If your app will store or process protected health information (PHI) for a covered entity, the platform it runs on has to sign a business associate agreement (BAA) with you. No BAA, no PHI, whatever the marketing page says about encryption. Most “best HIPAA no-code builder” lists are written by one of the builders, and they tend to rank themselves first. This one is also written by a vendor, and we are in the table. To keep it useful anyway, every row links to the vendor’s own pricing, legal or help page, and where we could not confirm something from the vendor itself, the table says so.
1. The Short Answer
As of 1 October 2026, these no-code and low-code platforms say on their own sites that they will sign a HIPAA BAA: Blaze, Caspio (HIPAA Edition), Knack (Knack Health plans), DrapCode, Quickbase (Business and Enterprise, annual contracts), Airtable (Enterprise Scale only), Google AppSheet (under Google’s Workspace or Cloud BAA), Microsoft Power Apps (under Microsoft’s BAA), Zoho Creator (on request), and Jotform for forms (Gold and Enterprise).
These do not sign one today: Bubble, Glide, Retool’s cloud, FlutterFlow and Budibase’s cloud service. Their own terms or documentation say so. Softr and Adalo do not mention HIPAA or a BAA anywhere we could find on their sites, which in practice means you should assume no.
The cheapest published path to a signed BAA is a forms tool (Jotform Gold) or a seat-priced suite you may already pay for (AppSheet, Power Apps). The cheapest dedicated healthcare app builders with published prices start at roughly $160 to $800 a month.
2. The 2026 Table: 18 Platforms
Prices are the vendor’s published starting price for the lowest plan that includes a BAA, in US dollars, checked on 1 October 2026. “Sales-only” means the vendor does not publish a price. Prices and plan names change often, so treat this as a shortlist, not a quote.
| Platform | Signs a BAA? | Plan you need | Published price | The catch |
|---|---|---|---|---|
| Blaze | Yes | Production or higher | From $750/mo | Production is 1 published app and up to 100 end users; the free Sandbox is for synthetic data only |
| Caspio | Yes | HIPAA Edition | From $800/mo, 1-year term | Caspio’s pages describe HIPAA both as a separate edition and as a $500/mo add-on to a standard plan; confirm the total with sales |
| Knack | Yes | Knack Health: HIPAA Forms, Starter or Core | Forms from $159/mo; Starter from $499/mo; Core sales-only | Forms is a forms product; full apps start at Starter. Knack’s own blog quotes different figures in places |
| DrapCode | Yes | Scale or Enterprise | Scale $650/mo | Also sells built-for-you apps from $10,000 per project; plan names on its pricing page are inconsistent |
| Quickbase | Yes | Business or Enterprise, annual or multi-year | Business from $55/user/mo, plus an unpublished platform minimum | Monthly contracts don’t qualify. Also documents FDA Part 11 use cases |
| Airtable | Yes | Enterprise Scale only | Sales-only | No PHI on Team or Business plans at all. Third-party integrations and outside AI services need their own assessment |
| Google AppSheet | Yes, under Google’s BAA | A Google Workspace or Cloud account with the BAA accepted; edition not stated | $5 to $20/user/mo | PHI must be marked as sensitive data and kept out of app definitions and support tickets; ask sales which edition you need |
| Microsoft Power Apps | Yes, under Microsoft’s BAA | Any in-scope commercial Power Apps license | Premium $20/user/mo, paid yearly | The BAA is included by default through Microsoft’s Data Protection Addendum, but only for Microsoft’s in-scope services, not third-party connectors |
| Zoho Creator | Yes, on request | Not published | Not published for HIPAA | Request Zoho’s BAA template from its legal team; the BAA lists which Zoho services it covers |
| Jotform (forms) | Yes | Gold or Enterprise | Gold $129/mo, or $99/mo billed yearly | A form builder, not an app builder. Signed in a self-serve wizard after upgrading |
| Bubble | No | — | — | Bubble says it does not meet HIPAA standards today; a dedicated Enterprise plan is “targeted for by the end of 2026” |
| Glide | No | — | — | Glide’s data rules prohibit HIPAA-covered PHI on the platform |
| Retool (cloud) | No | — | — | Its subscription agreement says Retool is not a business associate and PHI must not go to Retool Cloud. Teams that need PHI self-host it |
| FlutterFlow | No | — | — | Its terms say the service is not intended for HIPAA-protected health information. The backend you connect needs its own BAA |
| Budibase (cloud) | No | — | — | Its terms say the subscription service is not designed to comply with HIPAA |
| Softr | None published | — | — | Its security page does not mention HIPAA or a BAA. Ask sales in writing before assuming either way |
| Adalo | None published | — | — | We found no HIPAA or BAA statement from Adalo itself, only community-forum answers saying no |
| VertiComply | On request | Paid plans | Pro $49/mo | Our terms require a signed BAA before any PHI enters the platform. Hosted demo deployments are not for PHI yet; see section 9 |
3. How to Read the Table
Three patterns stand out.
- A BAA is usually a plan feature, not a platform feature. Airtable, Quickbase, Jotform and most of the healthcare builders sign only on specific plans, and often only on annual contracts. A free trial on the right plan is still not covered until the BAA is signed.
- The big suites are cheaper than they look, and harder than they look. If your organisation already pays for Google Workspace or Microsoft 365, AppSheet or Power Apps may be covered by a BAA you have already accepted. The work moves to configuration: keeping PHI inside the covered services, and out of every connector, add-on and AI feature that is not on the vendor’s in-scope list.
- “No” usually means the terms forbid PHI outright. Glide, Retool Cloud, FlutterFlow and Budibase do not just decline to sign; their terms tell you not to put PHI there. Using them for PHI anyway is a breach of contract as well as a HIPAA problem.
4. What a BAA Covers, and What It Doesn’t
A BAA is the contract HIPAA requires between a covered entity (or a business associate) and a vendor that creates, receives, maintains or transmits PHI on its behalf. Under HHS’s guidance on business associate contracts, it has to set out what the vendor may do with the PHI, require Security Rule safeguards, require the vendor to report breaches and unauthorised uses, flow the same terms down to the vendor’s subcontractors, and return or destroy the PHI when the contract ends.
What it does not do:
- It doesn’t make your app compliant. The platform promises to protect the PHI it holds. Your access rules, your audit-log reviews, your risk analysis and your staff training are still yours. Microsoft’s own HIPAA page says this in so many words.
- It doesn’t cover features outside its scope. Most BAAs list covered services. AI features, integrations, analytics and support tooling are the usual exclusions.
- It doesn’t cover anything you add. A plugin, a webhook to another service, or an email provider you configure is a separate vendor with its own BAA question.
For the legal distinction in more depth, see our BAA vs HIPAA explainer.
5. The BAA Chain: Every Vendor That Touches PHI
The platform BAA is the first link, not the last. Map every service PHI can reach:
| Layer | Typical vendors | What to check |
|---|---|---|
| App platform | The builder itself | The table above |
| Hosting and database | AWS, Google Cloud, Azure, a managed database | The cloud BAA, and that the specific service is on its eligible list |
| Email and SMS | Notification and messaging providers | Many transactional email and SMS services do not sign; keep PHI out of message bodies regardless |
| Payments | Card processors | Most general processors don’t sign; see our Stripe and HIPAA guide |
| Video | Telehealth video APIs | See our telemedicine guide for which providers sign |
| AI and LLMs | Model APIs, transcription, chat | Usually a separate enterprise agreement; see our HIPAA-compliant AI guide |
| Analytics and error tracking | Product analytics, session replay, logging | The most common silent leak. HHS has warned covered entities about tracking technologies on authenticated pages |
| Automation | Workflow and integration tools | Each one is a vendor holding PHI in transit, and many keep run logs |
This is why the platform that signs the BAA matters less than how many other vendors the finished app depends on. A builder whose features run inside one BAA-covered environment leaves you fewer links to check than one that relies on a plugin marketplace.
6. Why a “HIPAA Compliant” Badge Means Little on Its Own
HHS does not certify software for HIPAA, so there is no official badge. When a vendor says “HIPAA compliant,” it can mean anything from “we sign a BAA and have been audited” to “we use HTTPS.” Three questions cut through it:
- Will you sign a BAA, on which plan, and can I see it before I buy?
- Which of your features and subprocessors does it cover?
- Which independent reports can you share? A SOC 2 Type II report or a HITRUST certification is evidence about the vendor’s controls. It is not a BAA, and a BAA is not evidence of controls; you want both. Our SOC 2 Type II guide explains what to look for in the report.
7. Six Red Flags in a BAA
When a vendor sends its BAA, read these clauses first.
- A narrow list of covered services. If the BAA covers “the database” but your app also uses the vendor’s file storage, email or AI features, those are uncovered.
- Breach notice later than the law allows. HIPAA requires a business associate to notify the covered entity of a breach without unreasonable delay and no later than 60 days after discovery. Many covered entities negotiate far shorter windows, often 5 to 10 business days. A BAA that is vague here, or that only promises notice “as required by law,” leaves you little time for your own notifications.
- No subcontractor flow-down. The vendor must require its own subcontractors that handle PHI to agree to the same restrictions. Ask for the subprocessor list.
- No return or destruction on exit. You need PHI returned or destroyed when the contract ends, and a usable export before then.
- “Customer is responsible” for everything. Some BAAs shift almost every obligation back onto you. Shared responsibility is normal; a document that commits the vendor to nothing specific is not.
- A BAA that only exists on request, with no plan named. “Contact us” is fine; “contact us” with no commitment to which plan or price is a sign the answer may still be no after you have built on the platform.
8. How to Ask a Vendor for a BAA
Ask before you build, in writing, and keep the reply. A short email does it:
Two practical tips. Build your prototype with synthetic data only, so nothing is exposed before the BAA is signed. And check the price of the qualifying plan before you commit, because the jump from a self-serve tier to a BAA tier is often several hundred dollars a month.
9. Where VertiComply Fits
We are a vendor in this table, so here is our position on the same terms as everyone else’s.
- BAA: our terms of service prohibit putting real PHI into VertiComply unless a BAA has been signed, and direct BAA requests to compliance@verticomply.com. Our pricing page lists BAA documentation on paid plans, from Pro at $49 a month.
- What generated apps include: encryption at rest and in transit, audit logging and role-based access are built into the templates, and you can export the code on paid plans.
- Where the PHI should live today: our hosted deployments are currently intended for demos and staging, not production PHI. For production, deploy the exported app to your own cloud account under your cloud provider’s BAA, so the hosting link in the chain is one you control.
If you want help with that last step, our custom build team scopes production deployments. For a broader comparison of features beyond the BAA, see our no-code app builder comparison, our guide to building a HIPAA app without code, and the head-to-head pages for Knack and Caspio. If you are moving a prototype off a tool that doesn’t sign, our vibe-coding HIPAA gap list covers what to fix first.
10. Frequently Asked Questions
Which no-code app builders will sign a HIPAA BAA?
As of October 2026, Blaze, Caspio (HIPAA Edition), Knack (Knack Health plans), DrapCode, Quickbase (Business and Enterprise on annual contracts), Airtable (Enterprise Scale), Google AppSheet and Microsoft Power Apps (under their parent companies’ BAAs), Zoho Creator (on request) and Jotform for forms (Gold and Enterprise) all say they will sign a BAA. Bubble, Glide, Retool Cloud, FlutterFlow and Budibase Cloud do not. Always confirm the plan and price with the vendor before building.
Does Bubble sign a BAA in 2026?
Not yet. Bubble’s own article from 29 July 2026 says Bubble does not currently meet HIPAA standards and that a dedicated Enterprise plan with HIPAA support is targeted for the end of 2026. Until Bubble’s documentation confirms that plan is available, do not store PHI in a Bubble app.
Is Glide HIPAA compliant?
No. Glide’s user data rules prohibit collecting HIPAA-protected health information, such as diagnoses, treatment information, test results or prescriptions created on behalf of a healthcare provider or health plan, and Glide does not offer a BAA.
Is Airtable HIPAA compliant?
Airtable signs a BAA, which it calls a Health Information Exhibit, only for customers on its Enterprise Scale plan, and only after the account team enables HIPAA for the organisation. Team and Business plan customers may not store PHI in Airtable at all.
Do I need a BAA if my app only collects appointment requests?
Usually yes, if the app is built for a covered entity such as a clinic. A name combined with an appointment at a healthcare provider is individually identifiable health information, so it is PHI when a covered entity or its business associate handles it. Apps a consumer uses entirely for themselves, outside any provider relationship, may fall outside HIPAA but can still be subject to the FTC Health Breach Notification Rule and state health-privacy laws.
Is a HIPAA badge or SOC 2 report the same as a BAA?
No. HHS does not certify software, so a “HIPAA compliant” badge is a marketing claim. A SOC 2 or HITRUST report is independent evidence about a vendor’s controls, which is valuable, but HIPAA still requires a signed BAA with any vendor that handles PHI on your behalf.
What is the cheapest way to get a BAA for a no-code app?
If you already pay for Google Workspace or Microsoft 365, AppSheet or Power Apps may be covered under a BAA you can accept at no extra platform cost, priced per user. For forms alone, Jotform Gold is published at $99 a month billed yearly. Among dedicated healthcare app builders with published prices, entry points in October 2026 ranged from about $159 a month (Knack’s forms tier) to $800 a month (Caspio’s HIPAA Edition).
Can I use a platform that won’t sign a BAA if I keep PHI elsewhere?
Only if PHI never passes through it. A front end that calls a separate BAA-covered backend can work, but PHI typed into a form, shown on a page, or written to a workflow or error log on the non-covered platform is PHI that platform handles. If you cannot guarantee that, choose a platform that signs.
Last reviewed 1 October 2026. Each row is based on the vendor’s own pricing, legal or help pages on that date; plans, prices and BAA terms change often, so confirm with the vendor before you rely on them. VertiComply is one of the vendors listed. Nothing here is legal advice.