Healthflo

Enterprise-Grade Security & Compliance

Your data security is non-negotiable. Healthflo is built for protected health information from the ground up, with enterprise-grade encryption, strict tenant isolation, and an active HIPAA compliance program.

HIPAA Compliant — Powered by Accountable

Compliance

HIPAA compliant, verified by Accountable. Published policies covering encryption, access rights, audit controls, transmission security, breach notification, and incident response. Employee HIPAA training complete. Business Associate Agreements in place with vendors who access PHI.

Data protection

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Tenant isolation enforced at the network and application layers. No shared network path between clients.

Audit trail

  • Every PHI access logged
  • Every agent action logged, including HITL approvals

Access control

  • Multi-factor authentication
  • Role-based access control
  • Enterprise SSO

Infrastructure

Healthflo runs on Railway in the US West region. Railway is SOC 2 Type II and SOC 3 certified and operates under a signed BAA.

Containerized deployments to client clouds are available, such as Azure, GCP, or AWS.

BAA & Vendor Assessment

We make vendor procurement easy. Sign a BAA, and get started with confidence.

Business Associate Agreement

We provide a BAA as part of our standard onboarding for all healthcare organizations. Our BAA covers all required HIPAA provisions and can be signed electronically for fast turnaround.

  • Standard BAA included with all healthcare contracts
  • Electronic signature for fast execution
  • Custom provisions available upon request