Skip to content

HIPAA Compliance Statement

Last updated: October 1, 2026

Our role

Flow RCM acts as a Business Associate to the healthcare providers we serve, as defined by the Health Insurance Portability and Accountability Act (HIPAA). We execute a Business Associate Agreement (BAA) with every client before accessing PHI.

Administrative safeguards

We maintain written HIPAA privacy and security policies, designate a Privacy and Security Officer, perform annual risk assessments, and require HIPAA training and background checks for all workforce members.

Technical safeguards

PHI is encrypted in transit and at rest. Access requires unique user IDs and multi-factor authentication, is limited by role, and is logged and monitored.

Physical safeguards

Systems containing PHI are hosted with HIPAA-eligible providers under BAAs. Workforce devices are managed, encrypted, and protected with endpoint security.

Breach notification

We maintain an incident response plan and will notify affected clients of any breach of unsecured PHI without unreasonable delay, in accordance with the HIPAA Breach Notification Rule and our BAAs.

Website forms

Please do not submit patient information through our website forms or chat assistant. Contact us to arrange secure data exchange.

Template text for reference only. Have this page reviewed by qualified legal counsel before publishing.