Security & Privacy
Privacy and cybersecurity controls
Because our platform may store names, locations, signatures, delivery details and potentially health information, we apply layered security controls.
Role-based access
Users see only the data their role requires — admin, dispatcher, driver or customer — limiting exposure of sensitive records.
Multifactor authentication for admins
Administrator accounts require MFA to reduce the risk of compromised credentials.
Automatic logout
Sessions expire after a period of inactivity to protect unattended devices.
Encryption in transit and at rest
Data is protected with TLS in transit and encrypted storage at rest.
Audit logs
We log who viewed or changed records so activity can be reviewed and investigated.
Minimum-necessary on driver screens
Drivers see only the shipment and stop information needed to complete a delivery — not full clinical or account data.
Remote account disabling
Administrators can disable access immediately when an account is compromised or no longer needed.
Data retention & deletion
Defined retention periods and deletion processes aligned to legal and contractual requirements.
Backup & recovery
Regular backups and tested recovery procedures support availability and continuity.
Breach & incident reporting
Internal reporting and notification procedures for security incidents and potential breaches.
Vendor agreements
Business Associate Agreements and data-processing terms with vendors that handle protected information.
Compliance approach
There is no general government-issued "HIPAA certification." QFO does not claim to be HIPAA certified. Instead, we use privacy, security, access-control, training, and documentation procedures designed for compliant operations, and we enter Business Associate Agreements with clients where applicable. These controls are part of a broader program of training, monitoring and continuous improvement.
Need details for your security review?
Schedule a medical-grade pickup or track a delivery in real time.