Skip to main content

Is WP Engine HIPAA Compliant? The BAA Answer for 2026

By Joseph Abear ·
Is WP Engine HIPAA Compliant

Last updated: July 18, 2026

Healthcare teams love WP Engine, so is WP Engine HIPAA compliant? No. WP Engine offers no Business Associate Agreement (BAA) in its published terms. Without a signed BAA, it cannot lawfully store, process, or transmit protected health information (PHI). The answer has nothing to do with WP Engine's security, which is strong. HIPAA asks about the contract first. Under 45 CFR § 164.308(b), any vendor that touches PHI for you must sign a BAA before the first byte arrives. WP Engine's Terms of Service were updated January 1, 2026. They contain no BAA offer and no mention of HIPAA at all. WP Engine is still a fine host for a healthcare marketing site that collects zero patient data. But the moment a form asks about symptoms or appointments, you have crossed the line. This guide covers the two setups that work on the other side of it.

TL;DR: Quick answer

  • Is WP Engine HIPAA compliant? No. Its published terms offer no BAA path. Hosting PHI there violates the BAA rule at 45 CFR § 164.308(b).

  • WP Engine's Terms of Service (updated January 1, 2026) never mention HIPAA, PHI, or a BAA. Outside reviews through 2026 agree.

  • Strong security is not the test. A host with great encryption and no BAA still fails. No one has taken legal responsibility for the data.

  • WP Engine is fine for a healthcare marketing site with zero PHI. The line is crossed when any form collects health details.

  • Two setups work: keep WP Engine for the public site and put PHI on BAA-covered infrastructure, or move the whole site to HIPAA compliant WordPress hosting from $79 per month self-managed with the BAA included.

  • Vendor policies change. Wix reversed its no-BAA stance in March 2026. Re-check any host's current terms before you rely on them.

Why the BAA decides the answer

HIPAA does not grade hosts on their firewalls. It asks one question first: did the vendor sign a Business Associate Agreement? Under 45 CFR § 160.103, a company that stores or moves PHI on your behalf is a Business Associate. Section 164.308(b) requires the written agreement before any patient data changes hands. The BAA is what makes the host legally responsible for your patients' information. No BAA means no responsibility. That makes it a violation the moment PHI lands on the server, no matter how well the server is locked down. We apply the same test to every vendor we review, from AWS to Wix. It is also the first of the five tests in our guide to the best HIPAA compliant hosting. That one test is why "is WP Engine HIPAA compliant" has a one-word answer.

What do WP Engine's own terms say?

WP Engine's Terms of Service were last updated January 1, 2026. They contain no HIPAA provisions, no BAA offer, and no healthcare product. The security section points to its Privacy Policy and Data Privacy Addendum. Those cover general data protection, not the Security Rule. There is no published way to request a BAA, the way AWS offers one through Artifact or Google offers one in the Workspace Admin console. Outside reviews through 2025 and 2026 reach the same conclusion: WP Engine does not sign BAAs. Policies do change. Wix proved that in March 2026 when it introduced a BAA after years without one. So as of mid-2026, is WP Engine HIPAA compliant on any published plan? No. No tier includes a BAA. Confirm directly with WP Engine before you make a decision that depends on it.

When is WP Engine still a fine choice for healthcare?

A ban on PHI is not a ban on healthcare. Many practice websites collect no patient data at all. They describe the providers, list services, show the phone number, and link out to a portal that lives somewhere else. That kind of marketing site can sit on WP Engine without a HIPAA problem. HIPAA follows the data, not the industry. The question is what your forms actually ask. A form that takes a name and a business message is generally outside PHI territory. A form that invites symptoms, medications, insurance details, or an appointment request is collecting PHI. For a therapy practice, even a basic contact form submission can be PHI. Our breakdown of who needs HIPAA compliant hosting walks the full decision. In practice, asking "is WP Engine HIPAA compliant" only matters for the parts of your site that touch patient data.

Can your site stay on WP Engine? Scenario by scenario

WP Engine Scenario by Scenario

Here is how the answer plays out for common setups. The rows assume the current no-BAA terms, which is what makes "is WP Engine HIPAA compliant" a no for anything holding patient data.

Your site

Can it stay on WP Engine?

Marketing site, no forms

Yes

Contact form for business inquiries only, no health questions

Generally yes, keep health details out and say so on the form

Appointment requests or intake forms

No, submissions are PHI and need a BAA-covered home

Patient portal, telehealth, or stored records

No

Public site on WP Engine, PHI workflows on BAA-covered infrastructure

Yes, if the split is real and no health data touches the WP Engine side

The two setups that actually work

WP Engine Two Setups

Setup 1: split the architecture. Keep the public marketing site on WP Engine. Move everything that touches patient data, intake forms, booking, and portals, onto infrastructure with a signed BAA. The split must be real. No health questions on the WP Engine side, and links send patients to the covered environment before any PHI is typed. For a site that is mostly marketing, this is often the cheapest compliant path.

Setup 2: move the whole site to BAA-covered WordPress hosting. One environment, one BAA, no split to police. This is the simpler answer when forms and content live together, and it is what we build. Our HIPAA compliant WordPress hosting starts at $79 per month for a self-managed WordPress server with the BAA included. nginx, PHP, Redis, and the database come pre-configured; you migrate and manage the site. The fully managed tier starts at $229 per month with migration included and the BAA signed within 24 hours. Either way, the environment arrives with encryption, a firewall, audit logging, and tested backups already running. The hosting-layer steps are covered in how to make WordPress HIPAA compliant, and the wider market in our buyer's guide to HIPAA WordPress hosting.

Neither setup changes the answer to "is WP Engine HIPAA compliant." It changes where your PHI lives, which is the part you control.

If you would rather have it handled

Tell us what your site collects and which host it sits on today. If your WP Engine site truly holds no PHI, we will tell you it can stay put. That is the honest answer. If it does collect patient data, we sell HIPAA compliant hosting built for exactly that migration, so weigh that as a disclosure. Our client-side compliance review can also document what your current forms and trackers leak before you decide anything.

Frequently asked questions

Is WP Engine HIPAA compliant?

No. WP Engine offers no Business Associate Agreement in its published terms, so it cannot lawfully host protected health information. Its security is strong, but HIPAA's first test is the BAA, and WP Engine does not provide one.

Does WP Engine sign a BAA?

Not per its published terms as of mid-2026. Its Terms of Service, updated January 1, 2026, contain no BAA offer and no HIPAA provisions. Confirm directly with WP Engine before relying on this, since vendor policies change.

Can a medical practice use WP Engine at all?

Yes, for a marketing site that collects zero patient information. Provider bios, services, and directions are not PHI. The site must not collect health details through any form. Patient workflows must live on BAA-covered infrastructure elsewhere.

Is WP Engine's security good enough for HIPAA?

Security is not the deciding factor. Encryption and firewalls protect data. But HIPAA requires a vendor to accept legal responsibility through a BAA before PHI arrives. Without that contract, even excellent security leaves you in violation of 45 CFR § 164.308(b). That is why "is WP Engine HIPAA compliant" stays a no despite strong engineering.

What should I use instead of WP Engine for patient data?

WordPress hosting that signs a BAA and runs the Security Rule safeguards: encryption, access controls with MFA, audit logging, and tested backups. Options range from self-managed BAA-covered servers from $79 per month to fully managed environments from $229 per month with migration included.

Recap: is WP Engine HIPAA compliant?

To recap, is WP Engine HIPAA compliant? No, because it offers no BAA, and the BAA is the gate. Keep WP Engine for a truly PHI-free marketing site. Split the architecture if you want to keep it while patient workflows live on covered infrastructure. Or move the whole site to HIPAA compliant WordPress hosting with the BAA included. Whatever you choose, check what your forms actually ask. That is where compliance is won or lost.

This article is general information, not legal advice. WP Engine's terms are as published in mid-2026 and can change; confirm current policies with WP Engine directly, consult qualified counsel, and base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting and compliance reviews. Reviewed July 2026.

Sources