HIPAA-enabled CMS
Describes the differences and the features that are excluded from a HIPAA-enabled CMS (SaaS).
A HIPAA-enabled CMS complies with HIPAA regulations, essential for healthcare organizations and businesses that handle Protected Health Information (PHI). Optimizely CMS includes auditing and security measures to protect patient data and ensure privacy.
NoteThis content also applies to the PaaS Portal and Deployment API.
ImportantA HIPAA-enabled CMS is not compatible with other non-HIPAA-enabled Optimizely products. Data exchange outside the platform is allowed only with other HIPAA-enabled integrations, ensuring data handling remains compliant. Ensure any integrations or additional tools you use are also HIPAA-compliant.
Features and third-party integrations in CMS that are not HIPAA-compliant are modified or restricted to ensure data exchanges are secure and compliant. The following features are excluded from CMS (PaaS and SaaS) for HIPAA compliance:
- SendGrid SMTP
- Production database exports
- Content sync-down
- Edge log exports
- Project migration
Differences between standard and HIPAA-enabled CMS offerings
The following table compares the standard and HIPAA-enabled CMS with specific capabilities and benefits relevant to healthcare organizations:
Aspect | Standard CMS | HIPAA-enabled CMS |
---|---|---|
Compliance and security | Standard security measures | Additional auditing and security for HIPAA compliance |
Feature and integration restrictions | Full feature and integration availability | Certain features and integrations restricted for HIPAA compliance |
Data exchange | Flexible data exchange options | Data exchange with HIPAA-enabled integrations only |
Exclusions in PaaS & SaaS | Features like SendGrid SMTP, database exports, and so on, are available | Excludes SendGrid SMTP, database exports, content sync-down, edge log exports, and project migrations |
Compatibility | Compatible with a wide range of Optimizely products | Not compatible with non-HIPAA-enabled Optimizely products |
Capabilities and benefits | General content management capabilities | Delivers personalized experiences based on health needs and history. Tests content, layouts, and campaigns for effectiveness. Provides analytics and insights into performance and behavior |
Updated 6 days ago