Skip to content
Unbase44

Base44 and HIPAA: can you build a health app on it?

If your app stores or processes patient information for a healthcare provider, a health plan or one of their vendors, HIPAA decides where it can run. For Base44 the short answer is that its terms don’t allow protected health information on the platform without a separate written agreement.

Updated 5 min readBy the Unbase44 team

On this page

This article explains how HIPAA applies to app platforms in general terms. It isn’t legal advice, and nothing here makes an app compliant on its own. If you handle health information for a US covered entity, work with a compliance professional.

Who HIPAA applies to

HIPAA’s privacy and security rules apply to covered entities, meaning health plans, healthcare clearinghouses and healthcare providers that bill electronically, and to their business associates: companies that create, receive, maintain or transmit protected health information (PHI) on a covered entity’s behalf.

If you’re building a wellness tracker for yourself, HIPAA probably doesn’t apply. If you’re building patient intake forms for a clinic, appointment reminders for a dental practice, or a tool a therapist uses to keep notes, it very likely does. PHI is broader than many founders expect: a name next to an appointment time at a specific clinic can be enough.

What HIPAA asks of the software you use

Two requirements shape every technical decision.

A business associate agreement (BAA) with every vendor that touches PHI. Your hosting provider, your database, your file storage, your email service and your AI provider are all business associates if PHI passes through them, and each needs a signed BAA. No BAA, no PHI on that service.

The Security Rule’s safeguards. Administrative, physical and technical safeguards: a documented risk analysis, access controls, unique user accounts, audit logs, integrity controls, encryption in transit and at rest, backups and a plan for incidents.

A platform can be secure in many ways and still unusable for PHI, simply because it won’t sign a BAA.

What Base44 says

Base44’s terms of service (the version dated 22 June 2026) ask you to promise that you won’t share sensitive data protected by special legislation with the platform, naming protected health information alongside payment card data, unless Base44 has expressly agreed in writing beforehand and an appropriate agreement is in place.

Base44 doesn’t publish a HIPAA offering or a self-service BAA. Its security materials and privacy documentation describe SOC 2 Type II and ISO 27001, which are valuable security attestations but aren’t HIPAA compliance and don’t replace a BAA.

Two other documented facts matter for health data:

  • Location. Base44’s servers are in the United States, and data is stored there by default.
  • AI training. On plans other than Enterprise, workspace data can be used to train AI models, with no opt-out; on Enterprise it’s excluded automatically. Health information used to train a vendor’s models is exactly what HIPAA is designed to prevent.

In practice: unless you have a written agreement with Base44 covering PHI, an app that stores or processes PHI shouldn’t run on it.

Your options

1. Keep PHI out of the app. Some apps can be designed so they never hold PHI: a public information site, a scheduling tool that only collects a first name and a time, or an app that stores de-identified data. Be strict about the definition; this is where teams get it wrong.

2. Ask Base44 for a written agreement. The terms leave the door open to a separately agreed arrangement. If you’re an enterprise customer, ask what they will sign, what it covers, and which services it includes (hosting, database, files, email, AI).

3. Move the app somewhere you can sign the BAAs yourself. The large cloud providers offer BAAs. Amazon Web Services lets you accept its Business Associate Addendum through AWS Artifact in your own account, and then use its HIPAA-eligible services for PHI. Email and AI need the same treatment: choose providers that will sign a BAA for the way you use them. Some AI providers, OpenAI among them, offer BAAs to API customers on request, usually with conditions such as not retaining data.

Unbase44’s HIPAA-ready option

Unbase44’s HIPAA-ready setup is coming soon, as an optional add-on priced in your quote. Until it ships, talk to us if you need it. It moves the whole app, meaning the app itself, its database and its files, into your own AWS account, where you are the customer of record and can accept AWS’s BAA.

What that gives you:

  • Your data stays in your account. After the migration, nothing routes through Unbase44. We’re not in the data path of the running app, so we are not a vendor of your live app.
  • AI features run on your own provider account. You choose an AI provider and plan that will sign a BAA for your use.
  • The code is yours to audit. Your repository contains the whole app and the backend it runs on, so your compliance team can see exactly how data is handled.

One thing to know before you start: during the migration itself, your app’s data passes through our migration workers on its way to your AWS account, and isn’t kept afterwards. If your Base44 app already holds PHI, talk to us before you migrate so the arrangement for that step is agreed in advance.

HIPAA is more than hosting

Moving to BAA-covered infrastructure makes compliance possible. It doesn’t make it automatic. You still need to:

  • Carry out and document a risk analysis, and repeat it when things change.
  • Write the policies: who gets access, how access is reviewed, how incidents are handled.
  • Give every person a unique account, and remove access promptly when people leave.
  • Keep audit logs of who accessed or changed PHI, and look at them.
  • Confirm encryption in transit and at rest on every service.
  • Take backups and test restoring them.
  • Sign a BAA with every vendor that touches PHI, including email and AI.
  • Plan breach notification, with deadlines, before you ever need it.
  • Apply the minimum necessary principle: collect and show only what each role needs.
  • Train the people who use the app.

Questions and answers

Is Base44 HIPAA compliant?

Base44 doesn’t publish a HIPAA offering or a BAA, and its terms ask customers not to put protected health information on the platform unless Base44 has agreed to it in writing with an appropriate agreement in place.

Does SOC 2 or ISO 27001 mean a platform is HIPAA compliant?

No. They show a vendor runs a strong security programme, which helps, but HIPAA still requires a signed BAA with every vendor that handles PHI, and safeguards that you implement yourself.

Does moving to AWS make my app HIPAA compliant?

No. It lets you sign a BAA with your infrastructure provider and use services that are eligible for PHI. Compliance also depends on your policies, access controls, logging, other vendors and training.

Will Unbase44 sign a BAA?

After migration, your app doesn’t run through Unbase44 at all. For the migration step itself, if your Base44 app already contains PHI, contact us before you start so we can agree how that step is handled.

Sources

Checked on September 27, 2026. Base44 changes quickly; if something here is out of date, tell us.