Privacy Policy

Privacy Policy

At Morgan Records Management (MRM), we prioritize the confidentiality and security of our clients' information. Our services include secure electronic and hard copy records storage, expedited delivery, and destruction services, all designed to meet the highest standards of privacy.

Commitment to Security

We take pride in our state-of-the-art facility and robust information management system. Understanding the importance of security, we implement strict policies and training procedures to safeguard your vital information. Our comprehensive security measures protect against unauthorized access and disclosure.

Facility Security Measures
Our facility is designed with multiple layers of security to protect your sensitive information:

Controlled Access: Entry to our facility is strictly controlled. Only authorized personnel have access to sensitive areas, with access logs maintained for monitoring purposes. Surveillance Systems: We utilize 24/7 video surveillance to monitor all critical areas of our facility, ensuring that any unauthorized activity is promptly detected and addressed. Alarm Systems: Advanced alarm systems are in place to provide immediate alerts in case of unauthorized access or breaches, ensuring swift response from security personnel. Fire Safety Protocols: Our facility is equipped with state-of-the-art fire detection and suppression systems to protect against potential hazards that could compromise your records. Environmental Controls: We maintain optimal environmental conditions, including temperature and humidity controls, to ensure the physical integrity of hard copy records. Compliance with HIPAA

MRM is fully compliant with the Health Insurance Portability and Accountability Act (HIPAA), which sets stringent standards for the protection of sensitive patient information. We understand the critical nature of handling protected health information (PHI) and have implemented specific policies and procedures to ensure compliance.

HIPAA Training
All employees undergo mandatory HIPAA training to understand their responsibilities in protecting PHI. This training covers the importance of confidentiality, data security measures, and the proper handling of medical records.

Secure Storage and Access
We maintain secure storage solutions for PHI, with strict access controls to limit data access to authorized personnel only. Our systems ensure that PHI is encrypted both at rest and in transit, adhering to HIPAA's security requirements.

Business Associate Agreements (BAAs)
We enter into Business Associate Agreements (BAAs) with our clients who are covered entities under HIPAA. These agreements outline our responsibilities regarding the safeguarding of PHI and clarify the protocols we have in place to protect client information.

Subcontractors and Service Providers
Some of our services rely on technology providers that process information on our behalf. Where a provider handles protected health information, HIPAA requires us to have a Business Associate Agreement in place with that provider, and we do. These include our records request and delivery platform, which processes records requests submitted through this website and the status lookups associated with them; our cloud hosting and storage providers, located in United States data centers; and a text recognition provider used by our internal file indexing application, in the limited circumstances described in our Mobile Application Privacy Policy. We do not sell information, and we do not disclose protected health information for advertising or marketing purposes.

Data Encryption
All data stored and transmitted through our systems is encrypted using industry-standard protocols. This ensures that your information is protected both at rest and in transit, significantly reducing the risk of unauthorized access.

Regular Audits and Monitoring
MRM conducts regular security audits and monitoring of our systems to identify and address potential vulnerabilities. We continually assess and update our security practices to stay ahead of emerging threats.

Incident Response Plan
In the unlikely event of a data breach, we have a comprehensive incident response plan in place. This plan outlines immediate actions to mitigate any impact and ensures timely notification to affected clients, as required by HIPAA regulations.

Information You Send Us Through This Website
When you contact us using a form on this website, we collect the contact details and the information you choose to provide, such as your name, email address, telephone number and the details of your inquiry. We use it to respond to you and to keep a record of the request. Our website forms are hosted for us by a third-party form provider, which processes submissions on our behalf and does not use them for its own purposes. Submissions are kept for as long as needed to deal with the inquiry and to maintain our business records.

Please do not include medical or health details in a website inquiry form. If you are requesting your medical records, please use our records request process, which is designed for that purpose and handles your information accordingly.

Online Access
Our online records management portal is available 24/7 and is secured using industry-standard TLS encryption in transit and AES-256 encryption at rest. This ensures that your records are always accessible to you while remaining entirely confidential from others.

Data Retention and Disposal
We adhere to strict data retention policies, ensuring that your information is retained only as long as necessary to fulfill our contractual obligations. When it is time to dispose of records, we employ certified destruction methods, ensuring that all data is irretrievable.

Our Mobile Application
Morgan Records Management uses an internal mobile application, issued only to our own authorized personnel, to index physical records. It is not available to the public and cannot be used without an account we create. How that application handles information, including photographs of file folders and the text read from them, is described separately in our Mobile Application Privacy Policy.

Exceeding Standards
We are confident that our services provide a level of privacy and security that surpasses typical systems available at client locations. Our technology, policies, and procedures are all meticulously designed to prioritize your security.

Support and Communication
We are dedicated to delivering exceptional service and support to your company. Should you have any questions or feedback, please do not hesitate to reach out. We are here to assist you in any way possible. Questions about this policy, or about how we handle personal or health information, can be sent to patientrequests@morganrecordsmanagement.com.

3rd Party Disclaimer

Morgan Records Management provides complete medical records in response to authorized requests. Morgan Records serves solely as a custodian of records; we are not a medical office and therefore do not create, alter, or remove any information from the records we maintain. Records are not curated or limited to specific date ranges. By submitting a request, you agree to receive the full record and to pay the applicable service fee for the full record in accordance with state and federal pricing guidelines.

This policy was last updated on August 21, 2026.

Thank you for choosing Morgan Records Management!