FullStory is a digital experience analytics platform that helps businesses understand how users interact with their websites and applications. FullStory is HIPAA compliant based on several ways they meet data security guidelines.
FullStory is a digital experience analytics platform that helps businesses understand how users interact with their websites and applications. It provides:
The session replay feature is particularly notable. It captures a user's interactions during a website visit, allowing companies to see exactly what users saw, clicked, and experienced. This can be valuable for identifying usability issues, understanding customer behavior, and optimizing the user experience.
FullStory aims to provide comprehensive insights into user behavior to help businesses improve their digital products, troubleshoot issues, and ultimately enhance customer satisfaction.
FullStory demonstrates a strong commitment to data security through its access control and encryption measures, audit trail and monitoring, and compliance with GDPR, SOC 2, and SOC 3. Their ISO 27001 and ISO 27701 certifications further emphasize their willingness to protect the data shared with them.
The business associate agreement that was put in place further reinforces their compliance with HIPAA standards. Based on these factors, FullStory is HIPAA compliant.
Under the Health Insurance Portability and Accountability Act (HIPAA), a business associate agreement (BAA) is a crucial document that outlines the responsibilities of third-party vendors when handling protected health information (PHI). Any software or service that stores, processes, or transmits PHI on behalf of a healthcare entity is considered a business associate and should sign a BAA.
Given FullStory's functionalities, such as product analytics, data capturing, and session insights, it would likely be considered a business associate when utilized in healthcare environments.
We reviewed their official documentation to ascertain FullStory's commitment to HIPAA compliance. Upon reviewing their privacy help center articles, they state that they provide their BAA to support their customer's respective HIPAA obligations when using our services.
Their privacy help sector BAA mentions that they "like to have BAAs in place with customers that consider themselves a covered entity under HIPAA."
Go deeper: How to know if you're a business associate
FullStory takes data security seriously and implements several measures to protect the information it collects. Here are some key aspects of FullStory's approach to data security:
Related:
HIPAA compliance extends beyond just technical safeguards and software solutions. When evaluating a tool's or service's compliance, consider the following: