Tool Compliance

Is Your Tool Compliant?

Detailed compliance assessments for popular SaaS tools and platforms. Find out if the tools you use meet HIPAA, SOC 2, GDPR, and PCI DSS requirements — and what you need to configure.

HIPAA

16 tools
HIPAA
Conditional

Zoom

Video Conferencing

Zoom is HIPAA compliant only when you sign a BAA with Zoom and enable required security settings. The free and Pro plans do not qualify. You must use Zoom for Healthcare or a Business+ plan with the BAA executed.

View full analysis
HIPAA
Conditional

Google Meet

Video Conferencing

Google Meet is HIPAA compliant when used through Google Workspace (Business, Enterprise, or specific education/nonprofit tiers) with a signed BAA. The free consumer version of Google Meet is not HIPAA compliant.

View full analysis
HIPAA
Not Compliant

GoDaddy

Web Hosting

GoDaddy is NOT HIPAA compliant. They do not offer a BAA, do not provide the required technical safeguards for PHI, and their terms of service explicitly do not address HIPAA requirements. Do not use GoDaddy for any application that handles protected health information.

View full analysis
HIPAA
Conditional

HIPAA-Compliant CRM Software

CRM

Several CRM platforms can be HIPAA compliant with proper configuration. Salesforce Health Cloud is purpose-built for healthcare. HubSpot offers a BAA on Enterprise plans. Freshsales and Zoho CRM also offer BAAs. Always verify BAA availability and configure access controls before storing PHI.

View full analysis
HIPAA
Conditional

HIPAA-Compliant Email Providers

Email

Several email providers offer HIPAA-compliant email solutions. Paubox provides seamless encryption without requiring recipient action. Virtru adds encryption to Gmail and Outlook. Hushmail is designed for small healthcare practices. Google Workspace and Microsoft 365 can also be compliant with BAAs and proper configuration.

View full analysis
HIPAA
Conditional

HIPAA-Compliant Cloud Storage

Cloud Storage

AWS S3, Azure Blob Storage, Google Cloud Storage, and Box all offer HIPAA-compliant cloud storage with signed BAAs. Each requires specific configuration including encryption, access controls, and audit logging to maintain compliance.

View full analysis
HIPAA
Conditional

ChatGPT

AI Assistant

ChatGPT is HIPAA compliant ONLY on the Enterprise plan, where OpenAI signs a BAA and does not use your data for training. Free, Plus, and Team plans are NOT compliant and must never be used with PHI. The OpenAI API also supports BAAs for developers building healthcare applications.

View full analysis
HIPAA
Conditional

Gmail

Email

Free Gmail is NOT HIPAA compliant. Google Workspace Gmail (Business, Enterprise plans) is HIPAA compliant when you sign the BAA in the Admin Console and configure security settings. Even with Workspace, Gmail does not provide end-to-end encryption for external recipients without third-party add-ons.

View full analysis
HIPAA
Conditional

Google Workspace

Productivity Suite

Google Workspace is HIPAA compliant when you sign the BAA in the Admin Console. Core services including Gmail, Drive, Meet, Docs, Sheets, Slides, Calendar, and Chat are all covered. However, additional Workspace services and third-party Marketplace apps may not be covered.

View full analysis
HIPAA
Conditional

HIPAA-Compliant Video Conferencing

Video Conferencing

Several video conferencing platforms are HIPAA compliant with BAAs. Doxy.me is purpose-built for telehealth with no downloads required. Zoom for Healthcare offers a comprehensive BAA. Microsoft Teams and Google Meet are compliant through enterprise plans with BAAs. Each requires specific configuration.

View full analysis
HIPAA
Conditional

HIPAA-Compliant Hosting Providers

Web Hosting

AWS, Microsoft Azure, Google Cloud Platform, Liquid Web, and Atlantic.Net all offer HIPAA-compliant hosting with BAAs. Major cloud providers require you to configure compliance yourself, while specialized providers offer pre-configured HIPAA hosting environments.

View full analysis
HIPAA
Conditional

HIPAA-Compliant Telehealth Platforms

Telehealth

Purpose-built telehealth platforms like Doxy.me, SimplePractice, TheraNest, and VSee are all HIPAA compliant with included BAAs. The best choice depends on your practice size, specialty, and whether you need integrated EHR, billing, and scheduling features.

View full analysis
HIPAA
Conditional

Slack

Team Messaging

Slack is HIPAA compliant ONLY on the Enterprise Grid plan with a signed BAA from Salesforce (Slack's parent company). Free, Pro, and Business+ plans do not qualify. Enterprise Grid provides the encryption, DLP, and admin controls required for HIPAA.

View full analysis
HIPAA
Conditional

Dropbox

Cloud Storage

Dropbox is HIPAA compliant on Business Advanced and Enterprise plans with a signed BAA. Free, Plus, Professional, and Business Essentials plans are NOT compliant. Even on qualifying plans, you must configure sharing restrictions and access controls.

View full analysis
HIPAA
Conditional

Microsoft Teams

Team Collaboration

Microsoft Teams is HIPAA compliant with a Microsoft 365 Business or Enterprise BAA. The BAA covers Teams messaging, video, file sharing, and integrations with other M365 services. Configuration of DLP, retention, and access controls is required.

View full analysis
HIPAA
Not Compliant

Trello

Project Management

Trello is NOT HIPAA compliant. Atlassian does not offer a BAA for Trello, and the platform is not designed for handling protected health information. Do not use Trello for patient tracking, care coordination, or any workflow involving PHI.

View full analysis

Generate compliance policies for your tool stack

PoliWriter creates HIPAA, SOC 2, GDPR, and PCI DSS policies customized to the tools and platforms you actually use. AI-powered, audit-ready, hours not months.

Get Started Free