Screenata

HIPAA · Payments

Is Stripe HIPAA compliant?

Not published

Stripe does not publish a HIPAA BAA offering, so the honest answer is that you must confirm directly with Stripe before putting anything that counts as PHI through it. Payment data alone is often not PHI — but the moment it is joined to treatment information, it can be.

Which plans the BAA covers
Not published. Stripe's public documentation does not commit to executing a BAA, and its Identity product is documented as suitable for healthcare use only where the data supplied is not subject to HIPAA. Confirm your position with Stripe in writing.
All tools

Scope

What the BAA does and does not cover.

Covered

  • Nothing can be assumed covered without a BAA executed with Stripe in writing

Not covered

  • Stripe Identity for data subject to HIPAA — Stripe documents the healthcare use case as applying only where data is not HIPAA-covered
  • Any assumption that PCI DSS compliance implies HIPAA coverage; they are different regimes with different scopes

Your side of the agreement

A signed BAA is not a configured system.

Signing shifts liability; it does not change a setting. These are the steps that remain yours once Stripe is in scope.
  1. 1Ask Stripe directly, in writing, whether it will execute a BAA for your use case, and keep the answer
  2. 2Map precisely what you send to Stripe — a card charge with no clinical context is usually not PHI, an itemised bill naming a procedure may well be
  3. 3Design the integration so PHI stays out of metadata, descriptions and statement descriptors
  4. 4If no BAA is available, keep the payment flow architecturally separate from clinical records

Evidence

What an auditor will actually ask for.

Every item below is evidence someone has to produce, date and re-produce at the next audit. Screenata's agent collects these on a schedule instead.
  • Written confirmation from Stripe of its BAA position for your account
  • A data-flow diagram showing exactly which fields reach Stripe
  • Code or configuration evidence that PHI is excluded from metadata and description fields
  • Your vendor risk assessment recording the decision and its rationale

See how Screenata handles this on HIPAA programs, or read what healthcare SaaS needs beyond SOC 2.

Sources

Verified against vendor documentation on 2026-08-08. BAA terms change — re-check before relying on this.