HIPAA-Compliant Infrastructure & Cloud Vendors

Infrastructure & Cloud vendors are evaluated against HIPAA when they handle the workflows this framework governs. Currently, 11 vendors in our Infrastructure & Cloud category hold HIPAA certification and 12 hold it partially or conditionally. Each listing below links to the vendor's full compliance profile.

Infrastructure & Cloud vendors that hold HIPAA certification

Google Cloud Platform logo

Google Cloud Platform

23/32

Google's suite of cloud computing services running on the same infrastructure Google uses for its products.

HIPAA is a regulation. Google Cloud offers BAA and HIPAA-eligible services.

Microsoft Azure logo

Microsoft Azure

23/32

Microsoft's cloud computing platform for building, deploying, and managing applications and services.

HIPAA is a regulation. Azure offers BAA via Microsoft Product Terms and HIPAA/HITRUST built-in policy initiative.

Amazon Web Services logo

Amazon Web Services

21/32

On-demand cloud computing platforms (IaaS/PaaS) offering compute, storage, and managed services.

HIPAA is a regulation. AWS offers standardized BAA and HIPAA-eligible services.

Cloudflare logo

Cloudflare

20/32

Global CDN, DDoS mitigation, DNS, Zero Trust, and edge computing services delivered over Cloudflare's network.

HIPAA/HITECH: Cloudflare can sign BAAs for enterprise customers using its security products.

Vultr logo

Vultr

12/32

Cloud infrastructure provider (VPS, bare metal, GPU compute) for developers.

Redis Cloud logo

Redis Cloud

12/32

Fully managed in-memory database and caching service.

Vercel logo

Vercel

10/32

Frontend cloud platform for deploying and scaling web applications, built on AWS infrastructure.

HIPAA compliance as Business Associate. annual audit completed and BAAs signed with eligible customers.

DigitalOcean logo

DigitalOcean

10/32

Cloud infrastructure provider offering compute, storage, and networking services for developers and startups.

HIPAA eligibility documented (BAA available for eligible workloads), digitalocean.com/trust and digitalocean.com/trust/certification-reports, checked 2026-09-06

Veeam logo

Veeam

10/32

Data backup, recovery, and cyber resilience software.

Netlify logo

Netlify

9/32

Web development platform for building, deploying, and scaling modern websites and applications.

HIPAA compliance via enterprise service offering with executed BAA, netlify.com/security/ and trust-center.netlify-corp.com (SafeBase), checked 2026-09-06

Rubrik logo

Rubrik

9/32

Data security and cyber resilience platform (backup, ransomware recovery).

Elasticsearch logo

Elasticsearch

8/32

Search and analytics engine, offered as Elastic Cloud.

Druva logo

Druva

8/32

SaaS-based data resiliency and backup platform.

Firebase logo

Firebase

7/32

Google's app development platform (backend, database, hosting, analytics).

BAA available for a subset of Firebase services under Google Cloud

Acronis logo

Acronis

6/32

Cyber protection platform combining backup, disaster recovery, and security.

Wasabi logo

Wasabi

6/32

Cloud object storage service.

Fastly logo

Fastly

5/32

Edge cloud platform for CDN, security, and edge compute.

Audited against Security and Privacy Rules

Backblaze logo

Backblaze

5/32

Cloud storage and backup service (B2 Cloud Storage, Computer Backup).

PlanetScale logo

PlanetScale

4/32

Managed MySQL-compatible serverless database platform.

Render logo

Render

4/32

Cloud application hosting platform (PaaS).

HIPAA-enabled workspaces available for handling US health data

Railway logo

Railway

3/32

Cloud application deployment platform (PaaS).

HIPAA BAA available as an add-on under a shared-responsibility model

Carbonite logo

Carbonite

2/32

Cloud backup and data protection software, part of OpenText.

BAA available with Carbonite Safe Pro subscription

Fly.io logo

Fly.io

2/32

Application hosting platform for deploying apps close to users globally.

Pre-signed BAA available for HIPAA apps

These infrastructure & cloud vendors do not currently hold HIPAA certification:

Know a vendor we're missing?

Data sourced from public trust centers. Not legal or compliance advice.

Logos and trademarks are property of their respective owners. Use does not imply endorsement, affiliation, or sponsorship.

© Compliance Posture 2026