Skip to content

Security

Security built for healthcare practice ops

CaseFlow PI protects case operations data with practice isolation, role-based access, audit logging, and careful handling of sensitive workflow records.

Access and tenancy

  • Authentication with access and refresh tokens, plus password policy controls
  • Role-based permissions so staff only act on what they are allowed to see
  • Practice-scoped tenancy across core records
  • Login domain controls for practice administrators

Visibility and accountability

  • Immutable activity events for meaningful case workflow changes
  • Clear ownership when someone asks who changed a status or assignment
  • In-app support tickets with practice context instead of a shared inbox free-for-all

Data in transit and attachments

  • TLS for production traffic via reverse proxy
  • CORS restricted to known origins
  • Secrets kept out of source control
  • Private object storage path for case attachments

How we work with practices

On a demo we walk through access model, audit trail, and hosting expectations for your environment. If your security or compliance team has a checklist, bring it. We will map CaseFlow controls to it directly.

Report a security issue

Email security@caseflowpi.com. Do not include patient or case identifiers in vulnerability reports.

Book a demo to discuss security requirements

See CaseFlow on a short demo

Tell us about your practices and workflows. We will show the product, talk fit, and follow up with pricing if it makes sense.