Privacy Policy

Sante Clinical Research
Effective Date: September 14, 2026

1. Purpose

Sante Clinical Research is committed to protecting the privacy and security of Protected Health Information (PHI) in accordance with HIPAA and applicable privacy laws.

2. PHI Protection

PHI may only be accessed, used, or disclosed for authorized business or healthcare purposes and is limited to the minimum necessary information.

3. Employee Training & Access

All employees receive HIPAA privacy and security training upon hire and annually thereafter. Access to PHI is based on job responsibilities and is removed when no longer needed or when employment ends.

4. Security

We use reasonable administrative, physical, and technical safeguards, including:

5. Vendors & Data Storage

PHI is only stored or transmitted through approved systems. Applicable vendors are reviewed for HIPAA compliance and have appropriate Business Associate Agreements (BAAs) in place.

We maintain an inventory of where PHI is stored, transmitted, and backed up and who has access to it.

6. Website & Marketing

Our website Privacy Policy explains how information collected online is handled. Website tracking, cookies, analytics, advertising, forms, and third-party services are reviewed to prevent improper disclosure of PHI.

Marketing campaigns, including email, text, direct mail, and advertising, are reviewed to ensure PHI is used and disclosed appropriately. Third-party marketing companies are evaluated to determine whether a BAA or patient authorization is required.

7. Incidents & Breaches

Employees must immediately report suspected unauthorized access, disclosure, loss, theft, or other security incidents. The company investigates incidents and follows applicable HIPAA breach-notification requirements.

8. Patient Privacy

Where required, the company provides a Notice of Privacy Practices explaining how PHI may be used and disclosed and describing applicable patient rights.

9. Ongoing Compliance

The company maintains a HIPAA security risk assessment and periodically reviews its policies, employee access, vendors, data storage, security controls, and marketing practices.