How we protect the data you trust us with.
This page is maintained by bedflow to answer the common security, privacy, and HIPAA questions we get from operators. It describes controls that are in place today. It is not a certification, and it is not legal advice. If something on this page is unclear or you need it in a specific format for procurement, email support@usebedflow.com.
bedflow is built for treatment centers handling PHI. We follow HIPAA-aligned administrative, physical, and technical safeguards. We are not HITRUST or SOC 2 certified at this time. If your compliance team needs specific evidence, we will walk you through what is available.
A BAA is available on request before any PHI is loaded into your workspace. We sign a mutual BAA covering our platform and our infrastructure subprocessors. New customers get a BAA as part of onboarding.
All data is encrypted in transit with TLS 1.2 or newer and at rest with AES-256 on managed cloud storage. Application secrets are held in a managed secret store. We do not store PHI in browser local storage beyond what a signed-in session needs.
Every workspace uses row-level security so users only see their own facility's data. In-app roles (director, clinical, house manager, staff, viewer) gate what each teammate can see or change. Admin actions are logged.
Data handling
- We collect only what is needed to run referrals, bed management, partner outreach, and alumni programs. We do not sell customer data.
- Your workspace is isolated at the database level. bedflow staff access customer PHI only when you request support and only through audited paths.
- Backups are encrypted and retained on the same schedule as the underlying managed database. Deletion requests are honored within 30 days after contract termination unless a longer retention is legally required.
- Data is hosted in the United States on major cloud providers (AWS and Cloudflare). Subprocessors that touch PHI are covered under our BAA.
Ongoing maintenance
- Dependencies are scanned continuously and patched on a rolling basis. Critical security fixes are shipped out of band.
- Every change goes through code review and automated tests before it reaches production. Migrations run with rollback plans.
- We monitor errors and performance in real time and alert on anomalies. Customer-impacting incidents are communicated by email to workspace admins.
Reporting a vulnerability
If you believe you have found a security issue, please email support@usebedflow.com with details and reproduction steps. We acknowledge reports within two business days and will keep you updated as we investigate.
Security documents
Our current mutual BAA, covering the platform and infrastructure subprocessors. Sent same business day.
Completed standard security questionnaire covering hosting, encryption, access control, audit logging, and incident response.
A live walkthrough of current HIPAA-aligned controls for your compliance team. Independent pentest evidence is not published at this time.
We are not SOC 2 or HITRUST certified at this time and won’t claim otherwise. Check the boxes in the request form below and we’ll email the selected documents to your compliance team. Independent pentest evidence is not published at this time.
HIPAA and BAA FAQ
Do you sign a Business Associate Agreement (BAA)?
Yes. We sign a mutual BAA with every customer before any PHI is loaded into their workspace. New customers get one as part of onboarding, and you can request the current version from the form below.
Are you HITRUST or SOC 2 certified?
Not at this time. bedflow follows HIPAA-aligned administrative, physical, and technical safeguards, but we are not independently certified. If your procurement team needs a specific attestation, tell us and we'll walk through what evidence is available.
Where is PHI stored, and is it encrypted?
PHI lives in a US-hosted managed database. Data is encrypted in transit with TLS 1.2 or newer and at rest with AES-256. Backups use the same encryption as the primary database.
Who at bedflow can see my facility's data?
Every workspace is isolated with row-level security. Only members you invite see your PHI. bedflow staff access customer data only when you request support and only through audited paths.
What subprocessors touch PHI?
Our infrastructure subprocessors (managed database, hosting, email delivery) are covered under our BAA where required. We can share the current subprocessor list on request.
How long do you keep data after we cancel?
Deletion requests are honored within 30 days after contract termination unless a longer retention is legally required. You can export your data at any time during the contract.
Do you use customer PHI to train AI models?
No. We do not sell customer data and we do not use identifiable PHI to train external AI models. AI features run per-workspace on your own data.
How do you notify us of a security incident?
Workspace admins are contacted by email as soon as we confirm a customer-impacting incident, with follow-ups as the investigation progresses. Timelines follow HIPAA breach notification rules where applicable.