HIPAA Compliance
Tremendous supports HIPAA compliance, and we can enter into a Business Associate Agreement (BAA) for qualifying customer programs.
If you are a Tremendous client and need a signed BAA, please reach out to your CSM or contact support at clients@tremendous.com
Configuration Guidance
Tremendous is SOC 2 Type II certified and supports programs that require HIPAA compliance. While Tremendous can be used as-is for many programs, the below features can be used depending on your internal policies.
What information Tremendous needs
To send a payout, Tremendous needs only a recipient's email address or phone number and the reward amount. No health information is required anywhere in the platform. A few fields are free text and fully controlled by your team — campaign names, team names, custom fields, and the message included with the payout. Teams that want to keep health information out of the platform entirely can keep those fields generic.
Team differentiation
Create multiple teams per study/program to customize which users can see recipients participating across different studies. See here for how to configure.
Custom roles and permissions
Assign custom roles and permissions to restrict which users can see payouts sent or other information by other users. See here for how to configure.
Audit logs
Visibility into which users / user types are logging into the Tremendous account.
-
To view your Audit Logs, go to Audit Logs in the left-side column.
Team security settings
Require SSO or multi-factor authentication to configure and secure which users are able to log into the account.
PII-stripped emails
Remove the recipient email/phone number from failed delivery notifications to prevent personal information from being distributed via email.
- Email clients@tremendous.com to have PII hidden in your account's emails.