Is Devin HIPAA compliant?
UnverifiedCognition · Coding
Not verified. Check directly with Cognition before using Devin with protected health information (PHI).
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Business Associate Agreement
- Not verified
- No public BAA was confirmed. Treat PHI use as blocked until Cognition provides written terms.
- Enterprise route
- Enterprise (no-training-without-consent guarantee plus tenant-isolated or VPC deployment)
- For regulated use, validate the BAA, configured service and users under the Enterprise (no-training-without-consent guarantee plus tenant-isolated or VPC deployment) contract.
- Default data training
- Opt-out required
- By default Cognition may use non-Enterprise data for model training; toggle off in Devin's Data Controls settings (also enables Zero Data Retention). On the Team plan only admins can toggle it.
- Business-tier training
- No by default
- Enterprise customers are never trained on without express prior written consent.
Practical risk: Devin holds SOC 2 Type II and ISO 27001:2022 with a downloadable DPA and dated all-US subprocessor list. But non-Enterprise customers are opted into model training by default and must turn it off, and there is no EU residency or confirmed BAA.
How to make a decision
Check the precise account tier, written contract and intended data before approving Devin. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Devin
Is Devin GDPR compliant?Is Devin SOC 2 compliant?Is Devin ISO 27001 certified?Does Devin train on your data?
See the full Devin risk profile, with every data-handling fact and its source, or browse all rated AI tools.