Current status (as of November 10, 2025):
UserGuiding has obtained an independent HIPAA Type 1 attestation. The examination assessed our controls against the HIPAA Audit Program protocols as of October 24, 2025, and the independent accountant concluded that management’s assertion of compliance was fairly stated in all material respects. We are currently within the audit period for a HIPAA Type 2 examination, which evaluates the operating effectiveness of controls over a period.
What HIPAA Type 1 means
A HIPAA Type 1 report is a point-in-time assessment of whether required safeguards (administrative, physical, and technical) are suitably designed and in place. Our report covers areas such as risk analysis and management, logging and incident response, continuity planning, and technical safeguards aligned to the HIPAA Audit Program.
What’s next (Type 2)
A HIPAA Type 2 examination tests the operating effectiveness of those safeguards over a defined review period. We will update this page when the HIPAA Type 2 report is complete and available for request.
Additional security attestations
UserGuiding also maintains a SOC 2 Type 2 report covering Security, Availability, Processing Integrity, Confidentiality, and Privacy for the period June 6, 2024 – June 6, 2025.
PHI handling and due diligence
Whether and how you may use UserGuiding with PHI depends on your organization’s risk assessment and contractual requirements. If you intend to process Protected Health Information (PHI) with UserGuiding, please contact us to discuss your compliance needs, obtain our current security reports, and evaluate contractual terms (including data processing terms and, where applicable, a BAA). Our data processing terms are available in our standard Data Processing Addendum (DPA).
Related documentation
- HIPAA Type 1 Report (2025) – available under NDA upon request.
- SOC 2 Type 2 Report (2025) – available under NDA upon request.
- Data Processing Addendum (DPA) – terms for processing personal data with UserGuiding.
- Selected security policies (e.g., Data Protection, Access Control, Logging & Monitoring) are available upon request for due diligence reviews.