Skip to content

Security and readiness

Practice access comes first.

AuthFlow is in preparation for a pilot. Live patient use depends on completing the deployment and operating review with each practice.

Controls implemented for local validation

The application requires a signed-in account and an active practice membership. Staff permissions differ by role, and practice records and documents are separated by organization.

Account provisioning runs on the server through an AuthFlow administrator. Platform administration is separate from clinical workspace access. Local tests cover these boundaries; they do not verify a deployed environment.

Work required before patient data

The release review must verify deployed access rules, hosting and vendor configuration, authentication requirements, audit reliability, backup and restoration, incident handling, agreements and the practice’s operating procedures.

This site does not claim HIPAA compliance, SOC 2 certification or executed vendor agreements.

People review the decisions

Document assistance can suggest details from pasted text for staff to check. It does not replace review of the source determination or make treatment decisions. Remote AI document analysis is outside the initial pilot workflow.

Review your practice’s requirements

Start with fictional examples. Before patient use, agree who can access records, how documents and history will be handled, and who to contact for support or an incident. Pilot-specific agreements and operating responsibilities must be documented with your practice.

Discuss readiness for your practice

See how this fits your practice

Try a fictional request, or tell us where your authorization workflow needs help.