HIPAA Compliance

HIPAA Compliance 

Tremendous supports HIPAA compliance, and we can enter into a Business Associate Agreement (BAA) for qualifying customer programs.

If you are a Tremendous client and need a signed BAA, please reach out to your CSM or contact support at clients@tremendous.com 

Configuration Guidance 

Tremendous is SOC 2 Type II certified and supports programs that require HIPAA compliance. While Tremendous can be used as-is for many programs, the below features can be used depending on your internal policies.

What information Tremendous needs

To send a payout, Tremendous needs only a recipient's email address or phone number and the reward amount. No health information is required anywhere in the platform. A few fields are free text and fully controlled by your team — campaign names, team names, custom fields, and the message included with the payout. Teams that want to keep health information out of the platform entirely can keep those fields generic.

Team differentiation 

Create multiple teams per study/program to customize which users can see recipients participating across different studies. See here for how to configure. 

Custom roles and permissions

Assign custom roles and permissions to restrict which users can see payouts sent or other information by other users. See here for how to configure. 

Audit logs

Visibility into which users / user types are logging into the Tremendous account.

  • To view your Audit Logs, go to Audit Logs in the left-side column. 

    Screenshot 2026-07-27 at 8.15.39 AM.png

Team security settings

Require SSO or multi-factor authentication to configure and secure which users are able to log into the account.

PII-stripped emails

Remove the recipient email/phone number from failed delivery notifications to prevent personal information from being distributed via email.

 

Was this article helpful?

0 out of 0 found this helpful