Spring Health
Spring Health

Spring Health

Spring Health



Badges

GDPR
GDPR
HIPAA
HIPAA
CCPA
CCPA

Quick Summary

One or more annual third-party audit(s)

Has a formal mobile device management (MDM) program

Annual third-party penetration testing

Has a disaster recovery plan

Subprocessors list available

Has cyber insurance

Will enter into a DPA

Deletes customer data on request

Uses a centralized IAM solution (SSO) to manage employee access

Has a privacy policy


Our Philosophy

Our mission: To eliminate every barrier to mental health.
Spring Health is the leading comprehensive mental health benefit for employers. We help employees understand their mental health issues and connect with best-in-class providers to get the right treatment at the right time.

From early detection to full recovery, Spring Health is the only clinically validated solution in the market proven to be more effective than traditional mental healthcare. By combining the latest technology with vetted providers, we help engage 1 in 3 employees, reduce recovery times, and lower healthcare costs.

To support these outcomes, our security program is comprehensive and inclusive of key capabilities that we monitor and continuously improve. This includes published and communicated security policies, procedures, and standards, company-wide security training and awareness, data and infrastructure security, situational awareness via continuous monitoring, incident lifecycle management, business continuity and disaster recovery programs and plans, physical security controls, and management of inherited risks through a vendor management process.

We are an award-winning, passionate, and mission-driven team with the support of leaders in psychiatry. Spring Health is committed to the security and privacy of our members, and we will continuously improve and enhance our security program to meet current and future challenges.

Coming Soon

SOC2 Audit Period: 9/1/2024 - 8/31/2025


Find an Answer


Announcements

Want to learn more about Spring Health and our approach?

Check out our blog here! https://www.springhealth.com/blog


Featured Documents


Subprocessors
19

Subprocessor
Location of Processing
Usage Details
Acuity Scheduling (Squarespace)

Acuity Scheduling (Squarespace)

United States
Cloud-based (SaaS) scheduling system used for tracking appointments between patients and care providers/navigators.
Aptible

Aptible

United States
HIPAA-compliant cloud hosting platform that primarily provides database and compute services for SHP.
AWS

AWS

United States
Cloud platform providing a broad range of services, but SHP's primary usage is through ECR and S3.
Datadog

Datadog

United States
Centralized SaaS logging.
Iterable

Iterable

United States
Cross-channel marketing platform.
Mailgun

Mailgun

United States
Platform email delivery service.
Mixpanel

Mixpanel

United States
Cloud based Analytics tool. Analytics for user behavior and engagement.
Paubox

Paubox

United States
HIPAA-compliant email delivery system used for transmitting high-criticality alerts related to patient health.
R3

R3

United States
Response personnel for certain patient scenarios.
SendSafely

SendSafely

United States
Secure file exchange.
Sentry

Sentry

United States
Application monitoring and error tracking software.
Smartpress

Smartpress

United States
Marketing materials for customers to provide to employees regarding services provided by Spring.
Talkdesk

Talkdesk

United States
Cloud-based call center software solution.
Twilio

Twilio

United States
Twilio is a platform as a service vendor that offers SMS, transactional email, and more.
Typeform

Typeform

United States
Member feedback survey tool for coaching and care navigation appointments.
Welkin Health

Welkin Health

United States
Case management tool.
Workplace Options

Workplace Options

United States
Response personnel for certain patient scenarios.
Zendesk

Zendesk

United States
Cloud-based (SaaS) help desk tool that provides a HIPAA-compliant way to interact with patients.
Zoom

Zoom

United States
HIPAA-compliant video-conferencing and tele-conferencing platform used for providing telehealthcare.
Last updated . .
View as:

Trusted by

Kayak
Whole Foods Market
BlackRock
J.B. Hunt
General Mills
Fortive
Wellstar Health System
Hershey's
Activision Blizzard
AppLovin
AES
Duolingo
Instacart
Docusign
Powered by Conveyor, the first end-to-end customer trust platform.
Learn more