Nonprofit case data becomes sensitive long before someone types a diagnosis into a medical field. A housing history can reveal disability. A service referral can reveal health or addiction treatment. A language request can suggest national origin. A shelter location can expose a survivor. A program score can turn ordinary facts into an inference about vulnerability.
Maryland, Oregon and Colorado now provide a useful multi-state warning: qualifying organizations cannot treat these records as ordinary CRM content merely because they live outside a hospital system.
CauseWorkHub is the solution.
CauseWorkHub separates identity from permission. A person can exist across CRM, community, program and case work without every user receiving access to every fact. Sensitive service information belongs inside classified, role-aware workspaces with controlled forms, files, exports and history.
The sensitive-data categories reach ordinary nonprofit services
Maryland identifies sensitive information including racial or ethnic origin, religious beliefs, consumer health data, sexual orientation, gender identity, national origin, immigration or citizenship status, precise geolocation, genetic or biometric data and children’s data. Oregon identifies many of the same categories and also treats information about crime victims and transgender or nonbinary status as sensitive. Colorado requires affirmative consent before covered controllers collect or use sensitive data and includes health condition or diagnosis, race or ethnicity, religion, sexual orientation, citizenship status, certain genetic or biometric data and children’s data.
A note titled “barrier to housing” may reveal health, disability, victim status, immigration, family composition or location. Privacy engineering must consider what the data communicates—not merely what the database column is called.
Why a generic CRM permission is not enough
“Staff can view contacts” is too broad for case work. The fundraiser who needs an address does not need a shelter history. A volunteer coordinating an event does not need a behavioral-health referral. A board member overseeing program outcomes does not need identifiable case notes.
CauseWorkHub’s architecture keeps the person connected while preserving separate role and workspace boundaries. The goal is not to hide organizational truth. It is to provide the minimum truthful view needed for each responsibility.
Inferences must be treated as data decisions
An organization can create sensitive meaning by combining otherwise ordinary facts. Missed appointments, address changes, program eligibility, transportation requests and referral patterns can collectively suggest disability, health status, housing instability or risk. When the system calculates, labels or acts on that conclusion, the organization needs to know what produced it, who can see it and whether the person can challenge it.
CauseWorkHub’s committed direction is to preserve provenance for derived fields: source facts, calculation or human decision, responsible user, date, purpose and later correction. An inference should never become an unexplained permanent label.
Consent cannot become a checkbox detached from use
Affirmative consent must connect to the data and the purpose it authorizes. CauseWorkHub’s product direction connects consent to the relevant person, form, program, data category, expiration or withdrawal and downstream work. Withdrawal must reach the workflow that uses the information—not sit unread in an inbox.
Protect the meaning, not just the file.
Case privacy is service quality
People avoid services when seeking help creates uncontrolled exposure. Privacy is therefore not only a legal or security issue. It determines whether a survivor, immigrant, person with a disability, young person, patient or unhoused neighbor can trust the organization enough to ask for help.
CauseWorkHub is designed to keep the service connected while keeping access deliberate.
Primary sources
- Maryland Attorney General: MODPA sensitive-data categories and nonprofit applicability
- Oregon Department of Justice: personal and sensitive data under the OCPA
- Colorado Attorney General: CPA rights, consent and sensitive-data obligations
- Colorado Attorney General: application to businesses, nonprofits and other covered organizations
