Is WordPress HIPAA Compliant? The Real 2026 Answer
Last updated: July 30, 2026
WordPress can be HIPAA compliant, but the answer splits in two. The WordPress software, self-hosted on the right server, can run a fully compliant site. WordPress.com, the hosted service, offers no Business Associate Agreement (BAA) and should never hold patient data. So is WordPress HIPAA compliant? It depends on which WordPress you mean. Most people do not know there are two. That mix-up causes real breaches. This guide splits the two apart. It shows which one can carry protected health information (PHI) and what that setup needs. It also covers WordPress VIP, plugins, and the traps that pull compliant sites back out of line.
TL;DR: Quick answer
The question is WordPress HIPAA compliant has two answers. The open source software: yes, on hosting that signs a BAA. WordPress.com: no, at any price.
Software cannot be compliant or non-compliant on its own. HIPAA binds the people and vendors who hold PHI. For a self-hosted site, that vendor is your host.
WordPress.com's terms include no BAA (checked July 2026). WordPress VIP, the enterprise tier, lists SOC 2 and FedRAMP but no HIPAA offering either.
A compliant WordPress site needs a signed BAA, encryption, MFA, audit logs, secure forms, and a written risk analysis (45 CFR § 164.308).
Stock form plugins, analytics trackers, and plain-text email are the usual drift points after launch.
The two WordPresses: the software and the service

The name WordPress covers two different things. The first is the open source software. You download it from WordPress.org for free and run it on any server you choose. The second is WordPress.com. That is a commercial hosting service run by Automattic. It runs the same software for you, on Automattic's servers, under Automattic's terms. Anyone who asks is WordPress HIPAA compliant is really asking about one of these two. The answers are opposites. The self-hosted software can power a compliant site. The hosted service cannot, because Automattic offers no BAA for it. We checked the WordPress.com Terms of Service in July 2026. They contain no BAA and no health data provisions at all.
The verdict, option by option

The table below answers is WordPress HIPAA compliant for each way people actually run it.
Option | BAA? | Verdict for PHI |
|---|---|---|
Self-hosted WordPress on hosting that signs a BAA | Yes, from the host | Compliant when configured with the safeguards below |
Self-hosted WordPress on ordinary shared hosting | No | Not compliant; the host will not take legal responsibility |
WordPress.com, any consumer or business plan | No | Never; no BAA exists at any price |
WordPress VIP (Automattic's enterprise platform) | No public HIPAA offering | Fine for marketing pages; not a stated home for PHI |
Managed WordPress hosts with no BAA (WP Engine and others) | No | Not compliant; see is WP Engine HIPAA compliant |
Why the software itself cannot sign anything

HIPAA does not certify software. It binds people and companies that create, store, or send PHI. A vendor in that position is a business associate, and the law requires a signed BAA before it touches your data (45 CFR § 164.308(b)). The WordPress software never phones home with your patient data. It is code you run yourself. There is no software vendor holding PHI, so there is no one to sign with and nothing to sign. The company that does hold the data is your host. Its servers store every form entry and every database row. That is why the whole question is WordPress HIPAA compliant collapses into a hosting question. The same logic runs through the plugin layer, which we cover in HIPAA compliant WordPress forms. What the server side must provide is covered in our guide to HIPAA compliant WordPress hosting requirements.
What a compliant WordPress site actually needs

Once the BAA is in place, the safeguards are standard. Encrypt data in transit with TLS and at rest with AES-256. Give every user a unique login and turn on MFA. Set automatic logoff. Keep audit logs and retain the documentation for six years (45 CFR § 164.316(b)(2)(i)). Replace stock forms with encrypted, BAA-covered forms. Write a risk analysis and train your staff (45 CFR § 164.308). None of this is exotic. It is a checklist, and it is very doable on WordPress. Working that checklist is what turns is WordPress HIPAA compliant into a yes for your site. The full checklist lives in our eight-step guide on how to make WordPress HIPAA compliant. Only the pages that touch PHI need this treatment. A plain blog post does not.
Where WordPress sites drift out of line

Most WordPress compliance failures happen after launch, not before. A stock contact form starts asking about symptoms. Entries land in the database and get emailed in plain text. An analytics tag starts tracking visitors on an appointment page. We map that tracker problem in is Google Analytics HIPAA compliant. A plugin update quietly adds a third-party service with no BAA. Each drift point reopens the gap the BAA closed. So the honest answer to is WordPress HIPAA compliant is not a one-time yes. It is yes, while someone keeps watching the moving parts.
If you would rather not build this yourself

We sell this, so weigh that as a disclosure. Our HIPAA compliant WordPress hosting comes with the BAA signed and the server side pre-built. The $79 per month self-managed plan gives you a configured server with the BAA included. You migrate and run the site yourself. The $229 per month managed plan includes migration, and we sign the BAA within 24 hours. Either way, the hosting question that decides is WordPress HIPAA compliant is answered on day one. Your side of the work, forms, policies, and training, stays yours on the $79 plan. The managed plan carries more of it for you.
Frequently asked questions
Is WordPress.com HIPAA compliant?
No. WordPress.com offers no BAA on any plan, and its terms have no health data provisions. Checked July 2026. Do not collect or store PHI on a WordPress.com site at any tier.
Does WordPress VIP sign a BAA?
WordPress VIP publishes SOC 2, FedRAMP, and ISO 27001 credentials, but no HIPAA or BAA offering, as of July 2026. Treat it as a strong platform for public content, not a stated home for PHI.
Is self-hosted WordPress HIPAA compliant?
It can be. Host it with a provider that signs a BAA, then add encryption, MFA, audit logs, secure forms, and a written risk analysis. The software is fine. The setup around it decides.
Is WordPress secure enough for healthcare?
Yes, when maintained. Keep core, themes, and plugins updated, remove unused plugins, and run a web application firewall. Most WordPress breaches trace to outdated plugins and weak logins, not the core software.
Do I have to leave WordPress to be compliant?
No. You have to leave hosting that will not sign a BAA. The site itself can usually move as-is, and the PHI-touching parts get secured after the move.
Recap: is WordPress HIPAA compliant
To recap, is WordPress HIPAA compliant depends on which WordPress you mean. The self-hosted software: yes, on hosting that signs a BAA and with the standard safeguards configured. WordPress.com: no, on every plan, because no BAA exists. WordPress VIP publishes no HIPAA offering either. The software cannot sign a contract. Your host can. Get the BAA from the host, configure the safeguards, keep the forms and trackers in line, and WordPress runs healthcare sites without drama.
This article is general information, not legal advice. WordPress.com terms and WordPress VIP compliance claims are as published in July 2026 and may change. Confirm current terms with the vendors. Consult qualified counsel. Base your safeguards on a written risk analysis. We sell HIPAA compliant hosting and compliance reviews. Reviewed July 2026.
Sources
WordPress.com: Terms of Service (updated April 10, 2026)
WordPress VIP: Security and compliance
45 CFR § 160.103 (business associate definition): ecfr.gov
45 CFR § 164.308 (administrative safeguards, BAA requirement): ecfr.gov
45 CFR § 164.312 (technical safeguards): ecfr.gov