Identify information, access and responsibilities
List the types of information processed and the people or providers who may access them. Review permissions, staff access reviews, account recovery and how support requests are handled. Ask which party is responsible for each control and incident response step.
Request useful evidence
Discuss audit history, encryption, backup restoration, vulnerability management and incident notification. Check the scope and date of any assessment or certification offered. Do not assume that an infrastructure provider’s certification automatically covers every application or operating process.
Keep the public website separate from clinical care
Flor’s marketing forms and public assistant accept product questions and business contact details. They are not patient-record systems. Clinical privacy, security, contracts and operational readiness remain release-review items. No HIPAA, PIPEDA or provincial compliance certification is claimed here.
Privacy questions for US practices
Where HIPAA applies, assess the actual services, safeguards and responsibilities involved. Ask about business associate agreements and verify the precise products covered. A vendor label or encryption feature alone does not establish compliance.
Read the guidance from US Department of Health & Human Services ↗
A few common questions
Is Flor HIPAA compliant?
Flor does not make a general HIPAA compliance claim on this site. Where HIPAA applies, review the exact services, business associate agreements and safeguards with the team.
Does Flor guarantee Canadian data residency?
No patient-data residency promise is made here. Hosting and processing locations must be confirmed for the actual clinical service and contract.
Prepared for clinic owners in United States. Updated September 16, 2026. These guides support product evaluation and do not replace professional or legal advice.