Is that tool HIPAA compliant?
A straight answer for 72 of the tools small healthcare organizations actually run — the verdict, the exact conditions, which plan you need, where to get the vendor's business associate agreement, and the sources we based it on with the date we read them.
- 5 Yes
- 59 Conditional
- 8 No
Free, no signup. Verdict, conditions and the vendor’s own agreement link.
Most looked up
How we decide
Primary sources only. We read the vendor’s own agreement page, trust page and documentation. Never another blog, never a competitor, never another checker.
Dated, and re-checked. Every page shows when we last read the sources and when it is due for review. Corrections appear in a visible change history, never as a silent edit.
No paid placement. Alternatives are listed on merit. We take no money from any vendor named here and use no affiliate links.
Email providers
All email providers →Gmail
ConditionalYes for Gmail inside a managed Google Workspace account once a super administrator accepts Google's amendment — a free personal Gmail address cannot be covered at all.
Hushmail
ConditionalOnly if you sign up on a Hushmail for Healthcare plan — the identically priced Small Business, Law and Personal plans are marked as not including a business associate agreement.
LuxSci
ConditionalYes — LuxSci includes the agreement at no extra cost, but an authorised officer must sign and return LuxSci's own form, and patient information must stay inside the services it lists as eligible.
Paubox
YesYes — every Paubox account includes a business associate agreement at no extra cost, and Paubox will not finish configuring your email until you have agreed to it.
Virtru
ConditionalYes on a paid Virtru package, but only after you email their BAA address and execute the agreement — Virtru does not issue it automatically, and its subscription terms require you to ask.
Video conferencing
All video conferencing tools →FaceTime
NoNo — Apple publishes no business associate agreement for FaceTime, and the COVID-era enforcement discretion that once let providers use it for telehealth expired on August 9, 2023.
Google Meet
ConditionalYes, if you run Meet inside a managed Google Workspace account and a super administrator accepts the amendment before any patient visit takes place.
GoTo Meeting
YesYes — GoTo's business associate addendum is published as a standing legal document that takes effect simply by using the services after its publication, and GoTo sells a dedicated Healthcare plan with recording and chat switched off.
Microsoft Teams
ConditionalYes — Teams is named on Microsoft's in-scope services list and the agreement applies to business subscriptions automatically, but you configure the tenant and keep patient information out of anything not on that list.
Whereby
ConditionalYes, but only on the Whereby Embedded platform with a signed agreement and the documented configuration — the compliance offering is aimed at products that embed video, not at teams looking for a meeting app.
Zoho Meeting
ConditionalYes, if the business associate agreement you request from Zoho names Zoho Meeting — Zoho publishes a Meeting-specific HIPAA page and names the exact fields it treats as patient information, which is more than most vendors in this category put in writing.
Zoom
ConditionalYes, if you are on a paid Zoom plan and you execute Zoom's business associate agreement before using Zoom for anything involving patient information.
Telehealth platforms
All telehealth platforms →Doximity
YesYes — Doximity builds its business associate agreement into the terms of service, effective the moment a clinician registers, which makes the free Dialer one of the rare covered tools a solo clinician can adopt in an afternoon.
Doxy.me
ConditionalYes — doxy.me gives every user a free agreement you generate yourself in account settings, but the version on individual accounts names one provider, so a practice with two or more clinicians needs the clinic version instead.
SimplePractice
YesYes — you agreed to SimplePractice's business associate agreement when you started your trial, it covers every feature including telehealth on all plans, and you never sign it again.
Tebra
ConditionalYes — Tebra is built for covered entities and states that it commits through a business associate agreement, so the work is executing it and configuring access rather than deciding whether the vendor will sign.
VSee
ConditionalYes for VSee Clinic once you email their compliance address and get the agreement signed — but the free VSee Messenger app is excluded, and VSee's own pages disagree about whether the free Clinic tier needs a paid subscription first.
Fax services
All fax services →eFax
ConditionalOnly on eFax's business-grade plans — the agreement is listed on Business and Corporate, and the consumer Personal plan does not include one, so a solo practice on a cheap eFax number is unprotected.
Documo (mFax)
YesYes — Documo states HIPAA compliance comes standard with every plan at no extra fee and that it signs a business associate agreement for healthcare customers, including on its cheapest tier.
MyFax
NoNot as sold. MyFax's own terms forbid storing patient information unless you have already executed a business associate agreement with them, and its own FAQ sends anyone wanting HIPAA-compliant faxing to a different product — eFax Corporate.
SRFax
ConditionalYes if you buy from SRFax's Healthcare Solutions range and request the agreement — the cheaper Standard Solutions plans are sold for general small business use, not healthcare.
Patient texting
All patient texting platforms →No — Meta's own platform terms state that it 'is not a Business Associate' and that the WhatsApp Cloud API 'is not HIPAA compliant', and no WhatsApp product on any tier comes with an agreement.
Spruce Health
ConditionalYes — the agreement is built into Spruce's standard terms and applies automatically on trials and both paid plans, but Spruce classes SMS, email, fax and phone as unsecure channels, so only app-to-app messaging inside Spruce is genuinely secure.
TigerConnect
ConditionalYes — TigerConnect's standard agreement applies automatically through its terms of service unless you negotiate your own, but it is a sales-quoted enterprise product and the invitation text reaching the patient is still ordinary carrier SMS.
Productivity suites
All productivity suites →Google Workspace
ConditionalYes, if a super administrator accepts Google's business associate amendment in the Admin console and you keep patient information only inside the specific Google services it covers.
Microsoft 365
ConditionalYes — the agreement already applies to business and enterprise subscriptions automatically through Microsoft's Data Protection Addendum, but you must keep patient information inside the services Microsoft lists as in scope.
File storage
All file storage and sharing tools →Box
ConditionalYes, if you are on a Box Enterprise-tier account and you request and sign the agreement before any patient files are stored.
Dropbox
ConditionalYes, if you are on a Dropbox team plan and your administrator signs the agreement in the admin console before any patient files are uploaded.
Google Drive
ConditionalYes on a Google Workspace or Cloud Identity account where a super administrator has accepted Google's business associate amendment — but Drive on a personal Google account cannot be covered, because there is no administrator to accept it.
OneDrive
ConditionalYes for OneDrive for Business on a Microsoft 365 business subscription, where the agreement applies automatically — but the consumer OneDrive on a personal Microsoft account is a different product and is not covered.
SpiderOak
ConditionalConditionally — SpiderOak accepts that it acts as a business associate and points to a route for requesting an agreement, but says it supports only 'certain customers' subject to HIPAA, so settle eligibility before you commit.
Tresorit
ConditionalYes — Tresorit states plainly that it signs business associate agreements, which is more than most encrypted-storage vendors will say, but you still have to ask for one and plan for what zero-knowledge encryption costs you.
Cloud infrastructure
All cloud platforms →AWS
ConditionalYes, if you accept the AWS business associate addendum in AWS Artifact and then keep patient data only inside the services on the HIPAA Eligible Services list.
Google Cloud
ConditionalYes — Google signs an agreement covering its entire infrastructure rather than a walled-off healthcare region, but only products on its covered list may touch patient data and what you build on top remains yours to configure.
Azure
ConditionalYes, and unusually there is nothing to sign — the agreement already applies if you bought Azure under a Microsoft licensing agreement, but only services in Microsoft's audit scope may hold patient data and everything you build on top is yours to secure.
Phone systems
All phone and VoIP systems →Google Voice
ConditionalYes, if you use Google Voice inside a paid Google Workspace account with licenses assigned to the staff who handle patient information, and your administrator accepts Google's amendment first — the free consumer version cannot be used with patient information.
OpenPhone (now Quo)
ConditionalYes for calls if you are on the Business or Scale plan and sign the agreement — but text messaging is explicitly excluded from it, so anything you text a patient sits outside the agreement entirely.
RingCentral
ConditionalYes, if you are a paying customer, ask RingCentral for their business associate agreement and sign it, and keep patient information within the specific services that agreement names.
Scheduling
All scheduling tools →Calendly
NoNo — Calendly's customer terms specifically forbid putting patient information into the service and Calendly does not offer a business associate agreement, so it should not be used to book patients or collect their details.
Google Calendar
ConditionalYes inside Google Workspace once an administrator has accepted the agreement — Google names Calendar in its included functionality — but an invitation is a disclosure, and whatever you type in the title travels to every attendee's inbox.
SimplyBook.me
ConditionalYes on the Standard plan and above, where SimplyBook.me's HIPAA feature and a signed business associate agreement are both stated to be available — but the agreement is affirmed on a marketing page rather than in the help or legal documentation, so get it in writing before the first patient books.
Acuity Scheduling
ConditionalYes, if you are on the Premium or Powerhouse plan and enter the agreement from your scheduling settings — but it covers Acuity only, and turning HIPAA mode on permanently disables invoices.
Zoho Bookings
ConditionalYes, if the business associate agreement you execute with Zoho names Zoho Bookings — and if you keep the reason for the appointment out of the booking form.
E-signature
All e-signature tools →signNow
ConditionalYes, on signNow's corporate plans once you have asked support to sign the business associate agreement — HIPAA features are off by default on every account until that happens.
Docusign
ConditionalYes, if you buy an Enhanced plan through Docusign sales and sign their business associate addendum first — the self-serve Personal, Standard and Business Pro plans do not include it.
Dropbox Sign
ConditionalOnly on an annual Standard or Premium plan that meets Dropbox's minimum contract value and has a signed agreement — there is no self-serve path and monthly billing does not qualify.
PandaDoc
ConditionalYes, but only as an optional capability on annual Enterprise plans with a minimum contract value — PandaDoc will sign a business associate agreement, and nothing below Enterprise has a route to one.
Zoho Sign
ConditionalYes, if you request Zoho's business associate agreement and the executed document names Zoho Sign — Zoho says the agreement itself defines which of its services are covered.
Email marketing
All email marketing tools →ActiveCampaign
ConditionalYes on the Enterprise plan, where ActiveCampaign lists HIPAA support and says a business associate agreement is available — but the agreement text, the request route and what is excluded under it are not published, so all three have to be settled with sales.
Mailchimp
NoNo — Mailchimp does not offer a business associate agreement and its terms put HIPAA responsibility entirely on you, so patient health details must stay out of your audiences, campaigns and merge fields.
Zoho Campaigns
ConditionalYes, unusually for email marketing — Zoho will sign a business associate agreement and names Zoho Campaigns among its services, but the agreement has to name it and the marketing rules still apply on top.
Docs and notes
All document and note tools →Asana
ConditionalOnly on Asana's top tier with the HIPAA feature switched on — and even then Asana forbids using it as your system of record or for contacting patients, so it is a staff task tracker and nothing more.
monday.com
ConditionalYes on the Enterprise plan only, once an admin accepts the agreement and clicks Activate HIPAA Compliance — and coverage ends the moment you downgrade to a lower plan.
Notion
ConditionalYes, if you are on the Enterprise plan, accept the agreement inside workspace settings and lock the workspace down as Notion requires — and even then you may not use Notion to communicate with patients.
Databases and app builders
All database and app-building tools →AI assistants
All AI assistants →Amazon Bedrock
ConditionalYes, if your AWS account has an executed business associate agreement and you stay off the two model families AWS carves out of Bedrock's HIPAA eligibility.
Claude
ConditionalYes on Claude Enterprise or the first-party API, once an organization owner has activated HIPAA compliance and accepted the agreement — consumer plans are not covered, and Anthropic excludes a long and specific list of features from the plans that are.
Google Gemini
ConditionalYes inside Google Workspace once an administrator has accepted the agreement — Google names the Gemini app, the Gemini Mac app and Gemini in Workspace as included functionality, and excludes Gemini in Chrome by name.
Microsoft Copilot
ConditionalYes for Microsoft 365 Copilot and Copilot Chat used under a commercial Microsoft 365 licence, where the agreement already applies — but the consumer Copilot signed into with a personal account is a different product and is not named in scope.
ChatGPT
ConditionalOnly on specific OpenAI products — ChatGPT for Healthcare, ChatGPT for Clinicians, sales-managed Enterprise or Edu, or the API with Modified Retention — and never on free, Plus, Pro or ChatGPT Business accounts.
HubSpot
ConditionalYes now, but only on an Enterprise subscription where a super admin switches on Sensitive Data, identifies the account as a covered entity and accepts the agreement — and only in the specific tools HubSpot lists.
Salesforce
ConditionalYes, if you sign Salesforce's business associate addendum through your account representative and it names the specific Salesforce service you are putting patient information into.
Zoho CRM
ConditionalYes, if you are on Zoho CRM Enterprise or Ultimate, email Zoho's legal team for the agreement, and then mark by hand every module and field that will hold patient information.
Form builders
All form builders →Formstack
ConditionalYes, if Formstack moves you onto one of its healthcare plans, which comes with a signed agreement but restricts your integrations, email and attachments.
Google Forms
ConditionalYes, if you use Forms inside a paid Google Workspace account where a super administrator has accepted Google's amendment — Forms is covered as part of Google Drive.
Jotform
ConditionalYes, if you are on the Gold or Enterprise plan and run Jotform's HIPAA setup wizard, which migrates your whole account to an isolated system and ends with you signing the agreement.
Squarespace website forms
NoNo — Squarespace states its contact form features, including the form block, cannot be part of a HIPAA compliant solution, and its addendum covers Acuity Scheduling and nothing else.
Typeform
ConditionalOnly on Typeform's enterprise-level plans, after you tell Typeform in advance and it agrees to sign — on the ordinary self-serve plans Typeform's own terms bar you from collecting patient information.
Turn this list into your vendor register.
Knowing which tools are allowed is step one. Tracking which agreements you have actually signed, when they expire and who owns each one is what a client’s security questionnaire actually asks for. Our platform keeps that register — and exports it as part of a dated evidence pack.
See how it worksKeep reading
- HIPAA glossaryPlain-language definitions, each with its citation.
- HIPAA compliance checklistEvery requirement, in order, with the evidence that proves it.
- Free HIPAA readiness scoreTwelve questions, each citing its regulation, scored in your browser.
- HIPAA to SOC 2 crosswalkAll 68 controls mapped to SOC 2 and NIST CSF, and the eight gaps.
- HIPAA training requirementsWho must be trained, how often, and what proof to keep.
- Is HIPAA certification real?No organization can hold one. What HHS says, and what to build instead.
- HIPAA compliance auditsThe three different things called an audit, and what each asks for.
- What an OCR audit isThe HITECH audit programme and a complaint-driven investigation are not the same thing.
- Practice management softwareHow to evaluate what a vendor is actually offering you.
- How we researchSourcing, review cadence and corrections policy.
- About the teamThe compliance officers, clinicians and security people behind the research.
Looking for the software rather than the explanation? Vendor and BAA register.
This checker is information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change their terms without notice, so confirm anything you rely on directly with them. Signing an agreement is necessary but not sufficient — whether your use is compliant also depends on how you configure the tool and how your staff use it.