Privacy Policy

PennSync by CareMetric · Effective July 22, 2026

PennSync by CareMetric ("PennSync", "we", "us") is a clinical documentation and care-coordination platform used by home health and hospice agencies and their staff. This policy explains what information the PennSync application collects, how it is used, and the choices available to you. PennSync is provided to you by, or on behalf of, the healthcare agency that provisioned your account ("your agency").

Information we collect

  • Account information — your name, work email address, role, credentials, and training records, provided by you or your agency when your account is created.
  • Patient health information (PHI) — clinical documentation, assessments, care plans, medications, visit notes, documents, and related records that you or your agency enter or upload while providing care. This information is processed on behalf of your agency, which is the covered entity responsible for it under HIPAA. PennSync acts as a business associate.
  • Usage and audit data — sign-in events, pages and records accessed, and actions taken. Healthcare regulations require audit trails over access to patient records; this data is collected for security and compliance, linked to your account.
  • Device data you choose to share — camera and microphone input when you use telehealth, dictation, document scanning, or photo attachment features. Access is requested only when you use those features and can be revoked in your device settings.

How we use information

Information is used solely to operate the platform for your agency: clinical documentation, scheduling and coordination, messaging, training, compliance monitoring, analytics for your agency, and security auditing. AI-assisted features process clinical text and documents to draft or check documentation; AI output is always subject to clinician review. We do not sell personal information, we do not use it for advertising, and we do not use health information for any purpose other than providing the service to your agency.

Sharing

Information is shared only with: (1) your agency and the colleagues your agency authorizes; (2) service providers that host and operate the platform under confidentiality and business-associate obligations (cloud hosting, secure file storage, fax/SMS/voice delivery, AI processing); and (3) authorities when required by law. Patient information is never shared for marketing.

Retention and deletion

Clinical records are retained according to your agency's medical-record retention obligations under federal and state law; the retention period is controlled by your agency, not by PennSync. You can request deletion of your account at any time from Settings → Delete My Account inside the app. Deletion requests are routed to your agency's administrators, who must complete them within the timeframes the law allows; records your agency is legally required to retain (for example, signed clinical documentation and audit trails) are retained by the agency for the mandated period and then destroyed.

Security

Data is encrypted in transit, access is role-based and audited, sessions time out after inactivity, and locally cached patient data on shared devices is purged on sign-out and idle timeout. Report suspected security issues to your agency administrator or the contact below.

Your choices

You may access and update your profile in Settings, control notification preferences, revoke camera/microphone permissions in your device settings, and request account deletion in-app. Patients seeking access to or correction of their records should contact the agency providing their care, which is the record holder.

Contact

Questions about this policy or our data practices: contact your agency administrator, or reach CareMetric at the support contact provided by your agency.

This policy applies to the PennSync application on the web and on mobile devices, including the iOS app.