On behalf of the clinic
Appointment data, intake responses, staff schedules, and supply ledgers are processed as a service to you. You decide retention inside the product. You decide who has a login. You configure what data you put in the system.
Home / Security
Trust
MedDesk Flow is administrative software that may process protected health information on behalf of a covered-entity customer. We take that seriously. We do not advertise a HIPAA certification we do not hold, and we do not pretend a vendor can be your entire compliance program.
Shared responsibility
If you are a covered entity or business associate, you remain responsible for policies, workforce training, patient rights, and deciding what you put into the system. We are a technology vendor. We are responsible for building and operating MedDesk Flow with administrative, technical, and physical safeguards appropriate to a B2B operations tool.
Business Associate Agreements are available on request if we process PHI on behalf of a covered entity. Ask at hello@stubclaw.com.
Data handling
Appointment data, intake responses, staff schedules, and supply ledgers are processed as a service to you. You decide retention inside the product. You decide who has a login. You configure what data you put in the system.
The customer sends reminders to their patients. Copy should stay operational: time, location, how to reschedule. We help you write templates that do not wander into clinical detail on a carrier network.
If you enable the notes relay, audio and drafts are processed to produce a clinician-reviewed note. You can disable it per visit. It is not an unsupervised medical record and it does not diagnose.
The inventory module is for non-pharmaceutical supplies. We do not host a controlled-substance cabinet or an e-prescribing network. We do not sell PHI.
Our HIPAA Compliance Server Audit (from $84.99) reviews configuration and hosting controls and returns written findings. It is not a certificate you hang in the lobby.
Card payments are processed by Stripe, Inc. We never see full card numbers. Stripe is an independent controller of card data. See Stripe's Privacy Policy.
This page is product language, not a legal opinion. It does not make MedDesk Flow HIPAA certified. No private vendor issues that stamp. Customers who need a Business Associate Agreement, a security questionnaire, or a walkthrough of our subprocessors should write to us before they put live patient data in the system.
Acceptable use is in our Terms of Service: you may not use MedDesk Flow to practice medicine as a service of the platform, or to sell drugs through it.
Request security details