(410) 881-5120 Mon–Fri, 9AM–6PM ET Rosedale, MD · Serving Practices Nationwide
Security & Compliance

Workflows built around HIPAA, not bolted on after the fact.

We don't claim certifications Flint RCM doesn't hold. Here's what we can tell you plainly about how account access and patient data are handled.

Stated Plainly

What we can tell you, without overstating it.

We don't claim certifications Flint RCM doesn't hold. If you need documentation for a security review, ask directly — we'll tell you exactly where things stand rather than pointing to a badge.

HIPAA-Aligned Workflows

Account access, claim handling, and patient data workflows are built around HIPAA requirements as a baseline, not an afterthought bolted on later.

US-Based Team

Patient and claims data is handled by a fully US-based team — no offshore subcontracting of billing operations.

No Unverified Claims

We won't display SOC 2, AAPC, or BBB badges we don't hold. If a certification matters to your decision, ask us directly and we'll answer plainly.

Access & Handling

How account access is scoped.

Scoped to billing functions

Access to your EHR/PM system during an engagement is scoped to the billing and coding functions the work requires — not a blanket handoff of every system your practice runs.

No data migration

Patient and claims data stays inside the system you already run. We don't require exporting your records to a separate platform to do the work.

US-based staff only

Everyone with access to patient and claims data as part of your account is a US-based Flint RCM employee — not an offshore subcontractor.

Ask before you sign

If your organization has a security questionnaire or vendor-review process, send it over — we'll answer directly rather than after the fact.

Have a security questionnaire to send us?

We're happy to work through a vendor review before you commit to anything.