Is PlanetScale HIPAA compliant?

Managed database · vendor site ↗

Signs a BAAPHI with conditions
Will PlanetScale sign a HIPAA BAA?
Yes — PlanetScale will sign a HIPAA Business Associate Agreement (BAA).
PlanetScale signs a BAA, and as of a 2026-03-25 changelog it is requestable self-serve from the dashboard (Settings → Legal) on any plan via DocuSign. The original 2022 launch limited BAAs to Enterprise, but PlanetScale later opened them to customers on any plan.
PHI eligibility
PHI may be stored/transmitted only after the BAA is executed; PlanetScale operates a shared-responsibility model where the customer must correctly configure and secure their environment.
SOC 2
Not publicly confirmed
Sub-processors
Notes
Self-serve BAA request added 2026-03-25; SOC 2 not confirmed on the HIPAA pages reviewed, so left unstated.
Last verified 2026-05-31confidence: high· Vendor terms change — confirm directly with PlanetScale before storing PHI.

Get notified when this changes

We track PlanetScale's BAA and HIPAA status. Leave your email and we'll send one note if the verdict on this page changes.

One email per change. No newsletter, no selling your address.

How to request and sign a BAA with PlanetScale

Yes — PlanetScale will sign a HIPAA Business Associate Agreement (BAA).

Request routeSelf-serve — enable it in your account
  1. 1
    Confirm your account is covered
    PlanetScale signs a BAA, and as of a 2026-03-25 changelog it is requestable self-serve from the dashboard (Settings → Legal) on any plan via DocuSign. The original 2022 launch limited BAAs to Enterprise, but PlanetScale later opened them to customers on any plan.
  2. 2
    Request the Business Associate Agreement
    PlanetScale lets you obtain the BAA without a sales call. Follow the path named in the plan requirement above — typically an in-product toggle or a billing / compliance settings page — then request and accept the agreement from your own account.
  3. 3
    Confirm what PHI is allowed before you store any
    PHI may be stored/transmitted only after the BAA is executed; PlanetScale operates a shared-responsibility model where the customer must correctly configure and secure their environment. Match your configuration to this scope before putting protected health information into PlanetScale.
Last verified 2026-05-31 · Plan tiers and BAA terms change often — confirm the current process directly with PlanetScale before you rely on it. This is cited public information, not legal advice.

Frequently asked questions

Does PlanetScale sign a HIPAA Business Associate Agreement (BAA)?
Yes — PlanetScale will sign a HIPAA Business Associate Agreement (BAA). PlanetScale signs a BAA, and as of a 2026-03-25 changelog it is requestable self-serve from the dashboard (Settings → Legal) on any plan via DocuSign. The original 2022 launch limited BAAs to Enterprise, but PlanetScale later opened them to customers on any plan.
Is PlanetScale HIPAA compliant?
PlanetScale can be used in a HIPAA-compliant way: it signs a Business Associate Agreement (BAA), which HIPAA requires before you process PHI with a vendor. PHI may be stored/transmitted only after the BAA is executed; PlanetScale operates a shared-responsibility model where the customer must correctly configure and secure their environment.
Can you store PHI (protected health information) in PlanetScale?
PHI may be stored/transmitted only after the BAA is executed; PlanetScale operates a shared-responsibility model where the customer must correctly configure and secure their environment.
Is PlanetScale SOC 2 certified?
We could not confirm a public SOC 2 report for PlanetScale. SOC 2 is separate from a HIPAA BAA — confirm both directly with PlanetScale.
How do I request a HIPAA BAA from PlanetScale?
PlanetScale lets you obtain the BAA without a sales call. Follow the path named in the plan requirement above — typically an in-product toggle or a billing / compliance settings page — then request and accept the agreement from your own account. Confirm current terms directly with PlanetScale before storing PHI.
What plan do I need to sign a BAA with PlanetScale?
PlanetScale signs a BAA, and as of a 2026-03-25 changelog it is requestable self-serve from the dashboard (Settings → Legal) on any plan via DocuSign. The original 2022 launch limited BAAs to Enterprise, but PlanetScale later opened them to customers on any plan.

Sources

https://planetscale.com/blog/planetscale-and-hipaa
Supports: Signs BAA; available to customers on any plan; shared responsibilitydated: 2022-11-18
https://planetscale.com/changelog/request-a-baa
Supports: Self-serve BAA request from the dashboarddated: 2026-03-25
This page is cited public information, not legal or compliance advice. A BAA's availability can depend on your specific plan, region, and contract. Always confirm current terms with PlanetScale before processing protected health information.

Check another vendor