QuickBooks DesktopUnable to confirmUnable to confirmVerify with vendorMedium2026-09-17
ChatGPTConditionalEligible products onlyPublic evidenceHigh2026-08-09
Google CalendarConditionalGoogle Workspace BAAPublic evidenceHigh2026-06-01
Google FormsConditionalGoogle Workspace BAAGoogle public evidenceHigh2026-07-16
ChimeUnable to confirmUnable to confirmVerify with vendorLow2026-05-18
ZelleUnable to confirmUnable to confirmVerify with participating bankLow2026-05-18
AirtableConditionalEnterprise Scale onlyPublic evidenceHigh2026-09-17
JotformConditionalAvailable with HIPAA featuresPublic evidenceHigh2026-07-27
ZapierNot supported for PHIUnable to confirmPublic evidenceHigh2026-05-15
AWSConditionalAWS BAA requiredPublic evidenceHigh2026-09-17
Amazon RDSConditionalAWS BAA requiredAWS public evidenceHigh2026-09-17
Amazon AuroraConditionalAWS BAA requiredAWS public evidenceHigh2026-08-09
Amazon ConnectConditionalAWS BAA requiredAWS public evidenceHigh2026-09-17
AWS BedrockConditionalAWS BAA requiredAWS public evidenceHigh2026-09-17
TwilioConditionalEligible accounts and productsTrust Center evidenceHigh2026-09-17
SendGridNot HIPAA eligibleNot available for SendGridPublic evidenceHigh2026-06-01
SalesforceConditionalCovered services onlyPublic evidenceHigh2026-08-09
Google WorkspaceConditionalGoogle Workspace BAAPublic evidenceHigh2026-04-30
PipedriveConditionalPublic signal - verify scopeYesLow2026-04-30
NotionConditionalPublic signal - verify scopeYesLow2026-04-30
monday.comEnterprise onlyBAA available on EnterprisePublic evidenceHigh2026-05-15
PauboxHIPAA-focused emailBAA requiredAWS-backed evidenceMedium2026-04-30
StripeUnable to confirmUnable to confirmPublic evidenceMedium2026-09-17
CalendlyNot designed for PHIUnable to confirmPublic evidenceMedium2026-06-15
SquareConditionalSquare HIPAA BAAVerify with vendorMedium2026-04-30
ZendeskConditionalAdvanced Compliance BAAPublic evidenceHigh2026-09-17
FreshdeskConditionalBAA for specified productsPublic evidenceMedium2026-08-19
Help ScoutConditionalPro plan BAAReport on requestHigh2026-07-16
ZoomConditionalStandard BAA availableSOC 2 + HITRUST evidenceHigh2026-08-28
Microsoft FormsConditionalMicrosoft BAA in-scope serviceMicrosoft audit evidenceHigh2026-08-28
AsanaConditionalEnterprise+ BAA activationPublic security evidenceHigh2026-08-28

Verification checklist

  • Open the linked vendor profile and review the first-party sources and last-checked date.
  • Confirm the exact product, plan, account, region, support channel, and subprocessors covered by the BAA.
  • Map PHI across fields, files, messages, prompts, logs, exports, notifications, support, and integrations.
  • Document customer-side controls, exclusions, retention, deletion, incident response, and minimum-necessary use.

How to use the index

Use the table to narrow a vendor shortlist, then open the linked profile for the underlying source notes, plan restrictions, PHI warnings, unresolved questions, and safer alternatives. Do not make a procurement decision from the status label alone.

How statuses are assigned

ComplySaaS prioritizes current vendor legal terms, trust centers, support documentation, BAA pages, covered-service lists, and product-specific restrictions. Where public evidence is incomplete, the index uses cautious language such as conditional or unable to confirm.

Update and correction policy

Vendor status can change. Every row carries the review date from its vendor profile, and material corrections are handled through the ComplySaaS research methodology and correction process.

FAQ

Does a BAA availability signal mean a SaaS vendor is HIPAA compliant?

No. It only indicates that a vendor may offer relevant contract terms for some scope. The buyer still needs covered-service, configuration, security, workflow, and legal review.

Why does the index say unable to confirm for some vendors?

Public first-party evidence may be absent, ambiguous, private, or product-specific. Unable to confirm is a research limitation, not a claim that no private option exists.

Can SOC 2 replace a BAA?

No. SOC 2 can provide security-control evidence, but it does not create HIPAA contractual coverage or approve an exact PHI workflow.

How often is the BAA Availability Index updated?

The index inherits the last-checked date from each vendor profile. High-impression profiles and material vendor policy changes receive priority review.

Related compliance research

Accounting and payments

hipaa compliant accounting software

Calendar and scheduling

hipaa compliant scheduling software

Cloud and database

hipaa compliant database

CRM and marketing

hipaa compliant crm

Forms and intake

hipaa compliant forms

Help desk and ticketing

hipaa compliant ticketing system

What Is a Business Associate Agreement (BAA)?

A Business Associate Agreement is a HIPAA contract between a covered entity and a vendor that may create, receive, maintain, or transmit PHI. A B...

Can You Store PHI in SaaS Tools?

You should only store PHI in a SaaS tool after verifying that the vendor, product, plan, agreement, configuration, and connected systems support ...

HIPAA Database Security Requirements for SaaS Teams

A database is not HIPAA compliant by itself. A HIPAA-ready database workflow requires a covered vendor or cloud service, appropriate BAA scope, e...

How to Evaluate a HIPAA-Compliant App Builder

A no-code app builder may support HIPAA-regulated workflows only if the vendor covers the exact product, database, file storage, automations, int...

Airtable

HIPAA: Conditional | SOC 2: Public evidence

Stripe

HIPAA: Unable to confirm | SOC 2: Public evidence

QuickBooks

HIPAA: Not HIPAA compliant | SOC 2: Verify with vendor

Wix

HIPAA: Conditional | SOC 2: Verify with vendor

Klaviyo

HIPAA: Not supported for health data | SOC 2: Public trust signal

Zendesk

HIPAA: Conditional | SOC 2: Public evidence

Freshdesk

HIPAA: Conditional | SOC 2: Public evidence

Amazon RDS

HIPAA: Conditional | SOC 2: AWS public evidence

Methodology and source notes

Methodology

  • Prioritize current first-party vendor legal, trust, support, BAA, and covered-service documentation.
  • Separate HIPAA and BAA signals from SOC 2, PCI, ISO, encryption, and generic security claims.
  • Use cautious status labels where public scope, plan eligibility, configuration, or written terms remain incomplete.
  • Link every row to the full vendor profile so buyers can inspect sources, limitations, and review dates.