Screenata

HIPAA · BAA directory

Is your stack HIPAA compliant?

Almost no tool is HIPAA compliant on its own. What matters is whether the vendor signs a Business Associate Agreement, which plan you need to get one, and what the agreement quietly leaves you to configure. Each entry below is checked against the vendor's own documentation and dated.

How to read this

Three answers, and only one is simple.

BAA available
The vendor publishes a BAA and it covers the product surface you would expect.
Conditional
A BAA exists, but only on certain plans or across part of the product. The conditions are the whole answer.
Not published
The vendor publishes no BAA position. Confirm in writing before PHI goes anywhere near it.

Directory

Tool by tool.

  • Gmail can be used with PHI, but only as part of Google Workspace with an accepted BAA. A personal @gmail.com account cannot be made HIPAA compliant, because Google does not offer a BAA for consumer accounts.

  • Is Google Workspace HIPAA compliant?ConditionalProductivity suite

    Google Workspace can be used with PHI once an administrator accepts the BAA in the Admin console, but the agreement covers only the services on Google's HIPAA Included Functionality list — not third-party add-ons and not Additional Google Services.

  • Is Google Drive HIPAA compliant?ConditionalFile storage

    Google Drive is covered by the Google Workspace BAA, including Docs, Forms, Sheets, Slides and Vids. It is not HIPAA compliant on a personal Google account, and sharing settings are where most Drive findings actually come from.

  • Google Chat is on Google's HIPAA Included Functionality list, so it is covered once your administrator has accepted the Workspace BAA. Retention and export settings are the part auditors ask about.

  • Is Slack HIPAA compliant?ConditionalTeam chat

    Slack supports HIPAA only on Enterprise Grid with a signed BAA, and even then PHI is permitted only in messages and uploaded files — not in other Slack features.

  • Is Zoom HIPAA compliant?ConditionalVideo conferencing

    Zoom will execute a BAA, but not on the free tier: you need at least one paid licence. Small practices can accept the BAA online for up to nine licences; larger deployments go through sales.

  • Is Notion HIPAA compliant?ConditionalDocs and wiki

    Notion supports HIPAA on the Enterprise plan only. HIPAA compliance is free of charge at that tier, but it must be switched on explicitly — accepting the BAA in workspace settings — and Beta Services stay outside the agreement.

  • Is Supabase HIPAA compliant?ConditionalDatabase and backend

    Supabase will sign a BAA, and has BAAs in place with its own vendors. Coverage is not automatic: projects that hold PHI must be configured as HIPAA projects and follow the security advisor's guidance.

  • Is Stripe HIPAA compliant?Not publishedPayments

    Stripe does not publish a HIPAA BAA offering, so the honest answer is that you must confirm directly with Stripe before putting anything that counts as PHI through it. Payment data alone is often not PHI — but the moment it is joined to treatment information, it can be.

The BAA is the beginning, not the finish line

Every tool above leaves work on your side: settings to configure, access to review, and evidence to produce again at each audit. Screenata's agent collects that evidence on a schedule and writes the policies to match what it actually finds, so a signed BAA turns into a provable control rather than a PDF in a folder. See HIPAA with Screenata or what it costs.