Privacy Policy
RecordsFlow ("we", "us") helps patients gather their own medical records and share them with the attorney they choose. This policy explains what we collect, why, who sees it, how we protect it, and how you can stop us. We handle your health information only under a written authorization that you sign.
What we collect
- Case details your attorney's office enters to open your case: your name, mobile number, date of birth, date of injury, preferred language, and the law firm's name.
- Your authorization: your typed signature, the time you signed, the choices you made, and technical details such as IP address and device, kept as proof of consent.
- Your medical and insurance records, retrieved only from sources you connect and approve, only after you sign.
- An access log of actions taken on your case (who did what, and when). The log records identifiers and actions, not the contents of your records.
What we do not collect
- Your portal and insurer passwords. You log in on each source's own website and approve sharing there. We never see or store your login.
- Payment card information. We do not collect it from patients.
Why we use it
We use your information only to retrieve the records you authorized, store them securely, organize them into a timeline, and deliver them to the attorney named in your authorization. The purpose of every retrieval is patient access with your consent. We do not use your records for marketing and we do not sell them.
Who can see it
- The attorney and law firm named in your authorization.
- Service providers that help us retrieve and store records on our behalf, such as the technology services that connect to patient portals and insurers. They may process your records only to provide the service to us.
- Automated summaries. If we use automated tools to summarize records, we use them only with providers that are bound by written agreements covering health information and that may not keep or train on your data.
- Legal requirements. We may disclose information when the law requires it.
Text messages we send contain a private link and a status word only, never health information.
Sensitive records
Mental health records, substance use treatment records, HIV/STD records and psychotherapy notes are not included unless you check that box yourself on the authorization.
How we protect it
- Your records are encrypted when stored, and each stored file is fingerprinted so that changes can be detected.
- Nothing is retrieved or stored for a case unless it has a current, unrevoked, unexpired authorization.
- Every action on a case is written to a tamper-evident log.
- Access is limited to authorized personnel and protected by a secret credential.
No system is perfectly secure. If a breach affects your information, we will notify you and others as the law requires.
How long we keep it, and how to stop us
- Your authorization lasts for the period stated on it (one year by default) unless you end it sooner.
- You can revoke at any time. When you revoke, we stop retrieving records for your case right away. You can also ask us to delete the records we stored for it, and we will. We keep a log that the deletion happened, but not what the files contained.
- Records that your attorney has already received are held by your attorney under their own obligations, and revoking with us does not undo that.
Your rights
You may ask us what we hold about you, ask us to correct case details, and revoke your authorization. You also keep your own rights to your records under federal and Texas law, including the right to request them directly from your providers. To make any request, email us at the address below.
Children and representatives
If the patient is a minor or cannot sign for themselves, we require a legal guardian or representative and the supporting documents. We do not proceed without them.
Changes
If we change this policy, we will post the new version here with a new effective date. A change does not widen what you already authorized.
Contact
RecordsFlow, Texas. Email hssolutions2181@gmail.com.