Practical reference
Which Vendors Sign a HIPAA BAA, and on Which Plan
Last verified 2026-09-26. Vendor terms and prices change; every row links to its source.
Short answer: AWS, Google Cloud and Microsoft Azure all include a HIPAA Business Associate Agreement at no extra charge, accepted in the console or built into their standard terms. Most SaaS tools work differently. The BAA sits behind a business or enterprise tier, a paid add-on or a sales conversation, and a few vendors, including Postmark, Resend, Calendly and Google Analytics, say plainly that they will not sign one. Whichever vendor you pick, a BAA covers only the services it lists, so read the conditions column before any PHI reaches a product. We checked every row against the vendor's own page.
BAA availability by vendor
Showing 77 of 77 vendors.
| Vendor | Signs a BAA? | Plan that unlocks it | Extra cost | Conditions | Source |
|---|---|---|---|---|---|
| Amazon Web Services (AWS)Cloud platforms | Yes | Any AWS account; accept the standard BAA in AWS Artifact | No extra cost | PHI only in the HIPAA-eligible services named in the BAA. Other services can run in the account if they never touch PHI. | Vendor page for Amazon Web Services (AWS) |
| Google CloudCloud platforms | Yes | Any Google Cloud account; review and accept the BAA in the console | No extra cost | Covers the 150+ products on Google's covered list only. Google says HIPAA customers pay the same prices as everyone else. | Vendor page for Google Cloud |
| Microsoft AzureCloud platforms | Yes | Included by default in the Microsoft Product Terms and DPA | No extra cost | No separate contract to sign. Applies to Azure services in Microsoft's HIPAA BAA scope list only. | Vendor page for Microsoft Azure |
| Oracle Cloud Infrastructure (OCI)Cloud platforms | Yes | Request through your Oracle account team | Not published | Oracle enters into a BAA for OCI customers in HIPAA scope. Keep PHI in the services and regions Oracle lists as HIPAA assessed. | Vendor page for Oracle Cloud Infrastructure (OCI) |
| DigitalOceanCloud platforms | Yes | Request from Sales (new customers) or Support (existing) | Not published | Covered list includes Droplets, Kubernetes, Spaces, Volumes and Load Balancers. Managed Databases is not on it. | Vendor page for DigitalOcean |
| VercelCloud platforms | Yes | Pro with the HIPAA BAA add-on, or Enterprise | Paid tier or add-on | Pro teams buy the add-on ($350/mo on Vercel's pricing page) in billing settings. Enterprise requests it from sales. | Vendor page for Vercel |
| NetlifyCloud platforms | Yes | Enterprise | Enterprise contract | Enterprise customers handling PHI can execute a BAA through sales. Not offered on self-serve plans. | Vendor page for Netlify |
| RenderCloud platforms | Yes | Scale or Enterprise workspace with HIPAA enabled | Paid tier or add-on | Adds a 20% fee on all usage in the HIPAA-enabled workspace. Render emails a BAA link after you opt in. | Vendor page for Render |
| Fly.ioCloud platforms | Yes | Any paid plan plus the HIPAA compliance package | Paid tier or add-on | HIPAA package is $99/mo. Fly.io pre-signs the BAA; it takes effect when you sign it. | Vendor page for Fly.io |
| HerokuCloud platforms | Yes | Heroku Shield (a package for Heroku Enterprise) | Enterprise contract | Open a ticket to sign the BAA. PHI only in Shield Private Spaces, Shield dynos and Shield data services. | Vendor page for Heroku |
| CloudflareCloud platforms | Yes | Enterprise | Enterprise contract | BAAs for Enterprise customers only. In-scope list includes CDN, WAF, DNS, Workers, R2, D1 and Zero Trust. | Vendor page for Cloudflare |
| SupabaseDatabases and backends | Yes | Team or Enterprise plan with the HIPAA add-on | Paid tier or add-on | Not available on Pro. You need a signed BAA and the HIPAA add-on enabled before handling PHI. | Vendor page for Supabase |
| FirebaseDatabases and backends | Partial | Through the Google Cloud BAA | No extra cost | Only Firestore and Cloud Storage for Firebase are on Google's list. Realtime Database, Hosting and Cloud Messaging are not. | Vendor page for Firebase |
| MongoDB AtlasDatabases and backends | Yes | Request from MongoDB sales | Not published | Covers Atlas, App Services, Charts, Data Lake and Atlas for Government. Beta and preview features are excluded. | Vendor page for MongoDB Atlas |
| PlanetScaleDatabases and backends | Yes | All plans, including Base; request in the dashboard | No extra cost | Settings, Legal, Create request. PlanetScale reviews each request; you must be a covered entity or business associate. | Vendor page for PlanetScale |
| NeonDatabases and backends | Yes | Scale plan; enable HIPAA in organization settings | Paid tier or add-on | No surcharge today; Neon says a 15% surcharge will apply later. The Data API and Managed Better Auth are not covered. | Vendor page for Neon |
| CockroachDB CloudDatabases and backends | Yes | Advanced plan | Paid tier or add-on | HIPAA-ready clusters are on the Advanced plan, and Cockroach Labs signs a BAA on request. | Vendor page for CockroachDB Cloud |
| SnowflakeDatabases and backends | Yes | Business Critical edition or higher | Paid tier or add-on | A signed BAA must be in place before any PHI is stored. Lower editions do not list PHI support. | Vendor page for Snowflake |
| DatabricksDatabases and backends | Yes | Compliance security profile, billed as the Enhanced Security and Compliance add-on | Paid tier or add-on | Have an active BAA first, and enable the compliance security profile on every workspace that processes PHI. | Vendor page for Databricks |
| Auth0 (Okta Customer Identity)Authentication | Yes | Enterprise plan with the HIPAA/BAA add-on | Enterprise contract | Not on self-serve plans. Auth0 says HIPAA is not available on its Azure deployments. | Vendor page for Auth0 (Okta Customer Identity) |
| Okta (Workforce Identity)Authentication | Yes | Purchase of Okta's HIPAA cell | Enterprise contract | Okta signs a BAA with customers who buy its HIPAA cell, before they store any PHI in Okta. | Vendor page for Okta (Workforce Identity) |
| ClerkAuthentication | Yes | Enterprise | Enterprise contract | Clerk's pricing page lists the HIPAA BAA on the Enterprise plan only. | Vendor page for Clerk |
| Firebase AuthenticationAuthentication | Partial | Upgrade to Google Cloud Identity Platform | Paid tier or add-on | Firebase Authentication is not on Google Cloud's covered list. Identity Platform, its paid upgrade path, is. | Vendor page for Firebase Authentication |
| Amazon CognitoAuthentication | Yes | Covered by the AWS BAA | No extra cost | Listed as HIPAA eligible on AWS's services reference. | Vendor page for Amazon Cognito |
| WorkOSAuthentication | Yes | Enterprise plans | Enterprise contract | WorkOS says it can sign BAAs for customers on enterprise plans. | Vendor page for WorkOS |
| StytchAuthentication | Yes | Enterprise | Enterprise contract | Stytch's pricing page lists HIPAA/BAA as an Enterprise plan feature. | Vendor page for Stytch |
| OpenAI APIAI and LLM APIs | Yes | Any API organization; request by email to baa@openai.com | No extra cost | No enterprise agreement needed. PHI only on BAA-eligible endpoints once your org has Zero Data Retention or approved retention. | Vendor page for OpenAI API |
| ChatGPT (Enterprise and Edu)AI and LLM APIs | Partial | ChatGPT Enterprise or Edu with a sales-managed account | Enterprise contract | OpenAI says only sales-managed Enterprise and Edu accounts qualify. It does not offer a BAA for ChatGPT Business. | Vendor page for ChatGPT (Enterprise and Edu) |
| Anthropic Claude APIAI and LLM APIs | Yes | First-party API; sign the BAA, then Anthropic enables it | Not published | Covers the Messages, Token Counting and Models APIs. Not Batch, Files, Code Execution, Computer Use or Web Fetch. | Vendor page for Anthropic Claude API |
| Claude EnterpriseAI and LLM APIs | Yes | Enterprise plan; Primary Owner accepts in organization settings | Enterprise contract | Chat, projects and artifacts are covered. MCP and other third-party integrations are not. Claude Code only with ZDR. | Vendor page for Claude Enterprise |
| Azure OpenAI (Foundry Models sold by Azure)AI and LLM APIs | Yes | Microsoft BAA, included through the Microsoft DPA | No extra cost | Processing is governed by the Microsoft DPA that carries the BAA. Check your model and modality against Microsoft's scope list. | Vendor page for Azure OpenAI (Foundry Models sold by Azure) |
| Gemini on Agent Platform (formerly Vertex AI)AI and LLM APIs | Yes | Covered by the Google Cloud BAA | No extra cost | Listed as "Generative AI on Gemini Enterprise Agent Platform", which is Vertex AI under its new name. | Vendor page for Gemini on Agent Platform (formerly Vertex AI) |
| Gemini API (Google AI Studio)AI and LLM APIs | No | Not covered | Not applicable | Not on Google Cloud's BAA covered list. For PHI, call Gemini through Agent Platform (Vertex AI) instead. | Vendor page for Gemini API (Google AI Studio) |
| Amazon BedrockAI and LLM APIs | Yes | Covered by the AWS BAA | No extra cost | Listed as HIPAA eligible on AWS's services reference. | Vendor page for Amazon Bedrock |
| CohereAI and LLM APIs | Partial | Custom model development engagements only | Enterprise contract | The BAA does not cover Cohere's hosted SaaS products. Cohere says not to send PHI through its SaaS services. | Vendor page for Cohere |
| Groq (GroqCloud)AI and LLM APIs | Yes | GroqCloud customers with a services agreement in place | Not published | Groq publishes its BAA. Beta, preview, trial and free-of-charge features are excluded. | Vendor page for Groq (GroqCloud) |
| Together AIAI and LLM APIs | Unclear | Not stated publicly | Not published | Says it adheres to HIPAA and has BAAs with its partners, but does not say publicly that it signs BAAs with customers. | Vendor page for Together AI |
| Hugging FaceAI and LLM APIs | Yes | Enterprise plan | Paid tier or add-on | Hugging Face says it can offer Business Associate Addendums through an Enterprise plan. Confirm which products are in scope. | Vendor page for Hugging Face |
| Twilio (SMS, Voice)Email, SMS and communication | Yes | Security Edition or Enterprise Edition | Enterprise contract | Use only products on Twilio's HIPAA Eligible list. SendGrid is not on it. | Vendor page for Twilio (SMS, Voice) |
| SendGridEmail, SMS and communication | No | Not offered | Not applicable | Twilio says it cannot sign BAAs for SendGrid and that customers should not use SendGrid with PHI. | Vendor page for SendGrid |
| PostmarkEmail, SMS and communication | No | Not offered | Not applicable | Postmark says it is not HIPAA compliant and cannot sign BAAs. | Vendor page for Postmark |
| MailgunEmail, SMS and communication | Yes | Not published; contact Mailgun | Not published | Mailgun publishes a HIPAA BAA as an addendum to its Terms of Service. The plan it requires is not stated. | Vendor page for Mailgun |
| Amazon SESEmail, SMS and communication | Yes | Covered by the AWS BAA | No extra cost | Listed as HIPAA eligible on AWS's services reference. | Vendor page for Amazon SES |
| ResendEmail, SMS and communication | No | Not offered publicly | Not applicable | Resend says it cannot sign a BAA. Its Enterprise terms allow PHI only if an order form includes a signed BAA. | Vendor page for Resend |
| Google WorkspaceEmail, SMS and communication | Yes | Any Workspace account; a super admin accepts it in the Admin console | No extra cost | Covers listed services such as Gmail, Drive, Calendar, Meet, Chat and Gemini in Workspace. Third-party add-ons are excluded. | Vendor page for Google Workspace |
| Microsoft 365Email, SMS and communication | Yes | Included by default through the Microsoft DPA | No extra cost | In scope: Exchange Online, Teams, SharePoint, OneDrive for Business, Copilot Chat and the other services Microsoft lists. | Vendor page for Microsoft 365 |
| ZoomEmail, SMS and communication | Yes | Paid plans: Pro online, or Business and above through sales | Paid tier or add-on | Pro buyers select the US BAA at checkout. Business, Business Plus and Enterprise customers sign through Zoom sales. | Vendor page for Zoom |
| SlackEmail, SMS and communication | Yes | Enterprise plan (Enterprise Grid) | Enterprise contract | Not for talking with patients. DLP is required, and Marketplace apps are not covered by Slack's BAA. | Vendor page for Slack |
| IntercomEmail, SMS and communication | Yes | Expert plan | Paid tier or add-on | Intercom lists HIPAA support on the Expert plan. The BAA is arranged through sales or your account manager. | Vendor page for Intercom |
| FrontEmail, SMS and communication | Yes | Annual contract above Front's threshold | Enterprise contract | Email notifications, email tags and Front's native email sending cannot process PHI under the BAA. | Vendor page for Front |
| PauboxEmail, SMS and communication | Yes | Every plan, including the Email API free tier | No extra cost | Paubox says all customers receive a BAA at no additional charge. | Vendor page for Paubox |
| CalendlyEmail, SMS and communication | No | Not offered | Not applicable | Calendly's customer terms require that your data contain no protected health information. | Vendor page for Calendly |
| Cal.comEmail, SMS and communication | Yes | Enterprise, or Organizations with 15+ users; add-on for smaller plans | Paid tier or add-on | BAA is $300/mo on Teams or Organizations plans under 15 users, and included on Enterprise. | Vendor page for Cal.com |
| StripePayments | No | Not offered | Not applicable | Stripe publishes no BAA, and its Services Agreement bars sending PHI as Third Party Data. Keep PHI out of Stripe entirely. | Vendor page for Stripe |
| SquarePayments | Yes | All sellers; the BAA is part of Square's terms | No extra cost | Applies only to features Square marks HIPAA-enabled, such as Appointments and Invoices. Buyer-facing services are excluded. | Vendor page for Square |
| DatadogMonitoring and analytics | Yes | Not published; arranged with Datadog | Not published | Log Management and Cloud SIEM are eligible, APM and about 30 others are extended eligible. Other services must not get PHI. | Vendor page for Datadog |
| New RelicMonitoring and analytics | Yes | Enterprise edition with Data Plus | Enterprise contract | US data region required. Your account rep must confirm the HIPAA-enabled account in writing before you send PHI. | Vendor page for New Relic |
| SentryMonitoring and analytics | Yes | Business plan or higher (not trials) | Paid tier or add-on | Owners or billing contacts accept it under Legal & Compliance in settings. Only Enterprise customers can negotiate changes. | Vendor page for Sentry |
| MixpanelMonitoring and analytics | Yes | Enterprise plan | Enterprise contract | BAA offered to Enterprise Plan customers; contact sales to confirm you qualify. | Vendor page for Mixpanel |
| AmplitudeMonitoring and analytics | Yes | Not published; arranged with Amplitude | Not published | Amplitude says it can enter a BAA with covered entities and business associates, and that its AI features are covered. | Vendor page for Amplitude |
| PostHogMonitoring and analytics | Yes | Boost ($250/mo), Scale or Enterprise package | Paid tier or add-on | PostHog Cloud only. The managed reverse proxy and PostHog AI features are not covered. | Vendor page for PostHog |
| SegmentMonitoring and analytics | Yes | Business tier | Enterprise contract | Not on Free or Team. Use only the Segment products on Twilio's HIPAA Eligible list. | Vendor page for Segment |
| Google Analytics (GA4)Monitoring and analytics | No | Not offered | Not applicable | Google does not offer a BAA for Analytics. Keep it off authenticated pages and pages about care. | Vendor page for Google Analytics (GA4) |
| Microsoft ClarityMonitoring and analytics | No | Not offered | Not applicable | Clarity's terms bar use with health care content, and Clarity is not in Microsoft's HIPAA BAA scope. | Vendor page for Microsoft Clarity |
| ZendeskSupport, CRM and productivity | Yes | Professional or higher with the Advanced Compliance add-on | Paid tier or add-on | Some Suite plans include the add-on. You must also turn on Zendesk's required security settings. | Vendor page for Zendesk |
| HubSpotSupport, CRM and productivity | Yes | Enterprise subscriptions (Marketing, Sales, Service, Data, Content or Smart CRM) | Paid tier or add-on | Turn on sensitive data and declare HIPAA status in settings. The BAA is part of HubSpot's Sensitive Data Terms. | Vendor page for HubSpot |
| SalesforceSupport, CRM and productivity | Yes | Through your Salesforce account representative | Not published | Covers only the services on Salesforce's HIPAA covered-services list. Check its BAA restrictions page. | Vendor page for Salesforce |
| NotionSupport, CRM and productivity | Yes | Enterprise plan | Enterprise contract | Free of charge on Enterprise. Beta features are not covered and must not process PHI. | Vendor page for Notion |
| AirtableSupport, CRM and productivity | Yes | Enterprise Scale | Enterprise contract | The BAA sits in Airtable's Health Information Exhibit. There is no migration path from non-HIPAA workspaces. | Vendor page for Airtable |
| Atlassian (Jira, Confluence)Support, CRM and productivity | Yes | Standard, Premium or Enterprise | Paid tier or add-on | Free and trial plans are excluded. Covers Jira, Jira Service Management, Jira Product Discovery and Confluence. | Vendor page for Atlassian (Jira, Confluence) |
| GitHubSupport, CRM and productivity | Unclear | No public BAA offer found | Not published | GitHub's DPA bars sending PHI without GitHub's prior written consent. Ask GitHub before any PHI reaches a repository. | Vendor page for GitHub |
| 1PasswordSupport, CRM and productivity | No | Not applicable | Not applicable | 1Password says it is not a business associate, and so not subject to a BAA, because it cannot decrypt vault data. | Vendor page for 1Password |
| DocuSign eSignatureE-signature, documents and storage | Yes | Arranged through DocuSign sales | Not published | DocuSign acts as a business associate when eSignature handles PHI. It does not publish which plans include the BAA. | Vendor page for DocuSign eSignature |
| DropboxE-signature, documents and storage | Yes | Standard, Business, Advanced, Business Plus or Enterprise | Paid tier or add-on | Team admins sign it in the Admin Console (US customers only). Reseller support can't be enabled once signed. | Vendor page for Dropbox |
| BoxE-signature, documents and storage | Yes | Enterprise, Enterprise Plus or Enterprise Advanced | Paid tier or add-on | Box requires one of these Enterprise tiers and a signed BAA. Lower tiers are not eligible. | Vendor page for Box |
| Google Drive (Workspace)E-signature, documents and storage | Yes | Google Workspace account with the BAA accepted | No extra cost | Drive, including Docs, Sheets, Slides and Forms, is on the Workspace HIPAA Included Functionality list. | Vendor page for Google Drive (Workspace) |
| OneDrive for BusinessE-signature, documents and storage | Yes | Microsoft 365 commercial plans, via the DPA | No extra cost | OneDrive for Business is in Microsoft's HIPAA scope. Consumer OneDrive is not on the list. | Vendor page for OneDrive for Business |
- Yes
- The vendor states it signs a BAA (subject to the plan and conditions shown).
- Partial
- Only some products or engagements are covered; read the conditions.
- No
- The vendor states it does not sign a BAA, or its terms bar PHI.
- Unclear
- The vendor's public wording does not settle it; ask the vendor in writing.
- No extra cost: Available on a standard account of the service; no upgrade or fee stated.
- Paid tier or add-on: Requires a specific published plan, add-on or surcharge.
- Enterprise contract: Requires a sales-negotiated enterprise plan or contract.
- Not published: The vendor does not publish the plan or price for its BAA.
What a BAA must contain
HIPAA sets the minimum terms for a business associate contract in 45 CFR 164.504(e). A vendor's BAA should do each of the following:
- Set out the permitted and required uses and disclosures of PHI by the business associate. (e)(2)(i)
- Bar any use or further disclosure beyond what the contract permits or the law requires. (e)(2)(ii)(A)
- Require appropriate safeguards, including compliance with the Security Rule (Subpart C) for electronic PHI. (e)(2)(ii)(B)
- Require reporting of any use or disclosure the contract does not allow, including breaches of unsecured PHI. (e)(2)(ii)(C)
- Flow the same restrictions down to any subcontractor that handles the PHI. (e)(2)(ii)(D)
- Support patients' rights of access, amendment and an accounting of disclosures. (e)(2)(ii)(E)-(G)
- Open the business associate's practices and records to HHS for compliance reviews. (e)(2)(ii)(I)
- Return or destroy PHI at termination, or extend the protections if that is not feasible. (e)(2)(ii)(J)
- Let the covered entity terminate the contract if the business associate breaches a material term. (e)(2)(iii)
Three things a BAA does not do
- It does not make your application compliant. A BAA puts the vendor's obligations in writing. Access control, audit logging, encryption settings, backups, risk analysis and your own policies are still yours to build and run.
- It covers the listed services only. Every BAA names what is in scope. AWS, Google Cloud and Microsoft publish service lists, and SaaS vendors carve out features such as AI assistants, beta products, native email sending or marketplace apps. PHI that reaches an unlisted service is outside the agreement.
- It does not cover your own misconfiguration. The vendor secures its platform; you secure how you use it. A public storage bucket, an over-broad IAM role or PHI in a log line is your exposure, BAA or not.
If you're mapping a BAA-scoped architecture, that's the work we do.
Sources
- Amazon Web Services (AWS) — checked 2026-09-26
- Google Cloud, Firebase, Firebase Authentication, Gemini on Agent Platform (formerly Vertex AI), Gemini API (Google AI Studio) — checked 2026-09-26
- Microsoft Azure — checked 2026-09-26
- Oracle Cloud Infrastructure (OCI) — checked 2026-09-26
- DigitalOcean — checked 2026-09-26
- Vercel — checked 2026-09-26
- Netlify — checked 2026-09-26
- Render — checked 2026-09-26
- Fly.io — checked 2026-09-26
- Heroku — checked 2026-09-26
- Cloudflare — checked 2026-09-26
- Supabase — checked 2026-09-26
- MongoDB Atlas — checked 2026-09-26
- PlanetScale — checked 2026-09-26
- Neon — checked 2026-09-26
- CockroachDB Cloud — checked 2026-09-26
- Snowflake — checked 2026-09-26
- Databricks — checked 2026-09-26
- Auth0 (Okta Customer Identity) — checked 2026-09-26
- Okta (Workforce Identity) — checked 2026-09-26
- Clerk — checked 2026-09-26
- Amazon Cognito, Amazon Bedrock, Amazon SES — checked 2026-09-26
- WorkOS — checked 2026-09-26
- Stytch — checked 2026-09-26
- OpenAI API, ChatGPT (Enterprise and Edu) — checked 2026-09-26
- Anthropic Claude API, Claude Enterprise — checked 2026-09-26
- Azure OpenAI (Foundry Models sold by Azure) — checked 2026-09-26
- Cohere — checked 2026-09-26
- Groq (GroqCloud) — checked 2026-09-26
- Together AI — checked 2026-09-26
- Hugging Face — checked 2026-09-26
- Twilio (SMS, Voice) — checked 2026-09-26
- SendGrid — checked 2026-09-26
- Postmark — checked 2026-09-26
- Mailgun — checked 2026-09-26
- Resend — checked 2026-09-26
- Google Workspace — checked 2026-09-26
- Microsoft 365, OneDrive for Business — checked 2026-09-26
- Zoom — checked 2026-09-26
- Slack — checked 2026-09-26
- Intercom — checked 2026-09-26
- Front — checked 2026-09-26
- Paubox — checked 2026-09-26
- Calendly — checked 2026-09-26
- Cal.com — checked 2026-09-26
- Stripe — checked 2026-09-26
- Square — checked 2026-09-26
- Datadog — checked 2026-09-26
- New Relic — checked 2026-09-26
- Sentry — checked 2026-09-26
- Mixpanel — checked 2026-09-26
- Amplitude — checked 2026-09-26
- PostHog — checked 2026-09-26
- Segment — checked 2026-09-26
- Google Analytics (GA4) — checked 2026-09-26
- Microsoft Clarity — checked 2026-09-26
- Zendesk — checked 2026-09-26
- HubSpot — checked 2026-09-26
- Salesforce — checked 2026-09-26
- Notion — checked 2026-09-26
- Airtable — checked 2026-09-26
- Atlassian (Jira, Confluence) — checked 2026-09-26
- GitHub — checked 2026-09-26
- 1Password — checked 2026-09-26
- DocuSign eSignature — checked 2026-09-26
- Dropbox — checked 2026-09-26
- Box — checked 2026-09-26
- Google Drive (Workspace) — checked 2026-09-26
- 45 CFR 164.504(e), business associate contracts (eCFR) — required contents of a BAA
Questions this page answers
Does AWS charge for a BAA?
No. AWS presents a standard Business Associate Addendum that you review and accept in AWS Artifact, and its HIPAA page lists no fee for it. Google Cloud says HIPAA customers get the same products at the same prices, and Microsoft includes its BAA in the Product Terms for every Azure customer. In all three cases, PHI may only go into the services the provider lists as covered.
Will OpenAI sign a BAA?
Yes, for the API: OpenAI reviews requests sent to baa@openai.com and does not require an enterprise agreement, but PHI may only go to BAA-eligible endpoints once your organization has Zero Data Retention or an approved retention setting. For ChatGPT, only sales-managed Enterprise and Edu accounts qualify, and OpenAI does not offer a BAA for ChatGPT Business.
Does Stripe sign a BAA?
Stripe publishes no BAA, and its Services Agreement says customers must not provide protected health information as Third Party Data. If you use Stripe, use it only to move money and keep diagnoses, visit details and other PHI out of descriptions, metadata and customer fields. HIPAA's payment-processing exemption (Social Security Act section 1179) covers moving the money, not storing health details alongside it. Square does publish a BAA for features it marks HIPAA-enabled, such as Appointments and Invoices.
Is Firebase covered by Google's BAA?
Only in part. Google Cloud's covered-products list includes Firestore and Cloud Storage for Firebase. Firebase Authentication is not on it, though Identity Platform (its paid upgrade path) is, and no other Firebase-branded product such as Realtime Database, Hosting or Cloud Messaging appears.
Which AI APIs will sign a BAA?
The OpenAI API, the Anthropic Claude API, Azure OpenAI through the Microsoft DPA, Gemini on Google's Agent Platform (formerly Vertex AI), Amazon Bedrock and GroqCloud all state they offer one, each with its own endpoint and retention conditions. Cohere's BAA covers custom model engagements only, and the Gemini API through Google AI Studio is not on Google Cloud's covered list.
Can I get a BAA without an enterprise plan?
Yes, from some vendors. AWS, Google Cloud, Azure, Google Workspace and Microsoft 365 include it on a standard account, PlanetScale offers it on every plan, Paubox includes it even on its free API tier, and Square builds it into its terms. Most other SaaS tools put it behind a named paid tier, an add-on fee or an enterprise contract.