Privacy Policy
Facets Novum LLC d/b/a EMRFlow ("EMRFlow", "we", "us", or "our") provides the EMRFlow electronic-health-records and practice-management software platform (the "Service"). This Privacy Policy describes how we collect, use, share, and protect information when you use the Service or visit our website at https://emrflow.com (the "Site").
The Service includes:
- The marketing website at https://emrflow.com
- The web application at https://emrflow.com/webapp and the Solo Practice web application at https://app.emrflow.com
- The EMRFlow mobile applications for iOS, iPadOS, and Android
- The patient intake portal at https://forms.emrflow.com
- The Solo Practice client portal, accessible only by magic-link issued by a Solo Practice clinician (no public landing page)
- The public feedback site at https://feedback.emrflow.com
By using the Service or the Site, you agree to this Privacy Policy. If you do not agree, do not use the Service.
1. Who We Are and Whom This Policy Applies To
EMRFlow processes information in two capacities:
- As a Business Associate under HIPAA when a covered-entity customer (a licensed clinician, group practice, or billing company, each a "Practitioner") uses the Service to document care or otherwise process Protected Health Information ("PHI") on behalf of patients for whom that Practitioner is the covered entity. In this role we operate under a Business Associate Agreement with the Practitioner.
- As a first-party data controller when we process information that is not PHI: account credentials, billing data, support inquiries, marketing-website visitors, product telemetry, and similar.
This Privacy Policy applies to:
- Practitioners who sign up for and use the Service.
- Visitors to the Site.
- Patients of Practitioners are not directly users of the Service. Patient PHI in EMRFlow is governed by (a) the Practitioner's own Notice of Privacy Practices and (b) the Business Associate Agreement between EMRFlow and the Practitioner. Patients with questions about their PHI should contact their Practitioner. Patients who use the Solo Practice client portal (via a magic-link issued by their clinician) to view appointments or join telehealth sessions are interacting with the Service under that arrangement.
2. Information We Collect
Information you provide directly
- Account information: name, email, password (hashed via bcrypt for Solo Practice; managed by Firebase Auth or OAuth for EHR-connected sign-in), practice name, license type, NPI number, taxonomy code, supervisor relationships where applicable. Solo Practice sign-in can optionally use Google or Apple sign-in; we do not see or store your Google or Apple password, and if you use Apple sign-in with "Hide My Email" we receive only the relay address Apple provides.
- Practice and patient records: when you use the Service, you create patient records, appointments, session notes, intake forms, supervision logs, claims, and similar clinical/administrative content. This is PHI; we are your business associate with respect to this information.
- Billing information: your subscription plan and status, your payment method (handled by Stripe; we do not see or store full credit-card numbers), invoice history. For Solo Practice Practitioners taking patient payments through their own Stripe Connect account, EMRFlow facilitates the flow but does not hold the funds; payments settle directly to the Practitioner's Stripe Connect account.
- Voice recordings: when you use voice dictation, audio is sent to our HIPAA-aligned transcription provider (Deepgram), transcribed to text, and then discarded by the provider after transcription. Audio is not stored on EMRFlow's servers.
- Telehealth session content: when you conduct a Solo Practice Pro telehealth session, video and audio are transmitted via Daily.co's HIPAA-mode infrastructure for the duration of the call. Session content is not recorded or stored.
- Patient intake responses: free-text and form-field responses submitted via the patient intake portal at https://forms.emrflow.com or via clinician-shared intake links.
- Provider-matching and early-access inquiries: when you submit a public interest form at https://forms.emrflow.com (for example, "Find a Therapist" for families seeking care, or "I'm a Therapist" for clinicians requesting early access), we collect the contact and routing details you provide: name, email address, and phone number (optional for families seeking care; required for clinicians requesting early access), plus, for care-seekers, ZIP code and the type of service requested. We use these solely to respond to your inquiry and, where applicable, match you with a provider, including by email, phone call, or text message. These are general business inquiries used to route and respond to you; they do not include clinical records.
- Support communications: when you contact us through Freshdesk or by email, we keep a record of the communication. A support ticket may optionally include diagnostic information you choose to attach (your app version, device model, operating system, role, and recent app log entries, with sensitive data automatically removed) to help us resolve your issue. PHI is out of scope for support tickets and feature requests; please contact us through the channels described in your Business Associate Agreement if you need to discuss patient-specific information.
- Website contact form: when you submit the contact form on emrflow.com, we collect your name, email address, area of interest, your message, and, if you choose to provide it, a phone number. The phone number is optional. If you also check the separate SMS consent box, we use your number to send the informational and conversational text messages described in Section 4 (SMS and text messaging). These are general business inquiries and do not include clinical records.
Information collected automatically
- Device and log information: IP address, browser/app version, operating system, device identifiers, device language, time zone, diagnostics, and pages or features used. Used for service operation, security monitoring, abuse prevention, customer support, and aggregate analytics.
- Crash and stability diagnostics: in our mobile apps (release versions only), we use Firebase Crashlytics to automatically collect crash reports — for example the error and stack trace, app and operating-system version, and device model — so we can diagnose and fix stability problems. These reports are not linked to your account identity and are configured to exclude PHI; they are not used for advertising or tracking.
- Anti-abuse tokens: Firebase App Check tokens (Apple App Attest on iOS/iPadOS, Play Integrity on Android) verify that an API request comes from a legitimate EMRFlow build. These are device-attestation tokens, not a fingerprint of you.
- Inactivity timestamps: the apps record a local timestamp of the most recent user interaction (touch, click, key press) to enforce automatic sign-out after 30 minutes of inactivity, an addressable HIPAA Security Rule safeguard. The timestamp is stored locally in SharedPreferences (mobile) or localStorage (web) and is not transmitted to EMRFlow.
- Cookies: the Site uses cookies for session management and basic analytics. You can control cookies via your browser settings.
Information from third parties
- Authentication providers: if you sign in via SMART on FHIR against your EHR (OpenEMR, Epic, Cerner, etc.), the EHR sends us a minimal authentication token. No PHI is shared by default during login; subsequent clinical reads against the EHR are scoped to what you authorize through the EHR's consent screen.
- Sign-in providers (Google / Apple): if you sign in to Solo Practice with Google or Apple, we receive a minimal authentication token and your email (or Apple relay address). No contacts, calendar, or other account data is requested. These providers handle only the sign-in step: no patient health information (PHI) is sent to Google or Apple as part of authentication. (Google / Firebase Authentication is covered under our Google Cloud BAA; Apple receives nothing beyond the sign-in.)
- Stripe: payment status and subscription events.
- ClaimMD: claim acknowledgments, eligibility responses, and ERAs (835 remittances) returned to EMRFlow for posting against the encounter.
3. How We Use Information
We use information to:
- Provide, operate, secure, and improve the Service.
- Authenticate users and prevent unauthorized access.
- Document patient care and produce clinical artifacts (SOAP notes, superbills, supervision logs, attendance records, claims, ERA postings).
- Submit insurance claims to clearinghouses on the Practitioner's behalf.
- Schedule, host, and document telehealth visits.
- Transcribe voice dictation (audio sent to Deepgram, then discarded; we do not retain audio after transcription completes).
- Generate AI-assisted draft notes (via Anthropic Claude on Amazon Bedrock) that the clinician must review and sign. AI-generated content is a tool, not a substitute for clinician judgment, and is not medical advice.
- Process platform subscription payments and patient-billing payments.
- Send transactional emails (account verification, password reset, receipt, telehealth invitation, intake invitation, supervision cosign request, client-portal magic link).
- Provide customer support and respond to inquiries.
- Detect, prevent, and respond to fraud, abuse, and security incidents.
- Enforce a 30-minute automatic sign-out after periods of inactivity as required by HIPAA Security Rule §164.312(a)(2)(iii).
- Comply with legal obligations, including HIPAA's six-year audit-log retention rule, state breach notification laws, and tax and financial recordkeeping requirements.
PHI is used only as permitted by the Business Associate Agreement and HIPAA: to provide the Service, for proper management and administration of EMRFlow, and to carry out our legal responsibilities. We do not use PHI for marketing, advertising, or to train AI models.
4. How We Share Information
We share information only as described below.
Service providers (sub-business associates)
We use the third-party service providers listed below to operate the Service. Each is bound by a written agreement that requires the same level of protection we provide. Where the provider handles PHI, a Business Associate Agreement is required.
| Provider | Purpose | PHI involved | BAA status |
|---|---|---|---|
| Google Cloud (Firebase, Firestore, Cloud Functions, Cloud Storage, Firebase Auth, App Check) | Database, authentication, file storage, serverless compute, device attestation | Yes | Yes; covered under Google Cloud BAA |
| Liquid Web | HIPAA-aligned VPS hosting for PHP backend and PostgreSQL | Yes | Yes; in place since EMRFlow's first production deployment |
| InMotion Hosting | Demo/test environment hosting only; no production PHI | No | Demo-only; out of scope |
| Stripe | Platform subscription billing; tokenized payment processing | No (PHI does not pass through Stripe) | Not required (no PHI); Stripe is PCI-DSS Level 1 |
| Stripe Connect | Per-Practitioner patient billing for Solo Practice (the Practitioner's own Connect account; we do not hold the funds) | No (no PHI; only patient name, invoice metadata, and tokenized payment) | Not required |
| Vercel | Hosting for app.emrflow.com Next.js application |
No (audited 2026-06-04; PHI-touching routes refactored or removed) | Not required (no PHI is stored or processed by Vercel serverless functions; remaining routes are opaque passthroughs to PHP/Firestore, same posture as Stripe) |
| Google Cloud Run + Firebase Hosting | Hosting for forms.emrflow.com patient intake application (Next.js SSR in a container) |
Yes (intake submissions are PHI) | Yes; covered under the existing Firebase BAA |
| ClaimMD | Insurance claims clearinghouse (837 claim submission, 270/271 eligibility, 277CA acknowledgments, 835 ERA retrieval) | Yes | Yes |
| Daily.co | Telehealth video and audio transport for Solo Practice Pro tier | Yes (ephemeral session content) | Yes; Healthcare add-on BAA in place |
| Deepgram | Voice dictation transcription (nova-2-medical model) |
Audio that may contain PHI during a session | Yes; Subcontractor BAA executed 2026-05-18 |
| AWS (Amazon Bedrock) | AI-assisted clinical note generation and form-fill suggestions, served via Anthropic Claude models hosted on Amazon Bedrock | Clinical narratives | Yes; covered under AWS BAA (same agreement covering SES) |
| AWS (Simple Email Service) | Transactional email (client portal magic link, balance reminder, cosign notification, superbill delivery) | Limited (recipient email address; body content varies by template) | Yes; covered under AWS BAA |
| Cloudflare Turnstile | Bot protection on public submission forms (intake portal, feedback board) | No (challenge token only) | Not required |
| Freshdesk | Customer support ticketing and feature-request tracking | No (PHI is out of scope for support tickets and feature requests by policy) | Not required (no PHI) |
| Firebase Crashlytics (Google) | Automatic crash and stability diagnostics for the mobile apps (release builds only) | No (configured to exclude PHI; only non-identifying crash context is sent) | Not required (no PHI) |
We do not sell, rent, or otherwise commercially license your personal information or PHI. We do not use PHI for advertising. We do not train AI models on customer PHI; clinical content sent to Anthropic Claude on Amazon Bedrock is processed under AWS Bedrock's terms, which prohibit training on customer inputs.
We update the table above as our infrastructure evolves. Significant changes are reflected in revisions to this Policy.
Legal requirements
We may disclose information when required by law, subpoena, court order, or governmental authority, or when necessary to protect the rights, property, or safety of EMRFlow, our users, or others.
Business transfers
If EMRFlow is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify Practitioners (and where required by law, individuals whose PHI is involved) before any such transfer, and the acquirer will assume the obligations of this Privacy Policy with respect to the data transferred.
With your consent
We may share information with third parties when you direct us to.
SMS and text messaging
If you give us your phone number and check the SMS consent box on a contact form on emrflow.com, you consent to receive informational and conversational text messages from EMRFlow related to your inquiry, such as replies to your question and account or appointment notifications. We do not send marketing or promotional text messages without your separate, express consent.
SMS consent is never a condition of using the Service or submitting a form, and you may decline it and still reach us by email or phone. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP, and reply HELP for help.
The phone number you provide for text messaging and your SMS consent are not shared, sold, or rented to third parties or affiliates for their own marketing or promotional purposes. We share a mobile number only with the service providers that help us deliver these messages (for example, our SMS provider acting on our behalf), and only to send the messages you asked for.
5. Data Security
We use administrative, physical, and technical safeguards to protect information, including:
- TLS 1.2 or higher for data in transit.
- AES-256 encryption for data at rest in primary stores.
- Role-based access controls with least-privilege defaults; Firestore security rules scoped per Practitioner and per bucket.
- Multi-factor authentication on administrative consoles.
- Firebase App Check device-attestation on protected API endpoints.
- Automatic sign-out after 30 minutes of inactivity (HIPAA Security Rule §164.312(a)(2)(iii) addressable safeguard).
- Apple Keychain on iOS/iPadOS and Android Keystore on Android for client-side credential storage.
- Audit logs for client CRUD, session note creation, form edits, supervision cosign send/failure, and other PHI-touching events.
- Daily encrypted backups; key-only SSH access to the production VPS; fail2ban on the production VPS.
- Annual risk assessments; subprocessors operate under written agreements requiring equivalent safeguards.
No system is completely secure. If we discover a breach of unsecured PHI, we will notify affected Practitioners as required by HIPAA and applicable state law (see Section 12).
6. Data Retention
We retain information for the periods described below.
| Category | Retention |
|---|---|
| Clinical records (PHI) | Duration of the Practitioner relationship plus the period required by the Business Associate Agreement and applicable state law (typically at least six years post-termination) |
| Practitioner account records (non-PHI) | Duration of the subscription plus a reasonable period for audit and tax purposes |
| Subscription billing records | Seven years for tax and accounting purposes |
| Telehealth session content | Not retained; Daily.co does not store session content beyond the call under HIPAA-mode operation |
| Voice-dictation audio | Discarded after transcription completes; the resulting transcript is retained as part of the clinical record |
| Audit logs | At least six years (HIPAA Security Rule §164.316(b)(2)(i)) |
| Marketing-website analytics | Up to 24 months in aggregate form |
| Support tickets (Freshdesk) | At least three years after the ticket is closed |
| Backups | Rolling encrypted backups on an operational recycle schedule; deleted records may persist in cold backup media for up to 90 additional days |
Practitioners may request deletion of their account at any time via the in-app account-deletion flow or by emailing privacy@emrflow.com. On termination:
- Practitioner accounts are scheduled for deletion 30 days after termination unless immediate deletion is requested.
- PHI is deleted, returned to the Practitioner, or extended under the Business Associate Agreement's retention provisions, per the Practitioner's instructions.
- Audit logs are preserved for at least six years even when the underlying records are deleted.
7. Your Rights
Depending on your jurisdiction, you may have rights regarding your information.
HIPAA (PHI in the Service)
Patients should contact their Practitioner; their rights to access, amend, request an accounting of disclosures, request restrictions, and request confidential communications are described in the Practitioner's Notice of Privacy Practices. EMRFlow's role as Business Associate is to support these rights, not to determine them. The Practitioner (the covered entity) is the legally responsible party.
U.S. state consumer privacy laws
Residents of states with comprehensive consumer privacy laws may have the rights described below with respect to non-PHI personal information we process about them in our first-party capacity. Most of these laws exclude PHI from their scope because HIPAA governs PHI.
Laws currently in scope (verify the up-to-date list with counsel):
- California (CCPA / CPRA)
- Virginia (VCDPA)
- Colorado (CPA)
- Connecticut (CTDPA)
- Utah (UCPA)
- Oregon (OCPA)
- Texas (TDPSA)
- Montana (MCDPA)
- Iowa (Iowa Consumer Data Protection Act)
- Indiana (Indiana Consumer Data Protection Act)
- Tennessee (TIPA)
- Delaware (DPDPA)
- New Hampshire (NH SB 255)
- New Jersey (NJ SB 332)
Rights typically include:
- Right to know what personal information we collect.
- Right to access a copy of your personal information.
- Right to delete personal information, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of "sales" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioral advertising.
- Right to non-discrimination for exercising these rights.
GDPR (EU/EEA)
If you access the Service from the EU or EEA, additional rights under GDPR may apply (access, rectification, erasure, portability, restriction, objection; lawful basis: contract performance and legitimate interest). Confirm with counsel whether EU/EEA users are in scope; the Service is operated from the United States and is not currently marketed to EU/EEA residents.
How to exercise your rights
Email privacy@emrflow.com with your request. We will respond within the timeframe required by applicable law (typically 30 to 45 days).
8. Children's Privacy
The Service is sold to healthcare professionals. We do not knowingly collect personal information directly from children under 13. PHI of pediatric patients of Practitioners is governed by HIPAA, applicable state law, and the consent of the patient's parent or legal guardian, as obtained by the Practitioner.
If you believe a child under 13 has provided us with personal information through the marketing website or another non-clinical surface, contact privacy@emrflow.com and we will delete the information.
9. International Users
EMRFlow is operated from the United States. Some subprocessors may operate edge infrastructure (e.g., content-delivery networks for marketing content) outside the United States; PHI does not transit those edge layers. If you access the Service from outside the United States, you consent to the processing of your information in the United States in accordance with this Policy.
10. Cookies and Similar Technologies
The Site uses cookies for:
- Strictly necessary cookies: session management, authentication, theme preference.
- Analytics cookies: aggregate usage analytics. We do not use cross-site advertising trackers.
The apps use SharedPreferences (mobile) and localStorage (web) for session state, theme preference, and the inactivity-logoff timestamp. None of this is shared with third parties.
You can control cookies via your browser settings. Disabling strictly necessary cookies will impair the Site.
11. Third-Party Links
The Site and Service may contain links to third-party websites. This Privacy Policy does not apply to those sites. We encourage you to read the privacy policies of any third party you visit.
12. Breach Notification
In the event of a breach of unsecured PHI as defined by the HIPAA Breach Notification Rule, we will notify the affected covered-entity Practitioner without unreasonable delay and no later than 60 days from discovery, providing the information necessary for the Practitioner to fulfill its own notification obligations to affected individuals, the U.S. Department of Health and Human Services Office for Civil Rights, and (where required) the media.
For non-PHI personal information, we will notify affected users in accordance with applicable state breach notification laws.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The "Effective Date" and "Last Updated" dates at the top reflect the current version. If we make material changes, we will notify Practitioners by email and/or post a prominent notice in the Service. We maintain prior versions on request; contact privacy@emrflow.com.
14. Contact Us
Questions, requests under this Policy, and complaints can be directed to:
Facets Novum, LLC d/b/a EMRFlow
3961 Floyd Rd, Suite 300-229
Austell, GA 30106
United States
Privacy contact: privacy@emrflow.com Security contact: security@emrflow.com General support: support@emrflow.com
If you are not satisfied with our response, you may file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at https://www.hhs.gov/hipaa/filing-a-complaint or with your state attorney general's consumer-protection office.