BAA Generator
HomeResourcesDoes FullStory Sign a HIPAA BAA?
Vendor BAA Guide

Does FullStory Sign a HIPAA Business Associate Agreement?

By BAA Generator Research Team  ·  Published Apr 20, 2026  ·  Last reviewed Apr 20, 2026  ·  4 min read

Need a BAA right now?

Generate my BAA → See pricing →

Key Takeaways

Direct answer: Yes — FullStory signs a HIPAA BAA for Enterprise plan customers. However, a signed BAA alone is not sufficient for HIPAA compliance with FullStory. Session replay tools are among the highest-risk vendor categories for PHI capture, and FullStory's privacy masking must be carefully configured to block all health-related form inputs and content before use on any health application.

FullStory is a digital experience intelligence platform that provides session replay, heatmaps, product analytics, and user behavior tracking. Healthtech companies use FullStory to understand how patients and providers navigate their applications — but the same technology that makes FullStory powerful also makes it uniquely dangerous for PHI exposure. Session replay tools can capture virtually everything a user does on a page, including health information they type into forms.

FullStory Plan Coverage for HIPAA BAA

Plan BAA Available? Notes
Free No BAA Not suitable for any health application with PHI
Business No BAA standard Custom pricing; BAA not included
Enterprise Yes — BAA available Custom pricing; request BAA through FullStory sales

Why Session Replay Tools Are the Highest-Risk Vendor Category for PHI

Most analytics tools receive data that you explicitly send to them — you control what events and properties are tracked. Session replay tools like FullStory work differently: they capture a near-complete recording of what happens in the browser, including:

HHS's Office for Civil Rights has specifically flagged session replay and tracking pixel technologies as PHI risk vectors in healthcare settings. Using these tools without a BAA and proper configuration is a high-profile compliance failure mode.

How to Get a HIPAA BAA from FullStory

FullStory's BAA is available through their Enterprise plan:

Configuring FullStory for HIPAA: Privacy Masking Requirements

Executing a BAA without configuring privacy masking creates false confidence. FullStory's privacy controls must be implemented at the engineering level:

For a comparison of session replay tools and their HIPAA eligibility, see our Hotjar HIPAA BAA guide. For healthtech startups building compliant analytics stacks, see our HIPAA BAA guide for healthtech startups.

Frequently Asked Questions

Does FullStory sign a HIPAA BAA?

Yes — FullStory signs a HIPAA BAA for Enterprise plan customers. Free and Business plans do not qualify. Request the BAA through FullStory sales as part of your Enterprise agreement.

Can FullStory session replays capture PHI?

Yes — FullStory can record keystrokes, form inputs, and page content that contain PHI if privacy masking is not configured. Health conditions, medications, symptoms, and other sensitive data entered or displayed on a page are at risk. Privacy masking rules must be configured to block PHI capture, and this configuration must be audited regularly.

Which FullStory plan includes a BAA?

FullStory's HIPAA BAA is available for Enterprise plan customers only. The free plan and Business plan do not qualify for HIPAA BAA coverage. Contact FullStory sales for an Enterprise quote.

How do I configure FullStory to be HIPAA compliant?

HIPAA-compliant FullStory use requires an executed Enterprise BAA plus properly configured privacy masking rules using FullStory's privacy API and element exclusion attributes. Apply masking to all health-related form fields and content areas, audit the configuration regularly, and test in staging to verify PHI is not captured before deploying to production.

More vendor BAA guides

Generate a compliant BAA in 5 minutes

HHS model BAA provisions · 45 CFR § 164.504(e) compliant · clean PDF + editable Word

No subscription · PDF + Word · Free watermarked preview

Related: Marketing, CRM & analytics

Frequently Asked Questions

Does FullStory sign a HIPAA BAA?
Yes — FullStory signs a HIPAA BAA for Enterprise plan customers. The free and standard Business plans do not qualify for a HIPAA BAA. Enterprise plan customers must request the BAA through FullStory sales and should also configure FullStory's privacy masking rules to prevent PHI capture.
Can FullStory session replays capture PHI?
Yes — FullStory session replay is extremely high-risk for PHI capture. FullStory can record keystrokes, form inputs, mouse movements, and page content in real time. On a health app or patient portal, this means FullStory can capture health conditions entered by users, medications, symptoms, demographic information, and other PHI. Privacy masking must be configured to block health-related form fields and content.
Which FullStory plan includes a BAA?
FullStory's HIPAA BAA is available for Enterprise plan customers only. The free plan and Business plan do not qualify for HIPAA BAA coverage. Contact FullStory sales to request an Enterprise quote that includes HIPAA BAA support.
How do I configure FullStory to be HIPAA compliant?
HIPAA-compliant FullStory use requires two things: (1) An executed BAA with FullStory on an Enterprise plan; and (2) Properly configured privacy masking rules that block FullStory from recording health-related form fields, PHI inputs, and sensitive page content. FullStory provides a privacy API and element-level exclusion rules. You must apply these rules to all pages and fields that could capture PHI, and audit them regularly as your application evolves.