How we protect the data you trust us with.
This page is maintained by bedflow to answer the common security, privacy, and HIPAA questions we get from operators. It describes controls that are in place today. It is not a certification, and it is not legal advice. If something on this page is unclear or you need it in a specific format for procurement, email support@usebedflow.com.
bedflow is built for treatment centers handling PHI. We follow HIPAA-aligned administrative, physical, and technical safeguards. We are not HITRUST or SOC 2 certified at this time. If your compliance team needs specific evidence, we will walk you through what is available.
A BAA is available on request before any PHI is loaded into your workspace. We sign a mutual BAA covering our platform and our infrastructure subprocessors. New customers get a BAA as part of onboarding.
All data is encrypted in transit with TLS 1.2 or newer and at rest with AES-256 on managed cloud storage. Application secrets are held in a managed secret store. We do not store PHI in browser local storage beyond what a signed-in session needs.
Every workspace uses row-level security so users only see their own facility's data. In-app roles (director, admissions, BD, alumni, read-only) gate what each teammate can see or change. Admin actions are logged.
Data handling
- We collect only what is needed to run referrals, bed management, partner outreach, and alumni programs. We do not sell customer data.
- Your workspace is isolated at the database level. bedflow staff access customer PHI only when you request support and only through audited paths.
- Backups are encrypted and retained on the same schedule as the underlying managed database. Deletion requests are honored within 30 days after contract termination unless a longer retention is legally required.
- Data is hosted in the United States on major cloud providers (AWS and Cloudflare). Subprocessors that touch PHI are covered under our BAA.
Ongoing maintenance
- Dependencies are scanned continuously and patched on a rolling basis. Critical security fixes are shipped out of band.
- Every change goes through code review and automated tests before it reaches production. Migrations run with rollback plans.
- We monitor errors and performance in real time and alert on anomalies. Customer-impacting incidents are communicated by email to workspace admins.
- A published changelog and product email keep your team aware of new features and behavioral changes.
Reporting a vulnerability
If you believe you have found a security issue, please email support@usebedflow.com with details and reproduction steps. We acknowledge reports within two business days and will keep you updated as we investigate.