HIPAA-compliant analytics and data activation: Unlock marketing insights with Piwik PRO
Understand patient journeys, optimize campaigns, and increase engagement while ensuring patient data remains secure and compliant.
Healthcare marketing and data activation
Maximize efficiency with the all-in-one platform
Access four powerful modules – Analytics, Consent Manager, Tag Manager, and Customer Data Platform – via one interface.
Get started right away
Onboard quickly with an easy-to-use platform that is based on familiar concepts. Analyze your marketing results using intuitive reports, dashboards, and heatmaps.
Make compliance easy
Keep sensitive health information safe and protected according to the highest security standards with a customized business associate agreement (BAA).
Discover insights from real data
Collect patient data safely and get deeper insights that help you stand out from companies that rely on anonymous statistics.
Integrate smoothly
Connect Piwik PRO with other tools in your data ecosystem, including Google Ads, Search Console, server-side tagging, CRMs, and more.
Get robust support and training
Take advantage of a large library of training materials and robust support to maximize the potential of your analytics and data activation platform.
What you can do with Piwik PRO
Reliable data at scale
Get complete and accurate data thanks to: unsampled and raw data, full data control, dedicated technical support and more. Use Tag Manager for more flexibility and Consent Manager for more control over data privacy.

Improve data control and quality
Improve the security and accuracy of your insights with server-side tracking possibilities available in Piwik PRO, and enjoy seamless integrations with platforms such as server-side Google Tag Manager, Jentis, Stape and TAGGRS.

More control, less effort
Quickly create, test and deploy tags from customizable templates. Coordinate tag behavior with Analytics, Customer Data Platform and Consent Manager to fit any data collection approach.

Boost sales, adoption, and acquisition with the right data
Understand who your customers are and how they interact with you across channels. Act on these insights to provide a personalized customer experience and optimize your campaigns. Respect user privacy every step of the way.

Meet your analytics & privacy needs
Get more data from more sources thanks to Piwik PRO’s flexible data privacy capabilities. Comply with regulations all over the world, such as HIPAA, GDPR and CCPA.

Success Story
Rochester Regional Health boosts its campaign and content performance with HIPAA-compliant insights gathered with Piwik PRO
“Piwik PRO felt familiar with both the UI and metrics. It has a low learning curve due to its similarity to Google Analytics, and we wanted to continue tracking all of the information we historically wished to capture in a HIPAA-compliant and easy way. We considered the price point, familiarity, capabilities, and functionality. The combination of all these factors led us to choose Piwik PRO. There wasn’t any other option on the market that allowed us to capture all the data we wanted and ensure it was HIPAA-compliant.”
Tyler Pierce
Manager, Digital Engagement at Rochester Regional Health
Piwik PRO analytics for healthcare in practice
Enhance marketing effectiveness
Measure the success of outreach initiatives, such as health awareness campaigns or patient education programs, and adjust strategies to drive stronger results.
Elevate patient engagement with data activation
Personalize patient experiences and deliver meaningful recommendations using a customer data platform for targeted email campaigns and on-site personalization.
Improve the ROI of your ad campaigns
Gain deeper insights into the performance of your Google Ads and other platforms, and activate actionable data directly – all while ensuring the protection of sensitive health information.
Improve SEO
Boost your website’s visibility by identifying trending topics and high-traffic keywords. Optimize content to improve search rankings and meet patient expectations, driving more traffic to your site.
Understand patients and their needs
Gain a holistic view of every digital touchpoint your patients encounter. Analyze user flow and funnel data to understand traffic sources through your website, social media, or email campaigns.
Optimize conversion rates
Streamline the patient journey from scheduling to service. Send conversion data like GCLID to refine targeting and boost performance.

The guide to HIPAA compliance in analytics
Learn how to make your company HIPAA-compliant in analytics, marketing and advertising, and find vendors who take compliance seriously.
How Piwik PRO keeps you aligned with HIPAA
Customizable BAA
Partner with us to enhance your healthcare marketing efforts with a customizable Business Associate Agreement (BAA) tailored to your needs, regardless of your chosen hosting option. Ensure joint compliance and liability for the provided services and establish clear responsibilities concerning PHI/ePHI.
Tailored compliance features
Piwik PRO offers HIPAA-compliant analytics with 256-bit AES encryption for ePHI and comprehensive audit logs to track user activity. These features protect patient data while providing valuable insights, enhancing accountability and building customer trust in your healthcare marketing strategy.
HIPAA certified
Piwik PRO has passed a comprehensive HIPAA-compliance analytics assessment as part of our SOC-2 Type II audit. Safeguard your patients’ sensitive health data with confidence, knowing you’re working with a vendor that meets the highest standards for security and compliance.
Anonymization options
Disable the collection of IP addresses and other identifiers. Reduce the risk of exposing PHI and ensure no location data is inadvertently collected. Protect patient privacy and focus on broad demographic trends without compromising sensitive information.
100% data control
Be the sole controller of granular information on visitors and access it at any time. Decide what ePHI you collect and how you use it to provide the best patient experience. We never use your data for other purposes or share it with third parties.
Secure backup storage and hosting
Use safe backup solutions that replicate sensitive data to HIPAA-compliant Microsoft Azure data centers. Support consistent marketing efforts with backup options in the US cloud or 60+ private cloud locations.
Success Story
Shepherd Center increased patient referrals by 40% with Piwik PRO as their HIPAA-compliant analytics platform
“As part of our marketing objectives to drive patient referrals, we partnered with Piwik PRO to gain valuable insights into the user experience on our referral web pages and the referral process. After enhancing our on-page content, we saw a remarkable 215% increase in page views and a 79% drop in bounce rates, resulting in a 40% rise in online referrals. We have created more engaging content that is easier to navigate, making our website a better patient-centered referral experience.”
Kelsey Harris
Web Strategist at Shepherd Center
Resources on HIPAA-compliant analytics
We’ve gathered our content on HIPAA to help you evaluate your organization’s compliance and understand the requirements to comply with the law. Learn how to collect and process patient data online, what security measures to apply across your organization and tech, and how to find a HIPAA-compliant analytics vendor.
-
Is Google Analytics HIPAA-compliant?
Disclaimer: This blog post is not legal advice. Piwik PRO provides privacy-friendly analytics software, but does not provide legal consultancy. If you’d like to make sure you’re in compliance with HIPAA guidelines, we encourage you to consult an attorney. SUMMARY Healthcare organizations use analytics platforms to collect and analyze data about their patients. The data…
-
The AHA’s lawsuit against HHS guidance on online tracking technologies: What it means for HIPAA-covered entities and their use of analytics
On June 20, 2024, a US district court ruled in favor of the American Hospital Association’s (AHA) lawsuit against the Department of Health and Human Services (HHS) bulletin on using online tracking technologies, declaring it beyond agency authority. The 2022 bulletin sought to inform entities regulated under HIPAA of their obligations concerning the use of…
-
HHS guidance on using online tracking technologies: How to make your analytics HIPAA-compliant
In December 2022, the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued guidance on online tracking technology to HIPAA-covered entities. The bulletin details healthcare companies’ use of third-party cookies, pixels and other tracking technologies and elaborates on the definition of protected health information (PHI) that HIPAA refers to.HHS’s bulletin…
-
HIPAA, marketing and advertising: How to run compliant campaigns in healthcare
Disclaimer: This blog post is not legal advice. Piwik PRO provides privacy-friendly analytics software, but doesn’t provide legal consultancy. If you’d like to make sure that you comply with HIPAA guidelines, we encourage you to consult an attorney.Healthcare organizations deal with tons of sensitive information concerning people’s health. It needs to be handled with proper…
-
A review of HIPAA-compliant analytics platforms
Disclaimer: This blog post is not legal advice. Piwik PRO provides privacy-friendly analytics software, but doesn’t provide legal consultancy. If you’d like to make sure that you comply with HIPAA guidelines, we encourage you to consult an attorney.Collecting and analyzing user data is essential to healthcare businesses that want to build relationships with prospects, better…
-
PHI and PII: How they impact HIPAA compliance and your marketing strategy
Disclaimer: This blog post is not legal advice. Piwik PRO provides privacy-friendly analytics software, but doesn’t provide legal consultancy. If you’d like to make sure that you comply with HIPAA guidelines, we encourage you to consult an attorney. Personally identifiable information (PII) and protected health information (PHI) may seem similar. However, there are critical distinctions…
Sign up for a free 6-month Piwik PRO Analytics Suite trial covered by a BAA and safely unlock the power of patient insights with an integrated customer data platform.
FAQ
Who must follow HIPAA requirements?
The HIPAA rules apply to any individual or organization that meets the definition of a covered entity as stated in HIPAA guidelines.
Covered entities include:
- Health plans – for example, health insurance companies, HMOs, company health plans, and certain government programs that pay for health care, such as Medicare and Medicaid.
- Healthcare providers that conduct certain business electronically, such as electronically billing your health insurance – including most doctors, clinics, hospitals, psychologists, chiropractors, nursing homes, pharmacies, and dentists.
- Health care clearinghouses – entities that process nonstandard health information they receive from another entity into a standard (i.e., standard electronic format or data content), or vice versa.
Beyond covered entities, the following must adhere to HIPAA:
- Business associates
- Subcontractors
- Hybrid entities
- Researchers
A business associate can be an individual or company that provides services to a HIPAA-covered entity that requires them to have access to, store, use, or transmit protected health information. Generally, an analytics vendor will be a business associate.
What is PHI and its electronic version (called ePHI) under HIPAA?
PHI and ePHI is a subset of personally identifiable information (PII) that refers explicitly to information processed by HIPAA-covered entities. When health information is combined with a personal identifier, the data becomes PHI.
Examples of health information include:
- Medical test results
- Prescription or treatment records
- Billing information
- Appointment scheduling information
When health information is combined with a personal identifier, the data becomes PHI.
The Department of Health and Human Services (HHS) lists the 18 HIPAA identifiers:
- Name
- All geographic subdivisions smaller than a state (street address, city, county, zip code)
- Dates, including birthdate, admission date, discharge date, and date of death
- Telephone number
- Fax number
- Email address
- Social Security number
- Medical record number
- Health plan beneficiary numbers
- Account number
- Certificate/license number
- Vehicle identifiers and serial numbers, including license plate number
- Device identifiers and serial numbers
- Web URL
- IP address
- Biometric identifiers, including fingerprints and voice
- Full face photo
- Any other unique identifying number, characteristic, or code
This means that not all health information acquired by organizations is considered PHI. For example, phone numbers and residential addresses alone are not PHI. But this data will be considered PHI if it includes health information about an individual’s condition, the treatment of that condition, or the payment for the treatment. It also must be transmitted and maintained in any form by a covered entity.
Specific examples of PHI and ePHI include:
- Information your doctors, nurses, and other health care providers put in your medical record.
- Conversations your doctor has about your care or treatment with nurses and others.
- Information about you in your health insurer’s computer system.
- Billing information about you at your clinic.
Importantly, PII collected on a covered entity’s website or app is considered PHI even if the individual does not have an existing relationship with the entity or the PII does not include specific treatment or billing information. When a covered entity collects such information, it is indicative that the individual has received or will receive health care services or benefits from it.
Why is HIPAA compliance important?
HIPAA introduced several benefits for the healthcare industry to help transition from paper records to electronic copies of health information. HIPAA has helped to streamline administrative healthcare functions, improve efficiency in the healthcare industry, and ensure that protected health information is shared securely.
People now care about the privacy of their data more than ever. Health information is a special category of personal information because it contains details about users’ conditions that they may not want to disclose. Protecting the privacy of health-related data helps you maintain the trust of individuals whose information you are processing.
Neglecting users’ rights related to HIPAA can negatively affect your business and have a long-lasting impact on how patients view your organization. Since HIPAA is a standard that must be followed by many organizations similar to yours, the lack of compliance can make you lose business to your compliant competitors. Not to mention that any covered entity that violates HIPAA regulations can face civil action lawsuits, criminal charges, and hefty monetary penalties.
How can you stay compliant with HIPAA?
HIPAA makes covered entities responsible for complying with a number of rules – the Privacy Rule, Security Rule, Breach Notification Rule, Enforcement Rule, and Omnibus Rule. The first three rules are particularly important.
The Privacy Rule provides federal standards to protect the privacy of PHI – particularly, it:
- Limits how covered entities may use and disclose individually identifiable health information they receive or create.
- Gives individuals rights concerning their protected health information, including a right to review and obtain a copy of their medical records and the right to ask covered entities to amend the information if it is inaccurate or incomplete.
- Imposes administrative requirements for covered entities, such as training of employees concerning the Privacy Rule.
- Establishes civil penalties.
The Security Rule requires covered entities to maintain reasonable and appropriate administrative, technical, and physical safeguards to protect ePHI. Specifically, they must:
- Ensure the confidentiality, integrity, and availability of all e-PHI they create, receive, maintain, or transmit.
- Identify and protect against reasonably anticipated threats to the security or integrity of the information.
- Protect against reasonably anticipated, impermissible uses or disclosures.
- Ensure compliance by their workforce.
- Perform risk analysis as part of their security management processes.
The Breach Notification Rule requires covered entities and their business associates to provide notification following a breach of unsecured protected health information.
Is Piwik PRO HIPAA-certified?
Piwik PRO successfully passed a HIPAA compliance assessment as part of its SOC-2 Type II audit. This means Piwik PRO is HIPAA certified.
HIPAA certification proves that Piwik PRO Analytics Suite is a verified solution for customers whose policies mandate partnering exclusively with HIPAA-compliant vendors. This certification demonstrates our commitment to ensuring a HIPAA-compliant analytics suite safeguarding Protected Health Information (PHI).
How can you ensure you have HIPAA-compliant analytics?
You must apply a few safeguarding practices while collecting and processing data online. Some requirements you must fulfill include:
- Establish a business associate agreement (BAA) with every platform you use for marketing, advertising, and analytics and any other business associate. Otherwise, you cannot disclose PHI to that vendor without the individuals’ authorization.
- Address the use of analytics and other data platforms in your risk analysis and management processes.
- Implement administrative, physical, and technical safeguards – such as encrypting PHI transmitted to the analytics vendor and enabling and using appropriate authentication, access, encryption, and audit controls when accessing PHI maintained in the analytics platform infrastructure.
- Work with vendors that support values such as privacy by design to fully control and understand what data you collect, store, and transfer.
- Remove all 18 identifiers from PHI. Once the data is impossible to trace back to one individual, it is no longer PHI and no longer has protection under HIPAA.
Note: De-identification of PHI is not necessary with Piwik PRO – you can sign a BAA and send the desired PHI.
You need to carefully select an analytics vendor that would allow you to achieve HIPAA compliance – for example, don’t forget that Google Analytics is not HIPAA compliant.
You must either make an extra effort to avoid passing any trace of PHI to your analytics or switch to an analytics platform that will help you process patient data with the proper safeguards.
Want to learn more about how to make your analytics HIPAA-compliant?
We’re here to help and answer all your questions!