How to read this. Healthplex is normally deployed on infrastructure you control. In that model your patient data never reaches our systems, which changes the shape of several clauses below — particularly those on data handling, suspension and termination. Section 3 sets out which deployment model applies to you.
This page is the standard form. If you have signed an Order with negotiated terms, that Order prevails over anything written here.
1. Definitions
Here is what the key terms mean throughout this agreement.
- "Healthplex"
- Healthplex, Inc., a Delaware corporation.
- "Customer"
- The legal entity that executes an Order with Healthplex or uses the Software.
- "Software"
- The Healthplex EHR platform in object and container form, including all modules, APIs and the Documentation.
- "Services"
- The Software together with any support, updates, implementation, hosting or customisation services described in the applicable Order.
- "Self-Hosted Deployment"
- A deployment in which the Software runs on infrastructure owned or controlled by Customer, and Customer alone administers the environment and the data within it.
- "Healthplex-Operated Deployment"
- A deployment in which Healthplex hosts or manages the environment on Customer's behalf, as expressly stated in an Order.
- "Tenant"
- Customer's logical instance within the platform, identified by a unique
org_id. - "Order"
- A sales order form, master service agreement, statement of work or other written instrument referencing these Terms.
- "Authorized User"
- An individual whom Customer has provisioned to use the Services on its behalf.
- "PHI"
- Protected Health Information as defined under HIPAA (45 C.F.R. §160.103) and equivalent definitions under applicable law (personal health data under GDPR / DPDP / Privacy Act 1988).
- "Customer Data"
- All data, including PHI, processed through the Software by or on behalf of Customer.
- "BAA"
- A Business Associate Agreement as required under HIPAA.
- "DPA"
- The Data Processing Addendum, as required under GDPR Article 28 and equivalent law.
- "Documentation"
- Healthplex's then-current technical documentation for the Software.
- "Effective Date"
- The date of execution of the applicable Order.
2. Licence grant
We give you a limited, non-exclusive right to run the platform for your own healthcare operations.
Subject to payment of fees and compliance with these Terms, Healthplex grants Customer a non-exclusive, non-transferable, revocable, worldwide (subject to regional deployment restrictions) licence to install, run and use the Software solely for Customer's internal healthcare operations during the Term, within the site, facility and user limits specified in the Order.
This grant does not include the right to: (a) sublicense, resell or offer the Software as a service to third parties; (b) use the Software to build a competing product; (c) exceed the user counts or site limits in the Order; (d) remove or obscure proprietary notices; or (e) transfer the Software to an affiliate or successor entity without written consent, except as permitted under Section 15.2.
3. Deployment models and control of data
In the default self-hosted model your data stays on your infrastructure and we never hold it. That is a deliberate design choice, and it changes who is responsible for what.
3.1 Self-Hosted Deployment (default). Unless an Order states otherwise, Customer operates the Software on its own infrastructure. In this model:
- Customer Data, including PHI, resides exclusively on Customer-controlled systems. Healthplex has no access to it and does not process it.
- Customer is solely responsible for infrastructure security, network controls, operating-system patching, backup, disaster recovery, physical security and availability.
- Healthplex's obligations are limited to supplying the Software, Documentation, updates and the support described in the Order.
- Availability and uptime commitments, where offered, apply only to Healthplex's delivery of updates and support — not to Customer's running environment.
3.2 Healthplex-Operated Deployment. Where an Order expressly places hosting or managed operation with Healthplex, Healthplex acts as a Business Associate under HIPAA and a processor under GDPR / DPDP, and the DPA and BAA govern that processing. The additional obligations in Sections 6.5 and 14 apply to this model only.
3.3 Support access. If Customer requests diagnostic support that requires Healthplex personnel to view a Self-Hosted environment, any such access is (a) initiated by Customer, (b) time-limited, (c) logged, and (d) subject to the DPA and, where PHI may be visible, an executed BAA. Healthplex will not access a Self-Hosted environment without Customer's request or consent.
4. Customer responsibilities
You are the data controller. You own your data. You are responsible for having lawful authority to process it and for your users' conduct.
4.1 Data controller / data fiduciary. Customer is the Data Controller under GDPR, the covered entity or business associate (as applicable) under HIPAA, and the Data Fiduciary under DPDP. In a Self-Hosted Deployment Healthplex is neither a processor nor a business associate with respect to Customer Data, because it does not process it. In a Healthplex-Operated Deployment, Healthplex acts as processor or business associate only, on Customer's documented instructions.
4.2 Lawful basis. Customer warrants that it has and will maintain a lawful basis for processing all Customer Data, including PHI, and has obtained all consents, authorisations and permissions required by applicable law.
4.3 Authorized Users. Customer is responsible for all acts and omissions of its Authorized Users and for the confidentiality of credentials issued to them.
4.4 Environment. Customer shall operate the Software on supported platform versions, apply security updates within the windows stated in the Documentation, and maintain the configuration baselines Healthplex publishes. Healthplex's warranty and support obligations do not extend to environments running materially out-of-date or unsupported builds.
4.5 Acceptable use. Customer shall comply with Section 14.
4.6 BAA / DPA. Where Healthplex will process PHI or personal data on Customer's behalf, execution of the applicable BAA or DPA is a condition of that processing.
5. Fees and payment
Invoices are due net 30. We can suspend support and updates after 30 days of non-payment, with written notice.
5.1 Fees. Customer shall pay the fees specified in the applicable Order.
5.2 Invoicing. Healthplex will invoice monthly or annually as specified in the Order. Invoices are due net 30 days from the invoice date.
5.3 Late fees. Overdue amounts accrue interest at the lesser of 1.5% per month or the maximum rate permitted by law, from the due date until paid.
5.4 Taxes. Fees are exclusive of applicable taxes. Customer is responsible for all sales, use, GST, VAT or similar taxes, excluding taxes on Healthplex's net income.
5.5 Suspension for non-payment. If an undisputed invoice is more than 30 days past due, Healthplex may, on 30 days' written notice, suspend support, updates and licence renewal until the overdue amount is paid. Healthplex will not disable, lock or degrade a running Self-Hosted clinical system for non-payment. Patient safety is not a collections instrument. Access is restored within 2 business days of receipt of payment.
6. Term and termination
The contract auto-renews annually. Either side can terminate for breach after a 30-day cure period. On termination the licence ends — but your data is already yours and stays where it is.
6.1 Initial term. The initial term begins on the Effective Date and continues for the period stated in the Order (typically 12 months).
6.2 Auto-renewal. Unless either party gives written notice of non-renewal at least 60 days before the end of the then-current term, the Agreement renews for successive one-year terms at Healthplex's then-current pricing.
6.3 Termination for cause. Either party may terminate on 30 days' written notice if the other materially breaches these Terms and fails to cure within that period. Healthplex may terminate immediately on notice if Customer violates Section 14 or fails to execute a required BAA.
6.4 Termination for convenience. Customer may terminate for convenience on 60 days' written notice. No refunds are owed for unused prepaid periods unless the Order states otherwise.
6.5 Post-termination data.
- Self-Hosted Deployment: Customer Data remains on Customer's infrastructure throughout and after the Term. Healthplex holds no copy and therefore has nothing to return or delete. Customer remains responsible for its own retention and disposal obligations.
- Healthplex-Operated Deployment: Healthplex will provide read-only export access for 30 days following termination. After that window Healthplex may delete Customer Data consistent with the DPA, its retention policy and applicable law. Customer is responsible for exporting within the window.
6.6 Effect of termination. On termination the licence in Section 2 ceases and Customer shall stop using and, within 30 days, uninstall the Software and destroy all copies, certifying destruction on request. Customer may retain Customer Data — it is Customer's. Sections 1, 5 (amounts owed), 6.5, 6.6, 7, 8, 9, 10, 11, 12 and 15 survive termination.
7. Intellectual property
Healthplex owns the platform. You own your data. We never sell your data — and in a self-hosted deployment we could not, because we do not have it.
7.1 Healthplex IP. Healthplex retains all right, title and interest in the Software, including all source code, algorithms, interfaces, Documentation and derivative works. No rights are granted except those expressly set out in Section 2.
7.2 Customer Data. Customer retains all right, title and interest in Customer Data.
7.3 Feedback. If Customer provides feedback or suggestions, Healthplex may use it without restriction or obligation.
7.4 Telemetry and aggregated data. Healthplex may collect aggregated, de-identified operational telemetry (feature usage counts, performance metrics, error rates) to improve the Software. Such telemetry never contains PHI or data identifying an individual. In a Self-Hosted Deployment telemetry is opt-in and disabled by default; where enabled, Customer may inspect exactly what is transmitted. Healthplex will not sell such data to third parties.
7.5 Customisations. Unless an Order says otherwise, bespoke workflows, forms, reports and integrations built for Customer are licensed to Customer under Section 2, and Healthplex retains ownership of the underlying components, tooling and generic techniques.
8. Warranties
We warrant that the platform materially does what the documentation says. Everything else is disclaimed, and clinical AI output is advisory only.
8.1 Platform warranty. Healthplex warrants that the Software will conform in all material respects to the Documentation during the Term, when operated on a supported configuration.
8.2 Disclaimer. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, EXCEPT AS EXPRESSLY SET OUT IN SECTION 8.1, THE SERVICES ARE PROVIDED "AS IS". HEALTHPLEX DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT AND ERROR-FREE OPERATION. HEALTHPLEX DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, TIMELY, SECURE OR FREE OF ERRORS.
8.3 Clinical advisory. Customer acknowledges that clinical decision support and other AI-generated output is advisory only and is not a substitute for the independent professional judgment of a licensed clinician. Customer is solely responsible for all clinical decisions made by its personnel, including those informed by platform output.
8.4 Remedy. Customer's sole remedy for breach of Section 8.1 is correction of the non-conformance or, where correction is not commercially practicable, a service credit as specified in the applicable support addendum, applied to a future invoice.
9. Limitation of liability
Our total liability is capped at 12 months of fees. We are not liable for lost profits or consequential damages. The cap does not apply to gross negligence, confidentiality breaches or our IP indemnity.
9.1 Cap. EXCEPT AS SET OUT IN SECTION 9.3, HEALTHPLEX'S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT — WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY OR OTHERWISE — SHALL NOT EXCEED THE TOTAL FEES PAID BY CUSTOMER TO HEALTHPLEX DURING THE 12-MONTH PERIOD IMMEDIATELY PRECEDING THE CLAIM.
9.2 Exclusion of consequential damages. EXCEPT AS SET OUT IN SECTION 9.3, IN NO EVENT SHALL HEALTHPLEX BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE OR EXEMPLARY DAMAGES, INCLUDING LOSS OF PROFITS, REVENUE, GOODWILL OR DATA, COST OF DATA RESTORATION, OR COST OF SUBSTITUTE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
9.3 Exceptions to the cap. The cap in 9.1 and the exclusion in 9.2 do not apply to: (a) damages arising from Healthplex's gross negligence or wilful misconduct; (b) Healthplex's material breach of its confidentiality obligations under Section 11; (c) Healthplex's obligations under the IP indemnity in Section 10.2; or (d) liability that cannot be limited under applicable law, including liability under data protection law for Healthplex's breach of its obligations as a processor or business associate.
10. Indemnification
You indemnify us for claims arising from your data or misuse. We indemnify you if someone sues you claiming our unmodified platform infringes their IP.
10.1 Customer indemnity. Customer shall defend, indemnify and hold harmless Healthplex against any third-party claim, loss, liability, damage or expense (including reasonable legal fees) arising out of: (a) Customer Data, including any claim that it violates applicable law or third-party rights; (b) Customer's use of the Services in breach of these Terms; (c) Customer's operation or security of its own infrastructure in a Self-Hosted Deployment; or (d) Customer's failure to comply with applicable law.
10.2 Healthplex IP indemnity. Healthplex shall defend, indemnify and hold harmless Customer against any third-party claim alleging that the unmodified Software infringes a third party's intellectual property rights. This does not apply to claims arising from (a) Customer's modification of the Software, (b) combination with third-party products not provided or approved by Healthplex, or (c) Customer Data.
10.3 Procedure. The indemnified party shall promptly notify the indemnifying party in writing, give it sole control of the defence and settlement, and cooperate reasonably at the indemnifying party's expense.
11. Confidentiality
We keep each other's confidential information private. The obligation survives for five years — and indefinitely for PHI.
11.1 Obligations. Each party ("Receiving Party") shall hold the other's Confidential Information in confidence using at least the degree of care it applies to its own (and no less than reasonable care), and shall not disclose it to third parties except as permitted here.
11.2 Definition. "Confidential Information" means information marked confidential or which a reasonable person would understand to be confidential, including pricing, technical architecture, Customer Data and business plans. It excludes information that (a) becomes public through no breach of this Agreement, (b) was known before disclosure, (c) was independently developed without reference to the disclosing party's information, or (d) must be disclosed by law, provided prompt written notice is given.
11.3 Duration. Confidentiality obligations survive termination for five years. Obligations with respect to Customer Data, including PHI, survive indefinitely.
12. Governing law and disputes
Delaware law applies. Disputes go to AAA arbitration in Delaware. Class actions are waived.
12.1 Governing law. This Agreement is governed by the laws of the State of Delaware, excluding its conflict-of-laws rules.
12.2 Arbitration. Any dispute arising out of or relating to this Agreement (except claims for injunctive relief protecting intellectual property or confidential information) shall be resolved by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, seated in Wilmington, Delaware. The arbitrator's decision is final and binding.
12.3 Class action waiver. Each party waives any right to bring claims as a class action or in any class, consolidated or representative proceeding.
12.4 Injunctive relief. Either party may seek emergency injunctive or equitable relief from a court of competent jurisdiction in Delaware to prevent irreparable harm, without prejudice to the arbitration obligation above.
13. Subprocessors
We publish who handles data on our behalf and give 30 days' notice before adding anyone new. In a self-hosted deployment, no subprocessor touches your patient data at all.
Healthplex maintains a current subprocessor list in the Trust Center. In a Self-Hosted Deployment no Healthplex subprocessor processes Customer Data, because Customer Data does not leave Customer's infrastructure; the published list then applies only to Healthplex's own marketing and sales systems.
Where Healthplex does process Customer Data — a Healthplex-Operated Deployment, or a Customer-enabled cloud AI provider under the BYOK gateway — Healthplex will notify Customer by email at least 30 days before engaging a new subprocessor. Customer may object in writing within 15 days on the grounds that the change would materially impair its compliance with applicable data protection law. If the objection is unresolved after 15 days, Customer may terminate for cause without penalty.
14. Acceptable use
Don't use the platform for unlawful purposes, don't upload malware, don't reverse-engineer it.
Customer shall not, and shall ensure its Authorized Users do not:
- Introduce malware, viruses or other malicious code into the Software.
- Process PHI or personal data through Healthplex-operated components without a valid BAA or DPA in place.
- Reverse-engineer, decompile or disassemble any component of the Software, except to the extent that restriction is unenforceable under applicable law.
- Scrape, crawl or systematically access Healthplex-operated interfaces disproportionately to reasonable use.
- Use the Services to store or transmit unlawful content.
- Circumvent rate limits, licence enforcement, authentication or access controls.
- Use the Services in violation of applicable law, including HIPAA, GDPR, DPDP or healthcare regulation in Customer's jurisdiction.
15. General provisions
Standard boilerplate — force majeure, assignment, notices, severability, entire agreement.
15.1 Force majeure. Neither party is liable for delays or failures caused by events beyond its reasonable control (natural disasters, pandemics, government action, third-party infrastructure failure), provided prompt notice is given and commercially reasonable efforts are used to resume performance.
15.2 Assignment. Customer may not assign this Agreement without Healthplex's prior written consent, such consent not to be unreasonably withheld in the case of a merger or reorganisation. Healthplex may assign in connection with a merger, acquisition or sale of substantially all assets, on written notice.
15.3 Notices. Notices must be in writing, sent to the addresses in the Order or by email. Notices to Healthplex: legal@healthplex.app.
15.4 Severability. If any provision is held unenforceable, the remainder continues in full force.
15.5 Entire agreement. This Agreement, together with all Orders and addenda (including the BAA and DPA), is the entire agreement between the parties on its subject matter and supersedes all prior agreements, representations and understandings.
15.6 Waiver. No waiver is effective unless in writing.
15.7 Counterparts. This Agreement may be executed in counterparts, each an original and all one instrument. Electronic signatures are valid.
Healthplex, Inc. — legal@healthplex.app