Is Shopify HIPAA Compliant?
Is Shopify HIPAA compliant? No — Shopify does not sign a BAA, so it is not HIPAA compliant for PHI. See BAA status, where PHI ends up, the AI/MCP gap, and how Strac protects it.
No — Shopify does not sign a BAA, so it is not HIPAA compliant for PHI. HIPAA compliance is never automatic — it depends on a signed Business Associate Agreement (BAA) with the vendor plus how you configure and use the tool. Below is where Shopify stands, where PHI ends up, and the AI/MCP gap most teams miss.

Shopify does not offer a BAA and is not HIPAA compliant. Health-and-wellness merchants often collect information that edges into PHI — conditions, prescriptions, health questionnaires — and that data is unprotected inside Shopify customer and order records.
Even teams that "don’t use Shopify for health data" accumulate PHI in it: customer health questionnaires, prescription or condition data, and order notes for health products. Under HIPAA, a single identifier tied to health information is enough to trigger the rules — so the question isn’t whether PHI could land in Shopify, it’s what protects it when it does.
Because Shopify already carries no BAA, connecting it to AI makes a bad situation worse. An agent querying Shopify over the Model Context Protocol (MCP) pulls PHI into a model’s context — and assistants like Claude Cowork carry no BAA of their own. The regulated data is unprotected at both ends.

Strac MCP DLP sits on the MCP path, detects PHI in every request and response, and redacts, masks, or blocks it before it reaches the assistant — so an AI that won’t sign a BAA never sees regulated data. And Strac browser and endpoint DLP catch PHI before it is pasted or typed into Shopify in the first place. Every action is audit-logged for HIPAA. See MCP integrations and Shopify MCP server.

Is Shopify HIPAA compliant in 2026? No — Shopify does not sign a BAA, so it is not HIPAA compliant for PHI.
Can I use Shopify with Claude or ChatGPT and stay HIPAA compliant? Only if PHI never reaches a model that isn’t under a BAA. Claude Cowork does not sign one, so connecting Shopify over MCP can expose PHI. Strac MCP DLP redacts PHI on the MCP path before it reaches the assistant.
Does Shopify store PHI? It can — customer health questionnaires, prescription or condition data, and order notes for health products. Whether or not that’s intended, it needs to be protected.
.avif)
.avif)
.avif)
.avif)
.avif)


.gif)

