Privacy Policy
Sante Clinical Research
Effective Date: September 14, 2026
1. Purpose
Sante Clinical Research is committed to protecting the privacy and security of Protected Health Information (PHI) in accordance with HIPAA and applicable privacy laws.
2. PHI Protection
PHI may only be accessed, used, or disclosed for authorized business or healthcare purposes and is limited to the minimum necessary information.
3. Employee Training & Access
All employees receive HIPAA privacy and security training upon hire and annually thereafter. Access to PHI is based on job responsibilities and is removed when no longer needed or when employment ends.
4. Security
We use reasonable administrative, physical, and technical safeguards, including:
- MFA and individual user accounts
- Role-based access controls
- Encryption and secure data transmission
- Secure backups and monitoring
- Approved systems for storing and transmitting PHI
5. Vendors & Data Storage
PHI is only stored or transmitted through approved systems. Applicable vendors are reviewed for HIPAA compliance and have appropriate Business Associate Agreements (BAAs) in place.
We maintain an inventory of where PHI is stored, transmitted, and backed up and who has access to it.
6. Website & Marketing
Our website Privacy Policy explains how information collected online is handled. Website tracking, cookies, analytics, advertising, forms, and third-party services are reviewed to prevent improper disclosure of PHI.
Marketing campaigns, including email, text, direct mail, and advertising, are reviewed to ensure PHI is used and disclosed appropriately. Third-party marketing companies are evaluated to determine whether a BAA or patient authorization is required.
7. Incidents & Breaches
Employees must immediately report suspected unauthorized access, disclosure, loss, theft, or other security incidents. The company investigates incidents and follows applicable HIPAA breach-notification requirements.
8. Patient Privacy
Where required, the company provides a Notice of Privacy Practices explaining how PHI may be used and disclosed and describing applicable patient rights.
9. Ongoing Compliance
The company maintains a HIPAA security risk assessment and periodically reviews its policies, employee access, vendors, data storage, security controls, and marketing practices.