HIPAA-compliant analytics with Piwik PRO Analytics Suite

Apply the highest privacy and security safeguards as you collect data and analyze the full customer journey on your website or app.

If you fall under HIPAA, you’re responsible for providing the right safeguard for US citizens’ protected health information (PHI). There are two routes you can take to achieve it when doing analytics. You can either de-identify all PHI in your data or sign a business associate agreement (BAA) with your vendor to ensure the compliant collection and processing of PHI and ePHI. Regardless of which option you choose, Piwik PRO will support you in achieving HIPAA compliance.

How Piwik PRO keeps you aligned with HIPAA

Secure hosting

Know the exact location of your data and keep it on HIPAA-compliant data centers maintained by Microsoft Azure. Choose the US cloud or one of 60+ private cloud locations (dedicated database or dedicated hardware).

Safe backup storage

Keep sensitive information thoroughly protected and get maximum recovery capability. Benefit from replication to another location in the same region.

100% data control

Be the sole controller of granular information on visitors and access it at any time. We never use your data for other purposes or share it with third parties. Decide what ePHI you collect and how you use it to provide the best patient experience. 

Audit log & change log

Monitor and review user activity in the analytics platform, such as login attempts, password updates, modification of the settings and API calls, and more. Keep logs of these actions to improve your risk management process. Utilize advanced user-permission options.

Customizable BAA

Sign a business associate agreement (BAA) with us regardless of which hosting option you choose. Ensure joint compliance and liability for the provided services and establish responsibilities concerning PHI/ePHI.

Integrations

Create a holistic view of your patients by combining first-party data from multiple touchpoints. Expand your marketing capabilities through integrations and natively available Tag Manager, Consent Manager, and CDP with data activation features.

Data encryption & transmission

Piwik PRO fulfills HIPAA requirements to encrypt ePHI when the data is at rest. We use 256-bit AES encryption with Microsoft Azure native encryption mechanisms and customer-managed keys, which prevents Microsoft from accessing unencrypted data.

Security measures

Piwik PRO follows ISO 27001 and SOC 2 standards, including HIPAA compliance attested as part of our SOC 2 Type II report. We are regularly audited and pen tested by independent auditors, which translates into enhanced measures for handling sensitive data, preventing data breaches, and much more. 

HIPAA compliant settings

Use a feature in our product to switch off the collection of visitors’ IP addresses. With this setting, IP addresses are not collected or stored anywhere in Piwik PRO, allowing you to enhance your HIPAA compliance.

The guide to HIPAA compliance in analytics

Learn how to make your company HIPAA-compliant in analytics, marketing and advertising, and find vendors who take compliance seriously.

“Working with health information means working with sensitive data, which makes privacy compliance the key aspect that healthcare organizations should focus on. Noncompliance with HIPAA regulations could result in sanctions, not to mention the looming loss of users’ trust. Choosing a compliant vendor, like Piwik PRO, helps you avoid those risks because data privacy and security are at the core of our business.”

Lisette Meij

Data Protection Officer at Piwik PRO

Resources on HIPAA-compliant analytics

We’ve gathered our content on HIPAA to help you evaluate your organization’s compliance and understand the requirements to comply with the law. Learn how to collect and process patient data online, what security measures to apply across your organization and tech, and how to find a HIPAA-compliant analytics vendor.

  • The AHA’s lawsuit against HHS guidance on online tracking technologies: What it means for HIPAA-covered entities and their use of analytics

    On June 20, 2024, a US district court ruled in favor of the American Hospital Association’s (AHA) lawsuit against the Department of Health and Human Services (HHS) bulletin on using online tracking technologies, declaring it beyond agency authority. The 2022 bulletin sought to inform entities regulated under HIPAA of their obligations concerning the use of…

    Read more

  • HHS guidance on using online tracking technologies: How to make your analytics HIPAA-compliant

    In December 2022, the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued guidance on online tracking technology to HIPAA-covered entities. The bulletin details healthcare companies’ use of third-party cookies, pixels and other tracking technologies and elaborates on the definition of protected health information (PHI) that HIPAA refers to.HHS’s bulletin…

    Read more

  • HIPAA, marketing and advertising: How to run compliant campaigns in healthcare

    Disclaimer: This blog post is not legal advice. Piwik PRO provides privacy-friendly analytics software, but doesn’t provide legal consultancy. If you’d like to make sure that you comply with HIPAA guidelines, we encourage you to consult an attorney.Healthcare organizations deal with tons of sensitive information concerning people’s health. It needs to be handled with proper…

    Read more

  • A review of HIPAA-compliant analytics platforms

    Disclaimer: This blog post is not legal advice. Piwik PRO provides privacy-friendly analytics software, but doesn’t provide legal consultancy. If you’d like to make sure that you comply with HIPAA guidelines, we encourage you to consult an attorney.Collecting and analyzing user data is essential to healthcare businesses that want to build relationships with prospects, better…

    Read more

  • PHI and PII: How they impact HIPAA compliance and your marketing strategy

    Disclaimer: This blog post is not legal advice. Piwik PRO provides privacy-friendly analytics software, but doesn’t provide legal consultancy. If you’d like to make sure that you comply with HIPAA guidelines, we encourage you to consult an attorney. Personally identifiable information (PII) and protected health information (PHI) may seem similar. However, there are critical distinctions…

    Read more

  • Is Google Analytics HIPAA-compliant?

    Disclaimer: This blog post is not legal advice. Piwik PRO provides privacy-friendly analytics software, but does not provide legal consultancy. If you’d like to make sure you’re in compliance with HIPAA guidelines, we encourage you to consult an attorney. Healthcare organizations use analytics platforms to collect and analyze data about their patients. The data helps…

    Read more

FAQ

Healthcare organizations that chose Piwik PRO:

Want to learn more about how to make your analytics HIPAA-compliant?

We’re here to help and answer all your questions!