Security Practices

Sports Med Flow Pro is built to support Athletic Trainers who handle protected health information and student education records. These are the safeguards in the product today. AI features that would send clinical text to a model provider stay off until a platform administrator turns them on after processor agreements are on file. Software controls are not a HIPAA or FERPA certification.

Workspace isolation

Every trainer account has its own workspace. Records are filtered at the database level, not just hidden in the interface, so another account cannot reach them even by guessing an address. View-only seats cannot change student records.

Signed notes stay with their author

Signed clinical notes and their PDFs are readable only by the trainer who created and signed them. District administrators manage seats and billing and cannot open medical records.

Permanent access log

Opening a profile, downloading a signed note, exporting a treatment log, amending a visit, and signing in are written to a log that cannot be edited or deleted by any account.

Private file storage

Uploaded documents, signed PDFs, and credential files live in private storage and are opened through links that expire in about two minutes.

Session safeguards

Staff sessions end after ten minutes of inactivity. AT Sidekick parks the trainer session in an http-only cookie so a shared tablet never holds a live clinical login. A 4-digit exit code is required to return to staff screens, and copied sign-in tokens stop working when the kiosk is locked.

On-device facial matching

Kiosk face check-in matches on the device and stores only a numeric signature for the assigned campus. No face photographs are ever kept.

What the software cannot do for you

Compliance is a shared responsibility. Software safeguards are one part; your written policies, workforce training, breach-notification process, device rules, and any required agreements with your vendors are the rest. We do not claim any certification, audit outcome, or regulatory approval on your behalf. Confirm your own obligations with your organization before entering real records.

Reporting a vulnerability

If you believe you have found a security issue, contact your workspace owner with the details and steps to reproduce it, and please do not access records that are not yours while investigating.

Privacy Notice · Terms of Service