Enterprise
Cursor Enterprise HIPAA BAA: Eligibility, Scope & Configuration
Cursor offers a HIPAA Business Associate Agreement (BAA) on the Enterprise plan for covered entities and business associates. A signed BAA is required before any protected health information (PHI) enters Cursor. The agreement comes with an Implementation and Configuration Guide that details eligible services, eligible models and customer-configured controls.
On this page
Who can get a HIPAA BAA from Cursor?
HIPAA BAAs are available on the Enterprise plan to organizations that are covered entities or business associates under HIPAA. Prospects evaluating Enterprise can request one too, so you do not need a signed contract in hand before you ask. Healthcare providers, health plans, clearinghouses and the vendors handling PHI on their behalf are the organizations that fall into those two categories.
It is easy to treat the BAA as a post-signature formality, which pushes the eligibility question past the point where the commercial terms are still open. Asking during evaluation costs one line in an email to sales. The delay is a calendar problem more than a legal one, I think. Legal review and countersignature queue behind whatever else those functions are carrying, and that queue does not get shorter because a delivery team wanted to start this month.
Cursor's guidance is to hold PHI back until the Enterprise agreement and BAA are signed and your organization has completed the required implementation steps. Signing is only the first half. The published Eligible Services are covered for Enterprise customers with Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. enabled and locked organization-wide, so a signed agreement with Privacy Mode not yet locked does not put your usage inside scope.
This is covered hands-on in Teams and Enterprise Admin — 6 short modules, free to read.
What does the Cursor BAA cover?
The BAA covers Eligible Services and Eligible Models defined in the HIPAA Implementation and Configuration Guide, which is part of the agreement. Access to the guide is by request through the Trust Center. It holds the current details, and not every Cursor product, configuration or workflow qualifies automatically.
The guide splits scope four ways. Two parts define where PHI may go, and the other two, where most of the work actually sits, define what your organization has to set up and enforce.
- Eligible Services: the specific Cursor product surfaces where PHI is permitted.
- Eligible Models: the subset of available AI models covered by the BAA.
- Required controls: the settings your org must enable, starting with Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. enabled and locked org-wide.
- Customer responsibilities: what your team must configure and instruct users to do.
Cursor's BAA does not automatically cover third-party services. Before PHI moves, Cursor's own FAQ tells you to review your approved configuration, your model provider settings, integration usage and the guide. Anything you connect (MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. servers, external APIs, ticketing systems) stays your organization's to assess and configure.
Which Cursor services are covered by the BAA?
Cursor publishes the Eligible Services list, and coverage is conditional on one setting. These surfaces are covered for Enterprise customers with Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. enabled and locked organization-wide. The guide carries the current version, so read the list below as indicative and the guide as authoritative.
- Desktop IDE, including Agent, Tab, Edit, local agent mode and inline edit
- Cloud AgentsAgents that run in a Cursor-managed virtual machine, check out the repo, do the work and open a pull request, then shut down, with no load on your laptop. Press Enter for the full definition.
- Cursor for iOS
- CLI
- Tab
- BugbotCursor's automated PR reviewer that posts inline findings and can push fix commits from isolated VMs. Press Enter for the full definition.
- Automations
The services are public and the models are not, which is not the split I expected. Product surfaces change slowly enough to name in an internal policy. A model list moves whenever a provider ships something new, so point the policy document at the guide rather than restating the list, and it stops going stale on you.
What must we configure before using PHI?
Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. is the one required control named on the public page. Enable it and lock it organization-wide so members cannot turn it off. The rest of the required controls and the customer responsibilities sit in the HIPAA Guide, and Cursor's platform does not apply them on your behalf.
Read the guide before you touch any settings. That is not quite the right cut, though. The setting that genuinely depends on the guide is the model allowlist, because the guide is what names the Eligible Models. Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. you can enable and lock today without reading a word. Do that first, and let the allowlist wait for the document.
- 1Request the BAA from Cursor sales and sign it alongside the Enterprise agreement.
- 2Request access to the HIPAA Implementation and Configuration Guide in the Trust Center, and read it.
- 3Enable and lock Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. organization-wide.
- 4Restrict work to the Eligible Services and Eligible Models the guide lists.
- 5Train users to submit PHI only through Eligible Services and approved workflows.
Five steps, and the first two wait on somebody outside your team: the countersignature, and access to the guide, which is granted on request rather than self-served.
Personal API keys are the exception worth checking before rollout. Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition.'s zero-data-retention guarantee applies to Cursor-routed models; with a developer's own provider key, retention is governed by their agreement with that provider rather than Cursor's. An org-wide Privacy Mode lock can be in place while that traffic sits outside it. Restricting BYOK is a separate setting, and non-ZDRZero Data Retention. A contractual guarantee that the model provider won't store your code or train on it. Press Enter for the full definition. models need admin approval on top of that.
How do we request a HIPAA BAA?
Contact Cursor sales at cursor.com/contact-sales, tell them you need a HIPAA BAA, and say where you are: evaluating Cursor, moving off a Teams plan, or already on Enterprise. Those are the three answers the docs ask for. Security and compliance documents, including the HIPAA Guide and Cursor's SOC 2 Type II report, are requested through the Trust Center at trust.cursor.com.
That third question is the one that reorders your timeline if you are on Teams today, since a move to Enterprise has to come before the BAA does.
Ownership of the request is worth settling at the same time. On a team of ten the person who signs the BAA is usually the person who will lock Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition., so the guide gets read once by someone who can act on it. In a larger organization those are two different functions, and the guide tends to stop at legal, which is where the configuration step quietly stalls. Send it to whoever administers the model allowlist on the same day.
How do we show the required controls were in place?
Audit logs are the record. They are an Enterprise feature, they capture Privacy ModeCursor's setting that guarantees code data is not used for training by Cursor or its model providers, and that an admin can enforce org-wide; data-retention terms are a separate, contractual layer. Press Enter for the full definition. changes with a scope of user or team, and you can export them for whoever is assembling the evidence pack.
What they will not give you is the other half. Prompts and generated code are not in the audit log, so a question like whether any PHI reached a non-eligible model has no answer in the dashboard. Cursor's recommendation for that is hooks, which are code your team writes and maintains. My guess is that most organizations only meet this question once an incident is underway. Decide it now. Either you deploy the logging, or you write down that you accepted the gap.
What does a signed BAA not guarantee?
A BAA establishes the legal framework for handling PHI with Cursor; it does not make every product configuration safe for PHI by default. Your organization remains responsible for configuring Cursor and instructing users in accordance with the BAA, HIPAA requirements and the HIPAA Guide.
Four obligations stay on your side of the line once the agreement is signed. The platform does not enforce them for you, so treat each row below as work with a name against it. The third-party row is the one I suspect gets underestimated most, because integrations arrive after the rollout plan is written.
- Configuration
- Enable required controls per the Implementation Guide before routing any PHI.
- Scope
- Route PHI only through Eligible Services and Eligible Models listed in the guide.
- Third parties
- Assess and cover any integrations you connect to Cursor separately.
- User training
- Instruct users on PHI handling; the BAA does not substitute for internal policy.
Those four rows are the customer half of a split Cursor documents plainly. Cursor secures and operates the platform, and you decide how it gets configured and adopted. Read the BAA as a scope statement rather than a certificate. Assign an owner to each row before the first PHI-adjacent ticket, and write the names down.
Frequently asked questions
Is the Cursor HIPAA BAA available on the Teams plan?
No. BAA support is available on Enterprise. If your organization is on a Teams plan today, contact Cursor sales to discuss moving to Enterprise and requesting a BAA at the same time.
Do we have to be an Enterprise customer before we can ask for a BAA?
No. Enterprise customers and prospects evaluating Enterprise can both request a BAA, so you can raise it during evaluation rather than after signature. It typically applies to healthcare organizations and to vendors acting as covered entities or business associates.
Where do we get the HIPAA Implementation and Configuration Guide?
Request access in the Trust Center at trust.cursor.com. The guide is part of the BAA and carries the current details of Eligible Services, Eligible Models, required controls and customer responsibilities.
Can we use any Cursor model with a BAA in place?
Only Eligible Models listed in the HIPAA Implementation and Configuration Guide are covered by the BAA. Using PHI with models not on that list falls outside the agreement's scope. Note that Privacy Mode's zero-data-retention guarantee applies to Cursor-routed models: if a developer supplies their own provider API key, retention is governed by their agreement with that provider rather than Cursor's, so restrict personal API keys as well.
Where do we find Cursor's SOC 2 report for security review?
Cursor's SOC 2 Type II report is available on request through trust.cursor.com. Share that URL with your security team; it also links to Cursor's compliance and data governance documentation.
What happens if a team member sends PHI through a non-eligible model?
That usage falls outside the BAA. Your organization is responsible for restricting access to Eligible Models and training users accordingly. Restricting which models the organization can use is an admin setting, so configure it rather than relying on training.
Sources & last verified
- Cursor - HIPAA Business Associate Agreements
- Cursor - Privacy and Data Governance
- Cursor - Trust Center
- Cursor - Enterprise
Cursor ships frequently. Last updated July 28, 2026.
Keep reading
Rather do it than read about it? Run 11 interactive Cursor walkthroughs in a simulated editor. Free, no account needed.