Last updated: July 2026
Penna ("Penna," "we," "us") retrieves medical records and prepares source-cited medical chronologies for firms and providers. This policy explains what information we handle, how we use and protect it, and the choices you have. It covers our website at pennarecords.com and the services we provide under a signed agreement. It does not change any term of a Business Associate Agreement or services agreement between us; where those agreements say something different, they control.
We handle two very different kinds of information, and we treat them differently.
We do not run advertising trackers, and we do not sell or rent information to anyone.
Our marketing site is built to work without tracking cookies. We use cookieless analytics that count visits without identifying you or following you across other sites, so there is no tracking-cookie banner to click through. Signing in to a client account uses a strictly necessary session cookie to keep you logged in; it is never used for advertising.
We use protected health information only to perform the services set out in the Business Associate Agreement, and for no other purpose.
When we handle protected health information for a client, we act as a business associate under HIPAA. A signed Business Associate Agreement is in place before any protected health information moves. That agreement governs how we may use, disclose, safeguard, and dispose of protected health information, including our duties if a breach ever occurs, and it controls if anything in this policy appears to conflict with it.
We do not sell information, and we share it only as far as the work requires:
Information is handled and stored in the United States.
No system is perfectly secure, but we work to protect information using safeguards consistent with our obligations, and we hold our service providers to the same standard. The specific safeguards will be confirmed before launch.
We keep information for as long as we need it to provide the service and to meet our legal and contractual obligations, then delete or de-identify it. Handling and disposal of protected health information follow the applicable Business Associate Agreement. Specific retention periods will be confirmed before launch.
Depending on where you live and your role, you may have the right to access, correct, or delete certain information, or to object to some uses. Because we do not sell information or use it for targeted advertising, there is nothing to opt out of on that front. Requests that involve protected health information run through the client and the applicable Business Associate Agreement. To make a request, contact us using the details in section 13, and we will respond as the law requires.
Penna is a service for firms and providers, not for the general public, and our site is not directed to children. We do not knowingly collect information from children through the website. Medical records we handle for a case may relate to a person of any age, including a minor; that information is protected health information and is governed by the Business Associate Agreement, not by this section.
We may update this policy as our practices or the law change. When we do, we will revise the date at the top and, where appropriate, give additional notice.
Questions about this policy can be sent to [email protected], or through our contact page.