generated: '2026-09-07' method: searched source: https://www.centene.com/why-were-different/corporate-sustainability/business-accountability/data-privacy-security.html provider: Centene providerId: centene note: >- Centene does not run a dedicated trust portal - trust.centene.com does not resolve, and no Vanta/Drata/SafeBase-style surface was found. What it publishes instead is a corporate Data Privacy and Security disclosure inside its Corporate Sustainability section, which names one certification and one annual assessment regime in Centene's own words. Recorded as a trust surface because it is where the certifications actually live, and flagged for what it is not. trust_center: published: partial url: https://www.centene.com/why-were-different/corporate-sustainability/business-accountability/data-privacy-security.html http_status: 200 type: corporate-disclosure-page self_serve_document_request: false subprocessor_list: false probed: - url: https://trust.centene.com status: 0 note: Does not resolve. - url: https://www.centene.com/security.html status: 404 certifications: - name: ISO/IEC 27001 status: certified assessor: an accredited organization (not named) quote: >- "Our information security program conforms with ISO 27001 and is certified by an accredited organization." evidence: https://www.centene.com/why-were-different/corporate-sustainability/business-accountability/data-privacy-security.html - name: HIPAA Privacy and Security Rules status: assessed annually evidence: https://www.centene.com/why-were-different/corporate-sustainability/business-accountability/data-privacy-security.html - name: HITECH Act status: assessed annually evidence: https://www.centene.com/why-were-different/corporate-sustainability/business-accountability/data-privacy-security.html programs: - Enterprise Data Privacy Program - Business Continuity Management - Disaster Recovery - Vulnerability Disclosure Program (HackerOne) not_claimed: - SOC 2 Type II - HITRUST CSF - PCI DSS - FedRAMP - ISO 27017 / 27018 - note: >- Searched and not found. Not asserted here. For a Fortune 500 payer handling PHI at this scale, the absence of a published SOC 2 or HITRUST attestation is a notable gap rather than evidence that none exists - it may simply be available only under NDA. maintainers: - FN: Kin Lane email: kin@apievangelist.com