HIPAA-Ready Case Management Software for Nonprofits
Sumac gives community nonprofits the safeguards HIPAA expects: role-based access, audit trails, and secure hosting, built into case management software designed for social services.
Get a Demo
A 30-minute walkthrough of the permissions, audit trail, and field-level controls. Bring your privacy questions.
- Your information is secure and never shared.
★★★★★4.8/5from nonprofits just like yours
Most Nonprofits Ask About HIPAA. Fewer Are Covered By It.
HIPAA is written for a specific kind of organization: health care providers that bill electronically, health plans, clearinghouses, and the Business Associates that handle protected health information for them. A food bank, a housing program, a survivor support center, or a family services agency usually is not one of them, even when its case files contain health details.
Sensitive is not the same as regulated
Your client files deserve real protection, and your funders will want to see it. That is exactly the work Sumac is built for: role-based permissions, restricted fields, and an audit trail on every record, without the contractual layer that hospitals and clinics need from a vendor.
The fastest way to tell which side of the line your organization is on is to answer three basic questions. If every answer is no, you are very likely outside HIPAA and Sumac is a straightforward fit. If any answer is yes, the box below tells you where Sumac fits and where it does not.
Or answer them in the fit check below →Three questions that decide it
- Do licensed clinicians on your staff (physicians, nurses, therapists, licensed counselors) see clients in a clinical capacity?
- Do you bill insurance, Medicaid, Medicare, or any health plan electronically for services?
- Do you already maintain a system you treat as the clinical or medical record?
The straight answer on Business Associate Agreements
Despite Sumac providing a secure environment for your important and sensitive data, Societ’s policy is that it does not sign Business Associate Agreements (BAAs). If your organization is a HIPAA covered entity, or a funder requires a BAA from every vendor that stores protected health information for you, Sumac should not be the system of record for that data. Keep the clinical record in a platform that signs BAAs, and use Sumac for intake, program delivery, outcomes, and reporting. Many organizations run exactly that way.
You should also be aware that if a software provider signs a BAA it does not instantly make your organization compliant. You are still entirely responsible for many critical components of managing personal health information within the software system. Specifically, you must properly configure security settings like multi-factor authentication, session timeouts, password policies, sharing restrictions, audit logs and retention settings, as well as train employees on proper use.
Is Sumac the Right Privacy Fit for Your Organization?
Five questions, no email address, and nothing you enter leaves this page. It is a guide to help you ask the right question, not legal advice. Your funding agreements and your counsel have the final word.
How Sumac Protects Client Data
Whether or not HIPAA applies to you, your clients trusted you with their story. Sumac ships with the kinds of technical and administrative safeguards that HIPAA’s Security Rule describes.
Secure Data Storage & Transmission
- Encrypted data at rest and in transit
- Secure, professionally managed cloud infrastructure
- Ongoing system monitoring and updates
Role-Based Access Controls
- Custom user roles and permissions
- Access limited by job function
- Ability to restrict sensitive records and fields
Audit Trails & Accountability
- Detailed logs of user activity
- Tracking for record access and changes
- Support for audits and compliance reviews
Data Integrity & Availability
- Regular system backups
- Data integrity safeguards
- Reliable uptime and disaster recovery planning
These are the controls a funder review or an audit looks for.
Who is Sumac Built For?
Sumac is built for community nonprofits: housing, food security, family services, survivor support, disability services, settlement, and the thousands of programs that keep case files without being health care providers.
By focusing on understanding and supporting human and social services organizations, we are able to keep Sumac pricing aligned to their budgets. We focus our product development on the work they do every day: intake, case plans, case notes, outcomes, and funder reporting.
The clinical record
- Diagnoses and treatment plans
- Clinical and therapy session notes
- Prescriptions and lab results
- Insurance and health plan claims
The case management record
- Intake, eligibility, and consent
- Services delivered and program participation
- Goals, outcomes, and referrals
- Funder and board reporting
If your organization does both, this split is normal. It is how many Sumac customers operate, and we are glad to show you how the two sides fit together.
Questions We Get Asked
Is Sumac HIPAA compliant?
HIPAA compliance is something an organization achieves, not a certification software can hold. The U.S. Department of Health and Human Services does not certify software. Sumac provides many of the technical safeguards HIPAA’s Security Rule describes, including access controls, audit trails, encryption, and backups, and nonprofits across North America use it to protect sensitive client information. What Societ does not do is act as a HIPAA Business Associate and it is our policy that we do not sign Business Associate Agreements at this time. If your organization needs a BAA, Sumac should not hold your protected health information.
Do we need a Business Associate Agreement?
You require Business Associate Agreements from vendors if your organization is a Covered Entity, or a Business Associate of a Covered Entity. In this case, the vendor creates, receives, stores, or transmits your protected health information. Most community nonprofits are neither. The three questions above and the fit check are the fastest way to tell. When in doubt, look at your funding agreement: if a BAA is required, it is almost always attached to it.
Our funder says we need to be HIPAA compliant. Now what?
Ask for the specific document. The requirement often comes from a state or provincial agency that is itself a Covered Entity, and the agreement it attaches only covers information you handle on that agency’s behalf. Health details your clients share with you directly, for your own programs, usually fall outside it. Send us the attachment and we will walk through it with you.
Can we use Sumac alongside our EHR or clinical system?
Yes, and many organizations do. The clinical record stays in the system built to hold it. Sumac carries intake, eligibility, services delivered, goals, outcomes, referrals, and reporting. The two sides can reference each other by client without the clinical detail ever leaving the clinical system.
Sumac is a great, safe platform that’s HIPAA-friendly, which helps us with the privacy of our clients.
Ready for Secure Case Management?
Book a demo and we will show you the permissions, the audit trail, and the field-level controls on a live system. Bring your privacy questions. We answer them straight.