Cloudflare is a connectivity cloud platform that provides services for application security, performance, content delivery, web application firewalls, bot management, DNS, developer infrastructure, and Zero Trust access.

With Cloudflare, organizations can protect websites, applications, application programming interfaces, networks, and internal systems using Cloudflare’s global network.

Is Cloudflare HIPAA compliant? Yes, based on our research, Cloudflare is HIPAA compliant, but only for Enterprise customers with a signed business associate agreement (BAA).

 

What changed this year?

As of June 2026, our review did not identify any publicly disclosed changes to Cloudflare HIPAA-related policies or BAA terms.

Cloudflare continues to state that it will only enter into business associate agreements with Enterprise customers. Its public HIPAA materials also continue to describe HIPAA coverage as dependent on the specific Cloudflare services purchased and the applicable agreement.

 

Will Cloudflare sign a BAA?

Yes, Cloudflare will sign a BAA for Enterprise customers. Cloudflare’s US privacy law compliance page states that Cloudflare “will only enter into business associate agreements (BAAs) with its enterprise customers.”

Cloudflare’s Enterprise Subscription Agreement also references “any Business Associate Agreement between the parties (if applicable)” in its order-of-precedence language.

Cloudflare does not appear to publish a full standalone BAA for general self-service review. Healthcare organizations should contact Cloudflare sales or their account executive to confirm BAA availability, covered services, minimum spend requirements, and contract scope.

 

What does the Cloudflare BAA cover?

Cloudflare’s public HIPAA whitepaper states that its BAA incorporates HIPAA required clauses so organizations transmitting PHI can use Cloudflare security services while meeting their compliance requirements.

Cloudflare describes examples of services that may be in scope, saying services “in scope of HIPAA include CDN, WAF, and Bot Management.”

 

What does the Cloudflare BAA exclude?

Its public materials state that the BAA is available only for Enterprise-level customers, and Cloudflare’s current Trust Hub language says Cloudflare only enters BAAs with Enterprise customers.

Cloudflare also identifies some services that may fall outside HIPAA scope when purchased alone. Its HIPAA whitepaper says services “outside of scope if purchased alone” may include Magic Transit and DNS.

It means Cloudflare should not be treated as HIPAA compliant for all plans, all products, or all configurations. A self-serve Cloudflare deployment, or a Cloudflare service used without a signed BAA, should not be used to create, receive, maintain, or transmit PHI on behalf of a HIPAA covered entity or business associate.

 

Conclusion

Cloudflare is HIPAA compliant, but only for Enterprise customers that have signed a BAA and only for the services and configurations covered by that agreement.

Cloudflare should not be treated as HIPAA compliant for self-service plans, standalone services outside the BAA scope, or any use involving PHI without a signed BAA.

Learn more: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is a BAA?

A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.

 

What is HIPAA?

HIPAA sets national standards for protecting the privacy and security of certain health information.

HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.