New in Chargebee: Explore Reveal and understand your payment performance end-to-end.Try Now
Docschargebee docs
HomeBillingPaymentsRevRecGrowthReveal
Support

Product Updates


  • Release Notes

Getting Started


  • Overview
  • Chargebee Billing Data Centers
  • Object Relationship Model
  • Understanding Sites
  • Chargebee Tech Glossary
  • Articles and FAQ

Implementing Chargebee


  • Implementation Guide
  • Go-live Checklist
  • Articles and FAQ

AI in Chargebee


  • Chargebee Agents
  • Chargebee Copilot
  • Chargebee MCP Server (Model Context Protocol)

Developer Resources


  • Developer Resources Overview
  • Articles and FAQ

Product Catalog


  • Product Catalog Overview
  • Coupons
  • Articles and FAQ

Subscriptions


  • Working with Subscriptions
  • Billing
  • Orders
  • Articles and FAQ

Customers


  • Managing Customers
  • Account Hierarchy
  • Email Notifications
  • Branding
  • Configure Multiple Languages
  • Articles and FAQ

Entitlements


  • Entitlements Overview
  • Features Overview
  • Feature Management
  • Managing Product Entitlements
  • Subscription Entitlements
  • Customer Entitlements
  • Grandfathering Entitlements
  • Articles and FAQ

Usage Based Billing


  • Understanding Usages
  • Setting up Usage Based Billing
  • Usage Alerts
  • Metered Billing
  • Articles and FAQ

Chargebee CPQ


  • Chargebee CPQ
  • Chargebee CPQ for Salesforce
  • Chargebee CPQ for HubSpot

Invoices, Credit Notes, and Quotes


  • Invoices
  • Credit Notes
  • Quotes [Legacy]
  • Transactions
  • Articles and FAQ

Taxes


  • Overview
  • Configuring Taxes
  • Country-specific Taxes
  • Articles and FAQ

Hosted Capabilities


  • Overview
  • Hosted Checkout
  • Hosted Self-Serve Portal
  • Hosted Pages Features
  • Additional Hosted Pages
  • Payment Components
  • Pricing Table
  • Managing Payments with Chargebee.js
  • Mobile-Optimized Hosted Pages
  • Articles and FAQ

Site Configuration


  • Users & Roles
  • Custom Fields & Metadata
  • Approvals
  • Mandatory Fields
  • File Attachments & Comments
  • Advanced Filter Options
  • Multicurrency Pricing
  • Multi-decimal Support
  • Configuring Reason Codes
  • Events and Webhooks
  • API Keys
  • Time Zone
  • Time Machine
  • Transfer Configurations
  • Articles and FAQ

Multi Business Entity


  • Multi Business Entity Overview
  • Customer Transfer Overview
  • Articles and FAQ

Mobile Subscriptions


  • Overview
  • Omnichannel Subscriptions
  • Omnichannel One-Time Orders
  • Mobile Subscriptions (Legacy)

Reports and Analytics


  • RevenueStory
  • Home Dashboard
  • Frequently Asked Questions
  • FAQs for Classic Reports Sunset
  • Articles and FAQ

Integrations


  • Sales
  • Customer Support and Success
  • Finance
  • Tax
  • Marketing
  • Stitch
  • Collaboration
  • Contract Management
  • Ecommerce Management
  • Articles and FAQ

Data Privacy & Security


  • Two Factor Authentication
  • SAML Single Sign-On
  • System for Cross-Domain Identity Management (SCIM)
  • EU-GDPR
  • Consent Management
  • Personal Data Management
  • Compliance Certificates
  • HIPAA Guidelines
  • PCI Recommendations and Integration Types
  • Articles and FAQ

Data Operations


  • Bulk Operations
  • Migration
  • Articles and FAQ

HIPAA Configurations & Guidelines

Chargebee supports HIPAA compliance for its core billing and subscription management platform (Chargebee Billing). Upon customer's request and notice to Chargebee that the customer intends to disclose ePHI to Chargebee in its use of Chargebee Billing, Chargebee may evaluate customer’s necessity to share ePHI to the platform and choose to execute a business associate agreement (BAA) with the customer with respect to Chargebee Billing.

Note

Unless a BAA is executed by Chargebee with a customer, the customer is prohibited from sharing any ePHI with Chargebee.

Additionally, even if a BAA is executed by Chargebee with the customer, it only applies to Chargebee Billing and does not apply to any other component, product or service that Chargebee provides or makes available, including:

  1. Any middleware, integrations or other components that are capable of being used in conjunction with the platform.
  2. Other products or services such as Chargebee Receivables, RevRec, Retention/Growth, or Reveal.

The validity of the BAA is subject to continued compliance by the customer to the mandatory configuration requirements relating to Chargebee Billing set forth below.

Mandatory Configuration Requirements

Given below is the list of mandatory requirements for HIPAA compliance for Chargebee Billing.

  1. Custom SMTP: Chargebee allows email notifications to be sent out from Chargebee Billing using either Chargebee's SMTP server or customer's own SMTP server. However, for a HIPAA compliant account, customers must configure their own SMTP server to ensure autonomous control of incoming and outgoing emails and customers are prohibited from using Chargebee's SMTP servers. The custom SMTP server shall be completely managed by the customer. Please refer to the SMTP Configuration for more details.

  2. Abandoned Carts: Chargebee offers a report for tracking abandoned carts whereby a customer can track the number of visitors or end-customers leaving the checkout process without completing a purchase or leaving items in the cart. This classic report uses geolocation. However, for a HIPAA compliant account, customers must disable this feature by logging in to your Chargebee site, navigate to Settings > Configure Chargebee > Checkout and Self-Serve Portal > Disable "Track abandoned carts".

  3. Taxes Module: Chargebee offers a feature to verify customer tax details for accurate calculation as per tax norms for certain countries. However, for a HIPAA compliant account, a customer must disable this feature by logging in to your Chargebee site and navigate to Settings > Configure Chargebee > Taxes > Uncheck "Enable location validation".

  4. E-invoicing Module: Chargebee offers a feature to generate, transmit, and manage electronic invoices in compliance with applicable regulations in supported countries. However, for a HIPAA compliant account, a customer must either (a) ensure that transactions involving ePHI or transactions subject to HIPAA are not processed using the e-invoicing feature; or (b) disable the feature by logging in to your Chargebee site and navigate to Settings > Configure Chargebee > E-invoicing; on the E-invoicing configuration page, click Disable > Confirm. For more details, please refer to E-invoicing documentation.

  5. Auto-complete address in Checkout and Self-Serve Portal: Chargebee offers a feature to auto-complete addresses in checkout and self-serve portal. However, for a HIPAA compliant account, customer must disable this feature by logging in to your Chargebee site and navigate to Settings > Configure Chargebee > Checkout and Self-Serve Portal > Advance Settings > disable the toggle “Autocomplete addresses”. For more details, please refer to Hosted Checkout documentation.

  6. Atomic Pricing: Chargebee offers a feature that allows customers to host and embed dynamic, customizable pricing tables on their websites through a simple front-end integration. However, for HIPAA-compliant accounts, this feature must not be enabled.

  7. Integration with payment gateways: For a HIPAA compliant account, Chargebee recommends use of direct integrations that Chargebee makes available with the payment gateways (such as BlueSnap, Cybersource, NMI). For the following gateways, Chargebee currently offers integration through a payment aggregator and therefore, customer must either ensure that transactions involving ePHI or transactions subject to HIPAA are not processed through the following gateways or build and use direct integrations with the following gateways: BlueSnap, Cybersource, NMI, Ecentric, Windcave, JPM Mobility gateway, Pin Payments, eWay Rapid, Worldpay, Sage Pay, Ogone (Ingenico), Wirecard, Beanstream (Bambora), Paymill, dLocal, Metricsglobal, Nuvei, Paypal Pro, Orbital (Chase), Paypal Payflow, Moneris, BluePay, Elavon.

  8. Customer must not submit any ePHI or other information subject to HIPAA as part of the inputs provided to any of the AI capabilities offered by Chargebee. Customers must also not cause any such ePHI or information to be processed by the AI capabilities (for example, in response to the inputs/prompts provided to the AI capabilities or otherwise through any configuration or use of the Chargebee services).

  9. Chargebee recommends customers to refrain from submitting any ePHI to Chargebee’s pre-release offerings.

Please reach out to your Account Manager or Chargebee Support for any queries.

Was this article helpful?