Is WordPress HIPAA Compliant? The Real 2026 Answer
HIPAA Compliant Hosting · https://hipaacomplianthosting.com/blog/is-wordpress-hipaa-compliant
Last updated: September 23, 2026
WordPress can be HIPAA compliant, but the answer splits in two. The WordPress software, self-hosted on the right server, can run a fully compliant site. WordPress.com, the hosted service, offers no Business Associate Agreement (BAA) and should never hold patient data. So is WordPress HIPAA compliant? It depends on which WordPress you mean. Most people do not know there are two. That mix-up causes real breaches. This guide splits the two apart. It shows which one can carry protected health information (PHI) and what that setup needs. It also covers WordPress VIP, plugins, and the traps that pull compliant sites back out of line.
TL;DR: Quick answer
The question is WordPress HIPAA compliant has two answers. The open source software: yes, on hosting that signs a BAA. WordPress.com: no, at any price.
Software cannot be compliant or non-compliant on its own. HIPAA binds the people and vendors who hold PHI. For a self-hosted site, that vendor is your host.
WordPress.com's Terms of Service (last updated April 10, 2026) contain no BAA and no mention of HIPAA or health data (checked September 23, 2026). WordPress VIP, the enterprise tier, lists FedRAMP Moderate, SOC 2 Type 2, ISO 27001, GovRAMP, and TX-RAMP, but no HIPAA or BAA offering.
A compliant WordPress site needs a signed BAA, encryption, MFA, audit logs, secure forms, and a written risk analysis (45 CFR § 164.308).
Stock form plugins, analytics trackers, and plain-text email are the usual drift points after launch.
The two WordPresses: the software and the service

The name WordPress covers two different things. The first is the open source software. You download it from WordPress.org for free and run it on any server you choose. The second is WordPress.com. That is a commercial hosting service run by Automattic. It runs the same software for you, on Automattic's servers, under Automattic's terms. Anyone who asks is WordPress HIPAA compliant is really asking about one of these two. The answers are opposites. The self-hosted software can power a compliant site. The hosted service cannot, because Automattic offers no BAA for it. We re-checked the WordPress.com Terms of Service on September 23, 2026 (last updated April 10, 2026). They contain no BAA and no mention of HIPAA, business associates, protected health information, or health. Automattic's enterprise tier, WordPress VIP, lists FedRAMP Moderate, SOC 2 Type 2, ISO 27001, GovRAMP, and TX-RAMP, but no HIPAA or BAA offering.
The verdict, option by option

The table below answers is WordPress HIPAA compliant for each way people actually run it.
Option | BAA? | Verdict for PHI |
|---|---|---|
Self-hosted WordPress on hosting that signs a BAA | Yes, from the host | Compliant when configured with the safeguards below |
Self-hosted WordPress on ordinary shared hosting | No | Not compliant; the host will not take legal responsibility |
WordPress.com, any consumer or business plan | No | Never; no BAA exists at any price |
WordPress VIP (Automattic's enterprise platform) | No public HIPAA offering | Fine for marketing pages; not a stated home for PHI |
Managed WordPress hosts with no BAA (WP Engine and others) | No | Not compliant; see is WP Engine HIPAA compliant |
The managed WordPress hosts say so in their own words. WP Engine "does not sign BAAs and should not be used as a repository for patient health records" (blog post updated September 17, 2026). Kinsta "does not offer a HIPAA-compliant hosting product" and signs no BAA (technical FAQ updated September 18, 2026). Pressable "is not HIPAA compliant" (knowledge base, August 21, 2024). Bluehost states, "We do not sign Business Associate Agreements" (help article, December 5, 2025). Liquid Web does sign BAAs, but on dedicated servers, not on a managed WordPress plan.
Why the software itself cannot sign anything

HIPAA does not certify software. It binds people and companies that create, store, or send PHI. A vendor in that position is a business associate, and the law requires a signed BAA before it touches your data (45 CFR § 164.308(b)). The WordPress software never phones home with your patient data. It is code you run yourself. There is no software vendor holding PHI, so there is no one to sign with and nothing to sign. The company that does hold the data is your host. Its servers store every form entry and every database row. That is why the whole question is WordPress HIPAA compliant collapses into a hosting question. The same logic runs through the plugin layer, which we cover in HIPAA compliant WordPress forms. What the server side must provide is covered in our guide to HIPAA compliant WordPress hosting requirements. Drupal sites face the same hosting question; see whether Drupal HIPAA compliant sites are possible, where Acquia and Upsun sign a BAA and Pantheon does not. For a Drupal site that needs its host to sign, our HIPAA compliant Drupal hosting runs the server under a BAA. Joomla has no Acquia of its own: no Joomla-branded host signs a BAA, so a Joomla HIPAA compliant site needs an outside host or cloud that will.
What a compliant WordPress site actually needs

Once the BAA is in place, the safeguards are standard. Encrypt data in transit with TLS and at rest with AES-256. Give every user a unique login and turn on MFA. WordPress core still has no two-factor login as of version 7.1. Add the WordPress.org Two Factor plugin (version 0.16.0, March 27, 2026) or single sign-on with MFA. Set automatic logoff. Keep audit logs and retain the documentation for six years (45 CFR § 164.316(b)(2)(i)). Replace stock forms with encrypted, BAA-covered forms. Write a risk analysis and train your staff (45 CFR § 164.308). HHS proposed a Security Rule update on January 6, 2025 (Federal Register document 2024-30983) that would make MFA and encryption required rather than addressable. As of September 23, 2026, it has not been finalized, so the current rule text still governs. None of this is exotic. It is a checklist, and it is very doable on WordPress. Working that checklist is what turns is WordPress HIPAA compliant into a yes for your site. The full checklist lives in our eight-step guide on how to make WordPress HIPAA compliant. The same checklist scales up to a HIPAA compliant patient portal. Only the pages that touch PHI need this treatment. A plain blog post does not. Weighing a headless CMS instead? Our guide to whether Strapi HIPAA compliant builds are possible covers the same BAA question for Strapi. Newsletter publishers on Ghost get theirs in our guide to whether Ghost CMS HIPAA compliant sites are possible. Running a store on it? The ecommerce version of this verdict is is WooCommerce HIPAA compliant.
Where WordPress sites drift out of line

Most WordPress compliance failures happen after launch, not before. A stock contact form starts asking about symptoms. Entries land in the database and get emailed in plain text. Form plugins also carry their own security flaws. In September 2026, Gravity Forms fixed two unauthenticated file upload flaws: CVE-2026-84434 (CVSS 10.0, fixed in 3.1.1) and CVE-2026-19513 (CVSS 9.0, fixed in 3.0.3). WPForms Lite fixed an unauthenticated access control flaw, CVE-2026-48835 (CVSS 7.5), in version 1.10.0.5 on May 28, 2026. An unpatched form plugin can turn the answer to is WordPress HIPAA compliant back to no. An analytics tag starts tracking visitors on an appointment page. We map that tracker problem in is Google Analytics HIPAA compliant. A plugin update quietly adds a third-party service with no BAA. The plugin layer has its own sorting test, covered in HIPAA compliant WordPress plugins. Each drift point reopens the gap the BAA closed. So the honest answer to is WordPress HIPAA compliant is not a one-time yes. It is yes, while someone keeps watching the moving parts.
If you would rather not build this yourself

We sell this, so weigh that as a disclosure. Our HIPAA compliant WordPress hosting comes with the BAA signed and the server side pre-built. Plans start at $89 per month*; see current plans for the WordPress tiers. You migrate and run the site yourself. The $249 per month managed plan includes migration, and we sign the BAA within 24 hours. Either way, the hosting question that decides is WordPress HIPAA compliant is answered on day one. Your side of the work, forms, policies, and training, stays yours on a self-run tier. The managed plan carries more of it for you. When you are ready to pick a host, the ranked options are in best HIPAA WordPress hosting.
*The $89 entry plan is a managed SFTP server; the full plan lineup is being finalized. See current plans for what each tier includes.
Frequently asked questions
Is WordPress.com HIPAA compliant?
No. WordPress.com offers no BAA on any plan, and its Terms of Service (last updated April 10, 2026) never mention HIPAA or health data. Checked September 23, 2026. Do not collect or store PHI on a WordPress.com site at any tier.
Does WordPress VIP sign a BAA?
WordPress VIP publishes FedRAMP Moderate, SOC 2 Type 2, ISO 27001, GovRAMP, and TX-RAMP credentials, but no HIPAA or BAA offering, as of September 2026. Treat it as a strong platform for public content, not a stated home for PHI.
Is self-hosted WordPress HIPAA compliant?
It can be. Host it with a provider that signs a BAA, then add encryption, MFA, audit logs, secure forms, and a written risk analysis. The software is fine. The setup around it decides.
Is WordPress secure enough for healthcare?
Yes, when maintained. WordPress 7.1.1 (September 17, 2026) was the fifth security release of 2026, with 11 fixes. Plugin and theme auto-updates are off by default. Core has no two-factor login as of 7.1; add the Two Factor plugin or single sign-on. Remove unused plugins and run a web application firewall. Most breaches trace to outdated plugins and weak logins.
Do I have to leave WordPress to be compliant?
No. You have to leave hosting that will not sign a BAA. The site itself can usually move as-is, and the PHI-touching parts get secured after the move.
Recap: is WordPress HIPAA compliant
To recap, is WordPress HIPAA compliant depends on which WordPress you mean. The self-hosted software: yes, on hosting that signs a BAA and with the standard safeguards configured. WordPress.com: no, on every plan, because no BAA exists. WordPress VIP publishes no HIPAA offering either. The software cannot sign a contract. Your host can. Get the BAA from the host, configure the safeguards, keep the forms and trackers in line, and WordPress runs healthcare sites without drama.
This article is general information, not legal advice. WordPress.com terms and WordPress VIP compliance claims are as published in September 2026 and may change. Confirm current terms with the vendors. Consult qualified counsel. Base your safeguards on a written risk analysis. We sell HIPAA compliant hosting and compliance reviews. Reviewed September 2026.
Sources
WordPress.com: Terms of Service (updated April 10, 2026).
WordPress VIP: Security and compliance.
WP Engine: Is Your Website HIPAA Compliant? 8 Questions to Ask Your Hosting Provider (updated September 17, 2026).
Pressable: Is Pressable HIPAA Compliant? (August 21, 2024).
Bluehost: Hosting Services: HIPAA Compliance and Limitations (December 5, 2025).
Liquid Web: HIPAA hosting (updated April 21, 2026).
WordPress.org: Releases, including WordPress 7.1.1 (September 17, 2026).
WordPress.org: Two Factor plugin (version 0.16.0, March 27, 2026).
Patchstack: Gravity Forms CVE-2026-84434 (September 18, 2026).
Patchstack: Gravity Forms CVE-2026-19513 (September 1, 2026).
Patchstack: WPForms Lite CVE-2026-48835 (May 28, 2026).
45 CFR § 160.103 (business associate definition): ecfr.gov.
45 CFR § 164.308 (administrative safeguards, BAA requirement): ecfr.gov.
45 CFR § 164.312 (technical safeguards): ecfr.gov.
Federal Register: HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, proposed rule 2024-30983 (January 6, 2025).