Is Shopify HIPAA Compliant?
Is Shopify HIPAA compliant? No — Shopify does not sign a BAA, so it is not HIPAA compliant for PHI. See BAA status, where PHI ends up, the AI/MCP gap, and how Strac protects it.
No. Shopify will not sign a BAA, and its Acceptable Use Policy affirmatively prohibits uploading PHI. Storing patient or health-order data in Shopify violates HIPAA and Shopify’s own terms — and Agentic Storefronts now pipe order data to third-party LLMs by default. HIPAA compliance is never automatic — it depends on a signed Business Associate Agreement with the vendor plus how you configure and use the tool. Below is exactly where Shopify stands, where PHI ends up, the AI/MCP gap most teams miss, and how to close it. Verified August 2026.

Shopify’s Acceptable Use Policy lists uploading “Protected Health Information subject to HIPAA” as an unsupported activity, and Shopify will not sign a BAA with U.S.-based covered entities. The prohibition applies across every plan from Basic to Plus — there is no compliant tier.
| Product / surface | PHI status |
|---|---|
| ✅ Non-health commerce data | Standard retail orders with no health context |
| ❌ Every plan, Basic to Plus | AUP prohibits PHI; no BAA on any tier |
| ❌ Order notes & custom form fields | Collecting symptoms or prescriptions violates the AUP |
| ❌ Customer accounts | Linking a person to health-product purchase history is prohibited |
Source: Shopify Acceptable Use Policy. Vendor terms change — reconfirm your plan’s eligibility in writing before sending PHI.
Even teams that never intend to handle PHI accumulate it in Shopify. The common places it lands:
Shopify ships official Storefront and Customer Accounts MCP servers, and its Agentic Storefronts went live by default for eligible U.S. merchants in 2026 — making millions of stores discoverable inside ChatGPT, Microsoft Copilot, Google AI Mode, and Gemini. Sidekick and Shopify Magic add generative AI across plans, exposing order and customer data to external agents.
PHI in Shopify is a contractual violation, not merely “unsupported” — and Agentic Storefronts are on by default, piping order and customer data to third-party LLMs with no BAA in the chain. This is the leak path traditional HIPAA controls were never designed to see: the data does not breach outward, it is pulled inward by an AI agent on a legitimate, authenticated tool call. Read more on MCP data loss prevention and MCP DLP.

A BAA is a contract — it makes the vendor liable for the data it holds. It does not inspect your data, and it does not follow PHI into the AI features, integrations, or exports that sit outside its scope. Whether or not Shopify signs one, three gaps remain: PHI a user pastes or uploads where it should not go; PHI an AI agent pulls out over MCP; and PHI already sitting in Shopify that no one has found. Closing them needs data-layer DLP, not just paperwork.
Because PHI should never be in Shopify in the first place, Strac works on both ends — stopping PHI from being entered and finding any that is already there:

Detection alone does not stop a HIPAA violation — remediation does. Strac does not just alert; it acts the moment PHI appears:

PHI does not stay inside Shopify. It flows into email, chat, cloud storage, GenAI tools, and AI agents — so point fixes leave gaps. Strac is one agentless-plus-endpoint platform covering SaaS, cloud, browser, GenAI, endpoint, and MCP under a single policy and classifier, live in minutes.

| Question | Answer |
|---|---|
| Does Shopify sign a BAA? | No — no BAA on any plan |
| Is the AI / MCP layer covered? | No — outside the BAA; the main leak path |
| Can PHI be used safely? | Only by keeping PHI out and monitoring for it |
| What closes the gap? | Strac MCP + Browser + Endpoint DLP and DSPM |
No tool is. Here it is worse — there is no BAA to sign, so PHI should never be entered.
No. That is the single most common misread — the AI/MCP layer sits outside the core BAA and is the most likely place PHI leaks to a model.
Yes. Shopify’s official MCP server lets an agent read data on an authenticated tool call. Strac redacts PHI on that path before the agent sees it.
No. A BAA assigns liability; it does not inspect your data or follow PHI into AI, integrations, or exports. You still need data-layer DLP.
Strac layers on without slowing Shopify down — redacting PHI at the MCP layer, blocking it in the browser and on the endpoint, and finding PHI already stored via DSPM.
Shopify will not sign a BAA, so PHI does not belong in it — but PHI still ends up there, and its MCP server and AI agents can pull it into an LLM. Strac closes the gap on every surface — redacting PHI at the MCP layer, blocking it in the browser and on the endpoint, and finding what is already stored. Book a demo to see it on Shopify.
.avif)
.avif)
.avif)
.avif)
.avif)


.gif)

