All engagements conducted under NDA·Evidence preserved to technical chain-of-custody standards·Engagements limited to qualified organizations

Free scanThe studyForensic TriageForensic AuditAI VendorsResearch
Free scan · no install

Is GitHub Copilot covered by your Microsoft HIPAA BAA?

Individual (Free, Pro, Pro+ & Max): Not named in Microsoft's HIPAA in-scope services list · Training is opt-in and off by default · Retention not published in GitHub's documentation

Business & Enterprise: Not named in Microsoft's HIPAA in-scope services list · Training contractually excluded · Retention not published in GitHub's documentation

Individual - Free, Pro, Pro+ & MaxBusiness & Enterprise
HIPAA BAANot documentedGitHub Copilot is not named in Microsoft's HIPAA in-scope services list, which names Microsoft 365 Copilot, Microsoft 365 Copilot Chat and Microsoft Copilot for Security. No GitHub BAA offer was found for individual plansNot documentednot named in Microsoft's HIPAA in-scope services list alongside the Microsoft 365 Copilot products
Trains on your dataOpt-in, off by default - "Allow GitHub to use my data for AI model training" must be actively enabled. When enabled: "GitHub may use your interactions with GitHub features and services—including inputs, outputs, code snippets, and associated context—to train and improve AI models." Setting available from April 24, 2026NoBusiness and Enterprise are explicitly excluded from the individual training setting; their data is covered by GitHub's Data Protection Agreement, which prevents such use without explicit authorization
Survives deletionNot stated in GitHub's documentationthe application card defers retention entirely to the Copilot Trust Center, which is not published as static documentationNot stated in GitHub's documentationretention is deferred to the Copilot Trust Center rather than published in the docs
Deployer / admin log accessNot stated for individual plansNot stated in the documents reviewed in this pass
Third-party attestationNot verified in this passGitHub's documentation defers certification detail to a trust portal that could not be read as published textNot verified in this passdeferred to a trust portal not published as static documentation
Commonly mistaken for — Individual - Free, Pro, Pro+ & Max

Microsoft 365 Copilot - a separate product under a separate agreement. Microsoft's HIPAA in-scope list names the Microsoft 365 Copilots but not GitHub Copilot. Also Copilot Business/Enterprise, where training exclusion is contractual rather than a user toggle

Commonly mistaken for — Business & Enterprise

Microsoft 365 Copilot, which is a different product with its own BAA coverage. Also the assumption that the individual opt-in toggle governs org plans - it does not; the exclusion is contractual

Source: https://docs.github.com/copilot/how-tos/manage-your-account/managing-copilot-policies-as-an-individual-subscriberDocument: GitHub Docs - Managing GitHub Copilot policies as an individual subscriberVerified: September 2, 2026Verified by: Adil — Shadow AI Forensics

Vendor terms change without notice. This page reflects what GitHub Copilot published as of September 2, 2026. Re-verified quarterly.

This page states what the vendor published. It does not score them.

If you need a scored Go / Conditional Go / No-Go verdict for a vendor decision — including a vendor not listed here — that's an AI Vendor Risk Assessment: three binary industry gates, nine scored criteria, four provenance fields on every finding. $997, delivered in 48 hours.

See how AVRA works →

Want all 13 tools in one file?

AI Vendor Compliance Quick-Reference

Covers 22 tiers across 13 tools — same sourcing, side by side, printable for a vendor file.