HIPAA · BAA directory
Is your stack HIPAA compliant?
Almost no tool is HIPAA compliant on its own. What matters is whether the vendor signs a Business Associate Agreement, which plan you need to get one, and what the agreement quietly leaves you to configure. Each entry below is checked against the vendor's own documentation and dated.
How to read this
Three answers, and only one is simple.
- BAA available
- The vendor publishes a BAA and it covers the product surface you would expect.
- Conditional
- A BAA exists, but only on certain plans or across part of the product. The conditions are the whole answer.
- Not published
- The vendor publishes no BAA position. Confirm in writing before PHI goes anywhere near it.
Directory
Tool by tool.
Gmail can be used with PHI, but only as part of Google Workspace with an accepted BAA. A personal @gmail.com account cannot be made HIPAA compliant, because Google does not offer a BAA for consumer accounts.
Google Workspace can be used with PHI once an administrator accepts the BAA in the Admin console, but the agreement covers only the services on Google's HIPAA Included Functionality list — not third-party add-ons and not Additional Google Services.
Google Drive is covered by the Google Workspace BAA, including Docs, Forms, Sheets, Slides and Vids. It is not HIPAA compliant on a personal Google account, and sharing settings are where most Drive findings actually come from.
Google Chat is on Google's HIPAA Included Functionality list, so it is covered once your administrator has accepted the Workspace BAA. Retention and export settings are the part auditors ask about.
Slack supports HIPAA only on Enterprise Grid with a signed BAA, and even then PHI is permitted only in messages and uploaded files — not in other Slack features.
Zoom will execute a BAA, but not on the free tier: you need at least one paid licence. Small practices can accept the BAA online for up to nine licences; larger deployments go through sales.
Notion supports HIPAA on the Enterprise plan only. HIPAA compliance is free of charge at that tier, but it must be switched on explicitly — accepting the BAA in workspace settings — and Beta Services stay outside the agreement.
Supabase will sign a BAA, and has BAAs in place with its own vendors. Coverage is not automatic: projects that hold PHI must be configured as HIPAA projects and follow the security advisor's guidance.
Stripe does not publish a HIPAA BAA offering, so the honest answer is that you must confirm directly with Stripe before putting anything that counts as PHI through it. Payment data alone is often not PHI — but the moment it is joined to treatment information, it can be.
The BAA is the beginning, not the finish line
Every tool above leaves work on your side: settings to configure, access to review, and evidence to produce again at each audit. Screenata's agent collects that evidence on a schedule and writes the policies to match what it actually finds, so a signed BAA turns into a provable control rather than a PDF in a folder. See HIPAA with Screenata or what it costs.