HIPAA Compliance
Tremendous supports HIPAA compliance, and we can enter into a Business Associate Agreement (BAA) for qualifying customer programs.
- If you are a Tremendous client and need a signed BAA, please reach out to your CSM or contact support at clients@tremendous.com
Compliance Configuration Guidance
Tremendous is SOC 2 Type II certified and supports programs that require HIPAA compliance. The optional account configuration steps below can further help your team minimize the protected health information (PHI) entered into the platform and support your own compliance efforts.
Team differentiation
Create multiple teams per study/program to customize which users can see patients/recipients participating across different studies.
-
To get started with creating your teams, go to the dropdown in the upper left-hand column and select Create New Team.
Custom roles and permissions on rewards sent
Assign custom roles and permissions to restrict which users can see rewards sent or other information by other users.
- To set custom roles and permissions, go to Team Settings > Users and Roles and select Roles.
Audit logs
Visibility into which users / user types are logging into the Tremendous account.
-
To view your Audit Logs, go to Audit Logs in the left-side column.
Team security settings
Require SSO or multi-factor authentication to configure and secure which users are able to log into the account.
- To set Team Security settings, go to Team Settings > Security.
PII-stripped emails
Remove the recipient email/phone number from failed delivery notifications to prevent personal information from being distributed via email.
- Email clients@tremendous.com to have PII hidden in your account's emails.