Candid Health · Trust Center

Candid Health Trust Center

Trust center

Candid Health operates a Drata-hosted trust center at trust.joincandidhealth.com. It is provisioned and live but sits behind a Cloudflare bot challenge, so its contents could not be read anonymously — the certifications recorded below come from Candid's own newsroom posts, each naming the report, the period and the auditing firm, not from the trust page itself.

Candid Health maintains a public trust center documenting SOC 2 Type 2, SOC 2 Type 1, SOC 1 Type 1, and HIPAA (Business Associate) compliance.

Medical BillingRevenue Cycle ManagementHealthcareClaimsEligibilityPrior AuthorizationRemittancePatient CollectionsCredentialingInsurance
Trust center: https://trust.joincandidhealth.com/

Certifications & Compliance

SOC 2 Type 2SOC 2 Type 1SOC 1 Type 1HIPAA (Business Associate)

Source

Trust Center

Raw ↑
generated: '2026-08-15'
method: searched
probe: true
source: https://trust.joincandidhealth.com/
name: Candid Health Trust Center
description: >-
  Candid Health operates a Drata-hosted trust center at trust.joincandidhealth.com.
  It is provisioned and live but sits behind a Cloudflare bot challenge, so its
  contents could not be read anonymously — the certifications recorded below come
  from Candid's own newsroom posts, each naming the report, the period and the
  auditing firm, not from the trust page itself.
url: https://trust.joincandidhealth.com/
platform: Drata
platform_evidence: 'DNS: trust.joincandidhealth.com CNAME trust.cname.drata.com'
readable_anonymously: false

certifications:
  - name: SOC 2 Type 2
    criteria: [Security, Availability, Confidentiality]
    period: 2025-01-15 to 2025-04-15
    opinion: unqualified
    auditor: AssurancePoint, LLC
    source: https://candidhealth.com/blog/candid-health-successfully-completed-type-2-soc-2-examination-with-an-unqualified-opinion
  - name: SOC 2 Type 1
    opinion: unqualified
    auditor: AssurancePoint, LLC
    source: https://candidhealth.com/blog/candid-health-successfully-completed-type-1-soc-2-examination-with-an-unqualified-opinion
  - name: SOC 1 Type 1
    as_of: '2025-12-31'
    opinion: clean
    auditor: AssurancePoint, LLC
    scope: >-
      Claims and Payment Interface Processing, Invalid Claims and Interface Error
      Handling, Account Balances, Billing, Data Communications, Logical Access,
      Change Management.
    source: https://candidhealth.com/blog/candid-health-achieves-type-1-soc-1-certification-with-clean-auditor-opinion
  - name: HIPAA (Business Associate)
    basis: contractual — BAAs with customers; PHI prohibited in the Sandbox environment
    source: https://candidhealth.com/privacy-policy

not_claimed:
  - ISO 27001
  - HITRUST CSF
  - PCI DSS
  - FedRAMP

report_access:
  self_serve_download: unknown
  note: >-
    Drata trust centers normally gate SOC reports behind an NDA click-through. Whether
    Candid's does could not be established without passing the bot challenge.

x-evidence:
  - url: https://trust.joincandidhealth.com/
    http_status: 403
    detail: >-
      Cloudflare managed challenge (cf-mitigated: challenge, server: cloudflare). The host
      resolves, serves TLS with HSTS preload, and CNAMEs to trust.cname.drata.com — so the
      trust center exists and is provisioned; it is simply not machine-readable.
  - url: https://candidhealth.com/blog/candid-health-successfully-completed-type-2-soc-2-examination-with-an-unqualified-opinion
    http_status: 200
  - url: https://candidhealth.com/blog/candid-health-achieves-type-1-soc-1-certification-with-clean-auditor-opinion
    http_status: 200
  - dns: trust.joincandidhealth.com
    record: CNAME
    value: trust.cname.drata.com

notes:
  - >-
    The trust center is on joincandidhealth.com while the marketing site and the audit
    announcements are on candidhealth.com. Both domains belong to Candid Health — the
    newer candidhealth.com Nuxt site links to app.joincandidhealth.com and the older
    joincandidhealth.com Webflow site links to candidhealth.com — but a buyer following
    the newer brand domain will not find the trust center, because nothing on
    candidhealth.com links to it.
  - >-
    No vulnerability disclosure program, bug bounty, or security.txt was found on any
    host, so no VulnerabilityDisclosure artifact is written and no Security pointer is
    emitted. For a HIPAA business associate handling PHI at this scale, a published
    disclosure channel is the most obvious missing piece of the security posture.