LynxFlow Health is a remote patient monitoring platform. It handles protected health information, and it is built to meet HIPAA requirements: access is scoped by role, every access to patient data is written to an audit log, and sensitive fields are encrypted at rest.
We use it to operate the monitoring service: to present readings to the clinicians responsible for a patient, to run the reports and analytics you request, to send service email such as invitations and scheduled summaries, to process subscription payments, and to secure the platform and meet our regulatory obligations. We do not sell personal information, and we do not use it for advertising.
When you ask AI Analytics a question, the platform builds a briefing from the records you are authorised to see and replaces patient identifiers with opaque tokens before anything leaves our systems. The AI provider receives the tokenised text — for example "PT-001" — never the patient's name. Identifiers are restored in the answer only after it returns, and only for you.
Files you attach are streamed to the provider to answer your question and are never written to our storage or database; only the filename, type, and size are recorded alongside the message. Every AI Analytics query that touches patient records is written to the audit log.
We share information with service providers who process it on our behalf, under contract and only for the purposes above:
We also share information with your own clinicians, facility, and organisation as the platform's role model requires, and where the law obliges us to.
Access is scoped by role and enforced server-side, not merely hidden in the interface. Sensitive fields are encrypted at rest, traffic is encrypted in transit, and every access to patient data is recorded in an audit log capturing who accessed what, when, and from where. Audit records are retained for six years in line with HIPAA requirements. No system is perfectly secure, but these controls are actively maintained and reviewed.
We use only essential cookies, for secure login and session management. There are no analytics, advertising, or tracking cookies. See the Cookie Policy for the full list.
You may request access to the personal information we hold about you, ask for corrections, and ask for deletion where we are not required to retain it. If your record is held by a healthcare provider using the platform, that provider is the custodian of your health record and we will direct your request to them. Contact us at the address below to make a request.
We keep account and health information for as long as your account is active and afterwards for as long as we are required to. Audit logs are retained for six years. Files attached to AI Analytics questions are not retained at all.
Privacy questions and requests can be sent to support@lynxflowhealth.com.