Skip to main content

Bedsideflow

Privacy Policy

Bedside Flow LLC | Effective Date: May 1, 2026

Applies to: iOS App | Web Application | All Institutional Deployments

Your privacy is foundational to how we built Code Blue Hero. We do not sell personal data. We do not use your data to train AI models. We collect only what we need to run the platform and support clinical care coordination.

1. Who We Are

Code Blue Hero is a product of Bedside Flow LLC, a healthcare technology company based in Downers Grove, Illinois. We built Code Blue Hero to help clinical teams coordinate cardiac arrest response in real time.

For questions about this Privacy Policy or your data, contact us at:

Privacy & HIPAA: privacy@codebluehero.org

Legal: legal@codebluehero.org

Website: www.codebluehero.org

2. Scope of This Policy

This Privacy Policy applies to all users of the Code Blue Hero iOS application and web application, including individual clinicians, institutional administrators, and pilot program participants. It describes how we collect, use, store, share, and protect information about you.

This Policy does not apply to third-party services (such as Epic EHR or your institution’s network infrastructure) that we integrate with but do not control. Those services are governed by their own privacy policies.

3. Information We Collect

We collect information in three ways: information you provide directly, information generated automatically when you use the Platform, and information provided by your institution.

3.1 Account & Registration Data

When you create an account or are provisioned by your institution, we may collect:

  • Full name and professional title
  • Work email address
  • Institution name and department
  • Role type (e.g., RN, MD, RT, Charge Nurse)
  • ACLS certification status (if self-reported or institution-provided)
  • Username and hashed password (we never store plain-text passwords)

3.2 Clinical Event Data

During an active code blue event, the Platform may capture:

  • Event start time, end time, and duration
  • Role assignments made during the event
  • Timer events and ACLS protocol steps completed
  • Medication administration records entered by users
  • Intervention notes and free-text fields
  • Post-code documentation entries

Clinical event data may constitute Protected Health Information (PHI) under HIPAA if it is linked to an identifiable patient. PHI is only processed where a Business Associate Agreement (BAA) has been executed between Bedside Flow LLC and the applicable institution. In non-BAA deployments, users must not enter patient-identifiable information.

3.3 Usage & Analytics Data

We automatically collect non-identifiable usage data to improve the Platform, including:

  • Feature interaction events (e.g., which timers were used, which protocol cards were opened)
  • Session duration and frequency
  • App version, OS version, and device type
  • Crash reports and error logs
  • Network connectivity status at time of use

Analytics data is stripped of PHI and direct personal identifiers before transmission. We do not use behavioral analytics that track individual users across sessions for advertising purposes.

3.4 Device & Technical Data

We collect technical data to support app functionality and security:

  • Device identifier (for session management and single-device enforcement)
  • Push notification token (if notifications are enabled)
  • IP address (for authentication and fraud detection, not stored long-term)
  • Timezone and locale settings

3.5 Information from Your Institution

Healthcare institutions deploying Code Blue Hero may provide us with user roster data for provisioning purposes, including employee names, email addresses, departments, and role designations. This data is used solely for account provisioning and access management.

4. How We Use Your Information

We do NOT use your data to:

  • Train machine learning or AI models
  • Serve targeted advertising
  • Sell or broker to third parties
  • Build behavioral profiles for commercial purposes

5. How We Share Your Information

We do not sell personal data. We share information only in the following limited circumstances:

5.1 Your Institution

If you access Code Blue Hero through an institutional deployment, your employer or institution may have access to aggregate event data, usage reports, and (under a BAA) clinical event records generated during your use of the Platform. Institutional administrators can view, export, and manage data for users they have provisioned.

5.2 Service Providers (Subprocessors)

We use a limited set of trusted service providers to operate the Platform. These providers process data on our behalf under contractual data protection obligations. Current subprocessors include:

  • Cloud infrastructure provider (hosting, database, storage)
  • Analytics platform (anonymized usage data only)
  • Crash reporting and error monitoring service
  • Email delivery service (for account and system notifications)

We will update this list as subprocessors change. Institutions requiring a complete subprocessor list for HIPAA or procurement purposes may request it at privacy@codebluehero.org.

5.3 EHR Integration (Epic)

Where Epic write-back is configured, clinical event data is transmitted to your institution’s Epic environment via SMART on FHIR protocol. This transmission occurs only under an executed BAA and at the direction of your institution. Bedside Flow LLC does not retain a copy of data after confirmed write-back unless required for error recovery.

5.4 Legal Requirements

We may disclose your information if required by law, court order, or government authority, or if we believe in good faith that such disclosure is necessary to protect the rights, property, or safety of Bedside Flow LLC, our users, or the public.

5.5 Business Transfers

If Bedside Flow LLC is involved in a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction. We will notify affected users via email or in-app notice prior to any such transfer and ensure the receiving party is bound by equivalent data protection obligations.

6. HIPAA & Protected Health Information

If your institution has executed a Business Associate Agreement (BAA) with Bedside Flow LLC, the terms of that BAA govern the handling of Protected Health Information and supplement this Privacy Policy. The BAA controls in the event of any conflict with this Policy regarding PHI.

Bedside Flow LLC operates as a Business Associate under HIPAA where it creates, receives, maintains, or transmits PHI on behalf of a Covered Entity. Our HIPAA compliance commitments include:

  • Using and disclosing PHI only as permitted by the applicable BAA and HIPAA
  • Implementing administrative, physical, and technical safeguards to protect PHI
  • Reporting any breach of unsecured PHI to the Covered Entity within 60 days of discovery
  • Making PHI available for amendment, access, and accounting of disclosures as required
  • Returning or destroying PHI upon termination of the BAA

7. Data Retention

Users may request deletion of their account and associated non-PHI data at any time by contacting privacy@codebluehero.org. PHI deletion is subject to BAA terms and applicable legal hold obligations.

8. Data Security

Bedside Flow LLC implements industry-standard technical and organizational security measures to protect your data, including:

  • Encryption at rest (AES-256) for all stored data including on-device local storage
  • Encryption in transit (TLS 1.3) for all data transmitted between the app and our servers
  • iOS Keychain / Secure Enclave for sensitive on-device credential storage
  • Role-based access controls limiting staff access to data on a need-to-know basis
  • Regular security reviews and vulnerability assessments
  • Audit logging of all administrative data access
  • Offline-first architecture minimizing unnecessary data transmission

No security system is impenetrable. In the event of a data breach affecting your information, we will notify you and your institution in accordance with applicable law and our BAA obligations.

9. Your Rights & Choices

Depending on your location and applicable law, you may have the following rights regarding your personal data:

9.1 Access & Portability

You may request a copy of the personal data we hold about you. We will provide this in a structured, commonly used format within 30 days of a verified request.

9.2 Correction

You may request correction of inaccurate or incomplete personal data. Account data can be updated directly in app settings. For institutional account data, contact your institutional administrator.

9.3 Deletion

You may request deletion of your account and non-PHI personal data. Send deletion requests to privacy@codebluehero.org. Deletion will be completed within 45 days, subject to legal hold and BAA obligations.

9.4 Opt-Out of Analytics

You may opt out of non-essential analytics data collection in the app settings under Privacy Preferences. Opting out does not affect core Platform functionality.

9.5 Notification Preferences

You may manage push notification and email preferences in your account settings at any time.

9.6 California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know, delete, correct, and opt out of sale of personal information. We do not sell personal information. To submit a CCPA request, contact privacy@codebluehero.org. We will not discriminate against you for exercising your CCPA rights.

9.7 Institutional Users

If your account was provisioned by your employer or institution, some rights (such as data access and deletion) may be exercised through your institutional administrator. Bedside Flow LLC will cooperate with institutions in responding to individual rights requests.

10. Children’s Privacy

Code Blue Hero is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a user under 18 has provided personal data, we will delete it promptly. If you believe a minor has registered, contact privacy@codebluehero.org.

11. Cookies & Tracking (Web Application)

The Code Blue Hero web application uses the following types of cookies and local storage:

We do not use advertising cookies, third-party tracking pixels, or cross-site tracking technologies. Essential and security cookies cannot be disabled without impairing core functionality.

12. Offline Data & Device Storage

Code Blue Hero uses an offline-first architecture. Clinical event data is captured and stored locally on your device during an active event to ensure functionality in low-connectivity clinical environments. This data is:

  • Encrypted at rest using iOS Keychain / Secure Enclave (mobile) or encrypted local storage (web)
  • Synced to our servers when connectivity is available and the deployment is BAA-enabled for PHI
  • Purged from local device storage after confirmed server sync, per institutional configuration
  • Not accessible to other apps on the device

Users are responsible for maintaining device-level security (screen lock, biometric authentication, device encryption) consistent with their institution’s security policies.

13. Third-Party Links & Integrations

The Platform may contain links to third-party resources or integrate with institutional systems (e.g., Epic EHR, Vocera, Rauland). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you interact with through or alongside the Platform.

Bedside Flow LLC is not responsible for the privacy practices of third-party systems, including your institution’s Epic environment.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or applicable law. We will notify users of material changes via in-app notification or email at the work address on file, at least 30 days before the effective date of changes.

The current version of this Policy, including its effective date, is always accessible at www.codebluehero.org/privacy and within the app under Settings > Legal > Privacy Policy.

Continued use of the Platform after the effective date of a revised Policy constitutes your acceptance of the changes.

15. Contact & Data Requests

For privacy questions, data requests, HIPAA concerns, or to submit a rights request:

Bedside Flow LLC — Code Blue Hero

Privacy & HIPAA: privacy@codebluehero.org

Legal: legal@codebluehero.org

Downers Grove, Illinois, USA

www.codebluehero.org

We will acknowledge all privacy requests within 5 business days and respond substantively within 30 days.