We've been seeing more vendors, customers, and prospects asking about HIPAA compliant email services. Since Paubox is a Business Associate to thousands of customers, we’ve been wondering if they are able to use Instapage in a HIPAA compliant manner.
We know the HIPAA industry is vast, so we can empathize with just how many people need to use cloud services in this sector. Today we will determine if Instapage offers HIPAA compliant email marketing service or not.
Instapage allows users to build landing pages for online marketing and promotion campaigns. Their headquarters are a few blocks from us in San Francisco. If your landing pages are hosted by Instapage and wish to integrate them with a HIPAA compliant email marketing service, this post is for you.
What is a Business Associate?
A Business Associate is a person or company that performs certain functions or activities that involve the use or disclosure of protected health information (PHI) for a Covered Entity. In a nutshell, the role of a Business Associate is to help Covered Entities comply with the HIPAA Privacy Rule Read full article: What does it mean to be a Business Associate?
Business Associate Agreement provisions
If a Business Associate provides services to a Covered Entity, then a Business Associate Agreement (BAA) must be in place. A BAA is a written contract between a Covered Entity and a Business Associate and is required by law for HIPAA compliance. At a minimum, a Business Associate Agreement contains 10 provisions.
Read full article: Business Associate Agreement Provisions
Instapage and the Business Associate Agreement
We checked the Instapage site for mention of their ability to sign a Business Associate Agreement (BAA). We could not find any mention of PHI, Business Associate Agreement, or Business Associate on their site. While we did find several mentions of HIPAA ( here, here, here, here, and here), those mentions were not in relation to their ability to sign a BAA.
Does Interspire offer HIPAA Compliant Service?The Business Associate Agreement (BAA) is a key component to HIPAA compliance between a Covered Entity and a Business Associate. We were able to learn the following about Instapage:
- Instapage's marketing content lends itself towards abiding by HIPAA regulations
- They make no mention however, of their ability to actually sign a BAA with their customers
- While it may be argued they are excluded from HIPAA compliance regulations via the HIPAA Conduit Exception Rule, the argument for that case is not clear
Conclusion: Instapage does not make any mention of their ability to sign Business Associate Agreements with their customers. It's our conclusion that Instapage is not a HIPAA compliant solution provider.