Effective Date: March 31, 2024
This Healthcare Provider User Agreement ("Agreement") governs your use of HALai's Healthcare Intelligence platform, including HAL, MDMai, ENCOUNTERai, CODEai, REFERRALai, and all related services (collectively, the "Services"). 1. ACCEPTANCE OF TERMS By creating an account, accessing, or using the Services, you agree to be bound by this Agreement. If you are using the Services on behalf of a healthcare organization, you represent that you have the authority to bind that organization to this Agreement. 2. ELIGIBILITY The Services are available to licensed healthcare providers with an active National Provider Identifier (NPI). You represent and warrant that all information you provide during registration is accurate and complete. 3. ACCOUNT RESPONSIBILITIES You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account. You agree to notify us immediately of any unauthorized use of your account. 4. PERMITTED USE You may use the Services solely for legitimate healthcare purposes in connection with your practice. You agree not to: (a) use the Services for any unlawful purpose; (b) share your credentials with unauthorized persons; (c) attempt to reverse engineer the Services; (d) use the Services to store or transmit malicious code; (e) interfere with the integrity or performance of the Services. 5. DATA OWNERSHIP AND USE 5.1 Your Data: You retain all rights to the clinical data, encounter notes, and other information you submit through the Services ("Your Data"). 5.2 Our Use: We use Your Data solely to provide the Services to you, including but not limited to: processing encounter notes through MDMai, powering HAL's clinical decision support, training your personalized ENCOUNTERai documentation model, and generating analytics through HAL's Healthcare Analytics Intelligence. 5.3 Data Isolation: Your Data is stored in a dedicated, isolated Azure container. Your Data is never shared with other providers, never used to train external AI models, and never sold to third parties. 5.4 Aggregated Data: We may create de-identified, aggregated datasets from Your Data for the purpose of improving the Services. Such aggregated data cannot be used to identify you or your patients. 6. HIPAA COMPLIANCE 6.1 Business Associate Relationship: To the extent that we create, receive, maintain, or transmit Protected Health Information ("PHI") on your behalf, we act as your Business Associate under HIPAA. 6.2 Business Associate Agreement: The Business Associate Agreement ("BAA") set forth in Section 9 of this Agreement is incorporated herein by reference and governs our obligations with respect to PHI. 7. FEES AND PAYMENT 7.1 MDMai: MDMai is provided free of charge to all providers with an active NPI. 7.2 Premium Services: Fees for HAL, ENCOUNTERai, CODEai, REFERRALai, and other premium services are set forth on our pricing page and may be updated from time to time. 7.3 Payment Terms: Fees are billed in advance on a monthly or annual basis. All fees are non-refundable except as expressly set forth herein. 8. DISCLAIMERS 8.1 Not Medical Advice: The Services provide clinical decision support information only. HAL is not a healthcare provider and does not diagnose, treat, or prescribe. All clinical decisions remain the sole responsibility of the licensed healthcare provider. 8.2 No Guarantee of Accuracy: While we strive for accuracy, the Services are provided "as is" and we make no warranties regarding the completeness, accuracy, or reliability of any information provided through the Services. 8.3 No Guarantee of Revenue: MDMai provides billing optimization recommendations. We do not guarantee any specific financial outcomes. 9. BUSINESS ASSOCIATE AGREEMENT (BAA) 9.1 Definitions: Terms used in this BAA shall have the same meaning as those terms defined in HIPAA, including the Privacy Rule (45 CFR Part 160 and Part 164, Subparts A and E) and the Security Rule (45 CFR Part 160 and Part 164, Subparts A and C). 9.2 Obligations of Business Associate: (a) Not use or disclose PHI other than as permitted or required by this Agreement or as required by law; (b) Use appropriate safeguards to prevent unauthorized use or disclosure of PHI, including implementing administrative, physical, and technical safeguards; (c) Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement; (d) Ensure that any subcontractors that create, receive, maintain, or transmit PHI agree to the same restrictions and conditions; (e) Make available PHI in accordance with HIPAA's patient access requirements; (f) Make internal practices, books, and records available to the Secretary of HHS for purposes of determining compliance; (g) Return or destroy all PHI upon termination of this Agreement. 9.3 Permitted Uses and Disclosures: Business Associate may use or disclose PHI solely for the purpose of performing the Services under this Agreement, including: processing encounter notes, generating billing recommendations, providing clinical decision support, generating documentation, and performing analytics. 9.4 Security Measures: Business Associate shall implement the following security measures: - AES-256 encryption at rest - TLS 1.3 encryption in transit - Azure Private Link network isolation - Tenant-isolated data containers - SOC 2 Type II compliant infrastructure - Regular security assessments and penetration testing - U.S. data residency only 9.5 Breach Notification: Business Associate shall report any Security Incident or Breach of Unsecured PHI to Covered Entity within 72 hours of discovery. 9.6 Term and Termination: This BAA shall remain in effect for the duration of the Agreement. Upon termination, Business Associate shall return or destroy all PHI in its possession. 10. LIMITATION OF LIABILITY IN NO EVENT SHALL HALAI BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING OUT OF OR RELATED TO THIS AGREEMENT. HALAI'S TOTAL LIABILITY SHALL NOT EXCEED THE FEES PAID BY YOU IN THE TWELVE MONTHS PRECEDING THE CLAIM. 11. GOVERNING LAW This Agreement shall be governed by the laws of the State of California without regard to conflict of laws principles. 12. AMENDMENTS We may update this Agreement from time to time. Material changes will be communicated via email or through the Services. Your continued use constitutes acceptance of the updated terms. Contact: HALai, Inc. | info@halai.ai Artificial Healthcare Intelligence, Inc. is a 501(c)(3) non-profit organization.