Security & data protection

Behavioral health data deserves a higher bar.

Substance use and mental health records carry protections most health data does not. HopeConnect is built to hold the least data necessary to coordinate a referral, gate it behind consent, and record every access.

Data minimization

We are not a clinical record system.

HopeConnect coordinates referrals between organizations. It holds what a referral needs to move, and deliberately does not hold a patient's chart. That boundary is enforced by the data model itself, not by policy alone.

What HopeConnect holds

  • The referral and its event history
  • Documents attached to a referral, under consent
  • Messages on the referral
  • Appointments scheduled from the referral
  • Eligibility checks for the referred service
  • Provider credentials, availability, and insurance
  • Users, roles, and audit logs

What it does not hold

  • No patient chart
  • No progress or therapy notes
  • No medication lists
  • No diagnosis history
  • No treatment plans
  • No billing or claims records
How access is controlled

Consent gates, roles, and a trail on every write.

42 CFR Part 2 consent gates

Where Part 2 applies, a referral cannot be sent until consent is verified. The gate is explicit and blocking, not a warning someone can click past.

Role-based access

Users hold defined roles, and access to a referral follows the role and the organization, not a shared login or a general directory browse.

Audit logs on every write

Who did what and when, recorded on the referral. When you have to answer for a decision, the trail exists.

Referral-scoped documents

Records travel attached to a specific referral under consent. They are not pooled into a shared repository other organizations can browse.

Identity and authentication

Access runs through a managed identity layer with per-user accounts, so activity is attributable to a person rather than a department.

Event history, not overwrites

Referral events are recorded as they happen, so status changes leave a history rather than quietly replacing what came before.

Straight with you

What we claim, and what we don't.

Security pages are where vendors overstate. Here is the honest position for a company at our stage.

HIPAA-aligned and built for Part 2, without borrowed badges.

HopeConnect is designed to HIPAA requirements and to the stricter consent rules of 42 CFR Part 2, and the data model above reflects that. We are pre-launch, and we do not display certification logos or audit badges we have not earned. If your security review needs documentation of our controls, ask us directly and we will tell you plainly what exists today, what is in progress, and what is not yet done. Founding organizations help shape that review process with us.

Bring your security questions.

We would rather answer a hard review early than surprise you later.