When accuracy and expert analysis matter

Privacy Policy

How MedChrona handles information from this website and from client accounts. Version of August 23, 2026. The current version is always posted here.

What this policy covers

This policy describes how MedChrona handles information collected through this website and in connection with client accounts. Medical records and protected health information are governed separately: they move only through the secure client portal, under the Master Services and Engagement Terms and, where applicable, a Business Associate Agreement. This policy summarizes that handling at a high level but does not replace those agreements.

Information we collect

The registration form collects business contact information: your name, organization, work email, phone number, organization type, and the colleagues you list for portal logins. Email correspondence with office@medchrona.com is retained as ordinary business records. When you become a client, we maintain account and engagement records such as case numbers, page counts, invoices, and payment status.

This website itself sets no cookies and runs no analytics or advertising trackers. The instant estimator counts your files entirely inside your browser; no file contents, file names, page counts, or other file information are transmitted to MedChrona or anyone else.

Protected health information

Medical records are accepted only through the secure client portal, never through this website or by email. Records are maintained in HIPAA-supported systems, access is limited to the assigned clinician and quality-review staff and is logged, and invoices and notifications reference case numbers rather than patient identifiers. Where MedChrona acts as a business associate under HIPAA, the applicable Business Associate Agreement governs.

Service providers

MedChrona uses a small number of service providers to operate: website hosting, form delivery for the registration page, business email, the secure client portal, and payment processing. Payment card and bank details are collected and stored by our payment processor, not by MedChrona. Providers that handle protected health information on our behalf do so under business associate agreements.

Retention

Source medical records and working files are retained for a limited period after a case is completed and then securely deleted; completed deliverables and ordinary business records are retained longer, as described in the Master Services and Engagement Terms. Registration inquiries that do not become client relationships are retained only as ordinary business correspondence.

Security

Information is encrypted in transit and at rest, portal accounts require individual logins with two-step verification, and access to client materials is limited and logged. No system is perfectly secure, and clients should maintain their own copies of source records and completed work product.

Your choices and contact

To ask what information we hold about you or your organization, to correct it, or to request deletion of information we are not required to retain, write to office@medchrona.com. Do not include patient information in that email. We may update this policy from time to time; material changes will be posted on this page.