Security

Security and privacy built into every step.

Florence handles some of the most sensitive information a family has, so protection and consent are part of the product, not an afterthought.

HIPAA and compliance

Health information in the United States is protected by HIPAA, and our approach is to build as if every piece of family information deserves that level of care, whether or not a given data flow technically requires it. That shapes how we store information, who can see it, and what gets logged.

Where we are today: encryption in transit and at rest with customer-managed keys, role-scoped access, and logging on access to health information. We share our full posture with partner organizations directly, including what is and is not yet independently assessed.

What we are working toward: independent validation of our security program. We would rather tell you plainly what is done and what is in progress than put a badge on a webpage.

Most systems treat consent as a form you sign on the way in. Florence treats it as the way the whole product works. Nothing about a family moves anywhere without the family choosing it.

The family owns the profile

A family builds their profile once and it belongs to them. Florence holds it on their behalf, not the other way around.

Sharing follows the care relationship

As we bring partner organizations on, information will flow to a provider only because that provider already serves the family. Florence never shops a profile around.

The family sees and controls access

Consent is a living setting, not a one-time signature: families will always be able to see who has access to their profile, change it, and revoke it.

This is also why Florence is free for families. Our model is that the provider organizations already serving a family partner with us to receive the profile that family chooses to share. Families are the point of the product, never the product itself.

How we handle data

  • Encrypted in transit and at rest

    Family information is encrypted whenever it moves and wherever it is stored, with customer-managed encryption keys on our databases and document storage.

  • Role-based access

    Access is scoped in the database itself: row-level security policies mean an account can read its own family’s records and nothing else.

  • Audit trail

    Access to family information is logged, so there is a record of who accessed what, and when.

Questions about security

If you have questions about our security practices or how we handle family information, we want to hear them. Reach us at info@florence.care.