Security, privacy, and how BookMediFly works.
Last Updated: September 8, 2026
This page explains BookMediFly's role, the information used for a quote request, who may see it, and the practical safeguards currently used to protect the platform.
What BookMediFly is
BookMediFly is software for requesting and comparing quotes for scheduled fixed-wing medical transport. It connects requesters with participating operators; it is not a transport broker, aircraft operator, medical provider, emergency dispatcher, or 911 service.
What we do not collect
Do not submit protected health information (PHI) or patient-identifiable information. This includes patient names, diagnoses, treatment plans, medical record numbers, dates of birth, Social Security numbers, insurance member numbers, and any of the 18 HIPAA-defined identifiers.
Provide only the contact and trip details needed for a quote request. The full boundary appears in Terms of Use §8.
What we do collect
For requester accounts and quote requests, BookMediFly may collect:
- Name, email address, phone number, and organization name when applicable.
- Trip details such as origin, destination, requested date, and related non-clinical logistics.
- Messages, inquiries, and account or request activity needed to operate and protect the platform.
- Technical information described in the Privacy Policy, such as IP address, browser or device characteristics, and usage data.
Who sees a request
Request details and the requester's business contact details (requester type, name, organization when available, email address, and phone number) are shared with participating affiliates authorized to view the case, including before they submit a proposal, so they can evaluate the case, prepare a proposal, coordinate insurance, and contact the requester directly for additional information. This direct contact must not be used to exchange patient medical or patient-identifiable information. Access within BookMediFly is limited to people and service providers who need it to run, support, or protect the platform. For more detail, see the Privacy Policy.
Any transport agreement and payment are handled directly between the requester and the selected operator. BookMediFly does not process transport payments and does not mark up operator quotes.
Security practices
Current application safeguards include:
- HTTPS for connections to the public platform.
- Session cookies configured with Secure, HttpOnly, and SameSite protections as appropriate.
- Cross-site request forgery (CSRF) protection for state-changing forms and requests.
- Rate limits and abuse controls on sensitive or high-traffic routes.
- Access limits intended to keep account and request information available only on a need-to-run basis.
No internet service can promise absolute security. These are current application practices, not a claim of a particular compliance certification or healthcare business-associate status.
Subprocessors
BookMediFly uses third-party service providers to support platform operations. Rather than maintain a separate or incomplete vendor list on this page, we describe the relevant categories and data-sharing practices in the Privacy Policy.
How we review operators
BookMediFly reviews operator-submitted documentation at onboarding. That documentation-based review is not an endorsement, ranking, guarantee, or certification of an operator. Read How We Review Operators for the scope of the review and what remains the operator's responsibility.
Contact
Questions about this page, privacy, or a possible security concern can be sent to support@bookmedifly.com.