πŸ”’ Security & HIPAA β€” For PE CFOs

The five questions your legal team
will ask about CaseFlow.

CaseFlow is a HIPAA-grade communication layer. PHI stays on the EHR side of the boundary β€” we operate on tokens and scheduling metadata. Patient names, diagnoses, clinical notes, and lab results never cross into CaseFlow infrastructure.

BAA included on every plan US-only data hosting (Render / AWS) 72-hour breach notification SLA No AI training on patient data SOC 2 Type I in progress
πŸ”’ TLS 1.2+ in transit
πŸ” AES-256 at rest
πŸ“‹ HIPAA BAA on every plan
πŸ‡ΊπŸ‡Έ US-only data hosting
🚫 No PHI in AI model training

What crosses the boundary. What doesn't.

The diagram below shows exactly where the integration boundary sits between your EHR and CaseFlow's infrastructure. Teal items cross into CaseFlow. Red items stay in the EHR β€” always.

PRACTICE EHR (ModMed / Athena / eCW) Patient Name / DOB Diagnosis / ICD-10 Codes Clinical Notes Lab Results / Imaging Medication Records STAYS IN EHR β€” NEVER SENT INTEGRATION BOUNDARY CASEFLOW Scheduling communication layer Appointment ID (token) Slot Time + Procedure Type Patient Phone (SMS delivery) Consent Flag (YES/NO) Anon. Waitlist Score SCHEDULING METADATA ONLY PATIENT CHANNEL SMS (Twilio) + Email (Postmark) Slot time + opt-in link YES / NO reply captured Pre-op reminders (no Dx) Post-op check-in cadence NO APP REQUIRED β€” SMS ONLY BAA COVERED BAA COVERED
Crosses into CaseFlow (scheduling metadata, phone for SMS)
Stays in EHR β€” never transmitted (names, diagnoses, clinical notes, labs)
Patient-facing channel (SMS/email β€” no clinical content)

BAA included. No negotiation required.

Every CaseFlow customer β€” pilot or full plan β€” receives a signed BAA before going live. Download our template, review with your legal team, and send back for counter-signature.

CaseFlow Business Associate Agreement
Pre-filled with CaseFlow as Business Associate. Covered Entity fields are blank for your practice or platform name. Standard HIPAA Subpart C language β€” your counsel will recognize the structure.
Download BAA Template β†’
BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ("Agreement") is entered into as of the date last signed below ("Effective Date") between: COVERED ENTITY: Organization Name: _______________________________________ Address: _________________________________________________ Authorized Representative: ________________________________ BUSINESS ASSOCIATE: Organization Name: CaseFlow (operated by Polsia, Inc.) Address: 548 Market St, San Francisco, CA 94105 ... [Download full template for complete terms β€” counter-signature: hipaa@surgeoncaseflow.com]
Step 1
Download the template. Fill in your organization name, address, and authorized representative.
Step 2
Review with your legal or compliance team. The language follows standard HIPAA 45 C.F.R. Part 164 Subpart C structure.
Step 3
Return to hipaa@surgeoncaseflow.com for counter-signature. Turnaround: under 2 business days.

Current controls + what's on the roadmap.

Honest status on every relevant framework. We don't claim SOC 2 until the audit is done.

Framework / Rule Current Control Roadmap Item Status
HIPAA Privacy Rule PHI minimum-necessary policy; BAA with every customer at contract; documented use/disclosure register. Formal Privacy Officer designation (Q3 2026). Active
Security Rule β€” Administrative Security risk analysis completed annually; workforce training on PHI handling; incident response policy. Annual third-party risk assessment (Q4 2026). Active
Security Rule β€” Physical Hosted on Render (SOC 2 Type II data centers); no on-premise servers; remote-wipe policy for contractor devices. Device MDM for all employees with PHI access (Q3 2026). Active
Security Rule β€” Technical TLS 1.2+ in transit; AES-256 at rest (Neon/Render managed); token-based patient IDs (no name/DOB in URLs); access logging. Automated secret rotation + SIEM alerting (Q4 2026). Active
Breach Notification Rule 72-hour internal notification SLA; incident log maintained; Covered Entity notification template ready. Automated breach-detection alerting pipeline (Q4 2026). Active
SOC 2 Type I Readiness assessment in progress with Vanta. SOC 2 Type I audit target: Q1 2027. In Progress
HITRUST CSF Not yet initiated. HITRUST e1 Certification on roadmap for Q2 2027 (typically required by large health systems). Roadmap

Every vendor that touches your data.

Full disclosure. If a subprocessor handles PHI, a signed BAA is in place before any data flows.

Transactional email delivery (appointment reminders, reports)
Patient name + appointment date in email body β€” BAA signed
Signed
SMS delivery (waitlist blasts, patient reminders, two-way messaging)
Patient phone number + scheduling message body β€” BAA signed
Signed
Cloud compute, web hosting, managed PostgreSQL
All application data including PHI at rest β€” BAA signed
Signed
Subscription billing and payment processing
None β€” billing data only, no PHI transmitted
N/A (no PHI)
Anthropic / OpenAI (AI proxied via Polsia)
Optional: cold email reply classification, photo triage scoring
De-identified text snippets only; no patient name, DOB, or clinical notes sent
N/A (de-identified; not PHI under 45 C.F.R. Β§ 164.514)

This list is updated within 30 days of any subprocessor change. Last updated: June 2026. To request advance notice of subprocessor changes, email hipaa@surgeoncaseflow.com.

72-hour notification. No exceptions.

HIPAA requires 60 days. We commit to 72 hours from discovery. Here's exactly what happens if a breach occurs.

πŸ”Ž
Detection (Hour 0–4)
Automated log anomaly detection + pager alert to incident commander. All affected systems are isolated within 2 hours of confirmed incident. A dedicated incident Slack channel is opened with timestamped log.
πŸ“ž
Covered Entity Notification (Hour 4–72)
You receive written notice within 72 hours: nature of the breach, PHI involved, estimated individuals affected, containment steps taken, and a draft HHS notification if required by the HIPAA Breach Notification Rule.
πŸ›‘οΈ
Incident Commander
A named incident commander is available 24/7 during an active incident. Direct phone line provided to your account team at kickoff. No "submit a support ticket" during a breach β€” you get a human immediately.
πŸ“„
Post-Incident Report
Within 30 days of resolution: full root cause analysis, remediation steps taken, control improvements implemented, and attestation for your compliance records. Suitable for HHS inquiry or audit documentation.
Customer Communication Template
"On [date], CaseFlow discovered a potential security incident affecting [N] patient records at [your practice name]. The affected data included [appointment IDs / phone numbers]. No clinical records, diagnoses, or financial data were involved. We have [contained / are actively containing] the incident and will provide a full report within 30 days. Your incident commander is [name] at [phone]. We have prepared the required HHS notification on your behalf β€” attached for your review and signature."

The questions your legal team will send.

Answered directly. Forward this page to your counsel.

Do you store PHI?
Minimally and temporarily. CaseFlow stores appointment IDs, slot times, patient phone numbers (for SMS), and confirmation status. We do not store clinical notes, diagnoses, lab results, or imaging. Patient names are stored only long enough to personalize reminders and are never used in model training or analytics.
Where is data hosted?
All data is hosted on Render Services (US-East, AWS-backed). Render holds a signed HIPAA BAA and operates SOC 2 Type II certified infrastructure. No data is stored outside the United States.
What happens if CaseFlow is acquired?
Your BAA travels with the data. Any successor entity inherits Business Associate obligations under 45 C.F.R. Part 164 Subpart C. You will be notified in writing at least 60 days before any change in data controller, with the right to terminate and receive a full data export at no charge.
Do you train AI models on patient data?
No. Patient data is never used to train or fine-tune any AI model β€” Polsia's, Anthropic's, or OpenAI's. The waitlist scoring engine is a rules-based algorithm. Optional AI features (photo triage, reply classification) use de-identified text snippets that do not meet the definition of PHI under HIPAA.
What EHR data do you access?
Nothing without explicit configuration. CaseFlow can integrate with ModMed, Athena, and eClinicalWorks via HL7 FHIR β€” but the pilot requires only a CSV export from your scheduler. When EHR integration is enabled, CaseFlow reads only: appointment status, slot time, procedure code, and patient contact information. Clinical records are never accessed.
Who has access to our patient data?
Only CaseFlow engineering and operations staff with a documented need and signed workforce agreement. Access is role-based and logged. Credentials rotate every 90 days. No third-party sales, marketing, or analytics vendors receive PHI.
How do you handle a breach?
We notify you within 72 hours of discovery β€” not 60 days. You'll receive: a description of what happened, which PHI was affected, what we've done to contain it, and a draft HHS notification if required. Our incident commander is available 24/7 during an active incident.
Do you sell or share patient data?
No. Never. Patient data is used exclusively to perform the services described in your order form. We do not sell, license, or share PHI with any third party for commercial purposes. This is a contractual obligation in the BAA β€” not just a policy.
Ready to move forward?

BAA in hand.
Pilot in 48 hours.

Download the BAA template, review it with your legal team, and email us for counter-signature. We'll have you live before the next board meeting.

Download BAA Template β†’ Start the Pilot

HIPAA questions: hipaa@surgeoncaseflow.com β€” 48h response guaranteed