Smarter Audience Targeting for Healthcare—Finally, It’s Compliant
Check it out
Login
Platform
Improve Marketing Performance
Drive growth without increasing budgets through better performance
Audiences
Smart, privacy-first targeting with lookalikes and retargeting lists
Healthcare Integrations
Bring full-funnel marketing to healthcare with 100+ integrations
Measure Marketing Impact
Prove marketing's value to unlock budget with real outcome data
Insights / Analytics
One dashboard with every channel's performance and real ROI metrics
Ad Performance
Optimize for patient visits, not form fills, with attended appointment data
Protect Privacy & Compliance
Safeguard your marketing strategy from compliance disruption
Web Tracker Manager
See every tracker on your site and identify compliance risks
Consent Management
Consent that actually works by enforcing preferences at the data layer
Event Tracking
Measure what users actually do, not just what they view on your site
Healthcare Solutions
By Healthcare Vertical
By Use Case
Hospitals & Healthcare Systems
Payers
Urgent Care
Pharma & Med Devices
Orthopedics
Specialty Providers
DSO & Dental
Improve Marketing Performance
Measure Marketing Impact
Protect Privacy & Compliance
Customers
Get started / for customers
Login
Docs
Freshpaint Status
Partner Directory
Featured Healthcare Case Studies
Allergy Partners
Dropped Their CPL from $300 to $12
BU Dental
Optimized their digital marketing, reducing CPA by 30%.
Baptist Health
Journey to HIPAA-Compliant Digital Marketing ipsum dolor sit
Explore all Case Studies
Product update
Freshpaint Audiences: Better ROI with Audience Targeting Built for Healthcare
Freshpaint Audiences gives healthcare marketers the power to run targeted ad campaigns that cut wasted spend, reach the right audience faster, stay fully privacy-compliant, and, most importantly, improve ROI.
Resources
Learn & Insights
Blog
Privacy Hub
FAQ
Prove your ROI
Marketing Hub
Events
Case Studies
Product update
Freshpaint Audiences: Better ROI with Audience Targeting Built for Healthcare
Freshpaint Audiences gives healthcare marketers the power to run targeted ad campaigns that cut wasted spend, reach the right audience faster, stay fully privacy-compliant, and, most importantly, improve ROI.
Plans & Pricing
Login
Book a Demo
Posted on 
April 22, 2022

What It Takes To Make A CDP HIPAA Compliant

Here’s a warning: software companies you might end up evaluating claim they’re HIPAA compliant, but they're not.

At Freshpaint, we’ve worked hand in hand with health tech companies like Osmind and Two Chairs to build a truly HIPAA compliant customer data platform that helps manage the flow of PHI to downstream tools.

And at the core of this is ID Masking, our de-identification feature.

How does de-identification work?

To make sure ID Masking is HIPAA compliant (and I’m going to get a bit technical here), we use cryptographic hashing. Hashing is like encryption, but it’s designed to be irreversible.

But hashing alone is not enough to be considered HIPAA compliant. You need to hash with a secret key (a secret key is like a password).

That’s because hashing without a secret key makes your data susceptible to a dictionary hack where the attackers could use cross-referencing of datasets to identify the user. In other words, a potential PHI disaster.

The US Department of Health & Human Services explicitly calls out that you must use a secret key or “salt” to ensure proper handling of PHI:

“A code corresponds to a value that is derived from a non-secure encoding mechanism. For instance, a code derived from a secure hash function without a secret key (e.g., “salt”) would be considered an identifying element. This is because the resulting value would be susceptible to compromise by the recipient of such data.”

The must haves for a HIPAA compliant CDP

Freshpaint’s ID Masking cryptographically hashes user identifiers using a secret key, and when running HIPAA mode, we require information sharing server to server, so that key will never be exposed. This is the right way to build a HIPAA compliant CDP.

So, for a customer data platform to be HIPAA compliant, we need:

  • A BAA
  • If you're sending data to third party tools de-identification that uses cryptographic hashing with a secret key
  • Must only share data server to server

What to look out for

So what should you look out for when you're evaluating vendors to help you build your customer data infrastructure?

Ask them how they handle data being sent to third party tools. We commonly see companies do de-identification without a secret key which is in clear violation of HIPAA when sending customer data to third party tools.

The other offender I’ve seen is when the code is built in a way that exposes the secret key. This is the same as not having the secret at all. Using that company’s software is going to expose you to HIPAA violations.

When evaluating tools to help manage your customer data, make sure you get more than “we sign a BAA” or “yes, we’re HIPAA compliant.” The details are key here.

If you have questions about keeping your customer data HIPAA compliant, reach out to us. We’d be happy to talk about it.

‍

Get Freshpaint in your email

If you want to learn how to be even more agile with customer behavioral data, join more than 3k+ others by signing up.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Michael Malis
Founder & CEO
view All Posts
Featured Posts
Hipaa Compliance
Direct Response, Remarketing, and Programmatic Advertising: The HIPAA Pitfalls You Didn't Know
Hipaa Compliance
IP Addresses and HIPAA Compliance: Unpacking the Risks for Healthcare Websites
Use Cases
Don't Remove It! Make Google Analytics HIPAA Compliant Instead
Hipaa Compliance
Staying HIPAA-Compliant: How to Detect Web Tracking Risks on Your Website
Hipaa Compliance
A Privacy-First Framework for HIPAA Compliance: Managing Third-Party Tracking on Healthcare Websites
Hipaa Compliance
Cut the Jargon: A Look at the FTC-HHS Privacy Warning and What It Means For Your Healthcare Org
Use Cases
How To Make Facebook Ads HIPAA Compliant and Still Get Conversion Tracking
Use Cases
What HHS Has to Say About Tracking Technologies in Latest HIPAA Guidance
Growth & Startups
Two Chairs Journey to a HIPAA Compliant Growth Stack
Stay Connected
Platform
Improve Marketing Performance
Audiences
Healthcare Integrations
Measure Marketing Impact
Insights / Analytics
Ad Performance
Protect Privacy & Compliance
Web Tracker Manager
Consent Management
Event Tracking
Healthcare solutions
Hospitals & Health Systems
Health Tech & Virtual Care
Payers & Health Plans
Urgent Care & Outpatient
Dental & Specialty Practices
Pharma & Medical Devices
DSO (Dental Support Organizations)
Orthopedics
Specialty Providers
Resources
FAQ
Blog
Events & Webinars
Marketing Hub
Privacy Hub
Newsletter Signup
About
About Us & Careers
News & Press
Plans & Pricing
Contact Us
Get a Demo
Case Studies
Customers
Login
System Status
Docs
Follow Us
Privacy Policy
Terms of Service
© 2025 Perfalytics, Inc. Crafted in San Francisco - Site By Takeoff®