Last updated: September 2026
HIPAA Guidelines for Customers
Purpose
This page explains how HIPAA applies when you use the Platform to build or run applications that may involve Protected Health Information (PHI). It describes what our platform covers under our Business Associate Agreement (BAA), what it doesn't, and what you're responsible for as a Covered Entity or Business Associate under HIPAA.
This is a shared responsibility model: we secure the underlying infrastructure and services we control, but because you can build custom apps and connect your own integrations, you control how PHI flows through what you build.
Who This Applies To
These guidelines apply to any customer who has signed a BAA with us, and builds, configures, or uses an app on our platform that creates, receives, stores, or transmits PHI. If you haven't signed a BAA with us, you may not use our platform to handle PHI in any capacity.
What's Covered Under Our BAA
The following platform components are covered when used as intended and within a HIPAA-enabled workspace:
Core hosting infrastructure – our managed servers, containers, and networking for apps you build or deploy through the platform
Primary database and storage services we provide natively (e.g., our built-in database, file storage) when PHI is stored in designated, encrypted data stores
Authentication and access control features built into the platform
Audit logging of platform-level access to your workspace and data
Pre-built apps that we have officially designated in writing as HIPAA-compliant, and only when used according to their documented configuration. An app is not covered simply because it is available on the platform. Coverage applies only to the specific apps we have expressly identified as HIPAA-compliant
Data encryption in transit and at rest for the services listed above
What's NOT Covered
The following are out of scope for our BAA:
All third-party integrations or APIs you connect or enable yourself (payment processors, email/SMS providers, analytics tools, external AI/ML services, etc.). This includes integrations that are available, listed, or offered directly within the platform. Simply because an integration is accessible or pre-configured within the platform does not mean it is covered; it is out of scope unless we've separately confirmed in writing that it is covered.
Public or shareable app links/demo environments – these are not intended for PHI and are not covered
Any pre-built app not explicitly designated as HIPAA-eligible
Free-tier, sandbox, staging, trial environments, or any plan other than our Enterprise plan. HIPAA coverage under our BAA is only available to customers on an active Enterprise plan; no other plan tier includes HIPAA-covered infrastructure, regardless of the features or environments used.
Custom code you write yourself that transmits data outside our infrastructure (e.g., calling an uncovered external API, writing to an unapproved third-party database)
Any field, table, or component you've configured to store PHI outside of our designated secure storage – for example: custom database tables or fields you create outside the designated HIPAA-covered data store, environment variables or config files used to pass PHI between components, local/browser storage or client-side caching within an app you build, spreadsheet or CSV exports generated by your app, log fields or debug outputs that capture user-submitted data, and file uploads directed to a non-designated storage bucket or third-party file service.
If you're not sure whether something is covered, don't put PHI there, ask us first.
Your Responsibilities as a Customer
As a HIPAA customer, you agree to:
1.Only store or process PHI within HIPAA-enabled workspaces and designated covered features listed above.
2.Vet and obtain your own BAAs for any third-party service, plugin, or API you connect to your app if that service will touch PHI.
3.Configure access controls appropriately – apply role-based access, strong authentication, and least-privilege principles to any app you build.
4.Not use public sharing, demo links, or non-production environments for apps that handle PHI.
5.Train your workforce on proper handling of PHI within apps they build or use on the platform.
6.Report any suspected security incident or breach involving PHI on our platform to us within the timeframe specified in your BAA.
7.Review app configurations before going live to confirm PHI only flows through covered components.
8.Maintain your own HIPAA compliance program (risk assessments, policies, workforce training) independent of our platform-level safeguards.
Our Responsibilities as a Business Associate
We will:
1.Maintain administrative, physical, and technical safeguards for the covered services listed above
2.Encrypt PHI in transit and at rest within covered services
3.Maintain audit logs of platform-level access
4.Notify you of any breach of unsecured PHI within our covered services, per the terms of your BAA
5.Maintain and disclose our list of subprocessors that may handle PHI
6.Not use or disclose PHI in covered services other than as permitted by your BAA or required by law
Questions
If you're unsure whether a feature, integration, or workflow is covered, before you build with PHI contact privacy@blocks.diy to confirm.