AHI Logo
Products
Healthcare Intelligence
HAL
The Healthcare Intelligence
HALi
Healthcare guidance for families
Revenue Intelligence
MDMai
Revenue optimization — free
CODEai
Billing intelligence
Documentation
ENCOUNTERai
AI-generated encounter notes
REFERRALai
Referral processing
HAL Alert Network
HAL Alerts
Infectious disease intelligence
HALi Alerts
For your family
Vision
ACI + HAL CHI
The future of Healthcare Intelligence
ProductsHow It WorksAboutSecurityPricing
For Providers
HAL
MDMai
ENCOUNTERai
CODEai
REFERRALai
For Patients & Families
HALi
Log in
Get Started

Effective Date: September 5, 2026

Healthcare Provider User Agreement

This Healthcare Provider User Agreement ("Agreement") is a binding contract between you, the licensed healthcare provider or authorized organization you represent ("Provider" or "you"), and HALai, Inc. ("HALai," "we," "us," or "our"), a wholly-owned subsidiary of Artificial Healthcare Intelligence, Inc. ("AHI"). It governs your access to and use of the Healthcare Intelligence platform, including HAL, MDMai, ENCOUNTERai, CODEai, REFERRALai, and HAL Alerts (collectively, the "Services"). This Agreement incorporates by reference our Terms of Use and Privacy Policy, and includes a Business Associate Agreement in Section 9 that governs our handling of Protected Health Information. By creating an account, accessing, or using the Services, you agree to this Agreement and, on behalf of your organization (if applicable), you represent that you have the authority to bind that organization. 1. Eligibility The Services are available to individuals and organizations that (a) hold an active National Provider Identifier (NPI) or are a healthcare organization that employs or contracts with such individuals, (b) are legally authorized to access and use PHI in the United States, and (c) are located and licensed in the United States. You represent and warrant that all registration information is accurate, that you hold the licenses and credentials you claim, and that you will keep this information current. 2. Account Responsibilities You are responsible for the confidentiality of your credentials, for all activity under your account, and for ensuring that any workforce member you authorize to use the Services complies with this Agreement. Notify us immediately at security@halai.ai of any unauthorized use of your account or any suspected security incident. 3. Permitted Use You may use the Services only for legitimate healthcare, administrative, and business-operations purposes in your practice, consistent with law and professional standards. You will not: (a) use the Services in violation of any law, including HIPAA, state privacy law, or the terms of any license you hold; (b) upload PHI you are not legally authorized to disclose; (c) attempt to re-identify de-identified data; (d) share credentials with anyone not authorized under this Agreement; (e) reverse engineer or attempt to derive source code, except where prohibited by law; (f) use the Services to build a competing product or to train external AI models; or (g) interfere with the operation of the Services or the use of the Services by other Providers. Prohibited Clinical Uses. You will not (i) allow AI output from the Services to serve as the sole basis for a clinical decision, diagnosis, treatment plan, prescription, order, or referral without independent review by a licensed clinician; (ii) use the Services to make or support insurance eligibility, coverage, or claim denials without qualified human review of the underlying record; (iii) use the Services for law-enforcement, immigration-enforcement, or forensic triage; (iv) use the Services to profile or make automated decisions about patients on the basis of protected characteristics; (v) present AI output to patients as if authored or reviewed by a clinician when it has not been; or (vi) use the Services in any manner that a reasonable clinician would identify as endangering patient safety. Billing Integrity. You will not submit a claim at a level that your documentation does not support, whether or not the Services identified that level. You are responsible for reviewing every MDMai or CODEai report against your own documentation and your own professional judgment before billing. Do not use the Services to justify a code your record does not substantiate. Ambient Recording; Patient Consent. For any Service that captures audio (including ambient scribe, dictation, or realtime voice), Provider is solely responsible for obtaining and documenting all consents required by law before recording begins. In two-party (all-party) consent jurisdictions, this includes the informed consent of every person whose voice may be captured, including patients, family members, and other clinicians. Provider is responsible for complying with applicable federal and state wiretap, eavesdropping, and privacy laws, and for providing patient-facing notice of AI-assisted documentation where required. 4. Your Data Ownership. You retain all right, title, and interest in the clinical data, encounter notes, audio, documents, and other information you or your workforce submit to the Services ("Provider Data"), including any PHI within it. License to Us. You grant us a limited, non-exclusive, worldwide, royalty-free license to host, process, transmit, display, and modify Provider Data solely as necessary to provide the Services to you and to fulfill our obligations under this Agreement and the BAA. Tenant Isolation. Provider Data is stored in tenant-isolated Azure containers and logical partitions dedicated to your account. Provider Data is not commingled with other Providers' data, is not disclosed to other Providers, and is not sold. No Cross-Customer or External Training. We do not use Provider Data or PHI to train general-purpose AI models or models used to serve any other customer. The ENCOUNTERai personalized documentation model is trained exclusively on the individual Provider's own notes and is used exclusively to serve that Provider; that model is tenant-isolated. De-identified Data. To the extent permitted by 45 CFR § 164.514(a)-(c), we may create de-identified information from PHI and use that de-identified information for our own lawful purposes, including improving the Services, provided the information no longer identifies and cannot be used to identify any individual. If we exercise this right, we will apply the HIPAA Expert Determination or Safe Harbor method. 5. Fees, Billing, and Taxes MDMai. MDMai is provided at no charge to individual providers with an active NPI. Paid Services. Fees for HAL, ENCOUNTERai, CODEai, REFERRALai, HAL Alerts, and any other paid Service are set forth on the applicable pricing page or order form and are billed in advance, monthly or annually as elected. Fees are non-refundable except as required by law or as expressly stated. Late amounts accrue interest at the lesser of 1.5% per month or the maximum rate permitted by law. You are responsible for all applicable taxes other than taxes on our net income. Price Changes. We may change prices for paid Services with at least 30 days' prior notice, effective at the start of your next billing period. 6. Disclaimers Specific to Clinical Use Clinical Decision Support Only. The Services provide clinical decision support, documentation assistance, coding suggestions, referral summaries, and administrative analytics. They are not a substitute for the professional judgment of a licensed provider. HALai does not practice medicine, and no provider-patient relationship is created between HALai and any patient. AI Output Requires Review. AI-generated output, including MDM level recommendations, suggested codes, notes, and referral summaries, may be incomplete, inaccurate, or otherwise wrong. You must independently review, verify, and edit AI output before signing, submitting, or relying on it for any clinical, coding, billing, or regulatory purpose. You are the responsible party for any note signed, code submitted, or decision made. Advisory Output Only; Provider Controls Billing. MDMai analyzes an encounter note that the Provider has already authored and signed, and produces an advisory report identifying the medical decision-making level and codes that the documentation supports. That analysis runs in both directions: MDMai identifies documentation supporting a higher level, and equally identifies where documentation does not support the level a Provider might otherwise select. MDMai does not generate, populate, transmit, or submit any superbill, claim, or billing document, and does not integrate with electronic health record systems. The Provider independently prepares the superbill and independently determines what to bill. Nothing in the Services relieves the Provider of that responsibility. No Guarantee of Reimbursement. MDMai and CODEai provide coding and billing guidance. We do not guarantee that any code, level, or bill will be accepted, paid, or upheld on audit. You remain solely responsible for compliance with payer rules, coding guidelines, and applicable law, and for the accuracy of every claim you submit. Regulatory Status — Intended Use by Product. None of the Services is an FDA-cleared or FDA-approved medical device. The intended use of each Service is as follows: - MDMai and CODEai are administrative and reimbursement tools. They analyze documentation that a clinician has already authored and produce medical decision-making level and billing-code recommendations for coding and claims purposes. They are intended for administrative support of health care practice within the meaning of section 520(o)(1)(A) of the Federal Food, Drug, and Cosmetic Act. They are not intended to identify, suggest, or rule out any diagnosis, to assess clinical risk, or to inform any treatment decision. - ENCOUNTERai and REFERRALai are documentation and summarization tools. They restate and organize information a clinician or referring party has already provided. They are not intended to generate new clinical findings, diagnoses, or treatment recommendations. - HAL and HAL Alerts provide reference information and practice analytics to licensed health care professionals. They are intended to allow the professional to independently review the basis of any information presented, and are not intended to provide a specific directive for the diagnosis, treatment, prevention, or mitigation of any disease or condition, or to be relied on in a time-critical situation. You will not use any Service for a purpose outside the intended use stated above. Using a Service outside its stated intended use may cause it to become a regulated medical device, and you assume all regulatory responsibility for any such use. 7. Confidentiality Each party will protect the other's confidential information with the same care it uses for its own confidential information, and no less than reasonable care, and will not use or disclose it except as necessary to perform this Agreement. This obligation does not apply to information that is or becomes public through no fault of the receiving party, was known before disclosure without confidentiality restriction, is independently developed, or must be disclosed by law (with prior notice where legally permitted). 8. Security We host and operate the Services on Microsoft Azure's HIPAA-eligible infrastructure. Our security program includes AES-256 encryption at rest, TLS 1.2 or higher in transit, tenant-isolated data containers, private-network isolation, role-based access controls, multi-factor authentication for administrative access, continuous logging and monitoring, regular vulnerability scanning and third-party penetration testing, workforce training, and documented incident-response procedures. Details are available at halai.ai/security. A current list of subprocessors is maintained at halai.ai/subprocessors. 9. Business Associate Agreement This Section 9 is a HIPAA Business Associate Agreement ("BAA") between Provider, as Covered Entity or upstream Business Associate ("Covered Entity"), and HALai, Inc., as Business Associate. This BAA supplements, and does not replace, this Agreement. In the event of a conflict between this BAA and any other part of this Agreement with respect to PHI, this BAA controls. 9.1 Definitions Capitalized terms used but not defined in this BAA have the meanings given in the HIPAA Rules, 45 CFR Parts 160 and 164. "PHI" means Protected Health Information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity in connection with the Services. "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as amended. 9.2 Permitted Uses and Disclosures of PHI Business Associate may use or disclose PHI only: (a) to perform the Services described in this Agreement; (b) for the proper management and administration of Business Associate, and to carry out its legal responsibilities, provided that any disclosure to a third party is required by law or the third party provides written assurances of confidentiality and prompt notification of any breach; (c) to provide Data Aggregation services relating to the health-care operations of the Covered Entity, as permitted under 45 CFR § 164.504(e)(2)(i)(B); (d) to create de-identified information in accordance with 45 CFR § 164.514(a)-(c); and (e) as Required by Law. Business Associate will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted in this Section 9.2. Business Associate will apply the minimum-necessary standard to its uses, disclosures, and requests for PHI. 9.3 Prohibited Uses Business Associate will not (a) sell PHI, (b) use or disclose PHI for marketing except as permitted by 45 CFR § 164.508(a)(3), or (c) receive remuneration in exchange for PHI, except as permitted by HIPAA. Business Associate will not use PHI to train AI models that serve any other customer. 9.4 Safeguards Business Associate will implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, in accordance with the Security Rule (45 CFR Part 164, Subpart C), including but not limited to AES-256 encryption at rest, TLS 1.2 or higher in transit, tenant isolation, access controls, audit logging, U.S. data residency, and workforce training. 9.5 Subcontractors Business Associate will require any subcontractor that creates, receives, maintains, or transmits PHI on its behalf to enter into a written agreement containing restrictions and conditions at least as protective as those in this BAA, in accordance with 45 CFR § 164.502(e)(1)(ii) and § 164.308(b)(2). A current list of subprocessors that may access PHI is maintained at halai.ai/subprocessors. Business Associate will provide at least 30 days' advance notice of any new subprocessor that will process PHI, and Covered Entity may object on reasonable grounds; if the parties cannot agree, Covered Entity may terminate the affected Services without penalty. 9.6 Individual Rights Business Associate will: (a) make PHI available to Covered Entity as necessary for Covered Entity to meet its obligations under 45 CFR § 164.524 (individual access); (b) make PHI available for amendment and incorporate any amendments as directed by Covered Entity in accordance with 45 CFR § 164.526; (c) document and make available to Covered Entity the information required to provide an accounting of disclosures in accordance with 45 CFR § 164.528; and (d) comply with any restriction on the use or disclosure of PHI that Covered Entity has agreed to under 45 CFR § 164.522, provided Business Associate has been notified of the restriction. 9.7 Reporting; Breach Notification Business Associate will report to Covered Entity: (a) any use or disclosure of PHI not permitted by this BAA of which it becomes aware, without unreasonable delay; (b) any Security Incident (as defined at 45 CFR § 164.304) of which it becomes aware, provided that unsuccessful attempts (for example, routine pings, port scans, and blocked login attempts) that do not result in actual unauthorized access or disclosure are reported only in the aggregate on request; and (c) any Breach of Unsecured PHI of which it becomes aware, in accordance with 45 CFR § 164.410, without unreasonable delay and in no event later than 60 calendar days after Discovery. Business Associate will use reasonable efforts to notify Covered Entity within 72 hours of Discovery of a Breach. A report under (c) will include, to the extent known: identification of individuals affected; a description of the nature and circumstances of the Breach; the types of PHI involved; the steps individuals should take to protect themselves; and the mitigation and investigative steps Business Associate is taking. 9.8 Mitigation Business Associate will mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI by Business Associate in violation of this BAA, in accordance with 45 CFR § 164.530(f). 9.9 Access to Records Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with the HIPAA Rules. 9.10 Covered Entity Obligations Covered Entity will (a) notify Business Associate of any limitation in its Notice of Privacy Practices that affects Business Associate's use or disclosure of PHI; (b) notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent it affects Business Associate; (c) notify Business Associate of any restriction on the use or disclosure of PHI to which Covered Entity has agreed under 45 CFR § 164.522; and (d) not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity. 9.11 Term and Termination This BAA is effective on the Effective Date and remains in effect until termination of the Agreement or termination for cause under this Section 9.11, whichever is earlier. Either party may terminate this BAA and the Agreement for cause if the other party materially breaches this BAA and fails to cure the breach within 30 days after written notice. Upon termination, Business Associate will return or destroy all PHI in its possession, and will retain no copies, except to the extent return or destruction is infeasible; in that case, Business Associate will extend the protections of this BAA to such PHI and limit further use or disclosure to those purposes that make return or destruction infeasible, for as long as Business Associate maintains the PHI. 9.12 Interpretation Any ambiguity in this BAA will be interpreted to permit compliance with the HIPAA Rules. If the HIPAA Rules are amended, the parties will negotiate in good faith any amendments to this BAA necessary to bring it into compliance. 10. Term and Termination This Agreement begins when you create an account and continues until terminated. You may terminate by closing your account. We may suspend or terminate for material breach after 30 days' written notice if the breach is not cured, or immediately if the breach cannot reasonably be cured, involves misuse of PHI, or poses a security risk to any person. Sections that by their nature should survive termination will survive. Data Export on Termination. For 90 days following termination of the Agreement (or a shorter period the parties agree to in writing), we will make Provider Data available for export in machine-readable formats, including HL7 FHIR R4 bundles, C-CDA documents, and CSV or JSON for content that does not conform to those standards. After the export window closes, we will delete or return Provider Data in accordance with the BAA in Section 9. Fees for export beyond a reasonable one-time export are set forth on the pricing page. 11. Limitation of Liability TO THE MAXIMUM EXTENT PERMITTED BY LAW, IN NO EVENT WILL HALAI, AHI, OR THEIR AFFILIATES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUES, DATA, OR GOODWILL, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. General Cap. OUR AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE AMOUNTS PAID BY YOU TO US FOR THE SERVICES IN THE TWELVE MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM. HIPAA Breach Super-Cap. For claims arising directly from a Breach of Unsecured PHI caused by HALai's material breach of the BAA in Section 9, our aggregate liability will not exceed two (2) times the general cap above, on top of amounts we are required to pay under HIPAA or by law. Carve-Outs. The general cap does not apply to (a) a party's indemnification obligations under Section 12, (b) a breach of confidentiality under Section 7, (c) amounts owed under Section 5, or (d) liability that cannot be limited by applicable law. 12. Indemnification By Provider. You will defend, indemnify, and hold harmless HALai, AHI, and their affiliates from any third-party claim, loss, damage, liability, and expense (including reasonable attorneys' fees) arising out of (a) your use of the Services in violation of this Agreement or law, (b) Provider Data, including any allegation that our use of Provider Data as permitted by this Agreement violates the rights of a third party, (c) your breach of your HIPAA obligations as a Covered Entity, or (d) any claim you submitted, including any allegation that a claim was not supported by your documentation. By HALai. We will defend, indemnify, and hold harmless Provider from any third-party claim that (i) the Services, as provided by us and used in accordance with this Agreement, infringe a U.S. patent, copyright, or trademark, or misappropriate a trade secret, or (ii) AI output generated by the Services, as unmodified and used in accordance with this Agreement, infringes a third-party U.S. copyright. Our obligations under clause (ii) are conditioned on (A) Provider promptly notifying us in writing of the claim, (B) Provider not admitting liability or settling without our written consent, and (C) Provider providing reasonable cooperation. This indemnity does not apply to output that was materially modified after generation, that was used in violation of this Agreement, or where Provider disabled or bypassed content-safety controls we made available. If a claim covered above is made or in our reasonable view is likely to be made, we may at our option (1) procure the right for Provider to continue using the affected Service, (2) modify the Service to be non-infringing, or (3) terminate the affected Service and refund any pre-paid unused fees. This Section 12 states our sole liability and Provider's exclusive remedy for third-party intellectual-property claims. 13. Governing Law; Disputes This Agreement is governed by the laws of the State of California, excluding its conflict-of-laws principles. Any dispute arising out of or related to this Agreement will be resolved in accordance with the dispute-resolution provisions of the Terms of Use (Section 15), including binding arbitration and class-action waiver. 14. Amendments We may update this Agreement from time to time. If the changes are material, we will provide at least 30 days' prior notice by email or in-product notice. Your continued use of the Services after the effective date of a change constitutes acceptance. 15. Miscellaneous Entire Agreement. This Agreement, together with the Terms of Use and Privacy Policy, is the entire agreement between the parties regarding the Services. Order of Precedence. If there is a conflict between documents, the order of precedence is: (1) this BAA in Section 9, (2) the rest of this Agreement, (3) the Terms of Use, (4) the Privacy Policy. Assignment. You may not assign this Agreement without our prior written consent. We may assign this Agreement in connection with a merger, acquisition, financing, or sale of assets. Severability, No Waiver, Force Majeure, Notices, Relationship. As set forth in Section 19 of the Terms of Use. 16. Contact HALai, Inc. Attn: Privacy Officer / HIPAA Compliance privacy@halai.ai · security@halai.ai · legal@halai.ai

Related: Terms of Use · Privacy Policy · Consumer Health Data Privacy Policy · HALi User Agreement · Security & Compliance

Products

HALHALiMDMaiENCOUNTERaiCODEaiREFERRALai

Platform

How It WorksSecurityPricingHAL Alerts

Company

AboutWhitepapersAHI VisionInvest in AHIContactInvest in AHI

Legal

Privacy PolicyTerms of UseProvider AgreementBAA
© 2026 Artificial Healthcare Intelligence, Inc. All rights reserved.