BAA Generator
HomeResourcesDoes FullStory Sign a HIPAA BAA?
Vendor BAA Guide

Does FullStory Sign a HIPAA Business Associate Agreement?

By BAA Generator Editorial  ·  Published Apr 20, 2026  ·  Last reviewed Apr 20, 2026  ·  5 min read

Key Takeaways

Direct answer: Yes — FullStory signs a HIPAA BAA for Enterprise plan customers. However, a signed BAA alone is not sufficient for HIPAA compliance with FullStory. Session replay tools are among the highest-risk vendor categories for PHI capture, and FullStory's privacy masking must be carefully configured to block all health-related form inputs and content before use on any health application.

FullStory is a digital experience intelligence platform that provides session replay, heatmaps, product analytics, and user behavior tracking. Healthtech companies use FullStory to understand how patients and providers navigate their applications — but the same technology that makes FullStory powerful also makes it uniquely dangerous for PHI exposure. Session replay tools can capture virtually everything a user does on a page, including health information they type into forms.

FullStory Plan Coverage for HIPAA BAA

Plan BAA Available? Notes
Free No BAA Not suitable for any health application with PHI
Business No BAA standard Custom pricing; BAA not included
Enterprise Yes — BAA available Custom pricing; request BAA through FullStory sales

Why Session Replay Tools Are the Highest-Risk Vendor Category for PHI

Most analytics tools receive data that you explicitly send to them — you control what events and properties are tracked. Session replay tools like FullStory work differently: they capture a near-complete recording of what happens in the browser, including:

HHS's Office for Civil Rights has specifically flagged session replay and tracking pixel technologies as PHI risk vectors in healthcare settings. Using these tools without a BAA and proper configuration is a high-profile compliance failure mode.

How to Get a HIPAA BAA from FullStory

FullStory's BAA is available through their Enterprise plan:

Configuring FullStory for HIPAA: Privacy Masking Requirements

Executing a BAA without configuring privacy masking creates false confidence. FullStory's privacy controls must be implemented at the engineering level:

For a comparison of session replay tools and their HIPAA eligibility, see our Hotjar HIPAA BAA guide. For healthtech startups building compliant analytics stacks, see our HIPAA BAA guide for healthtech startups.

Frequently Asked Questions

Does FullStory sign a HIPAA BAA?

Yes — FullStory signs a HIPAA BAA for Enterprise plan customers. Free and Business plans do not qualify. Request the BAA through FullStory sales as part of your Enterprise agreement.

Can FullStory session replays capture PHI?

Yes — FullStory can record keystrokes, form inputs, and page content that contain PHI if privacy masking is not configured. Health conditions, medications, symptoms, and other sensitive data entered or displayed on a page are at risk. Privacy masking rules must be configured to block PHI capture, and this configuration must be audited regularly.

Which FullStory plan includes a BAA?

FullStory's HIPAA BAA is available for Enterprise plan customers only. The free plan and Business plan do not qualify for HIPAA BAA coverage. Contact FullStory sales for an Enterprise quote.

How do I configure FullStory to be HIPAA compliant?

HIPAA-compliant FullStory use requires an executed Enterprise BAA plus properly configured privacy masking rules using FullStory's privacy API and element exclusion attributes. Apply masking to all health-related form fields and content areas, audit the configuration regularly, and test in staging to verify PHI is not captured before deploying to production.

Need a BAA for your FullStory integration?

Generate a HIPAA-compliant Business Associate Agreement in minutes — covers all vendor types, free to start.

Generate Your BAA Free →