This document is a HIPAA Deployment Guide for Air360, focusing on the configuration necessary to ensure compliance with HIPAA regulations regarding the handling of Protected Health Information (PHI). The guide provides explicit instructions on recommended configurations to prevent the transmission of PHI to the platform, emphasizing the importance of session replay and custom properties management. It details the need for customers with a Business Associate Agreement (BAA) to enable full text obfuscation, ensuring that no identifiable text is captured in session replays. Furthermore, it outlines specific events and data types that should never be sent, including patient names and medical record numbers. The document instructs users to avoid including PHI in URL paths and parameters, and specifies customer responsibilities in ensuring compliance. Additionally, it highlights the need for thorough testing before production deployment to verify that no PHI is included in captured data. The guidance is aimed at healthcare customers utilizing Air360 for behavioral analytics.