Compliance Directory

The AI tool HIPAA compliance directory

Every entry answers three questions from the vendor's own documents: is there a BAA, on which tier, and does the tool train on your data. Sourced, dated, and updated as terms change.

How to Use This Directory

Every verdict below comes from the vendor's own trust center, privacy policy, or terms, with the source linked and the access date recorded in each tool's full entry. Where a vendor's documentation could not confirm a claim, the entry says UNVERIFIED instead of guessing.

Two patterns to watch as you read. A BAA does not mean the tool skips training on your data; some vendors offer both a BAA and a default right to train. And "HIPAA compliant" badges without published BAA terms are marketing until the paper exists.

Primary-source verdicts, updated as vendor terms change (accessed 2026-07-12 unless noted)
ToolBAATier requiredTrains on your dataVerdict
ChatGPTYesEnterprise / eligible APIConsumer tiers: yes by defaultEnterprise tier only
Microsoft CopilotYesM365 agreement scopeNoYes, with tenant controls in place
ClaudeYesEnterprise/API pathsConfirm per tierConfirm per tier
GeminiYesWorkspace/Cloud pathsConfirm per tierConfirm per tier
Otter.aiYesEnterprise onlyYes by default below EnterpriseEnterprise only
Zoom AI CompanionYesAll paid plansNoYes, strongest posture among meeting tools
Fireflies.aiYesEnterprise + Private StorageNo by defaultBoth switches required, not one
Read AIYesEnterprise+ annual, 5 seatsOff by defaultEnterprise+ annual only
PlaudUNVERIFIEDUNVERIFIEDNo (opt-in only)Never for PHI until confirmed
FreedYes (in ToS)All plansDe-identified notes onlyCleanest BAA posture in this directory
Heidi HealthYesTier unspecifiedNoYes, get the BAA attached to your plan
Retell AIYesAll plansYes by default (negotiate no-training)BAA yes, read the training default
KrispYesEnterprise, 100+ seatsNoEnterprise only, 100-seat minimum
Adobe Acrobat AI AssistantNo: absent from Adobe's HIPAA-Ready list (May 2026)n/aNo (moot for PHI)Never for PHI
Google Vertex AIYes (Cloud BAA)Product-enumeratedNoMatch your workload to a named covered product
BlueprintYes (in ToS)All plansNoOne of the cleanest postures in this directory
NablaYes (ToS appendix)All plansDe-identified use reservedMandatory BAA appendix
Doximity GPTMember-levelFree (verified clinicians)UNVERIFIEDIndividual yes, organizational coverage needs enterprise BAA

The Three Lessons the Table Teaches

What changes once you read past the BAA column

1

The training column matters more than the BAA column

Two tools in this directory sign BAAs while their terms permit model training on customer data by default. Read both columns before any PHI decision.

2

Tier gates put compliance out of reach quietly

Enterprise-only BAAs, seat minimums, and annual-plan requirements mean the version your staff downloaded is almost never the version the vendor's compliance page describes.

3

Your staff did not check this table

Every tool here was found in real healthcare workplaces. If the sanctioned answer does not exist yet, the unsanctioned usage already does. That is a governance decision, not a procurement one. See how HIPAA applies to AI tools.

Directory FAQ

What is a BAA and why does every entry start with it?

A Business Associate Agreement is the HIPAA-required contract before any vendor handles PHI on your behalf. No BAA, no PHI, no exceptions. It is the binary gate; everything else in each entry is about what the BAA does not cover.

A tool says "HIPAA compliant" on its website. Is that enough?

No. HIPAA has no official certification. The claim is real only when the vendor will sign a BAA for your tier and their data-handling terms hold up. That is what each entry verifies.

How current is this directory?

Each full entry carries the date its sources were checked. Vendor terms change quarterly; treat any entry older than six months as a prompt to re-verify before contracting.

Our staff already use one of the "never for PHI" tools. Now what?

Assess what was exposed, then give staff a sanctioned alternative before removing the unsanctioned one. Bans without alternatives produce invisible usage rather than compliant usage.

Turn the Table Into Policy

The directory tells you which tools can be sanctioned. Your acceptable use policy is where that decision becomes enforceable. Generate a healthcare-ready draft in minutes.