Most online PDF mergers upload your file to a server before doing anything with it. PHI shouldn't touch infrastructure you haven't vetted — PDFLite merges entirely in your browser instead.
Why the upload step is the problem
A typical online merger
Sends the file to a third-party server before merging — that's a disclosure the moment it leaves your device, whether or not anyone ever looks at it.
Why it matters here
A free online tool with no Business Associate Agreement is a HIPAA question you likely don't want to be asking after the fact.
What healthcare staff actually merge with this
Charts
Full patient record
Lab results
Multiple reports
Intake forms
Scanned paperwork
Referrals
Provider-to-provider
How PDFLite keeps files local
Runs the merge with a JavaScript library (pdf-lib) inside your browser tab. Your browser reads the file's bytes directly off your device's disk, restructures the pages in memory, and hands you back a file to download.
There's no server call at any point — free plan or Premium — so there's no third-party server holding PHI, even briefly, and no Business Associate Agreement question to sort out.
Step by step
Drop your PDFs into the box. Read straight off your device, not sent anywhere.
Order them with ↑ / ↓. Build the chart in chronological or department order.
Click Merge, then download. Built in your browser's memory — never anywhere else.
Free plan limits
3/day
Merge or split actions
15 pages
Cap per job
Larger charts or daily use? Premium removes both limits — $5/month, same no-upload behavior either way.
This page describes how the tool works technically; it isn't legal or compliance advice on your organization's HIPAA obligations, which depend on your role and covered-entity status.