AI Tool Risk Directory ← All 26 tools Assessed 29 July 2026

HIPAA-compliant AI tools: which vendors will sign a BAA?

No AI tool is "HIPAA compliant" on its own. HIPAA compliance is a property of your organisation and the contracts it holds — and the contract that matters here is the Business Associate Agreement. A BAA is the gate, not the security posture. A vendor can hold SOC 2 Type 2, ISO 27001, and a spotless breach record, and still be the wrong place for protected health information, because none of those documents put the vendor on the hook for HIPAA obligations. The BAA does.

So the useful question is not "is this tool HIPAA compliant." It is: will this vendor sign a BAA covering the specific service, on the specific plan, that my people are actually using? That is what the table below answers for all 26 tools in the directory, with the vendor document behind each answer.

What each status means

BAA status for 26 AI tools

ToolBAA statusWhat the vendor documentsOur tier verdict
Google Gemini for Workspace
Google
Yes
assessed 29 July 2026
Yes, on covered services. Google makes a HIPAA BAA available for acceptance in the Admin console, and its Workspace HIPAA documentation lists specific Gemini-powered features (help me write, contextual smart replies, side-panel) as HIPAA Included Functionality. Confirm which features your edition covers before putting PHI anywhere near them. source Approved
Microsoft Copilot for M365
Microsoft
Yes
assessed 29 July 2026
Microsoft states it enters into Business Associate Agreements with its covered-entity and business-associate customers for its enterprise products and services. Confirm that Copilot is in scope for your licence and configuration — a BAA covering Microsoft 365 is not automatically a decision about every feature you turn on. source Approved
ChatGPT Enterprise
OpenAI
Enterprise- or plan-dependent
assessed 29 July 2026
Available, but scope matters. OpenAI states it can sign BAAs in support of HIPAA compliance for its API Platform, and it offers a ChatGPT for Healthcare workspace designed to support HIPAA compliance. Coverage of your specific ChatGPT Enterprise deployment must be confirmed with OpenAI in writing. source Approved
Claude for Work / API
Anthropic
Enterprise- or plan-dependent
assessed 29 July 2026
Yes on the Enterprise plan or the first-party API — but only once someone switches it on. Anthropic states it "provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans", and that coverage is not automatic: the Primary Owner must activate HIPAA compliance in the organisation’s "Data and privacy" settings and accept the BAA, because "Standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner." Coverage is also per-organisation and per-feature — Anthropic excludes Workbench, Claude Console, Claude Cowork and beta features such as Claude in Office and Claude Design, treats connectors, MCP and Enterprise Search as usable but not covered when data goes to a third party, and states that Covered Models require 30-day retention and are not available with zero data retention enabled. Read the feature table before assuming your workflow is inside the BAA. source Approved
DALL·E (OpenAI Images)
OpenAI
Enterprise- or plan-dependent
assessed 29 July 2026
Depends on the OpenAI plan. There is no BAA on consumer ChatGPT; OpenAI states it can sign BAAs for its API Platform. Confirm the exact arrangement with OpenAI before any PHI is involved. source Limited
Fireflies.ai
Fireflies.ai
Enterprise- or plan-dependent
assessed 29 July 2026
Enterprise only. Fireflies states on its security page that it is "HIPAA - BAA Compliant" with PHI protection for healthcare — Enterprise only. Get the signed BAA before any call that could touch PHI. source Limited
Grok (xAI)
xAI
Enterprise- or plan-dependent
assessed 29 July 2026
On request, and scoped to the API. xAI publishes a BAA questionnaire described as being for customers requesting a Business Associate Agreement to enable HIPAA compliance when using xAI APIs, to be completed by an authorised company representative. A BAA is therefore something you request and sign for an API deployment — never something a consumer Grok account has. source (archived) Limited
Notion AI
Notion
Enterprise- or plan-dependent
assessed 29 July 2026
Notion states that Notion AI "enables HIPAA compliance" by using LLM providers’ zero-retention APIs and allows the processing of protected health information. That page does not set out BAA terms — get a signed BAA and confirm which plan it applies to before storing PHI. source Approved
Slack AI
Slack (Salesforce)
Enterprise- or plan-dependent
assessed 29 July 2026
Enterprise plans only. Slack states it can be configured to support HIPAA-compliant message and file collaboration on Enterprise plans, subject to agreeing to its Requirements for HIPAA Entities — and that you may not use Slack to communicate with patients or plan members. source Approved
Zoom AI Companion
Zoom
Enterprise- or plan-dependent
assessed 29 July 2026
By BAA with Zoom, not by product page. Zoom’s meeting-summary admin article lists among the feature’s requirements: "Meeting summary is available to customers with an active BAA." Two things follow from that sentence and no more — Zoom has customers holding an active BAA with it, and it does not withhold meeting summary from them. We did not read Zoom’s BAA itself, so it tells you nothing about which AI Companion features your own agreement covers. Confirm that in writing before a call could touch PHI. source (archived) Limited
Adobe Firefly
Adobe
Not publicly documented
assessed 29 July 2026
We could not check this. Adobe’s HIPAA and compliance material was not reachable from our network on this check date, so we assert nothing about Adobe’s position either way — including whether Firefly is or is not offered for protected health information. If you have a PHI use case, ask Adobe directly. Limited
Canva AI / Magic Write
Canva
Not publicly documented
assessed 29 July 2026
Not publicly documented in the sources we verified. Do not put PHI in design files. Limited
Grammarly Business
Grammarly (Superhuman Platform Inc.)
Not publicly documented
assessed 29 July 2026
Not publicly documented in the sources we could verify on this check date. Do not treat Grammarly Business as HIPAA-eligible without a signed BAA in hand. Limited
HubSpot AI (Breeze)
HubSpot
Not publicly documented
assessed 29 July 2026
Neither of the two documents we read end to end — the Data Processing Agreement and the Product Specific Terms, section 7 on HubSpot AI included — contains the words HIPAA, business associate, or protected health information anywhere. That is a checked absence in those two documents, and we are not claiming anything about what HubSpot may publish elsewhere. If PHI has to live in a CRM, put the question to HubSpot directly and get the answer in writing. Limited
Otter.ai
Otter.ai
Not publicly documented
assessed 29 July 2026
Not publicly documented in the sources we verified. Do not treat Otter as HIPAA-eligible without a signed BAA — assume it is not. Limited
Perplexity
Perplexity AI
Not publicly documented
assessed 29 July 2026
Not publicly documented as a BAA. Perplexity’s Enterprise page asserts the product is "GDPR and HIPAA compliant", but a compliance claim is not a Business Associate Agreement: we found no published BAA route, terms or request process. Treat that sentence as your cue to ask for the signed document, not as the document. Limited
Salesforce Einstein
Salesforce
Not publicly documented
assessed 29 July 2026
Not publicly documented in the primary sources we verified on this check date. Salesforce publishes HIPAA material separately — get BAA coverage of the specific Einstein features in writing before PHI is in scope. Approved
ChatGPT (free)
OpenAI
No
assessed 29 July 2026
No. OpenAI publishes BAA availability for its API Platform and offers a separate ChatGPT for Healthcare workspace; no BAA covers consumer ChatGPT accounts. source Limited
ChatGPT Plus
OpenAI
No
assessed 29 July 2026
No. OpenAI does not offer a BAA for consumer ChatGPT plans; its published BAA route is the API Platform, plus a separate ChatGPT for Healthcare workspace. source Limited
Claude (claude.ai free)
Anthropic
No
assessed 29 July 2026
No BAA is offered for free consumer claude.ai accounts. Limited
DeepSeek
DeepSeek (Hangzhou)
No
assessed 29 July 2026
No. Prohibited
Google Gemini (personal)
Google
No
assessed 29 July 2026
No. There is no BAA for consumer Gemini; Google’s HIPAA route is a Workspace BAA on covered services. source Prohibited
Grammarly (free)
Grammarly (Superhuman Platform Inc.)
No
assessed 29 July 2026
No BAA on free consumer accounts. Limited
Meta AI
Meta
No
assessed 29 July 2026
No. We found no published BAA or HIPAA-eligible business offering for Meta AI. Prohibited
Midjourney
Midjourney
No
assessed 29 July 2026
No. Midjourney is not offered as a system for protected health information. Limited
GitHub Copilot
GitHub (Microsoft)
N/A — not a PHI system
assessed 29 July 2026
Not applicable — GitHub does not market Copilot as a system for processing protected health information, and we found no published BAA for it. Limited

Status assessed 29 July 2026. Each tool page carries its own assessment date and the full source list.

The three mistakes that actually cause the problem

1. Treating a certification as a substitute for a contract

This is the most common one, and it is usually made by someone technical and well-intentioned. A SOC 2 Type 2 report describes how a vendor operates its controls over a period of time. It says nothing about whether the vendor has accepted HIPAA obligations toward you, whether it will report a breach to you on HIPAA’s timeline, or whether it will restrict downstream use of PHI. Only the BAA does that. Certifications are evidence a vendor is competent; the BAA is evidence they are accountable.

2. Assuming the BAA covers the AI feature

Several vendors here support a BAA at the platform level while saying much less about the AI features layered on top. A BAA covering a productivity suite is not automatically a decision about an AI assistant that reads across that suite, and a vendor may enumerate specific AI features as covered while leaving others out. When you ask for the BAA, ask in the same email which named features it covers — and keep the answer.

3. Writing the policy for the tools on the BAA list, not the ones people use

The consumer-tier general assistants are, by a wide margin, where PHI actually leaks: someone pastes a patient message in to soften the wording, or a meeting bot auto-joins a clinical call because it auto-joins everything. Those tools sit at the bottom of this table for a reason. A HIPAA-aware AI policy has to name them explicitly and give staff an approved alternative for the same task, or the rule loses to convenience.

How to use this table

Take the rows marked Yes or Enterprise- or plan-dependent as your candidate list, not your approved list. For each candidate, get the signed BAA, confirm the plan and the named features it covers, and only then write it into your policy as permitted for PHI. Everything marked Not publicly documented should be treated exactly like No until a signed document says otherwise — the absence of a published BAA route is not a technicality you can argue around after an incident.

Frequently asked questions

Which AI tools are HIPAA compliant?

Strictly speaking, none — HIPAA compliance is a property of an organisation and its contracts, not of a software product. What varies between vendors is whether they will sign a Business Associate Agreement covering the service you intend to use. Of the 26 tools tracked here, 10 publish a BAA route (some only on specific plans or by request), 7 do not publicly document one, 8 state or clearly indicate they do not offer one, and 1 are not offered for PHI at all.

Does a SOC 2 report mean a tool is safe for PHI?

No. A BAA is the gate, not the security posture. A vendor can hold SOC 2 Type 2, ISO 27001 and every certification on the market and still be the wrong place for protected health information, because what makes PHI processing lawful for a covered entity or business associate is the contract that assigns HIPAA obligations to the vendor. Certifications tell you how carefully a vendor runs its systems; a BAA tells you who is legally on the hook when something goes wrong.

The vendor says it is “HIPAA compliant” on its marketing page. Is that enough?

No. Treat a marketing claim as a signal that a BAA route probably exists, then go and get the signed BAA — and check which plan and which features it covers. Several tools here support a BAA only on an enterprise plan, and at least one vendor covers specific AI features rather than the whole product. Until you hold the signed document naming the service you actually use, assume you are not covered.

What should our AI policy say about PHI?

Name the rule in one line: no protected health information may be entered into any AI tool that is not covered by a signed Business Associate Agreement held by the company, and list the tools that are. Then name the failure mode people actually hit — pasting a patient message into a general assistant to “clean up the wording,” or letting a meeting bot join a clinical call. The tools your staff reach for by default are almost never the ones on the BAA list.

Healthcare companies do not get a generic tier list. If you handle PHI, the classification of every tool above changes: "Limited" for a marketing agency is often "Prohibited" for a clinic. The $79 policy kit generates the tier list, acceptable use policy, acknowledgment form and manager FAQ for your industry and data types — including the PHI rules in language staff will actually follow.

And BAA status moves. Vendors add HIPAA support to enterprise plans, and occasionally scope it back. Every row here carries the date we read the vendor’s own document; the $149/mo Monitor plan re-checks them for you.

Get the full policy kit

$79 one-time

A 4-document AI policy kit — acceptable use policy, tool tier list, acknowledgment form, manager FAQ — that classifies all of these tools for your company, industry, and data. Generated in about 10 minutes.

Generate my policy kit →

Keep it current with Monitor

$149/mo

We re-check vendor terms monthly, alert you when any tool’s data policy changes, and regenerate your kit so it never goes stale. This directory is a snapshot — Monitor is the live feed.

See Monitor plan →

Keep reading