HIPAA Policy
Last updated: July 22, 2026
Penta Solutions LLC is committed to the protection of Protected Health Information (PHI) in full compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HITECH Act, and their implementing regulations. As a Business Associate to our healthcare clients, we treat the confidentiality, integrity, and availability of PHI as a core responsibility.
Scope
This policy applies to all Penta Solutions workforce members, contractors, and systems that create, receive, maintain, or transmit PHI on behalf of our clients.
Permitted Uses and Disclosures
We use and disclose PHI only as necessary to perform billing, coding, credentialing, and revenue cycle services, and only as permitted by our Business Associate Agreements and applicable law. We apply the minimum-necessary standard to every use and disclosure.
Safeguards
Administrative Safeguards
We maintain documented policies, designate a Privacy and Security Officer, conduct regular risk assessments, and require ongoing workforce training and confidentiality agreements.
Physical Safeguards
Access to facilities and workstations that handle PHI is restricted, monitored, and logged. Devices are secured and disposed of using compliant media-sanitization procedures.
Technical Safeguards
We enforce unique user authentication, role-based access controls, encryption of PHI in transit and at rest, audit logging, and automatic session termination.
Business Associate Responsibilities
We enter into Business Associate Agreements with every covered-entity client, and require equivalent agreements with any subcontractor that may access PHI. We use PHI solely for the purposes authorized in those agreements.
Breach Notification
In the event of a breach of unsecured PHI, we will notify the affected covered entity without unreasonable delay and in accordance with HIPAA breach-notification requirements, providing the information needed for timely reporting.
Patient Rights
We support our clients in honoring patient rights under HIPAA, including access to records, requests for amendment, an accounting of disclosures, and requests for restrictions on certain uses and disclosures.
Workforce Training
All workforce members receive HIPAA privacy and security training upon hire and periodically thereafter. Violations of this policy are subject to disciplinary action up to and including termination.
Complaints and Contact
To report a concern or ask questions about our HIPAA practices, contact our Privacy Officer atcontact@pentasolutions.netor(737) 310-6860. You will not be retaliated against for filing a complaint.
