Penna Health LLC ("Penna Health," "we," "us," or "our") provides an electronic health record and practice-management platform for mental-health practices (the "Services"). This Privacy Policy explains how we collect, use, share, and protect Personal Information about the people who visit our websites, create or use a Penna Health account, contact us, or otherwise interact with us.
This Privacy Policy is incorporated into the Penna Health Terms of Service. By using the Services you agree to the practices described here. If you do not agree, please do not use the Services.
1. Important Note About Patient Information
Our customers are health-care practices and professionals ("Customers"). When a Customer enters information about its patients or clients ("Clients") into the Services, that information — including protected health information ("PHI") — is the Customer's information. We process Client information only on behalf of, and at the direction of, the Customer, under our Business Associate Agreement and the Terms of Service, not under this Privacy Policy. If those agreements conflict with this Privacy Policy, the agreements control.
If you are a Client and have questions about how your information is used, or want to access, correct, or obtain a copy of your records, please contact the practice that provides your care; it is the "covered entity" responsible for your records and for its own Notice of Privacy Practices. If you contact us directly, we will honor requests as required by law and will otherwise direct you to your practice. Clients who use the patient portal are also covered by the Client Portal privacy notice presented there.
2. Personal Information We Collect
"Personal Information" is information that identifies, relates to, or could reasonably be linked with an individual. It does not include de-identified or aggregated information that cannot reasonably be linked to a person.
Information you provide to us.
- Account and profile information — name, e-mail address, phone number, practice name and address, professional credentials and license numbers, NPI, DEA number (where e-prescribing is enabled), role, and password or authentication credentials.
- Identity verification information — information we or our identity-verification partners collect to confirm your identity and licensure, including government-issued identification for prescribers enrolling in electronic prescribing of controlled substances.
- Billing information — billing address, payment-method details (full card numbers are collected and stored by our payment processor, not by us), tax identifiers, and transaction history.
- Communications — the contents of support requests, e-mails, chat messages, survey responses, and feedback you send us, and recordings or transcripts of support calls where permitted by law.
- Configuration and content you create — practice settings, form templates, and other content you build in the Services.
Information we collect automatically.
- Usage and device information — IP address, browser type and version, operating system, device identifiers, pages and features accessed, timestamps, referring URLs, and crash or error reports.
- Audit and security logs — records of sign-ins, sign-outs, failed authentication attempts, and actions taken within the Services. These logs are required by HIPAA and are retained as described in Section 7.
- Cookies and similar technologies — see Section 6.
Information from third parties.
- Identity, licensure, and sanctions data from verification providers and public registries.
- Payment status from our payment processor.
- Business contact information from partners, referrals, or publicly available sources.
- Information from a Customer that adds you as a Team Member.
3. How We Use Personal Information
We use Personal Information to:
- provide, operate, secure, maintain, and support the Services, including authenticating users and enabling Feature Modules you activate;
- verify identity, licensure, and eligibility to use the Services;
- process payments, send invoices, and manage subscriptions;
- communicate with you about your account, security events, updates, and changes to the Services or our agreements;
- respond to support requests and improve support quality;
- monitor, detect, investigate, and prevent fraud, abuse, security incidents, and violations of our agreements;
- maintain audit trails required by HIPAA and other law;
- analyze usage in order to develop, test, and improve the Services;
- send product news and marketing about Penna Health (you may opt out at any time);
- comply with legal obligations and enforce our agreements; and
- for any other purpose disclosed to you at the time of collection or with your consent.
We may create de-identified or aggregated data from Personal Information and use it for any lawful purpose.
We do not sell Personal Information, and we do not use PHI to train general-purpose artificial-intelligence models.
4. How We Share Personal Information
We share Personal Information only as described below.
- Service providers. With vendors that host and process data on our behalf, including cloud infrastructure and database hosting, identity and authentication, e-mail and SMS delivery, fax transmission, video telehealth, e-prescribing networks, insurance clearinghouses, payment processing, AI and transcription engines, analytics, and customer support tools. These providers are permitted to use Personal Information only to perform services for us, and those that handle PHI are bound by business associate agreements.
- Within your Organization. With the Account Owner and administrators of the Customer account you belong to, who can see your profile, role, and activity within that account.
- At your direction. With third parties you ask us to share with, such as a pharmacy, payer, laboratory, or referral partner, when you use a feature that transmits information to them.
- Legal and safety. When we believe disclosure is required by law, subpoena, or court order; to respond to a lawful request from a government authority; to enforce our agreements; or to protect the rights, property, or safety of Penna Health, our Customers, Clients, or the public.
- Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business, in which case Personal Information may be transferred to the successor, subject to this Privacy Policy and applicable law.
- With your consent. For any other purpose with your consent.
We do not share Personal Information with third parties for their own direct-marketing purposes, and we do not engage in cross-context behavioral advertising.
5. Your Choices
- Account information. You can review and update most account information in your profile settings. Some information, such as audit logs and billing records, cannot be changed.
- Marketing e-mail. You may unsubscribe using the link in any marketing message. We will continue to send transactional and security messages required to operate your account.
- SMS. If you opt in to receive SMS from us, reply STOP to any message to opt out. Message and data rates may apply.
- Cookies. See Section 6.
- Account deletion. The Account Owner may close the Organization's account as described in the Terms of Service. Personal Information will then be handled under Section 7.
6. Cookies and Similar Technologies
We use cookies, local storage, and similar technologies to keep you signed in, remember preferences, secure the Services, and understand how the Services are used. Essential cookies are required for the Services to function and cannot be disabled. We use limited first-party analytics to measure performance; we do not use third-party advertising cookies or trackers within the authenticated Services. You can control cookies through your browser settings, but disabling essential cookies will prevent you from using the Services. We do not currently respond to "Do Not Track" browser signals, but we honor opt-out preference signals where required by law.
7. Retention and Security
Retention. We retain Personal Information for as long as needed to provide the Services, comply with legal and regulatory obligations (including HIPAA's six-year documentation requirement for audit logs and related records), resolve disputes, and enforce our agreements. When an account is closed, the Customer has an export window described in the Terms of Service, after which Customer data is returned or destroyed as provided in the Business Associate Agreement, subject to data that must be retained in immutable backups, security logs, or as required by law.
Security. We maintain administrative, technical, and physical safeguards designed to protect Personal Information, including encryption in transit and at rest, multi-factor authentication, role-based access controls, audit logging, malware scanning, and vendor due diligence. However, no method of transmission or storage is completely secure. We cannot guarantee the security of any information, and you provide it at your own risk. Our obligations with respect to security incidents involving PHI are set out in the Business Associate Agreement.
Your responsibilities. Protect your credentials, enable multi-factor authentication, keep your devices patched and encrypted, and notify us immediately at support@penna.health if you suspect unauthorized access.
8. State Privacy Rights
Residents of certain states (including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) have specific rights regarding their Personal Information. Depending on your state, these may include the right to:
- know what Personal Information we collect, use, and disclose, and the categories of sources and recipients;
- access and obtain a portable copy of your Personal Information;
- correct inaccurate Personal Information;
- delete Personal Information, subject to exceptions (for example, information we must retain by law or to complete a transaction);
- opt out of the sale of Personal Information, targeted advertising, and certain profiling — we do not sell Personal Information, engage in targeted advertising, or use automated decision-making that produces legal or similarly significant effects;
- limit the use of sensitive Personal Information — we use sensitive Personal Information only to provide the Services and as permitted by law;
- appeal a decision we make about your request; and
- receive equal service and not be discriminated against for exercising your rights.
Categories disclosed for business purposes in the preceding 12 months: identifiers and contact information; professional and licensure information; billing and commercial information; internet and device activity; audio and electronic information (support recordings, where applicable); and inferences drawn from usage. These were disclosed to the categories of service providers in Section 4. We have not sold or shared (for cross-context behavioral advertising) Personal Information.
Exercising rights. Submit a request to privacy@penna.health with the subject "Privacy Rights Request," or through the request form in your account settings. We will verify your identity using your account authentication or by requesting additional information. You may use an authorized agent; we may require proof of the agent's authority. To appeal a decision, e-mail privacy@penna.health with the subject "Privacy Request Appeal." Note that much of the information in the Services is PHI processed on behalf of a Customer; requests concerning PHI will be directed to the relevant Customer.
California "Shine the Light." California residents may request, once per year, information about Personal Information shared with third parties for their direct-marketing purposes. We do not share Personal Information for that purpose.
9. Additional Information
Children. The Services are intended for health-care professionals and their staff. We do not knowingly collect Personal Information directly from children under 13 through our public websites. Information about minor Clients is entered by Customers and governed by the Business Associate Agreement.
Visitors from outside the United States. We are located in the United States and the Services are hosted in the United States. If you access the Services from outside the United States, you consent to the transfer and processing of your Personal Information in the United States, where privacy laws may differ from those in your country.
Third-party websites. The Services may link to third-party websites or services. We are not responsible for their privacy practices, and this Privacy Policy does not apply to them.
Changes to this Privacy Policy. We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and, for material changes, notify Account Owners by e-mail or within the Services at least thirty (30) days before the change takes effect. Continued use after the effective date constitutes acceptance.
10. Contact Us
Questions, requests, or complaints about this Privacy Policy or our privacy practices may be directed to:
Penna Health LLC Attn: Privacy Officer 1309 Coffeen Avenue, Suite 1200 Sheridan, WY 82801 privacy@penna.health
For support questions: support@penna.health. For legal notices: legal@penna.health.
Acceptance Record
This Privacy Policy is presented and accepted electronically, together with the Terms of Service and the Business Associate Agreement, as the final step of account creation. Penna Health records and retains, under the Organization's practice profile, the document title and version, the accepting individual's name, title, and e-mail address, the Organization's legal name, the date and time of acceptance (UTC), and the IP address and browser user-agent from which acceptance was made. A copy of the accepted version is available to Organization administrators in the admin panel under Practice → Legal Agreements.