Our compliance posture
This page exists so a compliance officer can get a straight answer quickly, including about the things we have not done yet.
What we build to
- HIPAA. We operate in the business associate role for covered entities and handle protected health information accordingly. See our HIPAA page.
- 42 CFR Part 2. Substance use disorder records are gated on verified consent before a referral can be sent. See our Part 2 page.
- WCAG 2.1 AA. Targeted for this website. See our accessibility statement.
Compliance by design, not by attestation
The strongest compliance statement we can make is structural rather than procedural:
- The system holds referral-scoped data only. No chart, no notes, no medication list, no diagnosis history. Less data held is less data at risk.
- Consent is enforced as a blocking gate rather than a checkbox someone can click past.
- Access follows named users and defined roles, scoped by organization and case.
- Writes are audited, so a disclosure question can be answered with a record rather than a recollection.
- Inferred data is labeled as inferred, so nobody acts on a guess believing it was verified.
- Metrics are withheld below a valid sample, so reported figures are defensible.
What we have not done
We hold no SOC 2 report, no HITRUST certification, and no ISO certification. We have not completed an independent third-party security audit or penetration test that we can share. We display no trust badges, because we have not earned any. If a vendor at our stage shows you a wall of logos, it is worth asking which ones are theirs.
These are on the path, and founding organizations are helping us prioritize which come first based on what their own reviews actually require. We would rather tell you the gap now than have your security team find it in week three of a pilot.
Working with your review
Send us your security questionnaire, your vendor risk assessment, or just the three questions your reviewer always asks. You will get direct answers about what exists today, what is in progress, and what is not built. Where the answer is no, we will say no.
Contact info@hopeconnecthealth.com.