Security

Data Security Built for Behavioral Health Admissions

Census CRM is the behavioral health admissions CRM that protects patient data at every step. Admissions handles some of the most sensitive information there is, so data security is built into the product, not added on later. Your team can work fast, and the safeguards run underneath every call, text, and record.

Book a Demo
app.censuscrm.com/security
Monitored by Vanta
HIPAA
Compliant
SOC 2 Type II
In audit
42 CFR Part 2
Met
Encrypted
At rest + transit
Audit logs
Every action
BAA
Available
Encrypted
at rest and in transit
5
role-based access levels
HIPAA
+ 42 CFR Part 2, protected from day one

How we protect your data

Census CRM protects your data with layered security controls, from the moment a lead comes in to the handoff to your EMR. Each control has one job: keep sensitive patient information private, accurate, and available only to the people who should see it.

Security here is a product attribute, not a policy statement. Coordinators run the admissions process, and the protections work in the background without slowing them down.

The specifics

1

Data protection

Census CRM encrypts your data at rest and in transit. Patient records and messages are protected whether they are stored in the system or moving between your team and the CRM, so sensitive information stays private end to end.

2

Access control

Census CRM limits who can see what with role-based access. Each person is assigned a role, Admin, Director, Coordinator, Clinical, or Read-only, and sees only the view that fits that role, so a record is never open to more people than it should be.

3

Auditing

Census CRM records what happens in the system with audit logging. Every meaningful action leaves a trail, so you can see who did what and when, which matters for both accountability and any review of how patient data was handled.

4

Session security

Census CRM protects the account itself with session controls. Session timeout signs out an idle user, and reauthentication confirms identity before sensitive access continues, so an unattended screen does not become an open door.

What this means for you

Census CRM lets your team move fast without carrying the security risk alone. Instead of worrying about who can open a record or whether an idle screen is exposed, your team runs the admissions process and the protections hold in the background.

For an owner, that means you can grow admissions and marketing without adding exposure. The same system that fills more beds keeps patient data protected, from the first call through the clean handoff to your EMR.

Behavioral health CRM security FAQs

What happens to a patient record the moment a coordinator's session goes idle?

An idle coordinator session does not leave a patient record exposed, because session timeout automatically signs out an idle user and reauthentication confirms identity before sensitive access continues. That combination protects the record from an unattended screen becoming an open door, not just from an outside attacker.

If an admissions record gets changed incorrectly, can you tell who made the edit and when?

You can tell who made the edit and when, because Census CRM's audit logging records every meaningful action in the system. That trail supports both day-to-day accountability and any later review of how a specific patient record was accessed and handled.

Does a Read-only team member see the same patient data as a Clinical staff member?

A Read-only team member does not see the same data as a Clinical staff member, because access in Census CRM is controlled by role. Each person is assigned one of five roles, Admin, Director, Coordinator, Clinical, or Read-only, and the system limits their view to what fits that role, so a record is never open to more of the team than it should be.

Is patient data only encrypted while it's sitting in the database, or also while it's being sent?

Patient data is encrypted both while it's stored and while it's being sent, not just at rest. Records and messages are protected in transit between your team and the CRM as well as at rest inside the system, so sensitive information stays private end to end.

Where in the admissions process do Census CRM's security controls actually apply, just at intake or all the way through?

Census CRM's security controls apply across the entire admissions process, from the moment a lead comes in through the handoff to your EMR, not just at intake. Each layer, encryption, role-based access, audit logging, and session controls, has one job: keeping sensitive patient information private, accurate, and available only to the people who should see it.

Can an admissions team scale up call and text volume without multiplying its data exposure?

An admissions team can scale up call and text volume without multiplying its data exposure, because Census CRM's protections are layered into the product rather than added per interaction. The same encryption, role-based access, audit logging, and session security protect every additional call, text, and record the same way they protect the first one, so growth doesn't have to add risk.

Keep exploring

Explore more trust & security

See how the rest of Census CRM works together.

Book a demo

Census CRM keeps admissions fast and your patient data protected at the same time. Book a demo and we will walk through how it safeguards your data.

Book a Demo