Legal

HIPAA Notice

Last updated: February 18, 2026

ScensobConnect provides a Business Associate Agreement (BAA) to covered-entity customers who use the platform to staff roles involving access to Protected Health Information (PHI).

What we do

  • Encrypt all data at rest (AES-256) and in transit (TLS 1.2+).
  • Maintain audit logs of every administrative action involving worker, location, or shift records.
  • Restrict access on a least-privilege, role-based basis.
  • Sign HIPAA Business Associate Agreements with all sub-processors that may incidentally process PHI on our behalf.
  • Train all employees on HIPAA basics on hire and annually.

What ScensobConnect is not

The platform does not store medical records, clinical notes, lab results, or any other patient PHI. It stores workforce information: who worked where, when, and at what rate. PHI never enters the platform.

Getting a BAA

If your organization requires a BAA before going live, email security@scensobconnect.com. Standard BAA turnaround is 2 business days.

Incident response

Suspected breach? Email security@scensobconnect.com immediately. We will acknowledge within 4 hours and notify affected covered entities within 24 hours per HIPAA timelines.