
Search for HIPAA-compliant analytics and the results are consistent. The first page is about web and marketing analytics on a healthcare site: comparison lists, tracking pixels, and what to do about a form that captures a condition name.
That is a real problem. It is also not the problem a healthcare SaaS has when its own product shows a customer a dashboard built on patient records.
We measured the gap rather than assuming it. Of the first ten organic results for this query on 25 August 2026, all ten were about web or marketing analytics, and none addressed a product embedding dashboards over protected health information.
The Second Question Starts Where the First One Ends
The marketing-site version asks which tool may receive visitor data. The product version asks something narrower and heavier: when your customer's clinicians open a dashboard inside your application, who is holding PHI at each step, and what has each of those parties signed.
That question has a documented answer for the first step, and the clearest statement of it comes from a vendor rather than from a regulator.
The Role Rule Is Stated Plainly, and It Carries a Condition as Well as a Conclusion
Microsoft's HIPAA compliance page states the rule directly: "When a covered entity engages the services of a cloud service provider, such as Microsoft, the cloud service provider is a business associate under HIPAA. Moreover, when a business associate subcontracts with a cloud service provider to create, receive, maintain, or transmit PHI, the cloud service provider also becomes a business associate." (Microsoft Learn, HIPAA and the HITECH Act, read 25 August 2026.)
The second sentence is the one to read twice, and its condition matters as much as its conclusion. The role attaches to a provider that creates, receives, maintains or transmits PHI, so the chain reaches your analytics vendor when the arrangement puts PHI in their hands and not merely because you bought analytics.
So the question is not whether your analytics vendor is certified. It is whether the deployment model puts PHI in their hands at all.
Three Deployment Shapes, and the Data Path Picks One
The first shape is a vendor cloud that documents healthcare coverage. Microsoft's in-scope list includes the "Power BI cloud service either as a standalone service or as included in an Office 365 or Dynamics 365 branded plan or suite", and the agreement is "available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA".
The second shape is a vendor cloud whose security page does not mention healthcare. Metabase's security page names SOC 2 Type II, SOC 1 Type II, GDPR and CCPA, and does not mention HIPAA or a Business Associate Agreement. (Metabase security, read 25 August 2026.)
Treat that as an unanswered question rather than a refusal, and ask.
The third shape is self-hosted software where query results never leave your infrastructure. On that path the analytics vendor does not receive PHI, so it does not become a business associate on that route. That reasoning is ours rather than a quotation, and it carries a caveat: telemetry, support access and any hosted add-on are separate paths, and each is checked on its own.
A Signed Agreement Is Support, and the Vendor Saying So Is the Useful Part
Microsoft's page carries the question in plain words and answers it in one.
Asked whether holding a Business Associate Agreement ensures an organisation's compliance, the page answers in one word and then explains it.
"No. By offering a Business Associate Agreement, Microsoft helps support your HIPAA compliance. However, using Microsoft services doesn't on its own achieve HIPAA compliance."
The answer continues into where the work sits: "Your organization is responsible for ensuring that you have an adequate compliance program and internal processes in place."
A procurement plan that treats a countersigned BAA as the finish line has mistaken a supporting document for the work.
With Microsoft You Will Be Reviewing Their Paper Rather Than Negotiating Yours
The same page closes a door a procurement plan may assume is open.
Asked whether it can use a customer's Business Associate Agreement, Microsoft answers: "No, Microsoft can't use a customer's Business Associate Agreement. Because we offer hyperscale, multitenant services that are standardized for all our customers, we must operate in a consistent manner."
This is a statement about Microsoft rather than about vendors in general, and we did not collect equivalent policies from others. Read it as one data point with a scheduling consequence: at least one hyperscale provider will not start from your document, so reviewing theirs is work to schedule. Whether their own terms move is a separate question this page did not test.
Whether a smaller vendor will sign paper you bring is a question to ask them directly. If one does, the follow-up matters more than the signature, because a signed agreement describing controls a vendor does not operate is worse than an honest no.
Inside the Dashboard, the Compliance Question Becomes a Row Question
Everything above decides who holds PHI. One layer down, a second question decides how much of it any given viewer sees.
A clinician at one practice opening a dashboard in your product should reach that practice's patients and no others. That boundary is enforced by whatever the data layer evaluates, so it depends on the scope reaching it intact, which is the subject of row-level security and of what JWT authentication puts inside the signature, where the scope may travel inside the signed payload or beside it.
The reason it belongs on a HIPAA page rather than only on a security page is the minimum necessary standard. A dashboard that returns more rows than the viewer's role requires is an access design question before it is a performance one.
Three Questions, and the Order Is Part of the Advice
Which exact service is in scope. Vendor compliance pages list services by name, and a suite name does not carry down to every component inside it. Get the name of the service you will be running into the answer.
Where the query executes. If it runs against your database and results render in your customer's browser, the PHI path is short and describable. If it runs in the vendor's cloud, the path includes their storage, their caches and their logs, and each of those belongs in your own records of processing.
What happens during support. A support engineer with read access to a debugging session is a path into PHI, and it is easy to leave off an architecture diagram because it is not part of the request flow. Ask how that access is granted, logged and revoked.
Each question asks about a mechanism rather than a status. Our fuller treatment of the paths is in embedded analytics security, and the European counterpart to the whole question sits in GDPR and embedded analytics, which makes the case that erasure is the harder engineering problem there.
What This Page Leaves to Others, and One Gap in Our Own Research
Healthcare dashboard design, the metric definitions clinical and operational users argue about, and the source systems with their consent rules sit in the healthcare dashboard guide, which goes deeper than a blog post can.
One gap is worth naming rather than hiding. We could not open Sisense's security and compliance page at the URL published then, when we tried on 20 August 2026, so no row for it appears in the figure above. An absent row means we did not read it rather than that the vendor lacks coverage.
The test worth applying before any healthcare analytics purchase is whether you can draw the PHI path on one line and name who holds it at each step. A certification list will not answer that, and an embedded analytics product that cannot answer it in a sentence is one you will be explaining to an auditor later.
Where to Go Next
- Embedded Analytics articles: the rest of this cluster.
- Embedded analytics security: the paths to the data, including support and scheduled jobs.
- GDPR and embedded analytics: the European counterpart, which argues the harder engineering problem there is erasure rather than access.
- JWT authentication: what a signature covers, and where the row scope travels.
Ready to launch customer-facing analytics?
Stop losing customers to competitors with better analytics. Sumboard's customer-facing analytics platform lets you launch self-service dashboards in days, not months.


