← EMRFlow

Privacy Policy

Effective Date: 2026-05-09  ·  Last Updated: 2026-06-28

Facets Novum LLC d/b/a EMRFlow ("EMRFlow", "we", "us", or "our") provides the EMRFlow electronic-health-records and practice-management software platform (the "Service"). This Privacy Policy describes how we collect, use, share, and protect information when you use the Service or visit our website at https://emrflow.com (the "Site").

The Service includes:

By using the Service or the Site, you agree to this Privacy Policy. If you do not agree, do not use the Service.

1. Who We Are and Whom This Policy Applies To

EMRFlow processes information in two capacities:

This Privacy Policy applies to:

2. Information We Collect

Information you provide directly

Information collected automatically

Information from third parties

3. How We Use Information

We use information to:

PHI is used only as permitted by the Business Associate Agreement and HIPAA: to provide the Service, for proper management and administration of EMRFlow, and to carry out our legal responsibilities. We do not use PHI for marketing, advertising, or to train AI models.

4. How We Share Information

We share information only as described below.

Service providers (sub-business associates)

We use the third-party service providers listed below to operate the Service. Each is bound by a written agreement that requires the same level of protection we provide. Where the provider handles PHI, a Business Associate Agreement is required.

Provider Purpose PHI involved BAA status
Google Cloud (Firebase, Firestore, Cloud Functions, Cloud Storage, Firebase Auth, App Check) Database, authentication, file storage, serverless compute, device attestation Yes Yes; covered under Google Cloud BAA
Liquid Web HIPAA-aligned VPS hosting for PHP backend and PostgreSQL Yes Yes; in place since EMRFlow's first production deployment
InMotion Hosting Demo/test environment hosting only; no production PHI No Demo-only; out of scope
Stripe Platform subscription billing; tokenized payment processing No (PHI does not pass through Stripe) Not required (no PHI); Stripe is PCI-DSS Level 1
Stripe Connect Per-Practitioner patient billing for Solo Practice (the Practitioner's own Connect account; we do not hold the funds) No (no PHI; only patient name, invoice metadata, and tokenized payment) Not required
Vercel Hosting for app.emrflow.com Next.js application No (audited 2026-06-04; PHI-touching routes refactored or removed) Not required (no PHI is stored or processed by Vercel serverless functions; remaining routes are opaque passthroughs to PHP/Firestore, same posture as Stripe)
Google Cloud Run + Firebase Hosting Hosting for forms.emrflow.com patient intake application (Next.js SSR in a container) Yes (intake submissions are PHI) Yes; covered under the existing Firebase BAA
ClaimMD Insurance claims clearinghouse (837 claim submission, 270/271 eligibility, 277CA acknowledgments, 835 ERA retrieval) Yes Yes
Daily.co Telehealth video and audio transport for Solo Practice Pro tier Yes (ephemeral session content) Yes; Healthcare add-on BAA in place
Deepgram Voice dictation transcription (nova-2-medical model) Audio that may contain PHI during a session Yes; Subcontractor BAA executed 2026-05-18
AWS (Amazon Bedrock) AI-assisted clinical note generation and form-fill suggestions, served via Anthropic Claude models hosted on Amazon Bedrock Clinical narratives Yes; covered under AWS BAA (same agreement covering SES)
AWS (Simple Email Service) Transactional email (client portal magic link, balance reminder, cosign notification, superbill delivery) Limited (recipient email address; body content varies by template) Yes; covered under AWS BAA
Cloudflare Turnstile Bot protection on public submission forms (intake portal, feedback board) No (challenge token only) Not required
Freshdesk Customer support ticketing and feature-request tracking No (PHI is out of scope for support tickets and feature requests by policy) Not required (no PHI)
Firebase Crashlytics (Google) Automatic crash and stability diagnostics for the mobile apps (release builds only) No (configured to exclude PHI; only non-identifying crash context is sent) Not required (no PHI)

We do not sell, rent, or otherwise commercially license your personal information or PHI. We do not use PHI for advertising. We do not train AI models on customer PHI; clinical content sent to Anthropic Claude on Amazon Bedrock is processed under AWS Bedrock's terms, which prohibit training on customer inputs.

We update the table above as our infrastructure evolves. Significant changes are reflected in revisions to this Policy.

Legal requirements

We may disclose information when required by law, subpoena, court order, or governmental authority, or when necessary to protect the rights, property, or safety of EMRFlow, our users, or others.

Business transfers

If EMRFlow is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify Practitioners (and where required by law, individuals whose PHI is involved) before any such transfer, and the acquirer will assume the obligations of this Privacy Policy with respect to the data transferred.

With your consent

We may share information with third parties when you direct us to.

SMS and text messaging

If you give us your phone number and check the SMS consent box on a contact form on emrflow.com, you consent to receive informational and conversational text messages from EMRFlow related to your inquiry, such as replies to your question and account or appointment notifications. We do not send marketing or promotional text messages without your separate, express consent.

SMS consent is never a condition of using the Service or submitting a form, and you may decline it and still reach us by email or phone. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP, and reply HELP for help.

The phone number you provide for text messaging and your SMS consent are not shared, sold, or rented to third parties or affiliates for their own marketing or promotional purposes. We share a mobile number only with the service providers that help us deliver these messages (for example, our SMS provider acting on our behalf), and only to send the messages you asked for.

5. Data Security

We use administrative, physical, and technical safeguards to protect information, including:

No system is completely secure. If we discover a breach of unsecured PHI, we will notify affected Practitioners as required by HIPAA and applicable state law (see Section 12).

6. Data Retention

We retain information for the periods described below.

Category Retention
Clinical records (PHI) Duration of the Practitioner relationship plus the period required by the Business Associate Agreement and applicable state law (typically at least six years post-termination)
Practitioner account records (non-PHI) Duration of the subscription plus a reasonable period for audit and tax purposes
Subscription billing records Seven years for tax and accounting purposes
Telehealth session content Not retained; Daily.co does not store session content beyond the call under HIPAA-mode operation
Voice-dictation audio Discarded after transcription completes; the resulting transcript is retained as part of the clinical record
Audit logs At least six years (HIPAA Security Rule §164.316(b)(2)(i))
Marketing-website analytics Up to 24 months in aggregate form
Support tickets (Freshdesk) At least three years after the ticket is closed
Backups Rolling encrypted backups on an operational recycle schedule; deleted records may persist in cold backup media for up to 90 additional days

Practitioners may request deletion of their account at any time via the in-app account-deletion flow or by emailing privacy@emrflow.com. On termination:

7. Your Rights

Depending on your jurisdiction, you may have rights regarding your information.

HIPAA (PHI in the Service)

Patients should contact their Practitioner; their rights to access, amend, request an accounting of disclosures, request restrictions, and request confidential communications are described in the Practitioner's Notice of Privacy Practices. EMRFlow's role as Business Associate is to support these rights, not to determine them. The Practitioner (the covered entity) is the legally responsible party.

U.S. state consumer privacy laws

Residents of states with comprehensive consumer privacy laws may have the rights described below with respect to non-PHI personal information we process about them in our first-party capacity. Most of these laws exclude PHI from their scope because HIPAA governs PHI.

Laws currently in scope (verify the up-to-date list with counsel):

Rights typically include:

GDPR (EU/EEA)

If you access the Service from the EU or EEA, additional rights under GDPR may apply (access, rectification, erasure, portability, restriction, objection; lawful basis: contract performance and legitimate interest). Confirm with counsel whether EU/EEA users are in scope; the Service is operated from the United States and is not currently marketed to EU/EEA residents.

How to exercise your rights

Email privacy@emrflow.com with your request. We will respond within the timeframe required by applicable law (typically 30 to 45 days).

8. Children's Privacy

The Service is sold to healthcare professionals. We do not knowingly collect personal information directly from children under 13. PHI of pediatric patients of Practitioners is governed by HIPAA, applicable state law, and the consent of the patient's parent or legal guardian, as obtained by the Practitioner.

If you believe a child under 13 has provided us with personal information through the marketing website or another non-clinical surface, contact privacy@emrflow.com and we will delete the information.

9. International Users

EMRFlow is operated from the United States. Some subprocessors may operate edge infrastructure (e.g., content-delivery networks for marketing content) outside the United States; PHI does not transit those edge layers. If you access the Service from outside the United States, you consent to the processing of your information in the United States in accordance with this Policy.

10. Cookies and Similar Technologies

The Site uses cookies for:

The apps use SharedPreferences (mobile) and localStorage (web) for session state, theme preference, and the inactivity-logoff timestamp. None of this is shared with third parties.

You can control cookies via your browser settings. Disabling strictly necessary cookies will impair the Site.

The Site and Service may contain links to third-party websites. This Privacy Policy does not apply to those sites. We encourage you to read the privacy policies of any third party you visit.

12. Breach Notification

In the event of a breach of unsecured PHI as defined by the HIPAA Breach Notification Rule, we will notify the affected covered-entity Practitioner without unreasonable delay and no later than 60 days from discovery, providing the information necessary for the Practitioner to fulfill its own notification obligations to affected individuals, the U.S. Department of Health and Human Services Office for Civil Rights, and (where required) the media.

For non-PHI personal information, we will notify affected users in accordance with applicable state breach notification laws.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The "Effective Date" and "Last Updated" dates at the top reflect the current version. If we make material changes, we will notify Practitioners by email and/or post a prominent notice in the Service. We maintain prior versions on request; contact privacy@emrflow.com.

14. Contact Us

Questions, requests under this Policy, and complaints can be directed to:

Facets Novum, LLC d/b/a EMRFlow
3961 Floyd Rd, Suite 300-229
Austell, GA 30106
United States

Privacy contact: privacy@emrflow.com Security contact: security@emrflow.com General support: support@emrflow.com

If you are not satisfied with our response, you may file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at https://www.hhs.gov/hipaa/filing-a-complaint or with your state attorney general's consumer-protection office.