Security
Security built for healthcare practice ops
CaseFlow PI protects case operations data with practice isolation, role-based access, audit logging, and careful handling of sensitive workflow records.
Access and tenancy
- Authentication with access and refresh tokens, plus password policy controls
- Role-based permissions so staff only act on what they are allowed to see
- Practice-scoped tenancy across core records
- Login domain controls for practice administrators
Visibility and accountability
- Immutable activity events for meaningful case workflow changes
- Clear ownership when someone asks who changed a status or assignment
- In-app support tickets with practice context instead of a shared inbox free-for-all
Data in transit and attachments
- TLS for production traffic via reverse proxy
- CORS restricted to known origins
- Secrets kept out of source control
- Private object storage path for case attachments
How we work with practices
On a demo we walk through access model, audit trail, and hosting expectations for your environment. If your security or compliance team has a checklist, bring it. We will map CaseFlow controls to it directly.
Report a security issue
Email security@caseflowpi.com. Do not include patient or case identifiers in vulnerability reports.
See CaseFlow on a short demo
Tell us about your practices and workflows. We will show the product, talk fit, and follow up with pricing if it makes sense.