HHA DocFlow
Compliance

Ready for survey, not just for today.

HHA DocFlow keeps the documents that prove your care was ordered, signed, and timely — with a timestamped, append-only record behind every one. Here is how that maps to the rules you answer to, and where our job ends and yours begins.

01 · Plan of care

Built for the 485/486/487 plan-of-care workflow

HHA DocFlow is built around the document that anchors every Medicare and Medicaid home health episode: the physician-signed plan of care. We track each plan of care, verbal order, and recertification as a discrete item with a live signed-or-pending status.

That visibility maps to what the Conditions of Participation require: the plan of care must be established, periodically reviewed, and signed by the physician or allowed practitioner (42 CFR 484.60(a)), reviewed and revised at least every 60 days (42 CFR 484.60(c)), and verbal orders must be documented, dated, timed, and later authenticated (42 CFR 484.60(b)). Automatic text and email reminders help drive signatures in before deadlines pass — and before you bill, since certification must be signed and dated to support the claim (42 CFR 424.22).

DocFlow does not write your plan of care or exercise clinical judgment — your clinicians do. What it does is make sure the documents that prove your care was ordered, signed, and timely do not slip through the cracks.

02 · HIPAA Security Rule

HIPAA Security Rule alignment

HHA DocFlow acts as your HIPAA business associate and will execute a Business Associate Agreement.

Because HHA DocFlow processes protected health information, several of the HIPAA Security Rule's technical safeguards (45 CFR 164.312) map to features that ship in the product today:

  • Access control & unique user ID · 164.312(a)(1), (a)(2)(i)
    Role-based access limits ePHI to authorized users, and every action is tied to a uniquely identified account.
  • Audit controls & integrity · 164.312(b), (c)
    Our immutable, timestamped audit trail records and preserves system activity so records cannot be silently altered or destroyed.
  • Transmission security · 164.312(e)
    Data is encrypted in transit using TLS.

HIPAA compliance, though, is never something a vendor can hand you in a box. The Security Rule also requires safeguards that remain your agency's responsibility — conducting your own risk analysis (164.308(a)(1)(ii)(A)), training your workforce (164.308(a)(5)), and reviewing the audit logs we generate (164.308(a)(1)(ii)(D)). DocFlow gives you tooling that supports these obligations; it does not discharge them. We hold no third-party security certification, and we don't claim one.

03 · Record integrity

Audit trail & record integrity

Every signature, status change, and document event is written to an immutable audit trail with a timestamp and the identity of the user who performed it. Entries are append-only — they cannot be quietly edited or deleted after the fact.

This implements the audit-controls standard (45 CFR 164.312(b)), supports the integrity standard (164.312(c)), and directly serves the Conditions of Participation, which require that clinical-record entries be “appropriately authenticated, dated, and timed” — including by “secured computer entry by a unique identifier” (42 CFR 484.110(b)).

The practical payoff shows up at survey time: when a surveyor asks when an order was signed or who accessed a record, the answer is a timestamped log entry rather than a reconstruction from memory.

04 · Texas Medicaid

Texas Medicaid & EVV context

HHA DocFlow is built by a Texas team, and our first customer is a licensed Texas home health agency billing Texas Medicaid. Two things matter for Texas agencies, and we want to be precise about both.

First, retention: federal rules require clinical records be kept for five years after discharge (42 CFR 484.110(c)), and Texas licensing rules require the same five-year minimum (26 TAC §558.301(b)(1)). DocFlow's configurable retention lets you set a window that meets or exceeds those floors.

Second, EVV: Electronic Visit Verification is a separate federal mandate (21st Century Cures Act §12006) that runs in Texas through HHSC, the HHAeXchange EVV system, and the TMHP EVV Aggregator. HHA DocFlow is not an EVV system and does not replace your EVV obligations. We track your plan-of-care documents; your EVV vendor captures your visit data. The two complement each other — DocFlow does not integrate with, substitute for, or satisfy EVV.

05 · The honest split

What we do, and what stays yours

Here is the honest split — what the product does for you today, and what stays with your agency.

What HHA DocFlow does today
  • Encrypts data in transit with TLS
  • Maintains an immutable, timestamped audit trail
  • Enforces role-based access
  • Captures authenticated mobile e-signatures
  • Provides configurable record retention
  • Sends automatic reminders for unsigned and overdue documents
  • Receives inbound faxes on your own premises — the fax line terminates at your machine, not at a third-party fax service in the PHI path
  • Runs its document-reading AI and built-in help assistant locally — patient data is never sent to a cloud AI service, and in the default configuration the only outbound call is the optional license check. One admin-only exception ships off by default: an optional cloud troubleshooting assistant that, when your agency explicitly enables it, sends the administrator's questions and a non-PHI diagnostic bundle (counts, versions, configuration flags — never patient records, file names, log lines, or secrets) to the Anthropic API
  • Signs a Business Associate Agreement
  • Notifies you of any breach of unsecured PHI as required of a business associate (45 CFR 164.410)
What remains your agency's responsibility
  • Your own HIPAA risk analysis and risk management (45 CFR 164.308(a)(1)(ii)(A)-(B))
  • Workforce security and training (164.308(a)(3), (a)(5))
  • Reviewing the audit logs we generate (164.308(a)(1)(ii)(D))
  • The clinical accuracy and completeness of your records
  • Meeting visit frequencies and certification deadlines
  • Your EVV obligations

HHA DocFlow acts as your HIPAA business associate and will execute a Business Associate Agreement.

Want to see the audit trail and signed-or-pending tracking on your own documents? We'll walk you through it in about fifteen minutes.

Request a demo

This page describes how HHA DocFlow's features support your documentation and security obligations. It is not legal advice and does not certify compliance. Regulatory responsibility for HIPAA, the Medicare Conditions of Participation, and Texas Medicaid requirements remains with your agency; consult your compliance officer or counsel.