Analytics and monitoring vendors often advertise security certifications, encryption, healthcare customers, or BAA availability. Those are useful discovery signals. They do not prove that a particular account, SDK, replay feature, AI assistant, export, integration, or support workflow may receive the data your application sends. HHS also says OCR does not endorse, certify, or recommend specific technology products.
HHS guidance says a provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate can be a business associate even when it stores encrypted ePHI without the key. The parties need an appropriate BAA, while the regulated organization remains responsible for its risk analysis, configuration, safeguards, and permitted disclosures.
For tracking technologies, use the current HHS page with its court-order notice. The notice says a federal court vacated the guidance only to the extent it treated an IP address plus a visit to an unauthenticated public page about a condition or provider as automatically triggering HIPAA obligations. Do not turn that narrow point into a general exemption for pixels, SDKs, authenticated pages, mobile apps, appointment flows, or other telemetry that actually includes PHI.
Sources reviewed 21 August 2026: current HHS business-associate, cloud, sample BAA, and tracking-technology guidance; current first-party Sentry, Firebase Crashlytics, Mixpanel, and Google Analytics materials linked below.
Trace PHI and linkable metadata end to end
Begin with an observed data flow, not a sales questionnaire. Trace the browser tag or SDK through collection endpoints, processing, indexes, dashboards, alerts, exports, warehouses, integrations, support systems, subprocessors, backups, and AI features. Include development, staging, production, mobile, server, edge, and public-site surfaces.
Inventory intended fields and ambient data that frameworks collect automatically:
- User, account, patient, member, appointment, encounter, and device identifiers
- URLs, titles, referrers, query strings, search terms, and campaign parameters
- Errors, stack traces, request or response bodies, headers, logs, breadcrumbs, and local variables
- Events, properties, user or group profiles, cohorts, experiments, flags, session replay, heatmaps, and recordings
- Clinical content, free text, documents, screenshots, attachments, prompts, model responses, and support artifacts
- IP addresses, location, timestamps, installation, advertising, session, trace, and other linkable identifiers
Classify every field by source, purpose, identifiability, destination, retention, and owner. A pseudonym, hash, opaque ID, IP address, or device identifier is not automatically de-identified merely because a dashboard does not show a patient name. If the architecture claims a no-PHI boundary, enforce it with an allowlist and test the serialized payload, not only application source code.
Verify the BAA and eligible-product scope
Collect the executed BAA, order form, master terms, DPA, covered-services schedule, feature terms, support policy, and subprocessor list as one evidence package. Record precedence and effective dates. A general corporate BAA does not necessarily cover every subsidiary, acquired product, beta, preview, AI feature, or third-party integration.
| Scope item | Decision question | Evidence to retain |
|---|---|---|
| Parties and account | Are the correct customer entity, vendor entity, tenant, and order named? | Signed BAA, order form, account ID |
| Plan and service | Is the purchased analytics or monitoring product explicitly eligible? | Covered-services list and plan schedule |
| Features | Are replay, logs, traces, profiles, surveys, AI, support, exports, and integrations included or excluded? | Feature terms and written clarification |
| Environment and region | Does coverage or processing change by cloud, region, mobile SDK, or environment? | Architecture and data-location terms |
| Subprocessors | Which entities may receive PHI, for what function and location, and do restrictions flow down? | Dated list, notice terms, BAA language |
| Timing and change | Was coverage effective before the first event, and how are later contract changes accepted? | Effective date and change-control record |
Review permitted use, subprocessors, and secondary use
HHS describes BAA requirements covering permitted uses and disclosures, safeguards, incident reporting, subcontractor restrictions, and return or destruction at termination. Translate those clauses into the actual service design. Ask whether customer content or telemetry is used for product improvement, aggregated insights, benchmarking, advertising, abuse prevention, human support, or model training, and whether those uses are defaults, opt-ins, or contractually excluded.
- Identify hosting, CDN, support, communications, AI-model, and professional-services subprocessors that can receive or access customer content.
- Record processing purpose, country or region, data categories, access mode, and notice period for each relevant subprocessor.
- Confirm how to object to a new subprocessor and what happens if the objection cannot be resolved.
- Separate customer content from service telemetry or usage data and determine whether the contract treats each differently.
- Require a fresh review when an AI assistant, replay product, warehouse connector, or acquisition adds a new processing path.
Constrain collection and tracking features
SDK and tags
Field allowlists, explicit initialization, final send hooks, tag governance, consent behavior, IP handling, sampling, request filtering, and payload limits.
Rich capture
Replay masking and blocking, screenshots, heatmaps, DOM capture, network bodies, console logs, local variables, attachments, surveys, feedback, and profiling.
Identity
User and group profiles, device and installation IDs, advertising IDs, cookies, cross-domain linking, location, URL design, and correlation tokens.
Destinations
Alerts, email, chat, issue trackers, source control, warehouses, notebooks, exports, AI assistants, and vendor support tools.
Use deny rules as defense in depth, not as the primary schema. Prefer a small allowlist of controlled workflow states, stable error codes, and non-identifying technical attributes. Keep replay, advertising, cross-device identity, automatic page or screen capture, free-text feedback, and experimental or AI features off until each one has its own documented need and test evidence.
Define retention, deletion, export, and termination
One retention number rarely describes the whole service. Record separate periods for raw events, profiles, replays, logs, traces, attachments, indexes, aggregates, archives, support tickets, exports, and backups. Identify whether retention is fixed, configurable by data type, or dependent on the plan.
- Can an administrator delete one event, one user, a date range, an entire project, and all derived profiles or indexes?
- Does deletion propagate to alerts, integrations, exports, warehouse copies, support cases, disaster-recovery media, and subprocessor systems?
- What remains in backups, for how long, and under what restricted-use controls?
- Can the organization export usable data and audit evidence before termination without creating an uncontrolled copy?
- Who verifies deletion, what evidence is returned, and what happens when destruction is infeasible?
Test the lifecycle with synthetic canary records before PHI is permitted. Create a canary, find it through every supported surface, export it, delete it through the documented procedure, and confirm the expected result after indexing and backup windows. Record limits rather than claiming deletion is immediate or absolute when the evidence says otherwise.
Control support access, administration, and exports
Map every human and machine path into production telemetry: employees, contractors, vendor support, professional services, subprocessors, service accounts, API tokens, alert recipients, export jobs, and linked applications. Require least privilege, SSO and MFA where available, separate production roles, narrowly scoped tokens, controlled emergency access, and prompt offboarding.
Ask whether vendor staff access is disabled by default or always possible, how customer authorization is recorded, whether access is time-bound, which roles can approve it, and whether the customer can see who viewed or exported data. A support policy that says access is limited is weaker evidence than a ticket, approval, timestamp, actor, action, and closure record.
Confirm that audit logs cover authentication, membership and role changes, settings, API tokens, retention, deletion, replay access, exports, integrations, support access, and administrative activity. Record log retention, immutability, export API, clock source, and review owner. HHS cloud guidance notes that HIPAA does not itself expressly require a cloud provider to give customers audit documentation or audit rights, so obtain the evidence needed for the organization's risk management through the BAA, SLA, or other terms.
Pre-plan accidental collection and vendor incidents
Assume a release will eventually bypass a filter or expose a new field. The joint runbook should state how to disable ingestion, revoke tokens, isolate integrations, preserve appropriate evidence, search and export affected records, restrict access, request deletion, and verify downstream handling. Keep breach and notification determinations with authorized privacy, security, and legal owners.
| Incident question | Required decision |
|---|---|
| Reporting channel | Named 24/7 security route, severity threshold, authentication method, and escalation contacts |
| Notice clock | Contractual timing, discovery definition, update cadence, and required content |
| Investigation | Log preservation, customer access to facts, subprocessor coordination, and evidence format |
| Containment and deletion | Who can stop collection, quarantine data, remove active copies, and document backup handling |
| Recovery | Configuration repair, credential rotation, validation tests, corrective actions, and closure approval |
Prove the configuration and monitor change
A questionnaire is a snapshot; deployed telemetry is a running system. Build synthetic tests that put unique canary values into URLs, headers, bodies, errors, logs, profiles, replays, attachments, and integration payloads. Inspect the serialized outbound request, the stored vendor record after server-side scrubbing, alerts, exports, support surfaces, and every downstream destination. Fail the release if prohibited values survive.
- Save versioned exports or screenshots of approved organization, project, SDK, tag-manager, retention, access, replay, and integration settings.
- Pin or inventory SDK and agent versions; review release notes and changed defaults before upgrades.
- Monitor BAA, terms, DPA, eligible-product lists, security documentation, subprocessors, regions, support policy, and retention behavior.
- Reassess before enabling new modules, preview features, AI capabilities, destinations, acquisitions, or plan changes.
- Schedule periodic payload, access, export, deletion, incident-contact, and contract-scope tests with named owners.
Use first-party terms as gates, not rankings
These examples show why brand-level labels are insufficient. They are not endorsements or a conclusion that any product is appropriate for a particular deployment.
- Sentry: current first-party material for Seer references Sentry's HIPAA attestation and says DPA and BAA commitments apply when personal data or PHI is sent, including flow-down to infrastructure subprocessors used for Seer. That is still a prompt to verify the executed BAA, plan, service, AI feature, repositories, retention, support access, and integration scope.
- Firebase Crashlytics: the current service terms say Google does not generally intend the service to create HIPAA obligations, makes no representation that it satisfies HIPAA requirements, and prohibits transmitting PHI without Google's prior written consent. Do not infer Crashlytics coverage from a separate Google Cloud BAA.
- Mixpanel: the current terms classify PHI as prohibited information except as permitted by an executed HIPAA BAA. Verify the current BAA, order, features, region, tracking configuration, and downstream services before collection.
- Google Analytics: Google says it offers no BAA for Google Analytics and directs HIPAA-regulated entities not to expose PHI to the service. Its guidance says tags should not be placed on HIPAA-covered pages. Treat Google Cloud and Google Analytics as separate contract and product boundaries.
Do not approve with unresolved gates
| Decision | Meaning |
|---|---|
| Approved for defined PHI flow | Executed BAA and approved account, products, features, data, subprocessors, configuration, lifecycle, access, incidents, and evidence |
| Approved for tested no-PHI flow | Architecture enforces an allowlisted schema and canary tests prove prohibited data is blocked across downstream copies |
| Synthetic pilot only | Isolated environment with synthetic data while contract, configuration, or operating gates remain incomplete |
| Not approved | Required agreement, eligible service, control, transparency, evidence, or operating capability is unavailable |
Record the decision, exact account and environment, data classes, approved and prohibited features, configuration baseline, agreement versions, subprocessors, retention, deletion limits, integration inventory, test results, owners, expiration date, and reassessment triggers. The record should be specific enough that an engineer can decide whether a proposed SDK change or feature falls inside the approval.
Apply the checklist
Transactional Email Providers
Apply BAA, data-flow, tracking, logging, and operational review to email delivery products.
Responding to Suspected PHI Exposure
Use the vendor incident channel, preserve records, scope downstream access, and keep notification decisions with authorized owners.
Amazon Macie for HIPAA
Use sensitive-data discovery to find possible PHI in S3 and route findings into a controlled response process.
Sentry vs Crashlytics
Compare monitoring contracts, data collection, and practical deployment boundaries.
Mixpanel vs Google Analytics
Compare healthcare product analytics and public-site measurement.
Configure Sentry Without PHI
Turn the vendor decision into SDK, scrubbing, replay, access, and testing controls.
Analytics Events Without PHI
Design a controlled event taxonomy and validation pipeline.
Vibe Coding and HIPAA
Separate prototype tools from production data planes, vendor agreements, safeguards, and operating evidence.
Official HHS references: business associates, cloud computing, sample BAA provisions, and tracking technology guidance and court notice.
Official vendor references: Sentry Seer data privacy overview, Sentry security, Firebase Crashlytics terms, Mixpanel terms, Mixpanel HIPAA program, and Google Analytics and HIPAA.
Need a vendor and BAA stack review?
I can help map the telemetry path, separate BAA coverage from product configuration, and turn vendor decisions into engineering controls.
Please do not send patient information, PHI, credentials, or private system details by email.