🏥 HIPAA Hosting Quiz Text PJ
SideGuy Operator Reference · HIPAA BAA · Verified 2026-05-17

HIPAA BAA Vendor List 2026
Which SaaS Sign BAAs vs Don't

50+ SaaS vendors categorized by Business Associate Agreement availability. Email · CRM · Analytics · Payments · AI/LLM · Storage · Comms · Productivity · Forms · Video. Operator-honest gotchas per vendor. Built for healthcare SaaS founders + HIPAA-covered ops teams who keep getting asked "does that vendor have a BAA?"

⚠️ Verify before relying. Vendor BAA policies change. This reference reflects state as of 2026-05-17. Always confirm current BAA availability + required tier on the vendor's own security/compliance page BEFORE architecting any PHI workflow.

The first thing every healthcare SaaS founder learns

Signing a BAA does NOT make a vendor "HIPAA-compliant." It makes the vendor contractually obligated to safeguard PHI on your behalf. You still own configuration, access controls, audit logging, encryption setup, workforce training, risk assessment, and breach response. The BAA is the start of HIPAA compliance work — not the finish.

What this reference IS good for: a starting-point inventory of vendors your team can use vs cannot use when PHI is in the workflow. What it's NOT good for: assuming every vendor in the "yes" column requires zero further work. Most "yes" vendors have specific tier requirements (Enterprise vs Standard), specific service-scope (some services in their stack are BAA-eligible, others aren't), and specific configuration requirements you still need to enforce.

Vendor BAA reference · by category

Status legend: ✓ Available · ⚠ Conditional (specific tier / service-scope required) · ✗ Not available (cannot use for PHI workflows period).

☁️ Cloud Infrastructure (BAA-eligible compute · storage · databases)

VendorBAANotes / Gotchas
AWS⚠ ConditionalBAA via AWS Artifact (self-service). 200+ services BAA-eligible. Using non-eligible services with PHI = violation. ALWAYS verify current eligibility per service.
Azure⚠ ConditionalMicrosoft offers BAA via Online Services Terms. Auto-included for in-scope services. Verify HIPAA-eligible service list before architecting.
Google Cloud⚠ ConditionalBAA via Google Cloud Healthcare API contract. HIPAA-aligned services list maintained by Google. Vertex AI + BigQuery + Healthcare API are HIPAA-aligned.
Aptible✓ AvailableHIPAA + HITRUST baked into platform. BAA standard on every contract. Inherit-control-from-platform model. Best for first-time HIPAA SaaS.
Datica / Catalyze✓ AvailableHealthcare-specific managed services. BAA standard. Narrower than AWS/Azure but purpose-built for healthcare workloads.
DigitalOcean✗ Not availableNo BAA offering. Cannot use for PHI workflows. Use AWS / Aptible / Datica instead.
Heroku⚠ ConditionalHeroku Shield (Enterprise tier) supports HIPAA BAA. Standard Heroku does NOT. Verify Shield enrollment before relying.
Vercel✗ Not availableNo public BAA offering as of verification date. Cannot use for PHI. Static-only deployments without PHI are OK.
Netlify✗ Not availableNo BAA offering. Cannot use for PHI workflows.
Cloudflare⚠ ConditionalBAA available on Enterprise plan. Standard / Business plans do NOT have BAA. Verify Enterprise contract before architecting.

📧 Email + Workspace

VendorBAANotes / Gotchas
Google Workspace⚠ ConditionalBusiness Plus + Enterprise tiers support BAA. Standard / Starter do NOT. Admin console toggle required to enable HIPAA mode. Gmail + Drive + Docs + Calendar in scope; some Google add-ons not.
Microsoft 365⚠ ConditionalBusiness Premium + Enterprise tiers support BAA. Auto-included via Online Services Terms. Outlook + OneDrive + Teams + SharePoint in scope; Personal/Home tiers NOT.
Postmark✓ AvailableBAA on request via support. Transactional email HIPAA-eligible. Avoid sending PHI in subject lines regardless.
SendGrid (Twilio)⚠ ConditionalBAA via Twilio HIPAA pricing plan (Pro / Premier). Standard plans do NOT include BAA. Verify Twilio contract tier.
Mailgun✓ AvailableBAA available on Pay-as-you-go + Foundation + Growth + Scale plans. Verify current pricing-tier inclusion.
Mailchimp✗ Not availableNo BAA offering. Cannot use for PHI workflows including transactional emails containing PHI.
ConvertKit / Kit✗ Not availableNo BAA offering. Consumer marketing email tool.
ActiveCampaign✗ Not availableNo BAA offering. Cannot use for PHI workflows.

📊 Analytics + Product Analytics

VendorBAANotes / Gotchas
Google Analytics 4✗ Not availableNo BAA offering. Cannot use for PHI workflows. Healthcare SaaS must exclude PHI from GA4 tracking — never put patient IDs / health data in event parameters or user properties.
Mixpanel✓ AvailableBAA on Enterprise tier. Self-serve tiers do NOT include BAA. Verify Enterprise contract.
Amplitude✓ AvailableBAA on Enterprise + Growth tiers. Free + Starter do NOT include BAA. Verify tier.
Heap✓ AvailableBAA on Enterprise tier. Free + Pro tiers do NOT include BAA. Verify Enterprise contract.
Posthog✓ AvailableBAA on Enterprise tier. Cloud Scale + Self-hosted Enterprise both available.
Segment✓ AvailableBAA on Business + Enterprise tiers. Team / Free do NOT include BAA. Verify tier before routing PHI events.
Plausible✗ Not availablePrivacy-focused analytics but no formal BAA. Workaround: don't track PHI in event data — pageviews-only is fine since they don't capture PHI by design.

💬 Customer Comms + Support + Chat

VendorBAANotes / Gotchas
Zendesk✓ AvailableBAA on Enterprise tier. Standard tiers do NOT include BAA. Verify Enterprise contract.
Help Scout✓ AvailableBAA on Plus + Pro tiers. Standard does NOT include BAA.
Front✓ AvailableBAA on Scale + Premier tiers. Verify current tier inclusion.
Intercom⚠ ConditionalBAA available on enterprise contracts only. Standard / Starter / Pro do NOT include BAA. Significant cost step-up.
Drift✗ Not availableNo public BAA offering at standard tiers. Verify with Salesforce (current parent) before relying.
Slack⚠ ConditionalSlack Enterprise Grid with HIPAA-enabled workspace supports BAA. Standard / Pro tiers do NOT. Significant cost step-up.
Microsoft Teams⚠ ConditionalCovered under Microsoft 365 BAA when on Business Premium / Enterprise tiers.
Discord✗ Not availableNo BAA offering. Cannot use for PHI workflows.

📞 SMS + Voice + CPaaS

VendorBAANotes / Gotchas
Twilio⚠ ConditionalBAA via Twilio HIPAA pricing plan. Standard plans do NOT include BAA. Significant cost premium for HIPAA tier. Programmable Voice + SMS + Email all eligible at HIPAA tier.
Plivo✓ AvailableBAA available. Verify current contract.
Vonage✓ AvailableBAA available on enterprise plans. Verify tier.
Bandwidth✓ AvailableBAA available. CPaaS for SMS + voice + emergency services.
MessageBird / Bird⚠ ConditionalVerify current BAA status — has changed during platform consolidation.

🤖 AI / LLM

VendorBAANotes / Gotchas
OpenAI (ChatGPT / API)⚠ ConditionalBAA available on Enterprise + ChatGPT Enterprise / Team tier. Standard API + ChatGPT Plus do NOT include BAA. Verify Enterprise contract.
Anthropic (Claude)⚠ ConditionalBAA available on Enterprise tier (Claude for Enterprise). Standard API + Claude Pro do NOT include BAA. Verify current tier.
AWS Bedrock✓ AvailableCovered under AWS BAA (BAA-eligible service). Use foundation models on Bedrock for HIPAA workloads.
Azure OpenAI✓ AvailableCovered under Microsoft 365 / Azure BAA. Includes GPT-4, GPT-4 Turbo, embedding models.
Google Vertex AI✓ AvailableCovered under Google Cloud BAA. Includes Gemini + PaLM 2 + Vertex AI Search for healthcare workloads.
Cohere⚠ ConditionalVerify current BAA status with Cohere directly. Enterprise contracts may include.
Mistral AI⚠ ConditionalAvailable via Azure (covered under Azure BAA) and AWS Bedrock (covered under AWS BAA). Direct Mistral platform: verify current BAA.

💼 CRM + Marketing Ops

VendorBAANotes / Gotchas
Salesforce⚠ ConditionalSalesforce Health Cloud + Salesforce Shield support BAA. Standard Sales Cloud / Service Cloud do NOT include BAA. Significant cost step-up.
HubSpot✗ Not availableNo standard BAA offering. Workaround: don't store PHI in HubSpot — use it for non-PHI marketing/sales touches only.
Pipedrive✗ Not availableNo BAA offering. Cannot use for PHI workflows.
Close✗ Not availableNo BAA offering as of verification date.
Copper✗ Not availableNo BAA offering.

📝 Forms + Surveys

VendorBAANotes / Gotchas
Jotform✓ AvailableBAA available on HIPAA-enabled Gold + Enterprise tiers. Standard / Free do NOT include BAA. Toggle in account settings.
Formstack✓ AvailableBAA available on Platform + Enterprise tiers. Verify current tier.
Typeform✗ Not availableNo BAA offering. Cannot use for PHI workflows.
Google Forms⚠ ConditionalCovered under Google Workspace BAA (Business Plus + Enterprise tiers) when HIPAA mode enabled in admin console.
SurveyMonkey✓ AvailableBAA available via SurveyMonkey for HIPAA (HIPAA Healthcare plan). Verify current tier.
Tally✗ Not availableNo BAA offering.

📁 Storage + Files + Collab

VendorBAANotes / Gotchas
Dropbox⚠ ConditionalBAA available on Dropbox Business Advanced + Enterprise tiers. Standard / Plus / Family do NOT include BAA.
Box✓ AvailableBAA available on Box Enterprise + Business Plus tiers. Strong healthcare-vertical positioning.
OneDrive (M365)⚠ ConditionalCovered under Microsoft 365 BAA (Business Premium + Enterprise tiers).
Google Drive (Workspace)⚠ ConditionalCovered under Google Workspace BAA (Business Plus + Enterprise tiers).
Notion⚠ ConditionalNotion supports BAA on Enterprise tier. Standard / Plus / Business do NOT include BAA.

📹 Video + Telehealth

VendorBAANotes / Gotchas
Zoom⚠ ConditionalBAA available on Zoom for Healthcare plan. Standard Zoom Pro / Business / Enterprise tiers require explicit BAA enablement. Use Zoom Healthcare for PHI-containing visits.
Microsoft Teams⚠ ConditionalCovered under Microsoft 365 BAA (Business Premium + Enterprise). Healthcare-friendly Teams templates available.
Doxy.me✓ AvailableTelehealth-specific platform. BAA standard. Built for healthcare from day 1.
Loom⚠ ConditionalBAA available on Loom Business + Enterprise tiers. Verify current contract.
Vimeo✗ Not availableNo BAA offering.
Wistia✗ Not availableNo BAA offering as of verification date.

🔧 Operator field notes · 5 things first-time HIPAA SaaS buyers miss

  1. BAA tier is the trap. Most enterprise SaaS sign BAAs only at their highest tier (Salesforce Health Cloud · Microsoft 365 Business Premium · Google Workspace Business Plus · Mixpanel Enterprise · OpenAI Enterprise). The cost step-up from standard tier to BAA-tier is often 3-5x. Budget for it BEFORE you commit to a vendor.
  2. "Available" doesn't mean "automatic." Most vendors require you to REQUEST + SIGN the BAA separately. Some require submitting a ticket, some have self-service portals (AWS Artifact · Microsoft Service Trust · Google Admin). Track which BAAs you've actually signed in your vendor inventory · don't assume "available" means "in place."
  3. Subcontractor BAAs cascade. If your vendor uses sub-processors (e.g., a CRM that uses AWS for hosting, that uses Twilio for SMS), each sub-processor handling PHI also needs a BAA. Vendor's BAA should warrant they have downstream BAAs with sub-processors. Verify the subprocessor list quarterly.
  4. "HIPAA-compliant" is marketing language. No software is "HIPAA-compliant" inherently — only the implementation can be compliant. A vendor saying "we're HIPAA-compliant" without specifying BAA + tier + service-scope is vague marketing. Ask: "Do you sign a BAA? On what tier? Which of your services are in scope?"
  5. Re-verify quarterly. Vendors change BAA policies. Tier requirements shift. Service-scope expands or contracts. Sub-processors change. Quarterly vendor inventory review takes 1-2 hours and catches BAA-coverage gaps before they become incidents. Add it to the calendar.

Need a HIPAA-stack sanity check?

If your vendor inventory has 30-60 SaaS in it and you're not sure which actually have BAAs in place — that's the most common shape SideGuy gets called for. PJ runs a HIPAA-stack audit + builds your vendor inventory + flags coverage gaps. No agency theater. No retainer. Text PJ direct · 5-message scope · honest yes/no on whether the audit fits.

PJ Text PJ 858-461-8054
You can go at it without SideGuy — but no custom shareables for your friends & family. You'll be short a bag of laughs. 🌸
PJ Text PJ 858-461-8054
🎁 Didn't quite find it?

Don't see what you were looking for?

Text PJ a sentence about what you actually need — I'll build you a free custom shareable on the house. No email, no funnel, no SOW.

📲 Text PJ — free shareable
~10 min turnaround. Your friends will love it.
Ready to start?Operator Audit · $250 · 3-5 days · operator-honest signal-quality audit · credited if you upgrade · text PJ at 858-461-8054.