HIPAA Compliance

HIPAA Compliance 

 

Tremendous supports HIPAA compliance, and we can enter into a Business Associate Agreement (BAA) for qualifying customer programs.

 

  • If you are a Tremendous client and need a signed BAA, please reach out to your CSM or contact support at clients@tremendous.com 

 

Compliance Configuration Guidance 

Tremendous is SOC 2 Type II certified and supports programs that require HIPAA compliance. The optional account configuration steps below can further help your team minimize the protected health information (PHI) entered into the platform and support your own compliance efforts.

 

Team differentiation 

Create multiple teams per study/program to customize which users can see patients/recipients participating across different studies.

  • To get started with creating your teams, go to the dropdown in the upper left-hand column and select Create New Team.

     

Screenshot 2026-07-24 at 10.36.23 AM (1).png

 

Custom roles and permissions on rewards sent

Assign custom roles and permissions to restrict which users can see rewards sent or other information by other users.

  • To set custom roles and permissions, go to Team Settings > Users and Roles and select Roles.
Screenshot 2026-07-24 at 2.18.56 PM.png

Audit logs

Visibility into which users / user types are logging into the Tremendous account.

  • To view your Audit Logs, go to Audit Logs in the left-side column. 

    Screenshot 2026-07-27 at 8.15.39 AM.png

Team security settings

Require SSO or multi-factor authentication to configure and secure which users are able to log into the account.

  • To set Team Security settings, go to Team Settings > Security.
Screenshot 2026-07-14 at 2.55.11 PM.png

PII-stripped emails

Remove the recipient email/phone number from failed delivery notifications to prevent personal information from being distributed via email.

 

Was this article helpful?

0 out of 0 found this helpful