HIPAA Compliance
Learn how to protect private health information and ensure your organization and Appcues account is compliant with HIPAA regulations.
Table of Contents
What is HIPAA?
HIPAA, is the Health Insurance Portability and Accountability Act, a United States law that regulates the sharing of Protected Health Information (PHI). More information about HIPAA and privacy can be found on the HHS.gov website.
What is unique about a HIPAA-compliant Appcues account?
Standard Appcues accounts are configured to keep data secure and confidential. However, to properly safeguard any PHI sent to Appcues, your analytics data will be stored in a database specifically certified for HIPAA compliance (by default all non-analytics data is stored in a HIPAA compliant way). In addition legal agreements need to be signed that clearly state Appcues and the customers responsibilities to maintain HIPAA compliance.
How do I enable my account for HIPAA compliance?
Please follow these steps:
- HIPAA compliance starts on the Appcues Enterprise plan levels; contact sales@appcues.com to discuss adding HIPAA compliance to your account. You will need your Appcues account ID. As a part of this step they will provide you documents to review and sign.
- To protect your data, you must implement Identity Verification and review and adopt any relevant security features described in the Shared Responsibility Model for Security and Privacy.
- You will need to sign the agreements provided by Appcues, including the Appcues Business Associate Agreement (BAA), and the Appcues Business Associate Addendum. If you have a preferred BAA, Appcues can sign it, but even in that case you must also sign the Appcues Business Associate Addendum.
- Once steps 1-3 are complete, the Appcues team can configure your account to be HIPAA compliant.
- Once configured, Appcues will sign and return your BAA, signaling that your account is fully HIPAA compliant to process PHI.
What is the Appcues Business Associate Addendum?
Under HIPAA regulations, SaaS providers such as Appcues are considered business associates. The Business Associate Addendum is an Appcues contract that is required by Appcues to ensure that Appcues can appropriately safeguard protected health information (PHI). The Addendum also clarifies and limits, as appropriate, the permissible uses and disclosures of PHI by Appcues, based on the relationship between Appcues and our customers and the activities or services being performed by Appcues.
More Information
Appcues has a comprehensive security program that is documented in our Trust Center. You can find the answers to many common HIPAA questions in our Trust Center FAQ.