Short answer: No BI tool is HIPAA certified, because HHS certifies nothing. The question that matters is whether the vendor will sign a Business Associate Agreement, and under what conditions. As of September 2026: Microsoft covers Power BI under its standard BAA; Google covers Looker and Looker Studio under its Cloud BAA, but not Looker Studio Pro; Salesforce covers Tableau Cloud but excludes Tableau Server and Tableau Bridge; Domo, Qlik Cloud, Sisense, and Zoho Analytics sign BAAs, with conditions; Metabase, Klipfolio, Databox, and Geckoboard publish no BAA. DashboardFox signs a BAA on Enterprise Dedicated Cloud. Details, exclusions, and how to verify each are below.
What "HIPAA compliant" can and cannot mean for a BI tool
HIPAA regulates covered entities and their business associates. When a BI vendor can access protected health information in the course of providing its service, by querying it, caching it, displaying it, or logging report activity, the vendor is a business associate, and the covered entity may use it only under a written Business Associate Agreement. That agreement makes the vendor directly liable for its own HIPAA failures, which is why vendors are careful about when they sign one.
So a vendor's HIPAA position comes down to three facts: whether it signs a BAA at all, which products and plans the BAA covers, and what the BAA excludes. Marketing pages rarely state all three. The comparison below does, with the source for each, so you can verify before you rely on it.
BAA availability by vendor
Checked against each vendor's own legal, trust, or compliance pages in September 2026. Where a vendor publishes nothing, that is stated rather than guessed. Vendors change these terms, so confirm in writing before PHI is provisioned.
| Tool | Signs a BAA? | Conditions and coverage | Notable exclusions | Self-hosted option |
|---|---|---|---|---|
| Microsoft Power BI | Yes | Included by default in the Microsoft Online Services Data Protection Addendum for customers that are covered entities or business associates. No separate signature required. | Covers in-scope services only; preview features and some connectors may fall outside scope | Power BI Report Server (Windows only; licensed via SQL Server 2025 or Fabric F64+ reserved capacity) |
| Google Looker | Yes | Google Cloud BAA covers Looker hosted deployments. Request through your account manager. | Third-party services, insecure API integrations, and any feature not generally available, including previews | Customer-managed deployment |
| Google Looker Studio | Yes, with a catch | Covered under the Google Cloud Platform BAA. The older standalone Looker Studio BAA is no longer offered to new customers. | Looker Studio Pro is expressly excluded from the covered services | None |
| Tableau (Salesforce) | Yes, Tableau Cloud only | Salesforce Business Associate Addendum, arranged through your account representative. Tableau Cloud must be named as a covered service. | Tableau Server, Tableau Bridge, and Tableau Data Connect are excluded. Tableau Public terms prohibit PHI outright. | Tableau Server, but it is outside the BAA; you carry the compliance burden |
| Domo | Yes | Signs BAAs for customers that require them; lists HIPAA alongside SOC 2, HITRUST, and ISO 27001. Public documentation does not state which subscription tiers qualify. | Public embed is not available on HIPAA-configured instances; some AI configurations route requests to external providers | None, cloud only |
| Qlik Cloud | Yes, with conditions | Customers may host PHI when using Customer Managed Keys, and must execute a BAA with Qlik. Qlik Cloud holds a SOC 2 Type 2 + HITRUST attestation. | Qlik Sense Business does not support Customer Managed Keys, so it cannot hold PHI | Qlik Sense Enterprise on Windows |
| Sisense | Yes | Signs a BAA; SOC 2. | Third-party services, custom code, and uncertified plugins. A 2024 security incident exposed customer credentials, which reviewers will ask about. | Yes |
| Zoho Analytics | Yes, on request | Zoho provides a BAA template on request and describes itself as a business associate for customers handling PHI. | Coverage varies by product and plan; confirm Zoho Analytics is included | Zoho Analytics On-Premise |
| Metabase | No published BAA | Metabase Cloud advertises SOC 2 Type II but publishes no BAA. Metabase's own guidance for HIPAA workloads is to self-host. | n/a | Yes, open source or Pro/Enterprise self-hosted |
| Klipfolio | No published BAA | No HIPAA statement or BAA found on Klipfolio's site or documentation as of September 2026. | n/a | None |
| Databox | No published BAA | No HIPAA statement or BAA found as of September 2026. | n/a | None |
| Geckoboard | No published BAA | No HIPAA statement or BAA found as of September 2026. | n/a | None |
| DashboardFox | Yes, on Enterprise Dedicated Cloud | BAA with the Compliance Tier. PHI runs on a dedicated server and database; sub-processor BAAs with hosting and backup providers are executed before PHI is provisioned. Not offered on shared plans. | Shared Starter, Growth, and Scale plans | Yes, perpetual license; no BAA needed because the vendor has no access |
What the table doesn't tell you
A BAA covers named services, not a brand
The pattern across the large vendors is the same: the agreement is scoped to specific products, and adjacent products with similar names are left out. Google covers Looker Studio but not Looker Studio Pro. Salesforce covers Tableau Cloud but not Tableau Server or Tableau Bridge, which means a hybrid setup that pulls on-premise data into Tableau Cloud through Bridge has a gap in the middle. Microsoft's BAA covers in-scope services, and new features usually enter scope after general availability, not at preview. Read the covered-services list, not the press release.
Self-hosted removes the BAA question, not the compliance question
Where the software runs on your own infrastructure and the vendor has no access to your data, the vendor is not a business associate and no BAA is needed from it. Power BI Report Server, Tableau Server, self-hosted Metabase, Qlik on Windows, and DashboardFox Self-Hosted all work this way. The trade is that every safeguard, from patching and backups to audit logging and access control, becomes your job. That suits organizations with a strong IT function and is a poor fit for those without one.
AI features are the newest gap
Several vendors now route natural-language and AI features through third-party model providers. Google excludes non-GA features from its Looker BAA; Domo's AI can be configured to call external APIs; Tableau's AI features have raised the same question. If your users will type questions about patient data into an AI assistant, confirm in writing whether that feature is inside the BAA and where the prompts go.
Shared infrastructure is permitted, but it shifts the risk analysis
Most of the tools above run multi-tenant: many customers on shared application servers, separated by software logic. HIPAA does not prohibit that, and the big vendors' BAAs cover it. But your risk analysis has to account for it, and cross-tenant access-control flaws are among the most common findings in web application testing. Dedicated single-tenant hosting, where your PHI sits on a server and database that serve only you, removes that class of risk. Few of the vendors above offer it below enterprise pricing; DashboardFox offers it from $1,499 a month.
How to verify a vendor's HIPAA position in ten minutes
| Step | What you're looking for |
|---|---|
| 1. Find the BAA document, not the compliance page | A legal document with a covered-services definition. If the only thing on offer is a page that says "HIPAA compliant," ask for the agreement. |
| 2. Read the covered-services and exclusions sections | Your exact product, plan, region, and add-ons named. Anything not named is not covered. |
| 3. Ask which plan you must be on | Many vendors sign only on enterprise or top tiers. Get the plan name in writing. |
| 4. Ask about sub-processors | The vendor's hosting and backup providers must have BAAs with the vendor. Ask for the list. |
| 5. Ask where your data actually lives | Shared or dedicated? Which region? Is anything cached or copied? |
| 6. Ask what happens at termination | Return or destruction of PHI on a stated schedule, backups included. |
For the full list of what to require beyond the BAA, including audit log retention, enforced row-level security, and evidence for your security review, see HIPAA-Compliant BI and Dashboard Software: What to Require From a Cloud Vendor.
Where DashboardFox fits
DashboardFox is our product, so read this section with that in mind. We sign a Business Associate Agreement on Enterprise Dedicated Cloud with the Compliance Tier. PHI runs on a server and PostgreSQL database that serve your organization alone, in a US region that is a HIPAA/HITECH-attested facility, with BAAs executed with our hosting and encrypted-backup providers before any PHI is provisioned. Database audit logs are retained for six years, row-level and field-level security are enforced server-side on every plan, and the work is backed by a standalone $5 million cyber liability policy. A healthcare organization runs PHI on this arrangement in production today under a signed BAA.
We do not sign a BAA on our shared Starter, Growth, or Scale plans. A BAA makes us responsible for your PHI, and we are not willing to take that on for data sitting on shared infrastructure. If you would rather keep everything in-house, DashboardFox Self-Hosted is a perpetual license that runs entirely on your servers, and no BAA from us is needed because we never touch the data.
Compare deployment options → · Read our BAA terms → · Security review kit → · Talk to an engineer →
Frequently asked questions
Is Power BI HIPAA compliant?
Power BI can be used with PHI under Microsoft's BAA, which is included in the Online Services Data Protection Addendum for covered entities and business associates without a separate signature. Coverage applies to in-scope services; confirm that any preview features or third-party connectors you use are in scope. Power BI Report Server runs on your own infrastructure and needs no BAA from Microsoft.
Is Tableau HIPAA compliant?
Tableau Cloud can be, under a Salesforce Business Associate Addendum that names Tableau Cloud as a covered service. Tableau Server, Tableau Bridge, and Tableau Data Connect are excluded, and Tableau Public's terms prohibit PHI. The BAA is arranged through a Salesforce account representative, not self-service.
Is Looker Studio HIPAA compliant?
Looker Studio is covered under the Google Cloud Platform BAA, and Google publishes an implementation guide for configuring it with PHI. Looker Studio Pro is expressly excluded from that BAA. Customers must execute the Google Cloud BAA before using Looker Studio with PHI.
Is Metabase HIPAA compliant?
Metabase publishes no Business Associate Agreement for Metabase Cloud. Its own guidance for customers with HIPAA requirements is to self-host, in which case Metabase has no access to the data and no BAA is needed. Self-hosted Metabase can be part of a HIPAA-aligned stack if you supply the safeguards yourself.
Does a BI tool need a BAA if it only connects to a database and never stores PHI?
Yes, if the vendor can access PHI while providing the service. Querying, caching, rendering, and logging all count as access. The exception is self-hosted software, where the vendor has no access at all.
Which BI tools offer dedicated single-tenant hosting for PHI?
Most cloud BI vendors run multi-tenant and cover it under their BAA. Dedicated single-tenant hosting is usually an enterprise-contract item at the large vendors. DashboardFox offers a dedicated server and database as Enterprise Dedicated Cloud from $1,499 per month, and that is the only tier on which it signs a BAA.
Vendor terms were checked against the vendors' published legal and compliance pages in September 2026 and can change. This post is not legal advice; confirm coverage in writing with each vendor and with your own counsel before provisioning PHI.