Paubox blog: HIPAA compliant email - easy setup, no portals or passcodes

Is Affise HIPAA compliant? (2025 update)

Written by Kirsten Peremore | September 29, 2025

Affise is a performance marketing and affiliate tracking platform that helps advertisers, networks, and agencies run, track, and optimize partner marketing campaigns

Is Affise HIPAA compliant? No, based on our research, Affise is not HIPAA compliant.

 

Will Affise sign a business associate agreement (BAA)?

No, Affise will not sign a BAA and therefore is not HIPAA compliant.

 

What does Affise’s privacy/controls cover?

Affise’s e-privacy white paper describes its commitments to data protection and lists technical and organizational measures. It focuses on compliance with privacy laws such as GDPR and ePrivacy and explains controls such as access management, encryption at rest and in transit, logging, and incident response procedures. Key coverage items described in the white paper include:

  • Data minimization for tracking/attribution data.
  • Role-based access controls and staff security practices.
  • Encryption of sensitive data in transit and at rest where applicable.
  • Incident response and breach notification processes.

Conclusion

Affise does not sign a business associate agreement and is therefore not HIPAA compliant for handling PHI in typical covered-entity scenarios. Covered entities should not send PHI to Affise unless an executed BAA is in place.

Learn more: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is a business associate agreement?

A BAA is a legally binding contract establishing a relationship between a covered entity and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.

 

What is HIPAA?

HIPAA sets national standards for protecting the privacy and security of certain health information. HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, healthcare providers, health plans, and healthcare clearinghouses, and to business associates that perform services for covered entities and have access to PHI.