Get a Quote
Compliance › HIPAA

HIPAA Compliance for AI-Built Apps (No BAA Problem)

HIPAA applies to covered entities — health plans, providers, clearinghouses — and their business associates: any vendor that creates, receives, maintains, or transmits protected health information (PHI) on a covered entity's behalf. If your AI-built app handles PHI for or on behalf of a covered entity, it's in scope, whether or not you set out to build "healthcare software." Most AI app builders (Lovable, Bolt, Replit, Base44, v0) either exclude PHI outright or offer no Business Associate Agreement, while several of the hosts underneath them (Vercel, Supabase, AWS, Netlify) do offer BAAs — if someone manually configures them. That's how founders learn how to make an AI app HIPAA compliant the hard way: after an audit, not before one.

Get a Free Compliance Scan See the BAA Table
Who it applies to & the fines

Is my app HIPAA compliant, or just handling health data?

HIPAA reaches "covered entities" (health plans, providers, clearinghouses) under 45 CFR Part 162 and their "business associates" — any vendor that creates, receives, maintains, or transmits PHI on a covered entity's behalf. There's a real carve-out worth knowing: an app that merely lets an individual access their own ePHI at their own direction does not, by itself, create a business-associate relationship. The trigger is developing or providing the app for, or on behalf of, a covered entity and handling ePHI on its behalf.

Civil penalty tiers (effective for penalties assessed on/after 2026-01-28)

TierDescriptionPer-violation minimumAnnual cap
Tier 1No knowledgeup to *
Tier 2Reasonable cause max
Tier 3Willful neglect, corrected within 30 days max
Tier 4Willful neglect, uncorrectedup to
*Sources disagree on the annual cap: HIPAA Journal cites caps scaling to across tiers per the Federal Register (reflecting the 2025 COLA multiplier of 1.02598); another source cites OCR's post-2019 enforcement-discretion caps of / / for Tiers 1–3. We're presenting the range rather than picking a single number.

Criminal penalties (42 U.S.C. §1320d-6, unchanged since HITECH)

Tier 1: up to 1 year in prison plus roughly . Tier 2 (obtaining PHI under false pretenses): up to 5 years plus . Tier 3 (selling, commercial use, or malicious intent): up to 10 years plus .

This isn't theoretical — recent enforcement

MMG Fusion LLC — settled 2026-03-05

A dental-software business associate settled for a breach affecting roughly 15 million individuals (breach occurred December 2020) — the finding: failure to conduct a risk analysis and failure to notify. The company, now defunct, paid only plus a 3-year Corrective Action Plan.

Vision Upright MRI — settled May 2025

More than 21,000 individuals affected; no risk analysis on file and untimely breach notification. Settled for plus a 2-year Corrective Action Plan.

OCR's "Risk Analysis Initiative" has produced 13 completed enforcement actions as of April 2026, and more than 50 total HIPAA settlements and penalties as of January 2026.

What the rule actually requires

What HIPAA technically requires from your stack

  • Encryption at rest — no single algorithm is mandated; HHS guidance points to NIST SP 800-111, and AES-256 is the de facto standard for breach-notification safe harbor.
  • Encryption in transit — per NIST SP 800-52: TLS 1.2 minimum (1.3 recommended), with SSLv3/TLS 1.0/1.1 disabled; FIPS 140-2 validated modules for safe harbor.
  • Access control §164.312(a) — unique user ID and emergency access procedures are REQUIRED; automatic logoff and encryption are currently "addressable" (flexible) — the pending NPRM would end that addressable/required split.
  • Audit controls §164.312(b) — record and examine all ePHI activity: logins including failed attempts, and every create/read/update/delete action on PHI. A 6-year retention benchmark aligns with the §164.316 documentation-retention rule (a common vendor inference, not audit-log-specific rule text).
  • Integrity controls §164.312(c) and transmission security §164.312(e).
  • Administrative safeguards — a mandatory Security Risk Analysis (§164.308(a)(1)), the single most-cited failure in enforcement actions; a signed BAA with every vendor that touches PHI before PHI ever flows to them; workforce training; incident response; a sanctions policy.
Proposed rule watch: an NPRM published in the Federal Register on 2025-01-06 (comments closed 2025-03-07, roughly 4,700–5,000 comments) would mandate encryption at rest and in transit plus MFA for all ePHI access, and remove the "addressable" category entirely. As of July 2026 it remains unfinalized — OCR's spring-2026 target passed with nothing published, and there's no confirmed timeline. Expect a 180-day to 1-year compliance window once it is finalized.
Why your AI-built app fails HIPAA

The 7 ways vibe-coded health apps fail HIPAA

1. No BAA anywhere in the stack

Most AI builders prohibit PHI or provide no BAA at all. Letting PHI touch the generation layer of a tool with no BAA is an unauthorized disclosure the moment it happens.

2. PHI leaking into logs and error handlers

AI-generated error handling routinely echoes the offending data — including PHI — straight into unencrypted application logs.

3. Hardcoded secrets and unauthenticated admin endpoints

An open, unauthenticated "/api/patients"-style route is a common scaffold pattern — and a direct path to PHI for anyone who finds it.

4. No audit trail

AI scaffolds don't create an immutable access log by default, so there's no record of who touched what PHI, or when.

5. No real access controls

No row-level security, no role-based access control, no MFA — which means any authenticated user can often query other patients' records just by changing an ID in the request.

6. PHI leaking into analytics and observability tools

PostHog, Sentry, and Firebase Analytics autocapture are common defaults in AI-built apps — none of them have a BAA in place for PHI.

7. Confusing "the host is HIPAA-eligible" with "my app is compliant"

HIPAA hosting is a shared-responsibility model. You still have to actively sign the BAA, restrict PHI to the specific named covered services, and configure the controls yourself — the host being eligible doesn't do any of that for you.

The money section

Does your AI builder or host sign a BAA?

Per-platform BAA status, drawn from each vendor's own published terms and support documentation.

PlatformBAA statusNotes
LovableNo BAA"No Sensitive Data" clause excludes PHI outright — unusable for PHI.
Bolt.new / StackBlitzNo public BAA (April 2026 review)"Bolt for Enterprise" claims HIPAA "readiness" — a distinct, unverified claim.
ReplitNo BAANot HIPAA-eligible; its underlying GCP BAA is between Google and Replit and does not extend downstream to your app.
v0 (Vercel's AI product)Out of scopeExcluded from Vercel's BAA; Vercel support confirms v0 isn't covered — advises no PHI even as placeholder data.
Vercel (hosting, ≠ v0)Offers BAASelf-serve for Pro + Enterprise plans via the billing dashboard; BAA document last updated 2024-07-18.
Base44 (Wix, acquired ~M, June 2025)No BAAOnly a GDPR DPA, which is legally distinct; ToS restricts PHI.
Wix (core platform, ≠ Base44)Offers BAASupports HIPAA on qualifying Premium/Studio plans with a signed BAA.
SupabaseOffers BAATeam plan and above, plus a per-project "HIPAA Add-On" — necessary but not sufficient; you still must implement RLS, access controls, and encryption, and keep PHI out of logs.
Firebase / Google CloudPartialFirebase brand has no direct BAA; coverage only via the Google Cloud BAA, restricted to named "Covered Products" (as of 2026-05-20: Identity Platform, Firestore, Cloud Storage). Firebase Analytics, Crashlytics, Cloud Messaging, and Remote Config are out of scope even under the BAA.
AWSOffers BAA160+ HIPAA-eligible services, conditional on correct configuration, audit logging, and encryption.
NetlifyOffers BAA (enterprise)Dedicated HIPAA-compliant offering with extra audit beyond SOC 2/ISO 27001/PCI — contact sales, not self-serve.
OpenAIPartialAPI: BAA on request (baa@openai.com), 1–2 business days, covers only ZDR-eligible endpoints. ChatGPT Enterprise/Edu: BAA via sales only. ChatGPT Business, Free, and Plus: no BAA.
Anthropic (Claude)PartialBAA available for the first-party Claude API (Messages API + prompt caching, structured outputs, memory, web search, bash/text-editor tools, Token Counting, Models, Org Management, Compliance APIs) and HIPAA-ready Claude Enterprise (admin must enable after signing). Not covered: Workbench/Console, Free/Pro/Max/Team, Cowork, and beta features.
Fix it

The HIPAA compliant app development checklist

  • Inventory every place PHI could touch — data flows, AI-builder prompt/generation logs, analytics, error trackers, every vendor.
  • Migrate off any builder or host that won't sign a BAA — treat AI-scaffolded code as a starting point, not production.
  • Execute BAAs with every remaining PHI-touching vendor, including your hosting provider and your runtime LLM provider.
  • Restrict PHI to the specific services named in each BAA.
  • Encrypt at rest (AES-256) and in transit (TLS 1.2+, prefer 1.3); disable legacy TLS versions.
  • Build real access controls: unique user IDs, RBAC/RLS, MFA (TOTP), session rotation, automatic logoff.
  • Build audit logging — middleware on every PHI endpoint writing to a tamper-evident, hash-chained log table; retain roughly 6 years.
  • Strip PHI from logs and observability tools; disable analytics autocapture on PHI routes; move PHI-handling logic server-side.
  • Add soft-delete/tombstone records plus a scheduled purge job for integrity and retention.
  • Complete a formal Security Risk Analysis (§164.308(a)(1)) and keep it as an ongoing risk-management process, not a one-time checkbox.
  • Put workforce training, an incident-response plan, breach notification procedures, and a sanctions policy in writing.
  • Pen-test / HIPAA-audit the app before any real PHI touches it, and repeat the risk analysis periodically and after every material change.
What changed recently

HIPAA in 2026: what's actually new

  • A proposed HIPAA Security Rule update (NPRM) was published 2025-01-06, with public comments closing 2025-03-07 (roughly 4,700–5,000 comments). As of July 2026 it remains unfinalized with no confirmed date — it would mandate encryption and MFA and remove the "addressable" category.
  • A 1.02598 inflation multiplier applies to civil penalties assessed on or after 2026-01-28.
  • OCR's "Risk Analysis Initiative" has produced 13 completed enforcement actions as of April 2026, and more than 50 total HIPAA settlements since it and the separate Right-of-Access initiative began.
  • Two recent settlements — MMG Fusion (2026-03-05) and Vision Upright MRI (May 2025) — both cite "failure to conduct an accurate and thorough risk analysis" as the core violation; it's OCR's most common lever against small and mid-sized business associates and providers.
  • Washington's My Health My Data Act (RCW 19.373 — signed 2023-04-27; most provisions effective 2024-03-31, small-business provisions 2024-06-30; geofencing provisions 2023-07-23) reaches "consumer health data" that HIPAA does not — menstrual, mental-health, and wellness apps run by non-covered entities — and includes a private right of action. It's a key gap-filler for AI-built consumer health apps that assume HIPAA doesn't apply to them.
FAQ

Common questions about AI apps and HIPAA

Does my AI-built app need to be HIPAA compliant?

Only if it creates, receives, maintains, or transmits protected health information for or on behalf of a covered entity (a health plan, provider, or clearinghouse) — that makes you a "business associate" under HIPAA. An app that only lets someone access their own health data at their own direction does not, by itself, create that relationship.

Does Lovable, Bolt, or Replit sign a HIPAA Business Associate Agreement?

No. Lovable's terms exclude PHI outright with no BAA, Bolt.new/StackBlitz offers no public BAA as of an April 2026 review (its "Enterprise" HIPAA-readiness claim is separate and unverified), and Replit offers no BAA — its underlying Google Cloud BAA doesn't extend downstream to apps built on it.

My host offers a HIPAA BAA — doesn't that make my app compliant?

No. HIPAA hosting is a shared-responsibility model. Vercel, Supabase, AWS, and Netlify all offer BAAs, but you still have to actively sign the agreement, restrict PHI to the specific services named in it, and configure encryption, access controls, and audit logging yourself.

What happens if my AI-built app has a HIPAA violation?

Civil penalties run from a minimum up to annual caps in the millions depending on the tier and whether the violation was willful and uncorrected; criminal violations under 42 U.S.C. §1320d-6 can carry up to 10 years for the most serious cases. Recent OCR settlements have centered on a missing risk analysis, not just a breach itself.

Can I use OpenAI or Claude in a HIPAA-compliant AI app?

Only under specific conditions. OpenAI offers a BAA on request for its API, covering only ZDR-eligible endpoints (ChatGPT Free/Plus/Business have no BAA). Anthropic offers a BAA for the first-party Claude API and Claude Enterprise, but it excludes Workbench/Console, Free/Pro/Max/Team, Cowork, and beta features.

What's the single most common reason AI-built health apps get flagged?

A missing or inadequate Security Risk Analysis under §164.308(a)(1) — it's the most-cited failure in actual OCR enforcement actions. Combine that with no BAA, no audit logging, and PHI leaking into logs or analytics tools, and most AI-scaffolded health apps fail on several fronts at once.

Not sure if your app is HIPAA compliant?

Get a free scan and find out exactly where PHI is exposed, which BAAs are missing, and what it takes to fix it — before OCR or an auditor finds it first.

Get My Free Compliance Scan

Related searches: is my app HIPAA compliant · HIPAA compliant SaaS hosting · HIPAA compliant app development checklist · does Lovable sign a BAA · does Bolt sign a BAA · does Replit sign a BAA · HIPAA compliant AI tools for healthcare startups · vibe coding HIPAA compliance risk · HIPAA compliant database for health app · business associate agreement requirements for startups · HIPAA violation penalties for small business · how to make a Lovable/Bolt/Replit app HIPAA compliant · HIPAA audit logging requirements for developers · PHI in logs HIPAA violation