← Writing
Vendor Evaluation22 Jul 2026 · 11 min read

HIPAA Vendor Checklist for Analytics and Monitoring

Approve the exact telemetry flow, agreement, product, features, configuration, and operating evidence—not the vendor logo.

Direct answer: A BAA does not by itself approve an analytics or monitoring vendor for PHI. Map the complete data flow, verify the exact legal entity, plan, service, region, and features in scope, then prove the deployed configuration matches that approval. If any gate is unresolved, keep PHI out of the service.

Analytics and monitoring vendors often advertise security certifications, encryption, healthcare customers, or BAA availability. Those are useful discovery signals. They do not prove that a particular account, SDK, replay feature, AI assistant, export, integration, or support workflow may receive the data your application sends. HHS also says OCR does not endorse, certify, or recommend specific technology products.

HHS guidance says a provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate can be a business associate even when it stores encrypted ePHI without the key. The parties need an appropriate BAA, while the regulated organization remains responsible for its risk analysis, configuration, safeguards, and permitted disclosures.

For tracking technologies, use the current HHS page with its court-order notice. The notice says a federal court vacated the guidance only to the extent it treated an IP address plus a visit to an unauthenticated public page about a condition or provider as automatically triggering HIPAA obligations. Do not turn that narrow point into a general exemption for pixels, SDKs, authenticated pages, mobile apps, appointment flows, or other telemetry that actually includes PHI.

Sources reviewed 21 August 2026: current HHS business-associate, cloud, sample BAA, and tracking-technology guidance; current first-party Sentry, Firebase Crashlytics, Mixpanel, and Google Analytics materials linked below.

Scope: This is an engineering and procurement checklist for cross-functional review. It is not legal advice, a compliance determination, a vendor certification, or a guarantee that a configuration satisfies HIPAA.
Gate 1 · data boundary

Trace PHI and linkable metadata end to end

Begin with an observed data flow, not a sales questionnaire. Trace the browser tag or SDK through collection endpoints, processing, indexes, dashboards, alerts, exports, warehouses, integrations, support systems, subprocessors, backups, and AI features. Include development, staging, production, mobile, server, edge, and public-site surfaces.

Inventory intended fields and ambient data that frameworks collect automatically:

  • User, account, patient, member, appointment, encounter, and device identifiers
  • URLs, titles, referrers, query strings, search terms, and campaign parameters
  • Errors, stack traces, request or response bodies, headers, logs, breadcrumbs, and local variables
  • Events, properties, user or group profiles, cohorts, experiments, flags, session replay, heatmaps, and recordings
  • Clinical content, free text, documents, screenshots, attachments, prompts, model responses, and support artifacts
  • IP addresses, location, timestamps, installation, advertising, session, trace, and other linkable identifiers

Classify every field by source, purpose, identifiability, destination, retention, and owner. A pseudonym, hash, opaque ID, IP address, or device identifier is not automatically de-identified merely because a dashboard does not show a patient name. If the architecture claims a no-PHI boundary, enforce it with an allowlist and test the serialized payload, not only application source code.

Gate 2 · contract boundary

Verify the BAA and eligible-product scope

Collect the executed BAA, order form, master terms, DPA, covered-services schedule, feature terms, support policy, and subprocessor list as one evidence package. Record precedence and effective dates. A general corporate BAA does not necessarily cover every subsidiary, acquired product, beta, preview, AI feature, or third-party integration.

Scope itemDecision questionEvidence to retain
Parties and accountAre the correct customer entity, vendor entity, tenant, and order named?Signed BAA, order form, account ID
Plan and serviceIs the purchased analytics or monitoring product explicitly eligible?Covered-services list and plan schedule
FeaturesAre replay, logs, traces, profiles, surveys, AI, support, exports, and integrations included or excluded?Feature terms and written clarification
Environment and regionDoes coverage or processing change by cloud, region, mobile SDK, or environment?Architecture and data-location terms
SubprocessorsWhich entities may receive PHI, for what function and location, and do restrictions flow down?Dated list, notice terms, BAA language
Timing and changeWas coverage effective before the first event, and how are later contract changes accepted?Effective date and change-control record
Gate 3 · use and onward flow

Review permitted use, subprocessors, and secondary use

HHS describes BAA requirements covering permitted uses and disclosures, safeguards, incident reporting, subcontractor restrictions, and return or destruction at termination. Translate those clauses into the actual service design. Ask whether customer content or telemetry is used for product improvement, aggregated insights, benchmarking, advertising, abuse prevention, human support, or model training, and whether those uses are defaults, opt-ins, or contractually excluded.

  • Identify hosting, CDN, support, communications, AI-model, and professional-services subprocessors that can receive or access customer content.
  • Record processing purpose, country or region, data categories, access mode, and notice period for each relevant subprocessor.
  • Confirm how to object to a new subprocessor and what happens if the objection cannot be resolved.
  • Separate customer content from service telemetry or usage data and determine whether the contract treats each differently.
  • Require a fresh review when an AI assistant, replay product, warehouse connector, or acquisition adds a new processing path.
Gate 4 · configuration

Constrain collection and tracking features

SDK and tags

Field allowlists, explicit initialization, final send hooks, tag governance, consent behavior, IP handling, sampling, request filtering, and payload limits.

Rich capture

Replay masking and blocking, screenshots, heatmaps, DOM capture, network bodies, console logs, local variables, attachments, surveys, feedback, and profiling.

Identity

User and group profiles, device and installation IDs, advertising IDs, cookies, cross-domain linking, location, URL design, and correlation tokens.

Destinations

Alerts, email, chat, issue trackers, source control, warehouses, notebooks, exports, AI assistants, and vendor support tools.

Use deny rules as defense in depth, not as the primary schema. Prefer a small allowlist of controlled workflow states, stable error codes, and non-identifying technical attributes. Keep replay, advertising, cross-device identity, automatic page or screen capture, free-text feedback, and experimental or AI features off until each one has its own documented need and test evidence.

Gate 5 · lifecycle

Define retention, deletion, export, and termination

One retention number rarely describes the whole service. Record separate periods for raw events, profiles, replays, logs, traces, attachments, indexes, aggregates, archives, support tickets, exports, and backups. Identify whether retention is fixed, configurable by data type, or dependent on the plan.

  • Can an administrator delete one event, one user, a date range, an entire project, and all derived profiles or indexes?
  • Does deletion propagate to alerts, integrations, exports, warehouse copies, support cases, disaster-recovery media, and subprocessor systems?
  • What remains in backups, for how long, and under what restricted-use controls?
  • Can the organization export usable data and audit evidence before termination without creating an uncontrolled copy?
  • Who verifies deletion, what evidence is returned, and what happens when destruction is infeasible?

Test the lifecycle with synthetic canary records before PHI is permitted. Create a canary, find it through every supported surface, export it, delete it through the documented procedure, and confirm the expected result after indexing and backup windows. Record limits rather than claiming deletion is immediate or absolute when the evidence says otherwise.

Gate 6 · access and evidence

Control support access, administration, and exports

Map every human and machine path into production telemetry: employees, contractors, vendor support, professional services, subprocessors, service accounts, API tokens, alert recipients, export jobs, and linked applications. Require least privilege, SSO and MFA where available, separate production roles, narrowly scoped tokens, controlled emergency access, and prompt offboarding.

Ask whether vendor staff access is disabled by default or always possible, how customer authorization is recorded, whether access is time-bound, which roles can approve it, and whether the customer can see who viewed or exported data. A support policy that says access is limited is weaker evidence than a ticket, approval, timestamp, actor, action, and closure record.

Confirm that audit logs cover authentication, membership and role changes, settings, API tokens, retention, deletion, replay access, exports, integrations, support access, and administrative activity. Record log retention, immutability, export API, clock source, and review owner. HHS cloud guidance notes that HIPAA does not itself expressly require a cloud provider to give customers audit documentation or audit rights, so obtain the evidence needed for the organization's risk management through the BAA, SLA, or other terms.

Gate 7 · incident operations

Pre-plan accidental collection and vendor incidents

Assume a release will eventually bypass a filter or expose a new field. The joint runbook should state how to disable ingestion, revoke tokens, isolate integrations, preserve appropriate evidence, search and export affected records, restrict access, request deletion, and verify downstream handling. Keep breach and notification determinations with authorized privacy, security, and legal owners.

Incident questionRequired decision
Reporting channelNamed 24/7 security route, severity threshold, authentication method, and escalation contacts
Notice clockContractual timing, discovery definition, update cadence, and required content
InvestigationLog preservation, customer access to facts, subprocessor coordination, and evidence format
Containment and deletionWho can stop collection, quarantine data, remove active copies, and document backup handling
RecoveryConfiguration repair, credential rotation, validation tests, corrective actions, and closure approval
Gate 8 · continuous verification

Prove the configuration and monitor change

A questionnaire is a snapshot; deployed telemetry is a running system. Build synthetic tests that put unique canary values into URLs, headers, bodies, errors, logs, profiles, replays, attachments, and integration payloads. Inspect the serialized outbound request, the stored vendor record after server-side scrubbing, alerts, exports, support surfaces, and every downstream destination. Fail the release if prohibited values survive.

  • Save versioned exports or screenshots of approved organization, project, SDK, tag-manager, retention, access, replay, and integration settings.
  • Pin or inventory SDK and agent versions; review release notes and changed defaults before upgrades.
  • Monitor BAA, terms, DPA, eligible-product lists, security documentation, subprocessors, regions, support policy, and retention behavior.
  • Reassess before enabling new modules, preview features, AI capabilities, destinations, acquisitions, or plan changes.
  • Schedule periodic payload, access, export, deletion, incident-contact, and contract-scope tests with named owners.
Current vendor evidence

Use first-party terms as gates, not rankings

These examples show why brand-level labels are insufficient. They are not endorsements or a conclusion that any product is appropriate for a particular deployment.

  • Sentry: current first-party material for Seer references Sentry's HIPAA attestation and says DPA and BAA commitments apply when personal data or PHI is sent, including flow-down to infrastructure subprocessors used for Seer. That is still a prompt to verify the executed BAA, plan, service, AI feature, repositories, retention, support access, and integration scope.
  • Firebase Crashlytics: the current service terms say Google does not generally intend the service to create HIPAA obligations, makes no representation that it satisfies HIPAA requirements, and prohibits transmitting PHI without Google's prior written consent. Do not infer Crashlytics coverage from a separate Google Cloud BAA.
  • Mixpanel: the current terms classify PHI as prohibited information except as permitted by an executed HIPAA BAA. Verify the current BAA, order, features, region, tracking configuration, and downstream services before collection.
  • Google Analytics: Google says it offers no BAA for Google Analytics and directs HIPAA-regulated entities not to expose PHI to the service. Its guidance says tags should not be placed on HIPAA-covered pages. Treat Google Cloud and Google Analytics as separate contract and product boundaries.
Decision record

Do not approve with unresolved gates

DecisionMeaning
Approved for defined PHI flowExecuted BAA and approved account, products, features, data, subprocessors, configuration, lifecycle, access, incidents, and evidence
Approved for tested no-PHI flowArchitecture enforces an allowlisted schema and canary tests prove prohibited data is blocked across downstream copies
Synthetic pilot onlyIsolated environment with synthetic data while contract, configuration, or operating gates remain incomplete
Not approvedRequired agreement, eligible service, control, transparency, evidence, or operating capability is unavailable

Record the decision, exact account and environment, data classes, approved and prohibited features, configuration baseline, agreement versions, subprocessors, retention, deletion limits, integration inventory, test results, owners, expiration date, and reassessment triggers. The record should be specific enough that an engineer can decide whether a proposed SDK change or feature falls inside the approval.

Related reading

Apply the checklist

Transactional Email Providers

Apply BAA, data-flow, tracking, logging, and operational review to email delivery products.

Responding to Suspected PHI Exposure

Use the vendor incident channel, preserve records, scope downstream access, and keep notification decisions with authorized owners.

Amazon Macie for HIPAA

Use sensitive-data discovery to find possible PHI in S3 and route findings into a controlled response process.

Sentry vs Crashlytics

Compare monitoring contracts, data collection, and practical deployment boundaries.

Mixpanel vs Google Analytics

Compare healthcare product analytics and public-site measurement.

Configure Sentry Without PHI

Turn the vendor decision into SDK, scrubbing, replay, access, and testing controls.

Analytics Events Without PHI

Design a controlled event taxonomy and validation pipeline.

Vibe Coding and HIPAA

Separate prototype tools from production data planes, vendor agreements, safeguards, and operating evidence.

Official HHS references: business associates, cloud computing, sample BAA provisions, and tracking technology guidance and court notice.

Official vendor references: Sentry Seer data privacy overview, Sentry security, Firebase Crashlytics terms, Mixpanel terms, Mixpanel HIPAA program, and Google Analytics and HIPAA.

Need a vendor and BAA stack review?

I can help map the telemetry path, separate BAA coverage from product configuration, and turn vendor decisions into engineering controls.

Start a project inquiry

Please do not send patient information, PHI, credentials, or private system details by email.