The best HIPAA-compliant A/B testing tools
Contents
What do Optimizely, Convert, and Webtrends Optimize have in common?
- They're popular A/B testing tools
- None of them are HIPAA-compliant
And, while it's tempting to live without A/B testing for your healthcare product, doing so is like trying to navigate an ocean by sailing roughly in the correct direction. You'll probably arrive somewhere, but it won't be where you intended.
What you need for HIPAA compliance
You need to comply the Privacy Rule and the Security Rule. Breaching either can result in hefty financial penalties, but for the sake of this guide we're mostly interested in how the Privacy Rule impacts analytics and A/B testing.
There are three ways to comply with the Privacy rule when adopting analytics and testing tools:
Anonymize all PHI and identifiers: There are two so-called "De-identification Standards" – "Expert Determination," where an expert verifies that data isn't personally identifiable, and "Safe Harbor" where all 18 types of identifier are removed. The former is preferable simply because applying the Safe Harbor approach can render data effectively useless for analytical purposes.
Sign a BAA with a third-party tool: You must sign a Business Associate Agreement (BAA) with any third-party platform that handles your protected health information (PHI). This can mean signing multiple agreements, though, such as one with your analytical partner, but also any tools you use for importing and exporting data from your data warehouse.
Self-host and keep control of all your data: The less common is to self-host tools for analytics and experimentation on your own infrastructure. This reduces the number of BAAs and general legal wrangling needed to generate user insights. The only downside is you'll need the expertise to manage self-hosted instances, or third-party support to do so, and you are wholly liable for any security breaches.
These are the broad principles, but please consult an expert before making any final decision on how to implement tools in compliance with HIPAA.
The best HIPAA-compliant A/B testing tools
1. PostHog

Features
- Product analytics: ✔
- Web analytics: ✔
- Session replay: ✔
- Feature flags: ✔
- A/B testing: ✔
- Surveys: ✔
- Self-hostable: