Can my organization use Qualtrics and be HIPAA compliant?

Featured image

Share this article

Can my organization use Qualtrics and be HIPAA compliant? | Paubox

We’ve been seeing more vendors, customers, and prospects asking about HIPAA compliant services.

Since Paubox is a Business Associate to thousands of customers, we’ve been wondering if they are able to use Qualtrics in a HIPAA compliant manner.

We know the HIPAA industry is vast, so we can empathize with just how many people need to use cloud services in this sector.

Today we will determine if Qualtrics offers HIPAA compliant service or not.

Qualtrics

Qualtrics is an experience management company with co-headquarters in Provo and Seattle. The company was founded in 2002 by Scott M. Smith, Ryan Smith, Jared Smith, and Stuart Orgill.

In 2018, SAP announced it would acquire Qualtrics for $8 billion.

What is a Business Associate?

A Business Associate is a person or company that performs certain functions or activities that involve the use or disclosure of protected health information (PHI) for a Covered Entity.

In a nutshell, the role of a Business Associate is to help Covered Entities comply with the HIPAA Privacy Rule

Read full article: What does it mean to be a Business Associate?

Secure email for modern healthcare. Right out of the box.

Business Associate Agreement provisions

If a Business Associate provides services to a Covered Entity, then a Business Associate Agreement (BAA) must be in place.

A BAA is a written contract between a Covered Entity and a Business Associate and is required by law for HIPAA compliance.

At a minimum, a Business Associate Agreement contains 10 provisions.

Read full article: Business Associate Agreement Provisions

Qualtrics and the Business Associate Agreement

We checked the Qualtrics site for mention of their ability to sign a Business Associate Agreement (BAA).

On the Qualtrics Security page, we see that Qualtrics attained HITRUST CSF certification for at least one of their products. On the Qualtrics Security Statement page, we see they completed HITRUST CSF certification in September 2018.

As we saw with our own HITRUST journey a few years ago, this is certainly an attestation of commitment towards data privacy and security.

In addition, we found an answer about HIPAA compliance in the Qualtrics discussion forum.


Can my organization use Qualtrics and be HIPAA compliant? | Paubox


In a nutshell, we found further evidence that Qualtrics does in fact support HIPAA compliance for at least one of its products.

Does Qualtrics offer HIPAA Compliant Service?

The Business Associate Agreement (BAA) is a key component to HIPAA compliance between a Covered Entity and a Business Associate.

Conclusion: Not only can Qualtrics sign a BAA with its customer base, but it also achieved HITRUST CSF certification for at least one of its products in 2018.

Qualtrics can be configured as a HIPAA compliant cloud provider.

Try Paubox Email Suite for FREE today.
Author Photo

About the author

Hoala Greevy

Founder of Paubox. Kayak fishing when I can. Native Hawaiian CEO.

Read more by Hoala Greevy

Get started with
end-to-end protection

Bolster your organization’s security with healthcare’s most trusted HIPAA compliant email solution

The #1-rated email encryption 
and security software on G2

G2 Badge: Email Encryption Leader Fall 2022
G2 Badge: Security Best Usability Fall 2022
G2 Badge: Encryption Momentum Leader Fall 2022
G2 Badge: Security Best Relationship Fall 2022
G2 Badge: Security Users Most Likely to Recommend Fall 2022
G2 Badge: Email Gateway Best Relationship Fall 2022
G2 Badge: Email Gateway Best Meets Requirements Fall 2022
G2 Badge - Users Most Likely to Recommend Summer 2022
G2 Badge: Email Gateway Best Results Fall 2022
G2 Badge: Email Gateway Best Usability Fall 2022
G2 Badge: Email Gateway Best Support Fall 2022
G2 Badge: Email Gateway Easiest To Use Fall 2022
G2 Badge: Email Gateway Easiest Setup Fall 2022
G2 Badge: Email Gateway Easiest Admin Fall 2022
G2 Badge: Email Gateway Easiest to do Business with Fall 2022
G2 Badge: Email Gateway Highest User Adoption 2022
G2 Badge: Email Gateway High Performer Fall 2022
G2 Badge: Email Gateway Momentum Leader Fall 2022
G2 Badge: Email Gateway Most Implementable Fall 2022
G2 Badge: Email Gateway Users Most Likely to Recommend Fall 2022