HIPAA compliant AI agent platforms are the ones whose vendor will sign a Business Associate Agreement (BAA) for the exact product you use. As of October 1, 2026, that means OpenAI (ChatGPT Enterprise with Regulated Workspace, and the API with modified retention), Anthropic (Claude Enterprise and the API), Microsoft Copilot Studio, Google’s Gemini app inside Workspace, and Lindy on its Enterprise plan. Zapier and n8n Cloud say they won’t sign one. The catch everywhere: a BAA covers named features, and connectors, beta tools and browser automation are often left out.

We checked every claim below on the vendor’s own trust, help or legal page on October 1, 2026. This is a buyer’s map, not legal advice: your compliance officer or counsel decides whether a setup is acceptable for your practice.

What “HIPAA compliant” means for an AI agent

There’s no HIPAA certificate a software product can earn. HIPAA applies to covered entities (clinics, health plans, providers) and to the business associates that handle protected health information (PHI) for them. When an AI vendor processes PHI for you, it becomes your business associate, and the law requires a signed BAA between you before any PHI goes in.

So the useful question isn’t “is this platform HIPAA compliant?” It’s three narrower ones:

  1. Will the vendor sign a BAA with you? Some say no outright.
  2. Which products and plans does the BAA cover? Usually an enterprise tier, rarely the self-serve plan you can buy with a card.
  3. Which features does it exclude? This is where AI agents get tricky, because an agent’s value is reaching into other tools, and those connections are often outside the agreement.

An agent adds a fourth question that a chatbot doesn’t: where does the data go next? An agent that reads a patient email and then posts a summary to Slack, a CRM or a spreadsheet has just sent PHI to three more vendors. Each of them needs its own BAA too.

HIPAA compliant AI agent platforms at a glance

Platform Signs a BAA? Covered Not covered (examples)
OpenAI Yes ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT for Clinicians, ChatGPT FedRAMP, API with modified retention Free, Plus, Pro and self-serve ChatGPT plans
Anthropic Yes Claude Enterprise core features; Claude API (Messages API and listed features); Claude Code with Zero Data Retention Console, Cowork, beta features, MCP connectors, Batch, Files, Code Execution, Computer Use, Web Fetch; Free, Pro, Max
Microsoft Yes Copilot Studio, under Microsoft’s BAA Not intended as a medical device
Google Yes Gemini app and Gemini in Workspace (Workspace BAA, effective Aug 31, 2026); Agent Search on Gemini Enterprise Agent Platform (Cloud BAA) Gemini in Chrome
Lindy Yes, Enterprise only Lindy Enterprise Plus, Pro and Max plans
Zapier No — Everything involving PHI
n8n Cloud No — Everything involving PHI
Squad No public HIPAA claim — Runs on your own ChatGPT, Claude or Gemini plan

The pattern is the same across all five that say yes: the BAA lives on a sales-managed or enterprise plan, not on the plan you’d buy on a Tuesday afternoon.

OpenAI: ChatGPT and the API

OpenAI’s help center lists its HIPAA-eligible products by name: ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, the API with modified retention, and API FedRAMP with modified retention.

The two routes work differently. For the API, OpenAI says you don’t need an enterprise agreement: you email its BAA team with your company and use case, and it usually replies within one to two business days. It approves most requests, but some use cases don’t pass its review. For ChatGPT, only Enterprise or Edu customers with a sales-managed account are eligible, which rules out every self-serve plan.

What this means for agents: if you’re building your own agent on the API, the BAA route is open to a small team. If you want staff to use ChatGPT itself with patient data, you’re in an enterprise sales conversation.

Anthropic: Claude Enterprise and the API

Anthropic’s BAA page is the most specific of any vendor here, and it’s worth reading in full before you sign.

On Claude Enterprise, the BAA covers the core features: chat, Projects, Artifacts, file creation, voice, web search, research and skills. It excludes Claude Console, Claude Cowork and features in beta. Third-party integrations (MCP connectors, Enterprise Search and the Chrome extension) stay available but aren’t protected by the BAA. An organisation’s Primary Owner switches on HIPAA compliance in settings.

On the API, the Messages API and a list of named features are covered, while the Batch API, Files API, Skills API, Code Execution, Computer Use and Web Fetch are excluded. Claude Code is covered only with Zero Data Retention turned on. Consumer plans (Free, Pro and Max) aren’t covered at all.

For agents, those exclusions matter. Computer use and web fetch are exactly what you’d reach for to let an agent work in a portal with no API, and they’re the parts the agreement leaves out.

Microsoft Copilot Studio

Microsoft’s documentation is direct: “Microsoft Copilot Studio is covered under the Health Insurance Portability and Accountability Act (HIPAA) Business Associate Agreement (BAA).” The same page gives examples of agents that can collect health information from people, such as blood pressure or weight, and adds a caveat: Copilot Studio isn’t intended for use as a medical device.

If your organisation already runs on Microsoft 365 with a BAA in place, Copilot Studio is the shortest path to a covered agent. You still need to check every connector an agent calls, since a flow that writes to a non-Microsoft service sends data outside Microsoft’s agreement.

Google: Gemini in Workspace and Gemini Enterprise

Google has two agreements. Under the Google Workspace BAA, the list of HIPAA Included Functionality, effective August 31, 2026, includes the Gemini app (excluding Gemini in Chrome) alongside Gmail, Drive, Calendar, Meet and the rest of Workspace. So a clinic on Workspace with a signed BAA can use Gemini on the same terms as its email.

Under the Google Cloud BAA, the covered-products list names “Agent Search on Gemini Enterprise Agent Platform” and “Antigravity in Gemini Enterprise”, among many infrastructure services. Google’s Gemini Enterprise compliance page points back to that list rather than naming editions, so check the exact product you plan to use against it before you buy.

Lindy: only on the Enterprise plan

Lindy is the only one of the dedicated agent products in our catalog that offers a BAA, and only on Enterprise. Its pricing page lists “HIPAA compliance & signed BAA” under Enterprise, which is priced by its sales team. The self-serve plans (Plus at $29.99, Pro at $99.99 and Max at $199.99 per user a month) don’t include it.

Lindy’s pricing page: Plus at $29.99, Pro at $99.99 and Max at $199.99 per user a month, with an Enterprise plan that lists HIPAA compliance and a signed BAA

Lindy’s homepage also lists HIPAA among its compliance badges, which is easy to misread as covering every plan. It doesn’t: the BAA is the Enterprise line. Lindy also notes that its approval guardrails only apply in shared Slack threads, which matters if staff would message it with patient details in a DM. We cover the rest of Lindy’s limits on its tool page.

Platforms that won’t sign a BAA

Some popular automation and agent tools are clear that PHI isn’t allowed.

Zapier. Zapier’s own answer is “No, Zapier isn’t HIPAA compliant.” It says it doesn’t sign BAAs and that you shouldn’t store, send or automate anything involving PHI. You can still use it in a healthcare business for work that never touches patient data, such as marketing or scheduling non-clinical tasks. Our Zapier alternatives page lists the other workflow tools, none of which we’ve confirmed as BAA-ready.

n8n Cloud. An n8n team member wrote in January 2026 that “n8n does not offer a Business Associate Agreement (BAA) for HIPAA compliance.” Self-hosting n8n is the route people discuss for health data, and it can work, but in our reading it moves the whole burden to you: the server, logs, backups, access control and every service a workflow sends data to.

Squad. Squad makes no HIPAA claim on its site, and its pricing model rules it out for PHI as built: the work runs on your own ChatGPT, Claude or Gemini subscription, and consumer plans of those aren’t covered by any BAA. It’s a good fit for a practice’s non-clinical back office, such as supplier invoices or a weekly revenue report, and we’d keep patient data out of it. Our Squad review covers what it’s built for.

The gaps inside a BAA

A signed BAA doesn’t make every feature safe for PHI. Across the vendors above, the same kinds of features fall outside the agreement:

  • Connectors and MCP servers. Anthropic says outright that MCP connectors aren’t protected. When an agent pulls from or writes to another app, that app’s vendor needs its own BAA.
  • Beta features. Anthropic excludes them by name. New agent features tend to launch in beta, so the newest capability is often the uncovered one.
  • Browser and computer use. Anthropic excludes Computer Use and Web Fetch on the API. An agent that logs into a payer portal on your behalf may be using exactly the excluded parts.
  • Data retention settings. OpenAI’s API is covered with modified retention, and Claude Code only with Zero Data Retention. A BAA plus the wrong retention setting isn’t the covered configuration.
  • The plan your staff actually use. A clinic with ChatGPT Enterprise can still have staff pasting notes into a personal ChatGPT account. The BAA doesn’t follow them there.

A worked example: one agent, four agreements

Suppose a small physiotherapy clinic wants an agent that reads new-patient emails, drafts a reply, books the first appointment and posts a summary for the front desk. This is a hypothetical, but the shape is common.

  • The model. If the agent runs on Claude Enterprise or the OpenAI API with modified retention, the vendor signs a BAA for that part. If someone builds it on a personal ChatGPT Plus account, nothing is covered.
  • The inbox. The emails live in Gmail or Outlook. The clinic needs Google’s Workspace BAA or Microsoft’s BAA in place for that account.
  • The calendar or booking tool. If appointments go into a separate scheduling app, that vendor needs a BAA too, or the agent can’t send it patient names.
  • The summary. If the front-desk summary lands in Slack or a shared spreadsheet, that’s a fourth vendor holding PHI.

One agent, four agreements. If any link in that chain won’t sign, the fix is usually to cut the link: post the summary inside the covered email system instead of Slack, or keep names out of the message and link to the record instead.

How to check a platform yourself

You’ll meet vendors that aren’t on this list, especially voice agents for front desks and support agents for patient messaging. The same five steps work for any of them:

  1. Find the vendor’s own BAA page. A trust center, help article or legal page. A “HIPAA” badge on the homepage isn’t enough, as Lindy’s pricing shows.
  2. Write down the plan. Most BAAs sit on Enterprise or a sales-managed account. If you can buy it with a card, assume it isn’t covered until the vendor says so.
  3. List the excluded features, then compare them with what your agent needs to do. If the job needs an excluded feature, the agent can’t do it with PHI.
  4. Map every downstream tool. Each app the agent reads from or writes to needs a BAA too: email, CRM, storage, messaging.
  5. Get it signed before any PHI goes in, and set the retention options the BAA requires.

Which one fits your practice

  • You already run Microsoft 365 under a BAA: start with Copilot Studio, and audit every connector.
  • You run Google Workspace under a BAA: the Gemini app is covered on the same terms, excluding Gemini in Chrome.
  • You’re building your own agent: the OpenAI API (with modified retention) or the Claude API both offer a BAA without an enterprise seat contract, with Anthropic’s feature exclusions to read first.
  • You want a ready-made assistant in Slack: Lindy Enterprise, with guardrails set before anyone uses it, and remember that DMs aren’t guarded.
  • Your agent only touches non-clinical work: tools without a BAA, such as Zapier or Squad, are fine as long as patient data never enters them. Our list of the best AI agents for creative agencies shows what that kind of back-office agent looks like.

For the rest of a small team’s toolkit, see the must-have tools for founders, and every agent we’ve reviewed is in the AI agents category.