HIPAA Security & Readiness
Last updated: August 2026
PhysioFlow has implemented a comprehensive set of technical and administrative safeguards designed around HIPAA requirements and the protection of electronic protected health information (ePHI).
The measures below are active in PhysioFlow's production environment today and form part of our ongoing security architecture for clinics operating under U.S. law.
Multi-Factor Authentication
PhysioFlow supports multi-factor authentication (MFA) for platform administrators and for clinic Owner/Admin accounts, using time-based one-time passcodes (TOTP) compatible with standard authenticator apps. Single-use backup recovery codes are provided for account recovery, and every enrollment, login, and recovery event is logged.
Role-Based Access Control
Access within PhysioFlow follows a minimum-necessary model. Pre-built role templates — Admin, Therapist, Reception, Accountant, and Therapy Aide — give each team member access appropriate to their function, and every clinic's data is securely isolated from other clinics through tenant-level access controls enforced by the platform.
Session & Account Security
Access is revoked immediately when a team member's account is deactivated — not on their next login. Cached patient information is cleared from the session on logout, and every authentication event is subject to automated monitoring for repeated failed attempts.
Data Protection
Backups are generated automatically and encrypted using AES-256-GCM authenticated encryption before being written to disk. Restore procedures are tested and verified. Data in transit is protected using industry-standard TLS encryption.
Audit & Accountability
PhysioFlow maintains detailed audit logs covering authentication events, MFA enrollment and use, administrative actions, and account/security changes — giving clinics and PhysioFlow a clear, accountable record of activity.
PHI-Safe Tracking
Advertising and marketing tracking tools are technically restricted to public, pre-login marketing pages only. They are structurally excluded from every authenticated clinical workflow, so patient data is never exposed to advertising or analytics tooling.
AI & PHI Protection
PhysioFlow's AI-assisted features include an automated technical safeguard: for organizations identified as U.S.-based, real patient data is automatically restricted from AI processing until explicit administrative clearance is granted. Every clearance decision is individually logged for accountability, without logging patient data itself.
Infrastructure Security
Production infrastructure uses key-based access only, automated firewall protection, and intrusion-prevention controls. Deployments follow a controlled process with automatic health checks and rollback if a release doesn't pass verification.
Administrative Safeguards
PhysioFlow maintains a documented Information Security Policy, a formal risk analysis and risk management process, an Incident Response Plan with breach notification procedures, access control and authentication policies, data retention and deletion procedures, and an active vendor/subprocessor review process.
Current BAA Status
PhysioFlow is committed to supporting HIPAA-eligible use by qualifying U.S. healthcare organizations, and is finalizing Business Associate Agreements with its technology vendors alongside its own Business Associate Agreement for clinic customers. If your organization requires a signed BAA, contact us at support@physioflow.com to discuss your specific requirements and current availability.