Secure Your Environment
Get a secure Google Analytics environment that keeps PHI within your control – and away from non-compliant third-parties
Block Sensitive PHI
De-Identify sensitive PHI with a private key before it hits Google Analytics' servers, allowing you to utilize the power of Google Analytics without identifying patients
Built on Salesforce Data Cloud
Unify patient data, take action in real-time, and leverage the power of Google Analytics in a secure environment.
Featured Resource
Navigating the Waters of HIPAA Compliance in Digital Marketing
This on-demand webinar helps you unlock the full potential of your healthcare marketing efforts while protecting patient privacy.
Watch Now →HHS recommends Customer Data Platforms for OCR Compliance
We check all the boxes of the latest OCR bulletin.
Questions and Answers
What is Google Analytics?
Google Analytics is a web tracking tool used by millions of businesses to analyze website traffic. It provides in-depth insights about visitor behavior, demographics, and website performance.
Is Google Analytics HIPAA Compliant?
Not out-of-the-box. According to Google themselves, "Customers who are subject to HIPAA must not use Google Analytics in any way that implicates Google’s access to, or collection of, PHI, and may only use Google Analytics on pages that are not HIPAA-covered."
Why isn't Google Analytics HIPAA compliant?
Because without proper configuration, websites with a Google Analytics tag disclose PHI to Google. Something as simple as a page title that contains a health condition could be considered a violation of HIPAA because that data can be paired with a user identifier.
Can Google Analytics be used in a HIPAA-Compliant manner?
Yes, by filtering sensitive PHI from reaching Google's servers. This requires the configuration of a server side container and de-identification of potential PHI.
How long does it take to implement a compliant solution?
It depends on the complexity of your Google Analytics environment and the number of events you are tracking. However, compliance can be reached in as little as two weeks.