Skip to content

Commit

Permalink
Create 11_HIPAA.md
Browse files Browse the repository at this point in the history
  • Loading branch information
ironbrands16 committed Jul 11, 2023
1 parent 0e84725 commit 57a149b
Showing 1 changed file with 22 additions and 0 deletions.
22 changes: 22 additions & 0 deletions _docs/35_legal/11_HIPAA.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
---
title: HIPAA Compliance
category: legal
permalink: /hipaa
last_modified_at: 2023-07-11
---

## Is Simple Analytics compliant with HIPAA?

Simple Analytics can easily comply with HIPAA because **it does not collect any personally identifiable data from your visitors**. When no personally identifiable data are collected, the data we receive are not PHI and do not fall under the HIPAA Privacy Rule’s disclosure limitations.

In other words, **you don’t need to worry about HIPAA**.

## Why doesn’t Simple Analytics receive PHI?

Because we do not use cookies or other identifiers, we do not fingerprint users, either. In other words, **Simple Analytics is 100% tracking-free** and privacy-friendly. We only use visitors’ IP addresses for communication and drop them right after we serve requests- in other words, IP is never stored or used to track.

Using IP for communication without storing them is not considered collecting personal data. However, this could even be avoided altogether by implementing a proxy. This can be done easily by implementing a few lines of code on your website- click here for a [step-by-step guide](https://docs.simpleanalytics.com/proxy).

## Does Simple Analytics need a BAA?

You do not need a BAA to use Simple Analytics. You only need a BAA when an associate receives PHI from you. Since we do not receive any PHI, this is not relevant for Simple Analytics. Therefore, we do not qualify as Business Associates and do not require a BAA.

0 comments on commit 57a149b

Please sign in to comment.