Windsurf · Windsurf Security & Data Handling · View original document ↗

HIPAA Compliance and Business Associate Agreement Availability

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Windsurf Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Windsurf states its platform is HIPAA compliant and will provide a Business Associate Agreement for larger healthcare implementations, but notes that most code submitted to the platform is not considered protected health information.

This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Healthcare organizations using Windsurf should be aware that a BAA is described as available for 'significant implementations' rather than as a standard offering, meaning smaller healthcare customers may need to specifically request and negotiate one.

Interpretive note: The document does not define what constitutes a 'significant implementation' that would qualify for a BAA, leaving smaller healthcare customers uncertain about their eligibility or whether they must proactively request one.

Consumer impact (what this means for users)

This provision states that Windsurf maintains HIPAA compliance and will provide a BAA for significant healthcare implementations. Healthcare organizations should assess whether their use of Windsurf constitutes a significant implementation requiring a BAA and should proactively request one rather than assuming it is automatically in place.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Contact Windsurf at security@windsurf.com to request a Business Associate Agreement before deploying the platform in a healthcare context where PHI may be involved.

How other platforms handle this

Hugging Face Medium

While the categories of Restricted Content above provide a clear framework, we may also moderate other types of Content in response to evolving challenges posed by advancements in Machine Learning. As we assess such Content, we hold consent as a core value, ensuring our approach remains thoughtful, ...

Mistral AI Medium

Mistral AI may monitor use of the Mistral AI Products through automated means in accordance with the Usage Policy. This monitoring is conducted to ensure compliance with Mistral AI's terms and policies, and to maintain the security and integrity of Mistral AI Products. We reserve the right to review...

Neon Medium

This Neon Platform Services Product Specific Schedule ("Product Specific Schedule") is entered into as of the Effective Date between Neon, LLC ("Neon" or "we"), an affiliate of Databricks, Inc. ("Databricks"), and Customer (as defined below) ("Customer", "you," or "your") and governs Customer's use ...

See all platforms with this clause type →

Monitoring

Windsurf has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
HIPAA compliance: In most cases, the data that a customer provides to us is not Personal Health Information (PHI) and does not need special compliance considerations in order to use our platform, even if you are a healthcare organization. This is particularly true for code, which does not carry any PHI itself. That said, our platform is maintained as HIPAA compliant and for significant implementations, we will entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance.

— Excerpt from Windsurf's Windsurf Security & Data Handling

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly implicates HIPAA and its implementing regulations, including the Privacy Rule and Security Rule. HHS OCR is the primary enforcement authority. The document's statement that the platform is 'maintained as HIPAA compliant' is an assertion rather than a certification; covered entities and their legal teams should verify the scope and currency of this compliance posture. The availability of a BAA is a material HIPAA requirement where Windsurf functions as a business associate. (2) GOVERNANCE EXPOSURE: Medium. The document does not specify what constitutes a 'significant implementation' that would trigger BAA availability, nor does it indicate whether smaller healthcare customers can obtain a BAA on request. This ambiguity creates a potential gap for healthcare organizations that may require a BAA under HIPAA but do not meet an undefined significance threshold. (3) JURISDICTION FLAGS: All US-based covered entities and business associates under HIPAA face exposure if a BAA is not in place and Windsurf processes or has access to PHI. The document's assertion that code generally does not carry PHI may not hold in all implementation scenarios, particularly where developers work on healthcare applications that include PHI in code comments, variable names, or test data. (4) CONTRACT AND VENDOR IMPLICATIONS: Healthcare organizations should request a BAA before deployment and confirm that its scope covers all relevant use cases. Procurement teams should not rely on the document's general assertion that code does not carry PHI as a substitute for a PHI risk assessment specific to their implementation. The document does not specify the timeline or process for obtaining a BAA, which should be established during vendor onboarding. (5) COMPLIANCE CONSIDERATIONS: Legal and compliance teams at healthcare organizations should conduct a PHI risk assessment for their specific Windsurf use case, including whether any code, comments, or test data processed through the platform could contain PHI. Where a BAA is required, organizations should initiate that process before production use of the platform. HHS OCR guidance on business associate relationships should be reviewed in conjunction with this provision.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • Hhs Ocr
    HHS OCR enforces HIPAA requirements including the obligation for covered entities to have Business Associate Agreements in place with vendors who may access protected health information.
    File a complaint →

Applicable regulations

California AB 2013 AI Training Data Transparency
US-CA

Provision details

Document information
Document
Windsurf Security & Data Handling
Entity
Windsurf
Document last updated
May 11, 2026
Tracking information
First tracked
May 11, 2026
Last verified
May 12, 2026
Record ID
CA-P-010668
Document ID
CA-D-00783
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
712fafa072f4ddaa82cb418bf6718dcc9783559af0681efa6fe16d44b530e852
Analysis generated
May 11, 2026 12:52 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Windsurf
Document: Windsurf Security & Data Handling
Record ID: CA-P-010668
Captured: 2026-05-11 12:52:11 UTC
SHA-256: 712fafa072f4ddaa…
URL: https://conductatlas.com/platform/windsurf/windsurf-security-data-handling/hipaa-compliance-and-business-associate-agreement-availability/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Windsurf's HIPAA Compliance and Business Associate Agreement Availability clause do?

Healthcare organizations using Windsurf should be aware that a BAA is described as available for 'significant implementations' rather than as a standard offering, meaning smaller healthcare customers may need to specifically request and negotiate one.

How does this clause affect you?

This provision states that Windsurf maintains HIPAA compliance and will provide a BAA for significant healthcare implementations. Healthcare organizations should assess whether their use of Windsurf constitutes a significant implementation requiring a BAA and should proactively request one rather than assuming it is automatically in place.

Is ConductAtlas affiliated with Windsurf?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.