Candid Health · Trust Center

Candid Health Trust Center

Trust center

Candid Health operates a Drata-hosted trust center at trust.joincandidhealth.com. It is provisioned and live but sits behind a Cloudflare bot challenge, so its contents could not be read anonymously — the certifications recorded below come from Candid's own newsroom posts, each naming the report, the period and the auditing firm, not from the trust page itself.

Candid Health maintains a public trust center documenting SOC 2 Type 2, SOC 2 Type 1, SOC 1 Type 1, and HIPAA (Business Associate) compliance.

Medical BillingRevenue Cycle ManagementHealthcareClaimsEligibilityPrior AuthorizationRemittancePatient CollectionsCredentialingInsurance
Trust center: https://trust.joincandidhealth.com/

Certifications & Compliance

SOC 2 Type 2SOC 2 Type 1SOC 1 Type 1HIPAA (Business Associate)

Source

Trust Center

Raw ↑
generated: '2026-08-15'
method: searched
probe: true
source: https://trust.joincandidhealth.com/
name: Candid Health Trust Center
description: >-
  Candid Health operates a Drata-hosted trust center at trust.joincandidhealth.com.
  It is provisioned and live but sits behind a Cloudflare bot challenge, so its
  contents could not be read anonymously — the certifications recorded below come
  from Candid's own newsroom posts, each naming the report, the period and the
  auditing firm, not from the trust page itself.
url: https://trust.joincandidhealth.com/
platform: Drata
platform_evidence: 'DNS: trust.joincandidhealth.com CNAME trust.cname.drata.com'
readable_anonymously: false

certifications:
  - name: SOC 2 Type 2
    criteria: [Security, Availability, Confidentiality]
    period: 2025-01-15 to 2025-04-15
    opinion: unqualified
    auditor: AssurancePoint, LLC
    source: https://candidhealth.com/blog/candid-health-successfully-completed-type-2-soc-2-examination-with-an-unqualified-opinion
  - name: SOC 2 Type 1
    opinion: unqualified
    auditor: AssurancePoint, LLC
    source: https://candidhealth.com/blog/candid-health-successfully-completed-type-1-soc-2-examination-with-an-unqualified-opinion
  - name: SOC 1 Type 1
    as_of: '2025-12-31'
    opinion: clean
    auditor: AssurancePoint, LLC
    scope: >-
      Claims and Payment Interface Processing, Invalid Claims and Interface Error
      Handling, Account Balances, Billing, Data Communications, Logical Access,
      Change Management.
    source: https://candidhealth.com/blog/candid-health-achieves-type-1-soc-1-certification-with-clean-auditor-opinion
  - name: HIPAA (Business Associate)
    basis: contractual — BAAs with customers; PHI prohibited in the Sandbox environment
    source: https://candidhealth.com/privacy-policy

not_claimed:
  - ISO 27001
  - HITRUST CSF
  - PCI DSS
  - FedRAMP

report_access:
  self_serve_download: unknown
  note: >-
    Drata trust centers normally gate SOC reports behind an NDA click-through. Whether
    Candid's does could not be established without passing the bot challenge.

x-evidence:
  - url: https://trust.joincandidhealth.com/
    http_status: 403
    detail: >-
      Cloudflare managed challenge (cf-mitigated: challenge, server: cloudflare). The host
      resolves, serves TLS with HSTS preload, and CNAMEs to trust.cname.drata.com — so the
      trust center exists and is provisioned; it is simply not machine-readable.
  - url: https://candidhealth.com/blog/candid-health-successfully-completed-type-2-soc-2-examination-with-an-unqualified-opinion
    http_status: 200
  - url: https://candidhealth.com/blog/candid-health-achieves-type-1-soc-1-certification-with-clean-auditor-opinion
    http_status: 200
  - dns: trust.joincandidhealth.com
    record: CNAME
    value: trust.cname.drata.com

notes:
  - >-
    The trust center is on joincandidhealth.com while the marketing site and the audit
    announcements are on candidhealth.com. Both domains belong to Candid Health — the
    newer candidhealth.com Nuxt site links to app.joincandidhealth.com and the older
    joincandidhealth.com Webflow site links to candidhealth.com — but a buyer following
    the newer brand domain will not find the trust center, because nothing on
    candidhealth.com links to it.
  - >-
    No vulnerability disclosure program, bug bounty, or security.txt was found on any
    host, so no VulnerabilityDisclosure artifact is written and no Security pointer is
    emitted. For a HIPAA business associate handling PHI at this scale, a published
    disclosure channel is the most obvious missing piece of the security posture.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/candid-health-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.