At Piwik PRO, security and data protection have always been our top priority. Building privacy-friendly analytics is one part of that commitment, and we regularly invite independent auditors to evaluate our practices.
We’re pleased to share that our latest SOC 2 Type II audit was extended to include an assessment of our controls against the requirements of the HIPAA (Health Insurance Portability and Accountability Act) Security Rule. The independent assessment gives healthcare organizations additional assurance that the safeguards we use to protect data meet the standards HIPAA sets for covered entities and their business associates.
What this assessment means for our clients
HHS doesn’t offer or recognize any official HIPAA certification, so healthcare organizations have to judge for themselves whether a vendor can be trusted with protected health information (PHI). An independent assessment makes that judgment easier.
By extending our SOC 2 Type II audit to cover HIPAA Security Rule requirements, we give healthcare clients independent evidence that the administrative, physical, and technical safeguards protecting their data have been evaluated by an external auditor, not just described by us. In practice, this means:
- Faster vendor reviews. Security and compliance teams can rely on an independent audit report instead of starting their due diligence from scratch.
- Confidence in how PHI is handled. The assessment covers the controls that protect data processed in Piwik PRO, from access management to monitoring over time.
- A clear contractual foundation. We sign a business associate agreement (BAA) with healthcare clients, defining how we protect PHI and our responsibilities as a business associate.
How Piwik PRO supports HIPAA compliance
You may also like:
The assessment builds on safeguards that are already part of how Piwik PRO Analytics Suite works for healthcare organizations:
- Flexible options for handling PHI. Clients can configure data collection so that no PHI is collected, or sign a business associate agreement (BAA) with us to collect and process PHI in line with HIPAA requirements.
- Secure hosting. We host data in Microsoft Azure data centers that hold ISO 27001 certification, undergo SOC 2 audits, and are covered by Microsoft’s HIPAA BAA.
- Granular access controls. Clients can restrict data access to authorized personnel only.
- Detailed audit logs. Piwik PRO records data access and changes to data collection settings, so teams can track who did what and when.
HIPAA compliance is always a shared responsibility. Our safeguards cover the platform, while each organization remains responsible for how it configures tracking and uses the data it collects. We work with our healthcare clients to help them set up analytics that fits their compliance requirements.

