HIPAA-compliant incentives: A guide for research and patient engagement teams

By Abby Quillen6 min. readAug 17, 2026

illustration of woman in healthcare giving an incentive

If you send healthcare incentives, questions about the Health Insurance Portability and Accountability Act (HIPAA) inevitably come up. 

Consider this common scenario: A clinical research team prepares to launch a study and partners with a new incentive provider to send participant stipends. Before approving the vendor, the legal department asks what participant data the provider will handle and whether a Business Associate Agreement (BAA) is required. What seemed like a routine vendor review quickly becomes a HIPAA issue. 

And it’s not just clinical research. Health plans and healthcare organizations face the same questions when sending patient or member incentives for wellness, preventive, or value-based care programs.

The tricky part is that the incentive itself doesn’t determine compliance. A gift card, stipend, or reimbursement is not inherently compliant or noncompliant.

HIPAA enters the conversation when your process for sending incentives links identifiable participant information to health-related data. What matters is how that information is collected, shared, stored, and protected.

This guide takes the guesswork out of HIPAA compliance for incentives. You’ll learn three questions that determine whether HIPAA applies to your incentive program, how to reduce risk, and what to look for when searching for a HIPAA-compliant incentive vendor. 

When does HIPAA apply to research and healthcare incentives?

HIPAA sets the rules for how covered entities and their business associates must use and disclose protected health information (PHI). The law doesn’t automatically apply to every healthcare, research, or patient incentive program. 

Answer these three questions to determine whether it applies to yours.

1. Is your organization a covered entity or a business associate?

HIPAA-covered entities include health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically to process standard transactions, such as insurance claims and eligibility checks.

Business associates are a separate category. These are vendors or partners that contract with covered entities and handle PHI on their behalf. Both covered entities and business associates have obligations under HIPAA.

If your organization doesn’t fall into either category, HIPAA likely doesn’t apply to your incentive program, but other privacy laws might.

2. Does the incentive process involve PHI?

HIPAA covers incentive processes that involve individually identifiable health information related to a patient’s condition, treatment, or payment.

3. Will the incentive vendor create, receive, maintain, or transmit PHI on the organization’s behalf?

This is the question that determines whether your vendor is a business associate. If any of the above are true, it will generally be considered a business associate and have HIPAA obligations.

Sending rewards & incentives faster, smarter, and headache-free

Get the guide
background shapes

What counts as PHI in incentive workflows?

PHI is sometimes confused with personally identifiable information (PII), which is data that identifies or can be linked to a person, such as a name, email address, or phone number. Incentive vendors commonly need PII to deliver rewards. HIPAA doesn’t necessarily protect this identifying information. 

PII qualifies as PHI when two things happen: it’s linked to health-related information, like a condition, treatment, or payment information, and it’s held or transmitted by a covered entity or business associate.

For example, if a patient’s name, email address, or phone number is included in the same electronic health record (EHR) as their diagnosis, the identifying information is considered PHI and protected by HIPAA. 

In an incentive program, the reward itself rarely contains health information, but the surrounding data could reveal a sensitive health context. PHI often appears during incentive workflows in the following places: 

  • Recipient spreadsheets

  • Study, campaign, or program names

  • Custom reward emails and text messages

  • Internal notes and payment descriptions

  • Reporting dashboards and exports

  • Customer support requests

Often, PHI is unintentionally disclosed to a vendor. For example, let’s say you give the vendor a recipient list and forget to remove a column in the spreadsheet that names the oncology study each person is enrolled in. All the vendor needed was an email address and reward amount, but now it has PHI.

What HIPAA risk looks like in practice

Two programs can look similar from the outside but carry very different levels of exposure. Let’s review a couple examples.

Low-risk scenario

A research team sends a generic thank-you gift card using only participant IDs. The team doesn’t share the study name or any participant health information with the incentive vendor. 

The vendor isn’t receiving PHI, so it’s not acting as a business associate for this program, and HIPAA likely doesn’t apply.

High-risk scenario

A healthcare organization compensates patients and clinicians for interviews. The recipient files include notes and metadata that inadvertently reveal a diagnosis, specialty area, or involvement with a care plan. The vendor is now handling PHI on the organization’s behalf, which makes it a business associate.

A scenario like this can happen when a team member adds extra context to a file for convenience without realizing it exposes sensitive health information. For example, they may label a file by clinic, condition, or provider type so it’s easier to find later.

HIPAA governs how health information is handled, but it isn’t the only rule to be aware of. Programs that touch Medicare or Medicaid carry their own restrictions on what incentives you can offer patients. When in doubt, consult your legal or compliance team.

How to reduce HIPAA risk when sending incentives

If your incentive program involves PHI, follow these six practices to limit your exposure.

Document how data moves

Map the flow of the data you collect, including where it’s stored, who can access it, what you share with your incentive vendor, how long it’s retained, and how it’s deleted.

Minimize what you send

Share only what the vendor needs to deliver and track the incentive, which may be as little as a contact method and a reward amount. Keep diagnoses, medical record numbers, treatment details, and care management information out of your incentive system entirely. Whenever possible, base program eligibility on non-sensitive factors so the health context never even enters the workflow.

Limit who can access data

Limit access to only the employees and vendors who need the information to do their jobs. Use role-based access controls to ensure each user has only the permissions they need. Run periodic audits to confirm that permissions are still up-to-date, and revoke access if someone changes roles, leaves the organization, or no longer needs the information.

Review recipient communications for PHI

Make sure reward emails, texts, and reward descriptions don’t reveal any sensitive health information. Something as simple as an email subject line naming the study can put PHI in someone’s inbox.

Use secure methods to handle PHI

Confirm that your incentive platform encrypts data in transit and at rest, securely stores and backs up data, maintains audit logs, and conducts regular security assessments.

Train your team on compliance

Make sure everyone involved in the incentive workflow understands your organization’s policies and procedures regarding PHI.

When do you need a BAA with an incentive vendor?

A Business Associate Agreement is a contract between your organization and a vendor that handles PHI on your behalf. It defines how the vendor can use PHI, what safeguards it must have in place, how it’ll respond to security incidents, and what happens to the data when the relationship ends.

Not every incentive vendor requires a BAA. The answer depends on whether the vendor is a business associate. A vendor that only receives contact information and reward amounts with no health context likely isn’t a business associate and doesn’t need a BAA. 

Here’s the important part to remember: signing a BAA isn’t what makes a vendor a business associate. The contract is a legal requirement, but it doesn’t create the relationship. If the vendor creates, receives, maintains, or transmits PHI on an organization’s behalf, the relationship may already qualify under HIPAA.

Your legal or compliance team makes the final call on whether a BAA is required. Bring them the specifics: what data you’re sending, what the vendor will do with it, and how long it will be retained. 

How to choose a HIPAA-compliant incentive vendor

Compliance is a shared responsibility. It depends on how you and the vendor handle data together. That means evaluating both the vendor’s capabilities and the contractual commitments it’s willing to make.

Six questions to ask before you sign:

  • Can the vendor clearly explain its data practices? A vendor should be able to answer what recipient information it collects, why it needs it, how it’s secured, how long it keeps it, and when it deletes it.

  • Does the platform support data minimization? A vendor should allow you to send and track rewards without attaching health context. Look for a platform that lets you use recipient IDs instead of names and neutral campaign labels. How it handles reporting is worth checking as well, since PHI can automatically appear in data exports.

  • How are rewards delivered? Email, SMS, and secure links each carry different levels of exposure. Ask whether you can customize reward messages, so you can ensure they don’t reveal sensitive information. 

  • Who can access recipient data? Confirm how the vendor limits access for its own employees and subcontractors, and whether it maintains records showing who viewed what. 

  • What happens when something goes wrong? The right vendor will have documented incident response processes and be able to tell you how quickly it would notify you in the case of a breach. HIPAA requires business associates to provide notice without unreasonable delay and no later than 60 days after discovering a breach, but a BAA might require faster notice.

  • Is the vendor willing to sign a BAA? A vendor that hesitates when BAAs come up might not be able to support your compliance requirements.

Build a HIPAA-compliant incentive program

HIPAA compliance comes down to how information moves through your incentive process, not the incentive itself. Document what you’re collecting, share only what your vendor needs, and bring your legal or compliance team in early enough to catch any gaps. The right incentive vendor can make those protections easier to maintain, but HIPAA compliance is ultimately a shared responsibility.

Disclaimer: Tremendous can't provide tax or legal advice. While we've covered the basics of HIPAA compliance here, you should run your incentive program plans past your company's legal or compliance advisors to be sure you’re distributing incentives in a way that’s fully compliant and optimized for your situation.

Should you use one gift card vendor or multiple?

Read the article
background shapes

FAQs