HIPAA data
How to send lead and customer lists to Faraday when some of that data may be protected health information.
Faraday works with covered entities and their business associates: prescription retailers, clinics, insurers, and similar businesses. We sign Business Associate Agreements. This page explains how to send us lists of leads and customers without making an impermissible disclosure.
It is not a substitute for your own counsel. You decide, with your counsel, whether a given file is protected health information (PHI). Faraday treats your account as a HIPAA account when you tell us you may send PHI.
📘There is no HIPAA certification
HHS does not certify companies as HIPAA compliant. Faraday does not display HIPAA seals, and we will not tell your customers that a third party has reviewed your practices against HIPAA. What you get is a Business Associate Agreement plus the controls on this page.
Faraday's role
Faraday is a business associate when a covered entity or another business associate discloses PHI to us under a BAA.
- Your first-party data stays in your account. We do not use it to train other customers' models or to add records to the Faraday Identity Graph, which is commercially sourced consumer data, not PHI.
- Processing happens in the United States. The subprocessors that can see data we store are listed on Security.
- On a HIPAA-enabled account we turn off product analytics, error tracking, and in-app chat so row-level customer data cannot leak into those tools.
Is your list PHI?
HIPAA protects individually identifiable health information created or received by a covered entity or its business associate that relates to a person's health, the care they received, or payment for that care. Name, email, address, or phone is enough to identify the person. You do not need a diagnosis code on the row.
| What you send | Typical status if you are a covered entity |
|---|---|
| Prescription values, exam notes, diagnoses, claims, member IDs | PHI. Do not send unless your Faraday contact has agreed they are required. |
| People who completed an exam, got a prescription, or had insurance billed, even as bare name and email | Usually PHI. The row says the person received care from you. |
| People who bought non-prescription goods or joined a marketing list with no clinical relationship | Usually not PHI. |
Hashing an email does not change this: a hashed email plus the fact of care is still identifiable health information to anyone who can match the hash, and regulators have treated it that way. Stripping names is not de-identification either; if you plan to de-identify instead of signing a BAA, do it with counsel.
If you are a hybrid entity, only the health-care component is a covered entity. Your counsel should say which lists sit on which side of that line before you send them.
The default: do not send clinical columns
Most Faraday work does not need PHI. Send identity and commercial events. Faraday matches those people into the Identity Graph and builds models on graph attributes plus your commercial history. This is how Faraday already works with prescription retailers: the marketing team gets consumer context and predictions without waiting on clinical data.
Send: identity fields (name, postal address, email, phone), commercial events with dates and properties (purchased, started a home try-on, visited a store), and commercial traits (loyalty tier, order count, average order value).
Do not send: prescription numbers or values, exam findings or clinical notes, insurance member IDs or claim or procedure codes, or free-text fields that might contain any of those (notes, custom_1, chat transcripts).
🚧️Minimum necessary
If a model truly needs one clinical fact, such as "has an active prescription" as a yes/no, send that fact and nothing else. Name the column so a human can see what it is.
How to send the file
- Sign a BAA before any PHI leaves your systems. Ask your Faraday contact. We will not take PHI over email, Slack, or a support ticket while a BAA is in progress.
- Faraday enables HIPAA mode on the account after the BAA is in place.
- Use a connection or an in-app upload, never email. See how to upload PII. If you encrypt files yourself, use Faraday's public key.
- Review the column list with your Faraday contact the first time. It is cheaper to drop a column than to retrieve one.
What you can do with the results
The risk is usually not Faraday holding the file. It is where the output goes.
Fits a BAA. These stay inside your stack or inside Faraday:
- Enrich your own warehouse, CRM, or ESP with Faraday attributes and scores for people you already have.
- Train outcomes, persona sets, and recommenders on your commercial events.
- Score people already in the Identity Graph (lookalikes, market sizing) and take those scores back to your own systems.
- Deploy with a referenced representation so the file carries your key, not extra identifiers.
Needs a valid HIPAA authorization from each individual, and a cookie banner is not one (45 CFR 164.508):
- Uploading exam-completers, prescription buyers, or patients to an ad platform as a custom audience. Hashing the emails does not make it permitted, and Faraday's hashed representation is not de-identification.
- Putting a tracking pixel on a logged-in patient portal, appointment page, or intake form so an ad platform sees who they are.
- Retargeting people because of a clinical event.
To find more people like your patients without disclosing your patient list, train inside Faraday and score the Identity Graph, then activate those prospects through a channel you have a separate legal basis for. The scored prospects are not your patients, and the file is Faraday consumer data, not a copy of your patient file. Training on PHI is still a use of PHI, so confirm with your counsel that your BAA covers it when you execute the BAA.
What Faraday will not do
- Accept PHI before a BAA is signed
- Call you, or us, "HIPAA certified"
- Use your first-party data for any other account
- Enable third-party analytics or error tracking on a HIPAA-enabled account
- Put tracking technologies on your websites or apps
Getting set up
Talk to your Faraday contact, or talk to sales if you do not have one. They will execute the BAA, enable HIPAA mode, review the columns you plan to send, and confirm destinations.