CaseFlow is a HIPAA-grade communication layer. PHI stays on the EHR side of the boundary β we operate on tokens and scheduling metadata. Patient names, diagnoses, clinical notes, and lab results never cross into CaseFlow infrastructure.
The diagram below shows exactly where the integration boundary sits between your EHR and CaseFlow's infrastructure. Teal items cross into CaseFlow. Red items stay in the EHR β always.
Every CaseFlow customer β pilot or full plan β receives a signed BAA before going live. Download our template, review with your legal team, and send back for counter-signature.
Honest status on every relevant framework. We don't claim SOC 2 until the audit is done.
| Framework / Rule | Current Control | Roadmap Item | Status |
|---|---|---|---|
| HIPAA Privacy Rule | PHI minimum-necessary policy; BAA with every customer at contract; documented use/disclosure register. | Formal Privacy Officer designation (Q3 2026). | Active |
| Security Rule β Administrative | Security risk analysis completed annually; workforce training on PHI handling; incident response policy. | Annual third-party risk assessment (Q4 2026). | Active |
| Security Rule β Physical | Hosted on Render (SOC 2 Type II data centers); no on-premise servers; remote-wipe policy for contractor devices. | Device MDM for all employees with PHI access (Q3 2026). | Active |
| Security Rule β Technical | TLS 1.2+ in transit; AES-256 at rest (Neon/Render managed); token-based patient IDs (no name/DOB in URLs); access logging. | Automated secret rotation + SIEM alerting (Q4 2026). | Active |
| Breach Notification Rule | 72-hour internal notification SLA; incident log maintained; Covered Entity notification template ready. | Automated breach-detection alerting pipeline (Q4 2026). | Active |
| SOC 2 Type I | Readiness assessment in progress with Vanta. | SOC 2 Type I audit target: Q1 2027. | In Progress |
| HITRUST CSF | Not yet initiated. | HITRUST e1 Certification on roadmap for Q2 2027 (typically required by large health systems). | Roadmap |
Full disclosure. If a subprocessor handles PHI, a signed BAA is in place before any data flows.
This list is updated within 30 days of any subprocessor change. Last updated: June 2026. To request advance notice of subprocessor changes, email hipaa@surgeoncaseflow.com.
HIPAA requires 60 days. We commit to 72 hours from discovery. Here's exactly what happens if a breach occurs.
Answered directly. Forward this page to your counsel.
Download the BAA template, review it with your legal team, and email us for counter-signature. We'll have you live before the next board meeting.
HIPAA questions: hipaa@surgeoncaseflow.com β 48h response guaranteed