HIPAA applies to covered entities — health plans, providers, clearinghouses — and their business associates: any vendor that creates, receives, maintains, or transmits protected health information (PHI) on a covered entity's behalf. If your AI-built app handles PHI for or on behalf of a covered entity, it's in scope, whether or not you set out to build "healthcare software." Most AI app builders (Lovable, Bolt, Replit, Base44, v0) either exclude PHI outright or offer no Business Associate Agreement, while several of the hosts underneath them (Vercel, Supabase, AWS, Netlify) do offer BAAs — if someone manually configures them. That's how founders learn how to make an AI app HIPAA compliant the hard way: after an audit, not before one.
Get a Free Compliance Scan See the BAA TableHIPAA reaches "covered entities" (health plans, providers, clearinghouses) under 45 CFR Part 162 and their "business associates" — any vendor that creates, receives, maintains, or transmits PHI on a covered entity's behalf. There's a real carve-out worth knowing: an app that merely lets an individual access their own ePHI at their own direction does not, by itself, create a business-associate relationship. The trigger is developing or providing the app for, or on behalf of, a covered entity and handling ePHI on its behalf.
| Tier | Description | Per-violation minimum | Annual cap |
|---|---|---|---|
| Tier 1 | No knowledge | up to * | |
| Tier 2 | Reasonable cause | max | |
| Tier 3 | Willful neglect, corrected within 30 days | max | |
| Tier 4 | Willful neglect, uncorrected | up to |
Tier 1: up to 1 year in prison plus roughly . Tier 2 (obtaining PHI under false pretenses): up to 5 years plus . Tier 3 (selling, commercial use, or malicious intent): up to 10 years plus .
A dental-software business associate settled for a breach affecting roughly 15 million individuals (breach occurred December 2020) — the finding: failure to conduct a risk analysis and failure to notify. The company, now defunct, paid only plus a 3-year Corrective Action Plan.
More than 21,000 individuals affected; no risk analysis on file and untimely breach notification. Settled for plus a 2-year Corrective Action Plan.
OCR's "Risk Analysis Initiative" has produced 13 completed enforcement actions as of April 2026, and more than 50 total HIPAA settlements and penalties as of January 2026.
Most AI builders prohibit PHI or provide no BAA at all. Letting PHI touch the generation layer of a tool with no BAA is an unauthorized disclosure the moment it happens.
AI-generated error handling routinely echoes the offending data — including PHI — straight into unencrypted application logs.
An open, unauthenticated "/api/patients"-style route is a common scaffold pattern — and a direct path to PHI for anyone who finds it.
AI scaffolds don't create an immutable access log by default, so there's no record of who touched what PHI, or when.
No row-level security, no role-based access control, no MFA — which means any authenticated user can often query other patients' records just by changing an ID in the request.
PostHog, Sentry, and Firebase Analytics autocapture are common defaults in AI-built apps — none of them have a BAA in place for PHI.
HIPAA hosting is a shared-responsibility model. You still have to actively sign the BAA, restrict PHI to the specific named covered services, and configure the controls yourself — the host being eligible doesn't do any of that for you.
Per-platform BAA status, drawn from each vendor's own published terms and support documentation.
| Platform | BAA status | Notes |
|---|---|---|
| Lovable | No BAA | "No Sensitive Data" clause excludes PHI outright — unusable for PHI. |
| Bolt.new / StackBlitz | No public BAA (April 2026 review) | "Bolt for Enterprise" claims HIPAA "readiness" — a distinct, unverified claim. |
| Replit | No BAA | Not HIPAA-eligible; its underlying GCP BAA is between Google and Replit and does not extend downstream to your app. |
| v0 (Vercel's AI product) | Out of scope | Excluded from Vercel's BAA; Vercel support confirms v0 isn't covered — advises no PHI even as placeholder data. |
| Vercel (hosting, ≠ v0) | Offers BAA | Self-serve for Pro + Enterprise plans via the billing dashboard; BAA document last updated 2024-07-18. |
| Base44 (Wix, acquired ~M, June 2025) | No BAA | Only a GDPR DPA, which is legally distinct; ToS restricts PHI. |
| Wix (core platform, ≠ Base44) | Offers BAA | Supports HIPAA on qualifying Premium/Studio plans with a signed BAA. |
| Supabase | Offers BAA | Team plan and above, plus a per-project "HIPAA Add-On" — necessary but not sufficient; you still must implement RLS, access controls, and encryption, and keep PHI out of logs. |
| Firebase / Google Cloud | Partial | Firebase brand has no direct BAA; coverage only via the Google Cloud BAA, restricted to named "Covered Products" (as of 2026-05-20: Identity Platform, Firestore, Cloud Storage). Firebase Analytics, Crashlytics, Cloud Messaging, and Remote Config are out of scope even under the BAA. |
| AWS | Offers BAA | 160+ HIPAA-eligible services, conditional on correct configuration, audit logging, and encryption. |
| Netlify | Offers BAA (enterprise) | Dedicated HIPAA-compliant offering with extra audit beyond SOC 2/ISO 27001/PCI — contact sales, not self-serve. |
| OpenAI | Partial | API: BAA on request (baa@openai.com), 1–2 business days, covers only ZDR-eligible endpoints. ChatGPT Enterprise/Edu: BAA via sales only. ChatGPT Business, Free, and Plus: no BAA. |
| Anthropic (Claude) | Partial | BAA available for the first-party Claude API (Messages API + prompt caching, structured outputs, memory, web search, bash/text-editor tools, Token Counting, Models, Org Management, Compliance APIs) and HIPAA-ready Claude Enterprise (admin must enable after signing). Not covered: Workbench/Console, Free/Pro/Max/Team, Cowork, and beta features. |
Only if it creates, receives, maintains, or transmits protected health information for or on behalf of a covered entity (a health plan, provider, or clearinghouse) — that makes you a "business associate" under HIPAA. An app that only lets someone access their own health data at their own direction does not, by itself, create that relationship.
No. Lovable's terms exclude PHI outright with no BAA, Bolt.new/StackBlitz offers no public BAA as of an April 2026 review (its "Enterprise" HIPAA-readiness claim is separate and unverified), and Replit offers no BAA — its underlying Google Cloud BAA doesn't extend downstream to apps built on it.
No. HIPAA hosting is a shared-responsibility model. Vercel, Supabase, AWS, and Netlify all offer BAAs, but you still have to actively sign the agreement, restrict PHI to the specific services named in it, and configure encryption, access controls, and audit logging yourself.
Civil penalties run from a minimum up to annual caps in the millions depending on the tier and whether the violation was willful and uncorrected; criminal violations under 42 U.S.C. §1320d-6 can carry up to 10 years for the most serious cases. Recent OCR settlements have centered on a missing risk analysis, not just a breach itself.
Only under specific conditions. OpenAI offers a BAA on request for its API, covering only ZDR-eligible endpoints (ChatGPT Free/Plus/Business have no BAA). Anthropic offers a BAA for the first-party Claude API and Claude Enterprise, but it excludes Workbench/Console, Free/Pro/Max/Team, Cowork, and beta features.
A missing or inadequate Security Risk Analysis under §164.308(a)(1) — it's the most-cited failure in actual OCR enforcement actions. Combine that with no BAA, no audit logging, and PHI leaking into logs or analytics tools, and most AI-scaffolded health apps fail on several fronts at once.
Get a free scan and find out exactly where PHI is exposed, which BAAs are missing, and what it takes to fix it — before OCR or an auditor finds it first.
Get My Free Compliance ScanRelated searches: is my app HIPAA compliant · HIPAA compliant SaaS hosting · HIPAA compliant app development checklist · does Lovable sign a BAA · does Bolt sign a BAA · does Replit sign a BAA · HIPAA compliant AI tools for healthcare startups · vibe coding HIPAA compliance risk · HIPAA compliant database for health app · business associate agreement requirements for startups · HIPAA violation penalties for small business · how to make a Lovable/Bolt/Replit app HIPAA compliant · HIPAA audit logging requirements for developers · PHI in logs HIPAA violation