Bedside Flow LLC | Effective Date: May 1, 2026
Applies to: iOS App | Web Application | All Institutional Deployments
Your privacy is foundational to how we built Code Blue Hero. We do not sell personal data. We do not use your data to train AI models. We collect only what we need to run the platform and support clinical care coordination.
Code Blue Hero is a product of Bedside Flow LLC, a healthcare technology company based in Downers Grove, Illinois. We built Code Blue Hero to help clinical teams coordinate cardiac arrest response in real time.
For questions about this Privacy Policy or your data, contact us at:
Privacy & HIPAA: privacy@codebluehero.org
Legal: legal@codebluehero.org
Website: www.codebluehero.org
This Privacy Policy applies to all users of the Code Blue Hero iOS application and web application, including individual clinicians, institutional administrators, and pilot program participants. It describes how we collect, use, store, share, and protect information about you.
This Policy does not apply to third-party services (such as Epic EHR or your institution’s network infrastructure) that we integrate with but do not control. Those services are governed by their own privacy policies.
We collect information in three ways: information you provide directly, information generated automatically when you use the Platform, and information provided by your institution.
When you create an account or are provisioned by your institution, we may collect:
During an active code blue event, the Platform may capture:
Clinical event data may constitute Protected Health Information (PHI) under HIPAA if it is linked to an identifiable patient. PHI is only processed where a Business Associate Agreement (BAA) has been executed between Bedside Flow LLC and the applicable institution. In non-BAA deployments, users must not enter patient-identifiable information.
We automatically collect non-identifiable usage data to improve the Platform, including:
Analytics data is stripped of PHI and direct personal identifiers before transmission. We do not use behavioral analytics that track individual users across sessions for advertising purposes.
We collect technical data to support app functionality and security:
Healthcare institutions deploying Code Blue Hero may provide us with user roster data for provisioning purposes, including employee names, email addresses, departments, and role designations. This data is used solely for account provisioning and access management.
| Purpose | Data Used |
|---|---|
| Provide and operate the Platform | Account data, clinical event data, device data |
| Authenticate users and enforce session security | Account data, device identifier, IP address |
| Generate post-code event documentation | Clinical event data (PHI-enabled deployments only) |
| EHR write-back (where configured) | Clinical event data mapped to FHIR R4 resources |
| Improve the Platform (analytics) | Anonymized/pseudonymous usage data only |
| Send important notices and updates | Work email address |
| Respond to support requests | Account data, session logs |
| Legal compliance and fraud prevention | Account data, device data, IP address |
| Enforce Terms of Service | Account data, usage data |
We do NOT use your data to:
We do not sell personal data. We share information only in the following limited circumstances:
If you access Code Blue Hero through an institutional deployment, your employer or institution may have access to aggregate event data, usage reports, and (under a BAA) clinical event records generated during your use of the Platform. Institutional administrators can view, export, and manage data for users they have provisioned.
We use a limited set of trusted service providers to operate the Platform. These providers process data on our behalf under contractual data protection obligations. Current subprocessors include:
We will update this list as subprocessors change. Institutions requiring a complete subprocessor list for HIPAA or procurement purposes may request it at privacy@codebluehero.org.
Where Epic write-back is configured, clinical event data is transmitted to your institution’s Epic environment via SMART on FHIR protocol. This transmission occurs only under an executed BAA and at the direction of your institution. Bedside Flow LLC does not retain a copy of data after confirmed write-back unless required for error recovery.
We may disclose your information if required by law, court order, or government authority, or if we believe in good faith that such disclosure is necessary to protect the rights, property, or safety of Bedside Flow LLC, our users, or the public.
If Bedside Flow LLC is involved in a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction. We will notify affected users via email or in-app notice prior to any such transfer and ensure the receiving party is bound by equivalent data protection obligations.
If your institution has executed a Business Associate Agreement (BAA) with Bedside Flow LLC, the terms of that BAA govern the handling of Protected Health Information and supplement this Privacy Policy. The BAA controls in the event of any conflict with this Policy regarding PHI.
Bedside Flow LLC operates as a Business Associate under HIPAA where it creates, receives, maintains, or transmits PHI on behalf of a Covered Entity. Our HIPAA compliance commitments include:
| Data Type | Retention Period |
|---|---|
| Account registration data | Duration of account + 3 years after deletion request |
| Clinical event data (non-PHI) | 3 years from event date, then deleted |
| Clinical event data (PHI — BAA deployments) | As specified in BAA; default 6 years per HIPAA |
| Analytics/usage data (anonymized) | 24 months rolling |
| Crash logs and error reports | 90 days |
| Audit logs (admin access, data exports) | 6 years |
| Institutional roster data | Duration of institutional contract + 90 days |
| IP addresses (authentication) | 90 days maximum |
| Backup snapshots | 30 days rolling |
Users may request deletion of their account and associated non-PHI data at any time by contacting privacy@codebluehero.org. PHI deletion is subject to BAA terms and applicable legal hold obligations.
Bedside Flow LLC implements industry-standard technical and organizational security measures to protect your data, including:
No security system is impenetrable. In the event of a data breach affecting your information, we will notify you and your institution in accordance with applicable law and our BAA obligations.
Depending on your location and applicable law, you may have the following rights regarding your personal data:
You may request a copy of the personal data we hold about you. We will provide this in a structured, commonly used format within 30 days of a verified request.
You may request correction of inaccurate or incomplete personal data. Account data can be updated directly in app settings. For institutional account data, contact your institutional administrator.
You may request deletion of your account and non-PHI personal data. Send deletion requests to privacy@codebluehero.org. Deletion will be completed within 45 days, subject to legal hold and BAA obligations.
You may opt out of non-essential analytics data collection in the app settings under Privacy Preferences. Opting out does not affect core Platform functionality.
You may manage push notification and email preferences in your account settings at any time.
California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know, delete, correct, and opt out of sale of personal information. We do not sell personal information. To submit a CCPA request, contact privacy@codebluehero.org. We will not discriminate against you for exercising your CCPA rights.
If your account was provisioned by your employer or institution, some rights (such as data access and deletion) may be exercised through your institutional administrator. Bedside Flow LLC will cooperate with institutions in responding to individual rights requests.
Code Blue Hero is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a user under 18 has provided personal data, we will delete it promptly. If you believe a minor has registered, contact privacy@codebluehero.org.
The Code Blue Hero web application uses the following types of cookies and local storage:
| Type | Purpose |
|---|---|
| Essential session cookies | Authentication and session management — required for app function |
| Security cookies | CSRF protection and fraud prevention |
| Preference cookies | Storing user UI preferences (e.g., dark mode, notification settings) |
| Analytics cookies (optional) | Anonymized usage analytics — can be opted out in Privacy Preferences |
We do not use advertising cookies, third-party tracking pixels, or cross-site tracking technologies. Essential and security cookies cannot be disabled without impairing core functionality.
Code Blue Hero uses an offline-first architecture. Clinical event data is captured and stored locally on your device during an active event to ensure functionality in low-connectivity clinical environments. This data is:
Users are responsible for maintaining device-level security (screen lock, biometric authentication, device encryption) consistent with their institution’s security policies.
The Platform may contain links to third-party resources or integrate with institutional systems (e.g., Epic EHR, Vocera, Rauland). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you interact with through or alongside the Platform.
Bedside Flow LLC is not responsible for the privacy practices of third-party systems, including your institution’s Epic environment.
We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or applicable law. We will notify users of material changes via in-app notification or email at the work address on file, at least 30 days before the effective date of changes.
The current version of this Policy, including its effective date, is always accessible at www.codebluehero.org/privacy and within the app under Settings > Legal > Privacy Policy.
Continued use of the Platform after the effective date of a revised Policy constitutes your acceptance of the changes.
For privacy questions, data requests, HIPAA concerns, or to submit a rights request:
Bedside Flow LLC — Code Blue Hero
Privacy & HIPAA: privacy@codebluehero.org
Legal: legal@codebluehero.org
Downers Grove, Illinois, USA
www.codebluehero.org
We will acknowledge all privacy requests within 5 business days and respond substantively within 30 days.
Sign up now to be the first to see how Code Blue Hero works.