Workflows built around HIPAA, not bolted on after the fact.
We don't claim certifications Flint RCM doesn't hold. Here's what we can tell you plainly about how account access and patient data are handled.
What we can tell you, without overstating it.
We don't claim certifications Flint RCM doesn't hold. If you need documentation for a security review, ask directly — we'll tell you exactly where things stand rather than pointing to a badge.
HIPAA-Aligned Workflows
Account access, claim handling, and patient data workflows are built around HIPAA requirements as a baseline, not an afterthought bolted on later.
US-Based Team
Patient and claims data is handled by a fully US-based team — no offshore subcontracting of billing operations.
No Unverified Claims
We won't display SOC 2, AAPC, or BBB badges we don't hold. If a certification matters to your decision, ask us directly and we'll answer plainly.
How account access is scoped.
Scoped to billing functions
Access to your EHR/PM system during an engagement is scoped to the billing and coding functions the work requires — not a blanket handoff of every system your practice runs.
No data migration
Patient and claims data stays inside the system you already run. We don't require exporting your records to a separate platform to do the work.
US-based staff only
Everyone with access to patient and claims data as part of your account is a US-based Flint RCM employee — not an offshore subcontractor.
Ask before you sign
If your organization has a security questionnaire or vendor-review process, send it over — we'll answer directly rather than after the fact.
Have a security questionnaire to send us?
We're happy to work through a vendor review before you commit to anything.