HIPAA Compliance & Business Associate Commitment

Last updated: July 19, 2026

Census Health, Inc., operating Census CRM (“Census CRM,” “we,” “our,” or “us”), builds a customer relationship management platform for addiction treatment and behavioral health admissions teams. Because our customers are health care providers who entrust us with Protected Health Information (PHI), HIPAA compliance is a core requirement of the platform — not an afterthought. This page explains the role we play under HIPAA and the safeguards we maintain.

Our Role Under HIPAA

When a covered entity (such as a treatment center) uses the Census CRM platform to create, receive, maintain, or transmit PHI, Census Health, Inc. acts as a Business Associate as defined by the HIPAA Privacy and Security Rules. We use and disclose PHI only as permitted by our Business Associate Agreement with each customer and by applicable law, and we do not sell PHI. Where a customer's records are also subject to 42 CFR Part 2, Census Health additionally acts as a Qualified Service Organization (QSO) and agrees to be fully bound by Part 2.

Business Associate Agreements (BAA)

Census Health enters into a Business Associate Agreement with each customer whose use of the platform involves PHI. Where the customer's records are also subject to 42 CFR Part 2, that agreement additionally serves as a Qualified Service Organization Agreement (QSOA). A copy is available on request as part of onboarding. It governs the permitted uses and disclosures of PHI, the safeguards we maintain, breach-notification obligations, and the return or destruction of PHI at the end of the engagement.

How We Safeguard PHI

Consistent with the HIPAA Security Rule, we maintain administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI, including:

  • PHI encryption in transit and at rest;
  • role-based access controls that limit access to the minimum necessary;
  • comprehensive audit logging of access to and activity involving PHI;
  • session management, timeouts, and reauthentication gates;
  • workforce access controls and security awareness practices.

For a fuller description of our controls, see our security and compliance overviews.

Substance Use Disorder Records (42 CFR Part 2)

Records created by substance use disorder treatment programs can also be subject to the federal confidentiality regulations at 42 CFR Part 2, which impose requirements beyond HIPAA. Census CRM is built to help programs handle these records with the access controls, consent tracking, and redisclosure protections their obligations require. As a Qualified Service Organization, Census Health is fully bound by Part 2: we restrict the redisclosure of these records and mark them with the required Part 2 notice, will resist efforts in judicial proceedings to obtain them except as Part 2 permits, and will not use them to discriminate against any individual for having received substance use disorder treatment. Customers remain responsible for obtaining the consents and making the determinations required by Part 2 for their own programs.

Subprocessors and Third Parties

Where we rely on infrastructure or service providers that may process PHI on our behalf, we do so under written agreements that impose data-protection and confidentiality obligations consistent with our own. We share PHI with these subprocessors only as necessary to provide the service, and we do not use PHI for advertising or sell it to any third party.

Breach Notification

In the event of a breach of unsecured PHI, we will notify affected customers without unreasonable delay and, in any event, within five (5) business days of discovery, consistent with the HIPAA Breach Notification Rule and the applicable Business Associate Agreement, and we will cooperate with customers in their own notification obligations.

Independent Validation

Our HIPAA controls are monitored and attested through our trust center. A SOC 2 Type II audit is in progress; that report is not yet complete, and we describe it as pending rather than certified.

This Website

This marketing website (censuscrm.com) is separate from the Census CRM application and does not collect or store PHI. Please do not submit PHI through the demo request or contact forms on this site. For how we handle information collected through the website, see our Privacy Policy.

Contact Us

To request a Business Associate Agreement or security documentation, or to ask a question about our HIPAA practices, contact us at:

Census Health, Inc.

14 Alewife Brook Road

East Hampton, NY 11937

privacy@census.health