Medaflo, LLC ("Medaflo") acts as a trusted confidential application service provider dedicated to providing a secure Internet and mobile service.
Medaflo employs a high degree of security consciousness. One of Medaflo's priorities is to make reasonable efforts to ensure data security and to meet its obligations as a business associate under HIPAA. Access, integrity, availability, authorization, authentication, and confidentiality are all major considerations within the Medaflo Security Policy. Unfortunately, the Internet cannot be guaranteed to be 100% secure, and we cannot ensure or warrant the security of any information you provide to us.
Medaflo upholds its Security Policy with the following security measures:
Medaflo grants varying degrees of access to users with different levels of authority within a provider practice.
Communication between you and the Medaflo Service is encrypted in transit using current industry-standard protocols, and data at rest, including database storage and backups, is encrypted through provider-managed encryption. Encryption keys are generated, stored, rotated, and destroyed by our cloud service providers under provider-managed key management. Medaflo does not generate, hold, or escrow encryption keys.
Medaflo is a fully cloud-based service and does not operate its own offices, data centers, or on-premises production infrastructure. The Medaflo Service runs on managed cloud platforms whose providers are responsible for the physical and environmental security of the underlying facilities and for the network protections that shield those platforms from unauthorized access. Each provider that may handle protected health information on our behalf is bound by a business associate agreement. Production data is separated from development and test environments, which use synthetic data only.
Medaflo has internal policies that keep your data private and confidential. We will not share your data with any third party except as described in our Privacy Policy. Your data is your data only.
Access to your account is controlled by an individual login ID and a password that you choose. Medaflo enforces password requirements designed to prevent weak, common, and previously compromised passwords, and accounts are locked after repeated failed sign-in attempts. We do NOT store a plain text version of your password. Your password is stored using a one-way hash and verified using the same one-way hash every time you log in, which means no one at Medaflo knows what password you have chosen. If you ever forget your password, we require you to choose a new one using an email verification check. Privileged administrative access to production systems additionally requires multi-factor authentication and is reviewed on a regular basis.
Medaflo protects you against accidentally leaving your account active on a computer browser screen. The Medaflo Service ends your session after a period of inactivity, and closing your browser also logs you out. This prevents others from accessing your account when you leave a session and forget to log out.
Medaflo uses digital certificates issued by a recognized public certificate authority. This gives you the confidence that you are connected to a site or application operated by Medaflo, and authenticated as such.
Medaflo handles all your health information with respect to its confidentiality and privacy. We ask that you follow your provider's policy on communicating sensitive information in their practice.
Medaflo maintains an availability commitment for the production service, which is set out in its customer agreements. Encrypted database backups are created on a regular schedule, and database operations logs are captured continuously so that data can be restored to a point in time between backups. Backups and operations logs are retained for a defined period and are then purged. Medaflo also maintains documented business continuity and disaster recovery procedures with defined recovery time and recovery point objectives, and tests those procedures on a regular basis.
Application, hosting, database, and security activity is monitored continuously, with alerts raised when defined thresholds are met. Medaflo scans its software dependencies for known vulnerabilities on an ongoing basis and conducts recurring vulnerability scanning and application penetration testing of its external-facing systems. Identified vulnerabilities are prioritized by risk and tracked through remediation. Medaflo also maintains and periodically tests a documented incident response plan, and provides notifications consistent with applicable law, the HIPAA Breach Notification Rule, and its business associate agreements.
Changes to application code, dependencies, and configuration are authorized, documented, peer reviewed, and tested in a non-production environment using synthetic data before authorized personnel deploy them to production.
In order to protect your privacy while using Medaflo, you can:
We review this Security Policy periodically and update it when our practices, systems, or legal obligations change.
This Security Policy is provided for informational purposes only. It describes Medaflo's security practices as of the date shown below, is not incorporated into and does not form part of any agreement between Medaflo and any customer or user, and does not create any contractual commitment, representation, or warranty. Medaflo's obligations are set out in the applicable written agreement, including any Terms of Use, Service Agreement, or Business Associate Agreement.
Last updated: June 30, 2026