HIPAA & Security Overview
Captivated supports secure, compliant customer communication for organizations that require high standards of privacy, security, and operational control.
We work with organizations that need confidence in how messaging, communication workflows, and customer data are handled across modern channels.
HIPAA Support
Captivated supports healthcare-related communication workflows and, where appropriate, can make a Business Associate Agreement (BAA) available to customers whose use case requires one.
Our platform is designed to support secure communication workflows, including messaging, forms, and related interactions, while maintaining clear responsibilities between the platform provider and the customer.
Our platform is used by organizations that require strong operational controls, clear accountability, and consistent handling of sensitive communication workflows.
Security Approach
- Administrative, technical, and physical safeguards designed to protect customer data
- Role-based access and controlled system permissions
- Secure third-party infrastructure and service providers where applicable
- Ongoing operational processes designed to support privacy and security standards
- Structured handling of customer communication data across supported channels
Customer Responsibilities
Customers are responsible for:
- Determining what information constitutes protected or regulated data
- Obtaining any required consent or authorization from recipients
- Using the platform in a manner consistent with applicable laws and internal policies
- Limiting sensitive information to what is reasonably necessary for the intended purpose
- Configuring internal workflows and teams appropriately
SOC 2 and Platform Maturity
Captivated is committed to maintaining a mature security posture and operational discipline appropriate for organizations that expect strong controls, accountability, and trust in their communication platform.
Business Associate Agreement
A Business Associate Agreement (BAA) is available upon request for customers whose use of the platform requires one.