Skip to content
    HIPAA & Compliance 7 min 2026-08-28

    Is Zapier HIPAA compliant? (And Make, and n8n)

    Whether the big automation tools can touch PHI, what a BAA actually requires of your tier, and the self-hosting question n8n actually raises — answered per tool, honestly.

    Practices ask this the week the front office discovers workflow automation: can Zapier — or Make, or n8n — touch patient data? The per-tool answers below are short, and two of them are hard nos. But start with the reframe that makes the answers make sense: "is this tool HIPAA compliant" is the wrong question. The right one is: will this vendor sign a BAA, does your tier qualify, and can your deployment around it — data paths, logging, retention — survive an audit? That's the standard our HIPAA-compliant AI guide lays out, and it applies to automation platforms exactly as it does to AI chatbots.

    Zapier: no — and Zapier says so itself

    This one isn't a judgment call. Zapier's own data-privacy page states that regulated healthcare and medical data, including PHI under HIPAA, isn't supported on Zapier — and that Zapier can't sign business associate agreements for handling PHI. Zapier's own blog answers the title question with a flat no. That closes the matter: no BAA means no PHI, at any plan level, with any encryption settings. Zapier remains perfectly usable in a practice for workflows that never touch patient data — marketing, recruiting, vendor invoices — but the PHI line has to be drawn in policy, because the platform won't draw it for you.

    Make: no published HIPAA program — treat as unavailable

    Make's trust materials list ISO 27001 certification and a SOC 2 Type II audit — real security credentials, but neither is HIPAA. Make publishes no HIPAA program and no standard BAA offering, and its team has described HIPAA as something it's evaluating based on customer demand. Security certifications and HIPAA eligibility are different things: SOC 2 tells you the vendor runs a disciplined security operation; only a signed BAA creates the business associate relationship HIPAA requires. Until Make offers one in writing, the practical answer for PHI is the same as Zapier's: no.

    n8n: self-hosting changes the question, not the answer

    n8n is the interesting case because you can run it on your own infrastructure. Self-hosting genuinely changes the structure: n8n's own documentation notes that for self-hosted instances, n8n the company is neither controller nor processor of your data — the platform vendor largely exits the picture. What it doesn't do is discharge the compliance burden. It transfers all of it to you. n8n's security documentation is explicit that self-hosters are responsible for encrypting data in transit (via a reverse proxy handling TLS) and at rest; add to that the BAA with your cloud provider, access controls, audit logging, execution-data retention (n8n workflows store execution data, which will contain PHI if PHI flows through them), patching, and breach procedures. Self-hosted n8n can sit inside a HIPAA-compliant deployment — but only inside one your team builds and maintains deliberately. "We self-host, so we're fine" is how execution logs full of PHI end up on an unencrypted disk.

    The pattern, and the honest trade

    Notice what the three answers have in common: the compliance never lives in the tool. Zapier and Make fail at the BAA step; n8n passes the vendor question by handing you the entire checklist. The same trade shows up wherever healthcare automation gets built — the managed version of it is precisely what we do with Hosted Private AI: private infrastructure with the checklist — encryption, scoped access, audit logging, retention — built and documented as part of the deployment, rather than left as your homework.

    So what can a practice automate?

    Plenty — on either side of the PHI line. PHI-free workflows can run on ordinary automation tools under a written policy that names them. PHI workflows — insurance verification is the canonical one, with payer data and patient details in every transaction — belong on deployments built for the checklist from day one. If you're mapping which of your workflows fall on which side, that's the first thing an assessment sorts out.

    Frequently asked questions

    Brian Kelly

    Founder, Automated Edge

    Brian has spent twenty-plus years operating Managed Service Provider and Managed Security Service Provider environments for SMBs. Automated Edge applies that operational discipline to AI — assess, build, operate.

    Talk to a MAISP, not a consultant.

    Thirty minutes with the engineers who'll build and operate your AI — not the SDR queue. We listen, then we tell you the truth about whether AI fits.

    Book a Strategy Call

    Free · 30 min · no pitch