Mobile Application Privacy Policy

Mobile Application Privacy Policy

This policy describes how the Morgan Records Management file indexing application handles information. The application is published by Morgan Records Management LLC.

Information We Collect and How We Use It
From staff who sign in we collect an email address and password. These are used only to authenticate the user, and are stored in hashed form.

Staff photograph the tab of a physical file folder, and the application reads the text on it. From each folder we collect the patient’s last name and first name, their date of birth where shown, notes, the box number the file is stored in, and an identifier for the practice or hospital whose records these are. This is protected health information, and it is used solely to index and locate physical medical records held in our custody.

Photographs are used only to read that text. They are not sent to or stored on Morgan Records Management servers.

The application does not collect location data, contacts, calendar information or advertising identifiers, and no information from it is used for advertising or marketing.

Who We Share It With
Text is read on the device wherever possible, in which case the photograph does not leave the device. Where on-device recognition is not sufficient, the application sends the relevant portion of the image over an encrypted connection to Google Cloud Vision, a text recognition service operated by Google, which returns the recognized text. Because a folder tab can show a patient’s name and date of birth, an image sent this way may contain protected health information.

Google acts as our service provider for this processing under a Business Associate Agreement, and is obliged to protect that information to the same standard set out in this policy. The image is used only to return the recognized text, and not for advertising or to build user profiles. We do not share information from the application with anyone else, and we do not sell it.

Security
Information is transmitted over encrypted connections and stored encrypted at rest, on cloud infrastructure in the United States held under a Business Associate Agreement. Access is limited to authorized personnel.

Retention and Deletion
Photographs are held only on the device, and are deleted when the batch is submitted, when a record or batch is deleted, and when the user signs out.

Indexing data is retained for as long as required by our contracts with the practices and hospitals whose records we hold, and by applicable medical record retention law. Staff account records are kept while the account is active.

Staff may request access to, correction of, or deletion of their account information, or ask that their account be closed, by emailing patientrequests@morganrecordsmanagement.com. Closing an account ends access and removes its sign-in credentials. Consent is withdrawn by ceasing to use the application; it collects nothing optional. Requests concerning a medical record itself should be sent to the same address. We hold those records as a custodian for medical practices and cannot delete records we are required to retain, so where the decision rests with the practice we refer the request to them.

Contact
Questions about this policy, and any privacy request, can be sent to patientrequests@morganrecordsmanagement.com.

This policy was last updated on August 21, 2026. If we change how the application handles information we will update this page and revise that date.