Enterprise-Grade Security & Compliance
Your data security is non-negotiable. Healthflo is built for protected health information from the ground up, with enterprise-grade encryption, strict tenant isolation, and an active HIPAA compliance program.

Compliance
HIPAA compliant, verified by Accountable. Published policies covering encryption, access rights, audit controls, transmission security, breach notification, and incident response. Employee HIPAA training complete. Business Associate Agreements in place with vendors who access PHI.
Data protection
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- Tenant isolation enforced at the network and application layers. No shared network path between clients.
Audit trail
- Every PHI access logged
- Every agent action logged, including HITL approvals
Access control
- Multi-factor authentication
- Role-based access control
- Enterprise SSO
Infrastructure
Healthflo runs on Railway in the US West region. Railway is SOC 2 Type II and SOC 3 certified and operates under a signed BAA.
Containerized deployments to client clouds are available, such as Azure, GCP, or AWS.
BAA & Vendor Assessment
We make vendor procurement easy. Sign a BAA, and get started with confidence.
Business Associate Agreement
We provide a BAA as part of our standard onboarding for all healthcare organizations. Our BAA covers all required HIPAA provisions and can be signed electronically for fast turnaround.
- Standard BAA included with all healthcare contracts
- Electronic signature for fast execution
- Custom provisions available upon request