Refidly

Security at Refidly

Referral records are among the most sensitive data a healthcare organization keeps. Here is how the platform handles them.

Last updated · August 11, 2026

HIPAA and Business Associate Agreements

Safeguards

  • Each workspace is isolated. Records belonging to one organization are not reachable from another, including through search, export, analytics, and AI features.
  • Access is role-based and enforced on the server for every request. Owners control who is invited and what each member can do.
  • Protected health information is encrypted at rest, and all traffic between your browser and Refidly is encrypted in transit.
  • Sessions are short-lived and expire after inactivity. Signing out revokes access immediately.

Audit history

How your data is used

Reporting a vulnerability

Security questions