Skip to main content
Platforms & Comparisons
HIPAA
BAA
No-Code
Low-Code
App Builders
Comparison
Vendor Assessment
Healthcare Apps

Which No-Code Platforms Sign a HIPAA BAA? (2026 Table)

By Garvita Amin, Co-Founder & CTO, VertiComply

October 1, 2026

13 min read

Share this article

Which no-code platforms sign a HIPAA business associate agreement in 2026: a table of 18 platforms with BAA status, required plan and published price

If your app will store or process protected health information (PHI) for a covered entity, the platform it runs on has to sign a business associate agreement (BAA) with you. No BAA, no PHI, whatever the marketing page says about encryption. Most “best HIPAA no-code builder” lists are written by one of the builders, and they tend to rank themselves first. This one is also written by a vendor, and we are in the table. To keep it useful anyway, every row links to the vendor’s own pricing, legal or help page, and where we could not confirm something from the vendor itself, the table says so.

1. The Short Answer

As of 1 October 2026, these no-code and low-code platforms say on their own sites that they will sign a HIPAA BAA: Blaze, Caspio (HIPAA Edition), Knack (Knack Health plans), DrapCode, Quickbase (Business and Enterprise, annual contracts), Airtable (Enterprise Scale only), Google AppSheet (under Google’s Workspace or Cloud BAA), Microsoft Power Apps (under Microsoft’s BAA), Zoho Creator (on request), and Jotform for forms (Gold and Enterprise).

These do not sign one today: Bubble, Glide, Retool’s cloud, FlutterFlow and Budibase’s cloud service. Their own terms or documentation say so. Softr and Adalo do not mention HIPAA or a BAA anywhere we could find on their sites, which in practice means you should assume no.

The cheapest published path to a signed BAA is a forms tool (Jotform Gold) or a seat-priced suite you may already pay for (AppSheet, Power Apps). The cheapest dedicated healthcare app builders with published prices start at roughly $160 to $800 a month.

2. The 2026 Table: 18 Platforms

Prices are the vendor’s published starting price for the lowest plan that includes a BAA, in US dollars, checked on 1 October 2026. “Sales-only” means the vendor does not publish a price. Prices and plan names change often, so treat this as a shortlist, not a quote.

PlatformSigns a BAA?Plan you needPublished priceThe catch
BlazeYesProduction or higherFrom $750/moProduction is 1 published app and up to 100 end users; the free Sandbox is for synthetic data only
CaspioYesHIPAA EditionFrom $800/mo, 1-year termCaspio’s pages describe HIPAA both as a separate edition and as a $500/mo add-on to a standard plan; confirm the total with sales
KnackYesKnack Health: HIPAA Forms, Starter or CoreForms from $159/mo; Starter from $499/mo; Core sales-onlyForms is a forms product; full apps start at Starter. Knack’s own blog quotes different figures in places
DrapCodeYesScale or EnterpriseScale $650/moAlso sells built-for-you apps from $10,000 per project; plan names on its pricing page are inconsistent
QuickbaseYesBusiness or Enterprise, annual or multi-yearBusiness from $55/user/mo, plus an unpublished platform minimumMonthly contracts don’t qualify. Also documents FDA Part 11 use cases
AirtableYesEnterprise Scale onlySales-onlyNo PHI on Team or Business plans at all. Third-party integrations and outside AI services need their own assessment
Google AppSheetYes, under Google’s BAAA Google Workspace or Cloud account with the BAA accepted; edition not stated$5 to $20/user/moPHI must be marked as sensitive data and kept out of app definitions and support tickets; ask sales which edition you need
Microsoft Power AppsYes, under Microsoft’s BAAAny in-scope commercial Power Apps licensePremium $20/user/mo, paid yearlyThe BAA is included by default through Microsoft’s Data Protection Addendum, but only for Microsoft’s in-scope services, not third-party connectors
Zoho CreatorYes, on requestNot publishedNot published for HIPAARequest Zoho’s BAA template from its legal team; the BAA lists which Zoho services it covers
Jotform (forms)YesGold or EnterpriseGold $129/mo, or $99/mo billed yearlyA form builder, not an app builder. Signed in a self-serve wizard after upgrading
BubbleNo——Bubble says it does not meet HIPAA standards today; a dedicated Enterprise plan is “targeted for by the end of 2026”
GlideNo——Glide’s data rules prohibit HIPAA-covered PHI on the platform
Retool (cloud)No——Its subscription agreement says Retool is not a business associate and PHI must not go to Retool Cloud. Teams that need PHI self-host it
FlutterFlowNo——Its terms say the service is not intended for HIPAA-protected health information. The backend you connect needs its own BAA
Budibase (cloud)No——Its terms say the subscription service is not designed to comply with HIPAA
SoftrNone published——Its security page does not mention HIPAA or a BAA. Ask sales in writing before assuming either way
AdaloNone published——We found no HIPAA or BAA statement from Adalo itself, only community-forum answers saying no
VertiComplyOn requestPaid plansPro $49/moOur terms require a signed BAA before any PHI enters the platform. Hosted demo deployments are not for PHI yet; see section 9

3. How to Read the Table

Three patterns stand out.

  • A BAA is usually a plan feature, not a platform feature. Airtable, Quickbase, Jotform and most of the healthcare builders sign only on specific plans, and often only on annual contracts. A free trial on the right plan is still not covered until the BAA is signed.
  • The big suites are cheaper than they look, and harder than they look. If your organisation already pays for Google Workspace or Microsoft 365, AppSheet or Power Apps may be covered by a BAA you have already accepted. The work moves to configuration: keeping PHI inside the covered services, and out of every connector, add-on and AI feature that is not on the vendor’s in-scope list.
  • “No” usually means the terms forbid PHI outright. Glide, Retool Cloud, FlutterFlow and Budibase do not just decline to sign; their terms tell you not to put PHI there. Using them for PHI anyway is a breach of contract as well as a HIPAA problem.
What about Bubble? Bubble’s own HIPAA article (29 July 2026) says plainly that apps built on Bubble cannot be HIPAA compliant today and that it does not sign a BAA, with a dedicated Enterprise plan targeted for the end of 2026. Until that plan exists and Bubble’s documentation says so, keep PHI out of Bubble. A common workaround is a Bubble front end with no PHI that calls a separate backend under its own BAA, but every place PHI could pass through Bubble (forms, workflows, logs) breaks that design.

4. What a BAA Covers, and What It Doesn’t

A BAA is the contract HIPAA requires between a covered entity (or a business associate) and a vendor that creates, receives, maintains or transmits PHI on its behalf. Under HHS’s guidance on business associate contracts, it has to set out what the vendor may do with the PHI, require Security Rule safeguards, require the vendor to report breaches and unauthorised uses, flow the same terms down to the vendor’s subcontractors, and return or destroy the PHI when the contract ends.

What it does not do:

  • It doesn’t make your app compliant. The platform promises to protect the PHI it holds. Your access rules, your audit-log reviews, your risk analysis and your staff training are still yours. Microsoft’s own HIPAA page says this in so many words.
  • It doesn’t cover features outside its scope. Most BAAs list covered services. AI features, integrations, analytics and support tooling are the usual exclusions.
  • It doesn’t cover anything you add. A plugin, a webhook to another service, or an email provider you configure is a separate vendor with its own BAA question.

For the legal distinction in more depth, see our BAA vs HIPAA explainer.

5. The BAA Chain: Every Vendor That Touches PHI

The platform BAA is the first link, not the last. Map every service PHI can reach:

LayerTypical vendorsWhat to check
App platformThe builder itselfThe table above
Hosting and databaseAWS, Google Cloud, Azure, a managed databaseThe cloud BAA, and that the specific service is on its eligible list
Email and SMSNotification and messaging providersMany transactional email and SMS services do not sign; keep PHI out of message bodies regardless
PaymentsCard processorsMost general processors don’t sign; see our Stripe and HIPAA guide
VideoTelehealth video APIsSee our telemedicine guide for which providers sign
AI and LLMsModel APIs, transcription, chatUsually a separate enterprise agreement; see our HIPAA-compliant AI guide
Analytics and error trackingProduct analytics, session replay, loggingThe most common silent leak. HHS has warned covered entities about tracking technologies on authenticated pages
AutomationWorkflow and integration toolsEach one is a vendor holding PHI in transit, and many keep run logs

This is why the platform that signs the BAA matters less than how many other vendors the finished app depends on. A builder whose features run inside one BAA-covered environment leaves you fewer links to check than one that relies on a plugin marketplace.

6. Why a “HIPAA Compliant” Badge Means Little on Its Own

HHS does not certify software for HIPAA, so there is no official badge. When a vendor says “HIPAA compliant,” it can mean anything from “we sign a BAA and have been audited” to “we use HTTPS.” Three questions cut through it:

  1. Will you sign a BAA, on which plan, and can I see it before I buy?
  2. Which of your features and subprocessors does it cover?
  3. Which independent reports can you share? A SOC 2 Type II report or a HITRUST certification is evidence about the vendor’s controls. It is not a BAA, and a BAA is not evidence of controls; you want both. Our SOC 2 Type II guide explains what to look for in the report.

7. Six Red Flags in a BAA

When a vendor sends its BAA, read these clauses first.

  1. A narrow list of covered services. If the BAA covers “the database” but your app also uses the vendor’s file storage, email or AI features, those are uncovered.
  2. Breach notice later than the law allows. HIPAA requires a business associate to notify the covered entity of a breach without unreasonable delay and no later than 60 days after discovery. Many covered entities negotiate far shorter windows, often 5 to 10 business days. A BAA that is vague here, or that only promises notice “as required by law,” leaves you little time for your own notifications.
  3. No subcontractor flow-down. The vendor must require its own subcontractors that handle PHI to agree to the same restrictions. Ask for the subprocessor list.
  4. No return or destruction on exit. You need PHI returned or destroyed when the contract ends, and a usable export before then.
  5. “Customer is responsible” for everything. Some BAAs shift almost every obligation back onto you. Shared responsibility is normal; a document that commits the vendor to nothing specific is not.
  6. A BAA that only exists on request, with no plan named. “Contact us” is fine; “contact us” with no commitment to which plan or price is a sign the answer may still be no after you have built on the platform.

8. How to Ask a Vendor for a BAA

Ask before you build, in writing, and keep the reply. A short email does it:

A request you can copy We are a [covered entity / business associate] building an application that will store [describe the PHI, e.g. patient intake forms and appointment history]. Please confirm: (1) whether you will sign a BAA, (2) which plan and contract term is required and its price, (3) which of your features and subprocessors the BAA covers, and in particular whether it covers [file storage / email / AI features you plan to use], and (4) your breach-notification timeline. Please send your standard BAA for review.

Two practical tips. Build your prototype with synthetic data only, so nothing is exposed before the BAA is signed. And check the price of the qualifying plan before you commit, because the jump from a self-serve tier to a BAA tier is often several hundred dollars a month.

9. Where VertiComply Fits

We are a vendor in this table, so here is our position on the same terms as everyone else’s.

  • BAA: our terms of service prohibit putting real PHI into VertiComply unless a BAA has been signed, and direct BAA requests to compliance@verticomply.com. Our pricing page lists BAA documentation on paid plans, from Pro at $49 a month.
  • What generated apps include: encryption at rest and in transit, audit logging and role-based access are built into the templates, and you can export the code on paid plans.
  • Where the PHI should live today: our hosted deployments are currently intended for demos and staging, not production PHI. For production, deploy the exported app to your own cloud account under your cloud provider’s BAA, so the hosting link in the chain is one you control.

If you want help with that last step, our custom build team scopes production deployments. For a broader comparison of features beyond the BAA, see our no-code app builder comparison, our guide to building a HIPAA app without code, and the head-to-head pages for Knack and Caspio. If you are moving a prototype off a tool that doesn’t sign, our vibe-coding HIPAA gap list covers what to fix first.

10. Frequently Asked Questions

Which no-code app builders will sign a HIPAA BAA?

As of October 2026, Blaze, Caspio (HIPAA Edition), Knack (Knack Health plans), DrapCode, Quickbase (Business and Enterprise on annual contracts), Airtable (Enterprise Scale), Google AppSheet and Microsoft Power Apps (under their parent companies’ BAAs), Zoho Creator (on request) and Jotform for forms (Gold and Enterprise) all say they will sign a BAA. Bubble, Glide, Retool Cloud, FlutterFlow and Budibase Cloud do not. Always confirm the plan and price with the vendor before building.

Does Bubble sign a BAA in 2026?

Not yet. Bubble’s own article from 29 July 2026 says Bubble does not currently meet HIPAA standards and that a dedicated Enterprise plan with HIPAA support is targeted for the end of 2026. Until Bubble’s documentation confirms that plan is available, do not store PHI in a Bubble app.

Is Glide HIPAA compliant?

No. Glide’s user data rules prohibit collecting HIPAA-protected health information, such as diagnoses, treatment information, test results or prescriptions created on behalf of a healthcare provider or health plan, and Glide does not offer a BAA.

Is Airtable HIPAA compliant?

Airtable signs a BAA, which it calls a Health Information Exhibit, only for customers on its Enterprise Scale plan, and only after the account team enables HIPAA for the organisation. Team and Business plan customers may not store PHI in Airtable at all.

Do I need a BAA if my app only collects appointment requests?

Usually yes, if the app is built for a covered entity such as a clinic. A name combined with an appointment at a healthcare provider is individually identifiable health information, so it is PHI when a covered entity or its business associate handles it. Apps a consumer uses entirely for themselves, outside any provider relationship, may fall outside HIPAA but can still be subject to the FTC Health Breach Notification Rule and state health-privacy laws.

Is a HIPAA badge or SOC 2 report the same as a BAA?

No. HHS does not certify software, so a “HIPAA compliant” badge is a marketing claim. A SOC 2 or HITRUST report is independent evidence about a vendor’s controls, which is valuable, but HIPAA still requires a signed BAA with any vendor that handles PHI on your behalf.

What is the cheapest way to get a BAA for a no-code app?

If you already pay for Google Workspace or Microsoft 365, AppSheet or Power Apps may be covered under a BAA you can accept at no extra platform cost, priced per user. For forms alone, Jotform Gold is published at $99 a month billed yearly. Among dedicated healthcare app builders with published prices, entry points in October 2026 ranged from about $159 a month (Knack’s forms tier) to $800 a month (Caspio’s HIPAA Edition).

Can I use a platform that won’t sign a BAA if I keep PHI elsewhere?

Only if PHI never passes through it. A front end that calls a separate BAA-covered backend can work, but PHI typed into a form, shown on a page, or written to a workflow or error log on the non-covered platform is PHI that platform handles. If you cannot guarantee that, choose a platform that signs.

Last reviewed 1 October 2026. Each row is based on the vendor’s own pricing, legal or help pages on that date; plans, prices and BAA terms change often, so confirm with the vendor before you rely on them. VertiComply is one of the vendors listed. Nothing here is legal advice.


Share this article:

Build Compliant Healthcare Apps in Minutes

VertiComply generates production-ready code with HIPAA, GDPR, and SOC 2 compliance built in.

Related Articles

Continue reading about healthcare compliance and development

Vibe-Coding
14 min read
Vibe-Coded a Healthcare App? The HIPAA Gap List (2026)

Vibe-coded healthcare apps from Cursor, Lovable, Bolt, v0, Replit, or Base44 ship 7 HIPAA gaps by default — no BAA, plaintext PHI, no audit log, weak access controls. The triage list + the fix for each.

Read article

No-Code
12 min read
Best No-Code App Builders (2026): Free & Paid, Compared

Tested 11 no-code AI app builders for HIPAA compliance in 2026 — Blaze.tech, Bubble, FlutterFlow, VertiComply. Free BAA options, mobile vs web, verdict.

Read article

Comparison
12 min read
5 Best Blaze.tech Alternatives for HIPAA-Compliant Apps in 2026

The 5 no-code platforms that actually handle PHI: BAA terms, healthcare templates, encryption, and where each beats Blaze.tech for medical apps.

Read article

© 2026 VertiComply. All rights reserved.