Compliance question

Is Bloomz HIPAA compliant?

Bloomz does not claim to be. There is one sentence on its security page that gets misread as a HIPAA claim, and understanding why it is not one is genuinely useful, because the same confusion will come up with the next vendor you evaluate.

What Bloomz claims for itself.

Bloomz was created to facilitate communication between schools and families in a safe and private environment. To provide this, Bloomz complies with regulations like FERPA and COPPA and all applicable privacy laws, and is a signatory of the Student Privacy Pledge.

Bloomz, Bloomz Security Pledge · checked August 26, 2026

Schools and families, FERPA and COPPA, the Student Privacy Pledge. The sentence names its sector in its first clause. This is a school product describing itself accurately.

Now the sentence that causes the trouble.

Further down the same page, in a section on physical and network security:

The AWS infrastructure is managed in compliance with standards including HIPAA, SOC 1/2/3, PCI DSS Level 1, ISO 27001, FedRAMP, FISMA, ITAR and FIPS 140-2.

Bloomz, Bloomz Security Pledge · checked August 26, 2026

Read the subject of that sentence. It is the AWS infrastructure, not Bloomz. Bloomz is telling you who its hosting provider is and what that provider is audited against. It is not a claim about the Bloomz application, and Bloomz does not present it as one.

Three layers, and only one of them is settled.

This is the part worth taking away, because it applies to every vendor you will assess after this one. Compliance does not travel up the stack on its own.

The hosting provider can be HIPAA-eligible.

AWS runs a compliance programme, will sign a BAA with its own customers, and publishes a list of HIPAA-eligible services. That is genuine and it is what Bloomz is describing. It means the data centre and the underlying services are capable of carrying PHI lawfully.

The application on top may or may not be.

HIPAA obligations attach to how the application handles PHI: access controls scoped to the right people, audit logging you can produce on demand, retention and disclosure records, breach procedures, and a workforce trained on all of it. None of that is inherited from the host. You can build a flagrantly non-compliant product on compliant infrastructure without trying.

And the vendor still has to sign.

AWS signing a BAA with Bloomz does nothing for you. Your clinic needs a BAA between your clinic and Bloomz. That chain does not assemble itself, and a vendor whose compliance page names FERPA and COPPA as its own frameworks is telling you which chain it has built.

This is the most abused sentence in the category.

Comparison pages routinely cite the AWS line as evidence that a school app "mentions HIPAA", either to imply it is compliant or to imply it is being sneaky. Neither is fair. Bloomz is accurately describing its host in a section about physical and network security, which is where that information belongs.

What this means if you are running Bloomz today.

If you are a school or a preschool, very likely nothing. Bloomz is built for you and its statements cover your situation.

If you are an ABA clinic billing a health plan, you are holding clinical information about children in a tool that has not agreed to hold it, and the exposure is usually broader than people expect once photographs and free-text notes are counted. The practical route out is to work out what would have to be true of a replacement, which is the subject of choosing a parent communication app for an ABA clinic.

Questions clinics ask about this.

Is Bloomz HIPAA compliant?

Bloomz makes no claim to be. Its security pledge states that Bloomz was created to facilitate communication between schools and families, and that it complies with regulations like FERPA and COPPA and all applicable privacy laws, and is a signatory of the Student Privacy Pledge. Those are education-sector frameworks. For a clinic that is a covered entity, the absence of a HIPAA claim and of a BAA offer is the operative fact.

But the Bloomz security page mentions HIPAA. Does that not count?

It mentions HIPAA in a list of standards that Amazon’s infrastructure is managed against, in a section about physical and network security. That is a statement about AWS, not about Bloomz. Infrastructure being HIPAA-eligible is a precondition for a compliant application, never a substitute for one, and it creates no agreement between your clinic and Bloomz.

Does Bloomz sign a business associate agreement?

We have found no offer of a BAA in Bloomz’s published security documentation. Ask them directly and get any answer in writing. A vendor that describes its own compliance in FERPA and COPPA terms is generally not set up to act as a business associate, but the vendor is the authority on that, not us.

What is the Student Privacy Pledge?

A voluntary industry commitment about how student data is handled, principally around not selling it or using it for targeted advertising. It is a good thing for a school vendor to sign and it is entirely unrelated to HIPAA. It is another marker of which sector the product was designed for.

Multiple clinics in our group each picked a different one of these apps. Where do we start?

Start by finding out which of them hold anything that identifies a child plus anything clinical, because that is the exposure, and it is usually wider than expected once you count photos and free-text notes. Then consolidate onto one tool that will sign a BAA. The standardisation problem and the compliance problem have the same fix, which is the one piece of good news here.

Related

Sources

Every claim about another product on this page is a quote from that product’s own documentation, linked below with the date we last read it there. Vendors revise these pages. If you find one of these out of date, tell us and we will correct it.

  1. [1] BloomzBloomz Security Pledge · checked August 26, 2026
  2. [2] BloomzBloomz Security Pledge · checked August 26, 2026

Show us what you are using now.

Fifteen minutes. If what you have works for your caseload, we will tell you to keep it.