Skip to main content

Command Palette

Search for a command to run...

Teams & Enterprise

HIPAA Business Associate Agreements

Cursor supports HIPAA Business Associate Agreements (BAAs) for Enterprise customers.

Organizations that are covered entities or business associates under HIPAA can request a BAA as part of their Enterprise agreement. A signed BAA is required before submitting protected health information (PHI) to Cursor.

Request a BAA

BAAs are available on the Enterprise plan. To request one:

  1. Contact sales
  2. Tell us that you need a HIPAA BAA
  3. Share whether you are evaluating Cursor, moving from a Teams plan, or already on Enterprise

Request a HIPAA BAA

Contact sales to request BAA support for Cursor Enterprise.

Contact Sales

Using Cursor with PHI

The HIPAA Implementation and Configuration Guide is part of the BAA. It includes current details about Eligible Services, Eligible Models, required controls, and customer responsibilities. Request access in the Trust Center.

A BAA does not automatically make every product, configuration, or workflow appropriate for PHI. Your organization is responsible for configuring Cursor and instructing users in accordance with your BAA, HIPAA requirements, and the HIPAA Guide.

Before using Cursor with PHI:

  • Sign an Enterprise agreement and BAA with Cursor
  • Review the HIPAA Guide in the Trust Center
  • Enable and lock Privacy Mode organization-wide
  • Train users to submit PHI only through Eligible Services and approved workflows

Third-party services and integrations are not automatically covered by Cursor's BAA. Your organization remains responsible for assessing and configuring any third-party services it uses with Cursor.

Eligible Services

The listed Eligible Services are covered for Enterprise customers with Privacy Mode enabled and locked organization-wide:

  • Desktop IDE, including Agent, Tab, Edit, local agent mode, and inline edit
  • Cloud Agents
  • Cursor for iOS
  • CLI
  • Tab
  • BugBot
  • Automations

The HIPAA Guide has the latest details about Eligible Services and implementation requirements. Request access in the Trust Center.

FAQ

Who can request a BAA?

Enterprise customers and prospects evaluating Enterprise can request a BAA for Cursor. This typically applies to healthcare organizations and vendors that act as covered entities or business associates.

Is BAA support available on Teams?

BAA support is available on Enterprise. If your organization is currently on a Teams plan, contact sales to discuss moving to Enterprise and requesting a BAA.

Can we submit PHI before the BAA is signed?

No. Do not submit PHI to Cursor until your Enterprise agreement and BAA are signed and your organization has completed the required implementation steps.

Which Cursor services are covered?

Your signed BAA and the HIPAA Guide list the Eligible Services covered for PHI. Request access in the Trust Center.

Which models are covered?

The HIPAA Guide lists the current Eligible Models. Request access in the Trust Center.

Does Cursor's BAA cover third-party model providers or integrations?

Cursor's BAA does not automatically cover third-party services. Review your approved configuration, model provider settings, integration usage, and the HIPAA Guide before submitting PHI.

How do we get security and compliance documents?

Visit the Trust Center to request access to available security and compliance documents.