This ePrescribe Subscription Services Agreement (this “Agreement”) is a legally binding contract between Veradigm LLC and its affiliates (“Veradigm,” “we,” “us,” or “our”) and the healthcare provider, practice, or other organization on whose behalf the ePrescribe Services account is registered (“Customer,” “you,” or “your”), each a “Party” and together the “Parties.” Customer owns and controls the account, and any individual who registers, accepts this Agreement, or administers the account on Customer’s behalf represents that they are authorized to bind Customer. This Agreement governs all access to and use of the Services by Customer and its Authorized Users, including any free trial, evaluation, or other pre-subscription access.
BY CLICKING “I AGREE,” SIGNING UP FOR AN ACCOUNT, OR ACCESSING OR USING THE SERVICES, YOU AGREE TO BE BOUND BY THIS AGREEMENT, INCLUDING THE BINDING ARBITRATION PROVISION AND CLASS ACTION WAIVER IN SECTION 10. PLEASE READ IT CAREFULLY. DO NOT SIGN UP FOR AN ACCOUNT OR USE THE SERVICES IF YOU ARE UNWILLING OR UNABLE TO BE LEGALLY BOUND BY IT.
“Administrative Rights” means the rights to administer and direct use of your account, including granting, modifying, and revoking Authorized User access, assigning administrative privileges, configuring account settings, and authorizing third-party connections to share or receive Your Information through the Services.
“Administrator” means an Authorized User to whom you, or another Administrator with appropriate authority, grants Administrative Rights.
“Authorized User” means an individual employee, consultant, contractor, or agent of Customer whom you or an Administrator authorizes to access and use the Services on Customer’s behalf.
“BAA” means the Business Associate Addendum attached to and incorporated into this Agreement, which governs our use and disclosure of PHI.
“Billing Period” means the recurring period for which subscription fees are charged, as identified in the applicable Subscription Plan.
“Clinical Support Information” means prescription-related information made available through the Services, including information on drug interactions, allergies, dosages, formulary status, prescription benefits, prescription history, and patient education.
“Confidential Information” means nonpublic information concerning our business, financial affairs, products, services, or technology, and any other information we treat or designate as confidential or proprietary or that would reasonably be viewed as confidential or as valuable to our competitors. It excludes information we make public, information that becomes public other than through a breach of this Agreement, and PHI, which the BAA governs.
“ePrescribe Services” or the “Services” means the electronic medication prescribing services provided under this Agreement, including electronic prescribing of controlled substances (“EPCS”), prescription drug monitoring program (“PDMP”) functionality, prescribing-related clinical and benefit information services, pharmacy and payer communications, related prescribing features and functionality, standard support, and similar generally applicable services we make available from time to time.
“HIPAA” means the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act of 2009, and their implementing regulations, as amended.
“Personal Information” means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular individual or household, including anything constituting “personal information” or “personal data” under applicable privacy laws. It excludes PHI to the extent regulated by HIPAA and information de-identified under applicable law.
“Policies and Procedures” means our rules, policies, and procedures for access to and use of the Services, as amended from time to time and made available electronically on our website.
“Protected Health Information” or “PHI” has the meaning given to “protected health information” under HIPAA, excluding information de-identified in accordance with HIPAA.
“Provider License” means a subscription right assigned to one individually identified “health care provider” (as defined under HIPAA) to access and use provider-level functionality, such as prescribing and EPCS, as made available under the applicable Subscription Plan.
“Subscription Plan” means the online plan, checkout selection, order, or other ordering document accepted by Customer identifying the applicable fees, Billing Period, number of Provider Licenses, and any plan-specific terms.
“Subscription Services Addendum” means the addendum to this Agreement setting out the fees, billing, automatic renewal, tax, and cancellation terms for your subscription.
“Your Information” means information that Customer or its Authorized Users enter or upload into the Services, or that we receive on Customer’s behalf from patients, authorized service providers, or third-party partners in connection with the Services, including Personal Information and PHI.
2.1 Customer Account. Customer is the account holder, controls its account and Administrative Rights, and is responsible for all activity under the account, including all access and use by its Authorized Users. Only Customer may exercise the rights and remedies under this Agreement, even if an Authorized User established or administers the account, and delegating Administrative Rights does not relieve Customer of responsibility. Customer represents and warrants that the account information it submits is accurate and complete and that anyone who establishes the account or accepts this Agreement on Customer’s behalf is authorized to do so.
2.2 Authorized Users. An Authorized User may access and use the Services only for Customer’s benefit and within the scope Customer or its Administrator authorizes. By accepting this Agreement or using the Services, each Authorized User agrees to comply with all provisions applicable to Authorized Users, which we may enforce directly against that user.
2.3 Account Security. Customer and each Authorized User must access the Services using that individual’s own email address and password, together with any required multi-factor authentication or other security measures, and may use only the functionality permitted by the access level, permissions, and Provider License assigned to that user. Customer will:
(a) authorize, monitor, and control access and use by its Authorized Users, including assigning and revoking Provider Licenses and permissions;
(b) maintain reasonable and appropriate administrative, physical, and technical safeguards, in compliance with applicable law (including HIPAA), to protect information within the Services and the security of its access and use;
(c) train its Authorized Users on this Agreement and the applicable Policies and Procedures;
(d) promptly disable access for any Authorized User whose employment, engagement, authorization, or need for access ends;
(e) immediately notify us of any actual or suspected unauthorized access to or use of an account; and
(f) take reasonable steps to contain, mitigate, and remediate any unauthorized access or use.
2.4 Identity Verification and Licensure. Certain features, including EPCS and PDMP functionality, may require us to verify the identity, credentials, qualifications, licensure, eligibility, and prescribing authority of Customer or its Authorized Users (“Identity Verification”). Customer and each applicable Authorized User represent and warrant that all information submitted for Identity Verification is accurate, complete, current, and submitted with proper authority, and authorize us to use and disclose it, including Personal Information and disclosures to third parties, as reasonably necessary for Identity Verification. Customer will ensure that it and its Authorized Users maintain all licenses, permits, registrations, credentials, qualifications, and prescribing authority required to use the Services and, where applicable, to prescribe, and must immediately disable access for any Authorized User who no longer satisfies these requirements.
2.5 Right to Access and Use. Subject to your compliance with this Agreement and the Policies and Procedures, we grant you and your Authorized Users a personal, limited, non-transferable, non-sublicensable, non-exclusive right to access and use the Services during the term of your subscription, solely for your internal business purposes, only from within the United States or its territories, and only as permitted by this Agreement and applicable law.
2.6 Trials, Beta Programs, and Additional Services. If we make a free trial available, we grant you and your Authorized Users a limited right to use the Services for evaluation during the trial, subject to this Agreement; a trial may not include all features (prescribing requires an active paid subscription) and may be modified, suspended, or discontinued at any time. We may invite you to participate in beta testing, pilot programs, or feedback activities; participation is voluntary and may be subject to additional terms. We may also make additional products, services, functionality, content, or integrations available through the Services (“Additional Services”), which may be subject to separate terms that you agree to by using them and that control for those Additional Services to the extent they conflict with this Agreement.
2.7 Restrictions on Use. You will not, and will not permit or authorize any other person to:
(a) use the Services for time-sharing, rental, service bureau, or outsourcing purposes, or otherwise permit any third party to access, benefit from, or use the Services through your account;
(b) copy, modify, reverse engineer, decompile, or disassemble the Services or attempt to discover their source code;
(c) access or use the Services through any unauthorized integration, automated or scripted means, scraping, or any means other than the interfaces we authorize, or use the Services or anything obtained through them to copy, replicate, support, develop, train, improve, or create a competing product or service, or otherwise infringe or misappropriate our intellectual property or proprietary rights;
(d) introduce or attempt to introduce any virus, malware, disabling code, or other harmful code, or otherwise access, use, or interfere with the Services in a manner that compromises or attempts to compromise their security, integrity, availability, or proper operation, or that of any information in them;
(e) conduct or attempt to conduct any vulnerability scanning, penetration testing, security testing, load testing, or similar testing of the Services without our prior written authorization; or
(f) access or use the Services for any fraudulent, deceptive, or unlawful purpose.
2.8 Suspension of Access. We may immediately suspend your or any Authorized User’s access to all or part of the Services if we reasonably determine that: (a) you or an Authorized User has violated or may violate this Agreement, including Section 2.7; (b) we cannot verify required information or confirm that applicable verification, licensure, credentialing, or eligibility requirements are met; (c) an account has been compromised or used in an unauthorized manner; (d) access or use may threaten the security, integrity, availability, confidentiality, or proper operation of the Services or information in them; (e) continued access may create a legal, regulatory, security, patient safety, fraud, or other material risk; or (f) we cannot process payment, your payment method is invalid, or fees remain unpaid. Failure to satisfy any access requirement under this Agreement, including under Sections 2.4 and 7, may also result in suspension under this Section or termination under Section 9.3. Suspension does not limit our other rights or remedies, and we may restore access once the issue is resolved.
2.9 Your Compliance Obligations. You are solely responsible for ensuring that all use of the Services by Customer and its Authorized Users complies with applicable law, including laws on the privacy, security, and confidentiality of health information. You are also solely responsible for complying with all laws applicable to communications you elect to send, authorize, enable, or configure through the Services, including prescription reminders and communications delivered by text message, telephone call, email, or fax, and for obtaining and maintaining any consent, authorization, or permission required by law to send them.
2.10 Cooperation. You will reasonably cooperate with us on verification, credentialing, security, fraud prevention, legal, and compliance matters relating to your use of the Services, including by providing information we reasonably request to administer, protect, verify, or investigate unauthorized access, and by assisting any investigation of actual or suspected unauthorized, improper, fraudulent, or unlawful prescribing activity involving your account.
3.1 Clinical Support Information and Sponsored Content. The Services may provide Clinical Support Information and may display sponsored content, advertising, safety or regulatory materials, patient support materials, or other prescribing-related resources funded or sponsored by us or third parties, for which we may receive remuneration. All such information and content is provided for informational purposes only and is not intended to replace professional judgment or independent clinical decision-making. It may be provided by third parties beyond our control, and we do not warrant its accuracy, completeness, or availability. Customer and its Authorized Users are solely responsible for determining whether any medication, dosage, prescription, treatment decision, or other course of care is appropriate for a patient, and for reviewing and validating any Clinical Support Information before relying on or acting upon it.
3.2 Information Exchange and Third Parties. The Services facilitate the exchange of information among healthcare providers, pharmacies, pharmacy benefit managers, payers, PDMPs, governmental authorities, intermediaries, service providers, and other third parties. Customer authorizes us to transmit, receive, access, use, and disclose information submitted by or on behalf of Customer and its Authorized Users as reasonably necessary to provide the Services. The availability, timing, accuracy, and completeness of information exchanged may depend on systems maintained by third parties beyond our control.
Prescribing functionality requires an active paid subscription. Fees, billing, automatic renewal, taxes, cancellation, and other payment terms are set out in the Subscription Services Addendum, which forms part of this Agreement and applies to Customer as the account owner.
5.1 Your Information. As between us and you, you retain all rights in Your Information. We may use and disclose Your Information only as permitted by this Agreement, the BAA, and applicable law.
5.2 Our Technology. The Services, including all related software, technology, content, documentation, workflows, user interfaces, data structures, know-how, and intellectual property, are owned by us or our licensors. Except for the limited access and use rights expressly granted under this Agreement, no rights are granted to you in the Services or any related intellectual property.
5.3 Feedback. If you or an Authorized User provides suggestions, feedback, ideas, enhancement requests, or other input relating to the Services, we may use and incorporate it without restriction or obligation to you.
Except as expressly permitted in this Agreement, you will hold our Confidential Information in strict confidence, use it only as necessary to receive the Services, and disclose it only to Authorized Users who need it for purposes of this Agreement and who are bound by confidentiality obligations no less restrictive than those in this Agreement. You may disclose it as required by law, regulation, subpoena, court order, governmental request, or other legal process, provided that, to the extent legally permitted, you promptly notify us beforehand and reasonably cooperate with our efforts to obtain confidential treatment, a protective order, or other appropriate protection. The Parties agree that monetary damages may not be an adequate remedy for a breach of this Section 6 and that we may seek injunctive relief, in addition to all other remedies, to restrain any threatened or actual breach, without posting a bond.
7.1 Eligibility and Credentialing. In addition to Section 2.4, if you or any Authorized User uses EPCS or PDMP functionality, you are responsible for ensuring that each such individual satisfies all applicable federal and state requirements for that functionality, including identity proofing, credentialing, registration, authorization, delegation, DEA registration or other prescribing authority, multi-factor authentication, access controls, and permissible use; that all information submitted for those requirements is accurate, complete, and current; and that each complies with our Policies and Procedures for that functionality.
7.2 Prescribing Decisions. You are solely responsible for determining whether each prescription for a controlled substance is lawful, clinically appropriate, and issued by an individual with the required authority under applicable law.
7.3 Identity Verification Providers. EPCS functionality may require identity verification or credentialing through ID.me or another provider we designate, unless applicable DEA requirements and our Policies and Procedures permit you to conduct identity proofing for your own personnel. You and each applicable Authorized User must comply with the ID.me terms of service at id.me/terms and any other terms, policies, or procedures applicable to that process. We are not responsible for ID.me’s services, verification process, or handling of information except to the extent expressly required by applicable law or a written agreement between us and ID.me.
7.4 PDMP Information. Customer and its Authorized Users may access and use PDMP information only as permitted by applicable law, applicable PDMP terms, this Agreement, and our Policies and Procedures, and for no other purpose. You are solely responsible for determining whether PDMP information may be accessed, used, stored, copied, disclosed, or incorporated into a patient record, for ensuring that any such activity complies with applicable law and applicable PDMP terms, and for all access to and use of PDMP information by you and your Authorized Users. We may limit, suspend, or terminate access to PDMP functionality if we cannot verify required information, if applicable requirements are not met, or if we determine that continued access may create a legal, regulatory, security, patient safety, or fraud risk.
8.1 Disclaimer of Warranties. THE SERVICES AND ALL INFORMATION AND CONTENT MADE AVAILABLE THROUGH THEM ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTY OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, VERADIGM AND ITS LICENSORS AND SUPPLIERS DISCLAIM ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AND COMPLETENESS, AND ANY WARRANTY THAT THE SERVICES WILL BE UNINTERRUPTED, SECURE, TIMELY, ERROR-FREE, OR FREE OF HARMFUL CODE. YOU ARE SOLELY RESPONSIBLE FOR ANY ACTS OR OMISSIONS TAKEN IN RELIANCE ON THE SERVICES OR ANY INFORMATION MADE AVAILABLE THROUGH THEM. We are not responsible for any delay, failure, interruption, loss, corruption, or unauthorized access to the extent caused by your systems or access environment, by your or your Authorized Users’ acts, omissions, or misuse of login credentials, by another user’s conduct, or by networks, systems, software, or services not provided or controlled by us.
8.2 Indemnification. You will defend, indemnify, and hold harmless Veradigm, its affiliates, licensors, suppliers, and their respective officers, directors, employees, and agents from and against any third-party claims, demands, actions, damages, losses, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising out of or relating to: (a) any breach of this Agreement by Customer or its Authorized Users; (b) any unauthorized access to or use of the Services through your account; (c) your or your Authorized Users’ violation of applicable law; or (d) any medical decision, prescription, treatment decision, or other healthcare service provided by Customer or its Authorized Users.
8.3 Exclusion of Damages; Limitation of Liability. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL VERADIGM, ITS LICENSORS, SUPPLIERS, OR THEIR RESPECTIVE AFFILIATES, OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, OR CONTRACTORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, GOODWILL, DATA, BUSINESS OPPORTUNITY, OR BUSINESS INTERRUPTION, ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE SERVICES, WHETHER BASED ON CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, OR ANY OTHER LEGAL THEORY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES OR EVEN IF SUCH DAMAGES WERE REASONABLY FORESEEABLE. VERADIGM’S AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE SERVICES, REGARDLESS OF THE THEORY OF LIABILITY, WILL NOT EXCEED THE FEES PAID BY YOU FOR THE SERVICES DURING THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
9.1 Term. This Agreement and your right to use the Services begin when you click “I Agree,” establish an account, or first access or use the Services, whichever occurs first, and continue until terminated. Paid subscriptions are month to month and renew automatically for successive Billing Periods as described in the Subscription Services Addendum.
9.2 Termination. You may terminate this Agreement by cancelling your subscription through your account. Cancellation takes effect at the end of the then-current Billing Period, and fees already paid or due are non-refundable, as described in the Subscription Services Addendum. We may terminate this Agreement at any time on thirty (30) days’ prior notice. Termination of this Agreement automatically terminates all addenda unless the applicable addendum expressly provides otherwise.
9.3 Immediate Termination. We may terminate this Agreement or any Authorized User’s access immediately on notice if you or an Authorized User: (a) materially breaches this Agreement; (b) is subject to any ground for suspension under Section 2.8, including fraud, drug diversion, unsafe or unlawful prescribing, or a security, legal, regulatory, patient-safety, or verification failure; (c) is charged with or convicted of a crime relating to the Services or prescribing, is excluded from a federal or state healthcare program, or is found by a court or regulator to have violated a health-information privacy or security law; or (d) loses, or we cannot verify, any license, registration, credential, qualification, or authority required to use the Services or to prescribe. Termination under this Section is without liability to us and entitles you to no refund.
9.4 Effect of Termination; Your Information. On termination, all rights granted under this Agreement immediately terminate, Customer and its Authorized Users must cease all use of the Services, and you remain responsible for amounts accrued before termination. We may, in our discretion and as a courtesy, provide read-only access (“Limited Access”) allowing Customer to view, download, print, and export previously entered records for a period after termination. Limited Access is provided “as is,” may be changed or discontinued at any time, and we may archive or disable Limited Access accounts not accessed for twelve (12) consecutive months. You are responsible for exporting Your Information before termination or during any Limited Access period. Except for Limited Access and our obligations under the BAA and applicable law, we have no obligation to retain, return, or make Your Information available after termination, we may delete it or render it inaccessible, and we are not responsible for Your Information that becomes unavailable, is deleted, or is lost after termination.
9.5 Survival. Any provision that by its nature should survive termination will survive, including provisions on confidentiality, ownership, disclaimers, limitations of liability, indemnification, dispute resolution, and payment obligations.
10.1 Arbitration Agreement. EXCEPT AS PROVIDED IN SECTION 10.2, ANY DISPUTE, CLAIM, OR CONTROVERSY ARISING OUT OF OR RELATING TO THIS AGREEMENT, THE SERVICES, OR THE BREACH, TERMINATION, ENFORCEMENT, INTERPRETATION, OR VALIDITY OF THIS AGREEMENT, INCLUDING THE DETERMINATION OF THE SCOPE OR APPLICABILITY OF THIS AGREEMENT TO ARBITRATE, WILL BE RESOLVED BY FINAL AND BINDING ARBITRATION GOVERNED BY THE FEDERAL ARBITRATION ACT (9 U.S.C. §§ 1 ET SEQ.), ADMINISTERED BY THE AMERICAN ARBITRATION ASSOCIATION (“AAA”) UNDER ITS COMMERCIAL ARBITRATION RULES THEN IN EFFECT, BEFORE A SINGLE ARBITRATOR. JUDGMENT ON THE AWARD MAY BE ENTERED IN ANY COURT HAVING JURISDICTION.
10.2 Exceptions. Section 10.1 does not apply to claims seeking to enforce a Party’s rights relating to Confidential Information or intellectual property, including claims for misappropriation, infringement, or unauthorized use or disclosure.
10.3 Class Action and Jury Trial Waiver. EACH PARTY MAY BRING CLAIMS AGAINST THE OTHER ONLY IN AN INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF, CLASS MEMBER, OR REPRESENTATIVE IN ANY PURPORTED CLASS, COLLECTIVE, REPRESENTATIVE, OR PRIVATE ATTORNEY GENERAL PROCEEDING. YOU AND VERADIGM EACH WAIVE THE RIGHT TO A JURY TRIAL AND TO PARTICIPATE IN ANY CLASS, COLLECTIVE, REPRESENTATIVE, OR PRIVATE ATTORNEY GENERAL PROCEEDING. THE ARBITRATOR MAY NOT CONSOLIDATE CLAIMS OR PRESIDE OVER ANY SUCH PROCEEDING, AND MAY AWARD DECLARATORY OR INJUNCTIVE RELIEF ONLY IN FAVOR OF THE INDIVIDUAL PARTY SEEKING RELIEF AND ONLY TO THE EXTENT NECESSARY TO PROVIDE RELIEF WARRANTED BY THAT PARTY’S INDIVIDUAL CLAIM.
10.4 Severability. If any provision of this Section 10 is invalid, illegal, or unenforceable, the remaining provisions remain in full force and effect to the maximum extent permitted by applicable law.
11.1 Governing Law. This Agreement and any dispute arising out of or relating to it or the Services are governed by the laws of the State of Illinois, without regard to its conflict of laws principles, except that the Federal Arbitration Act (9 U.S.C. §§ 1 et seq.) governs the interpretation and enforcement of Section 10.1.
11.2 Changes to this Agreement. We may update the Services or this Agreement from time to time. Your continued use of the Services after an update becomes effective constitutes acceptance of the revised Agreement. For material changes, we may provide notice through the Services, by email, or on our website.
11.3 Notices. We may provide notices through the Services, by email, or by other reasonable means using the contact information associated with your account, and you are responsible for keeping that information current and accurate. Notices to Veradigm must be sent via first-class mail to: Veradigm LLC, Attn: Legal Department, 305 Church at North Hills Street, Raleigh, NC 27609, with an email copy to legal.notices@veradigm.com.
11.4 Assignment. You may not assign or transfer this Agreement, in whole or in part, without our prior written consent, except in connection with a merger, acquisition, sale of substantially all assets, or other reorganization involving Customer; we may require reasonable documentation to verify any such transaction and the authority of the parties involved. We may assign this Agreement without restriction. This Agreement binds and benefits the Parties and their permitted successors and assigns.
11.5 Independent Contractors; No Third-Party Beneficiaries. We and you are independent contractors, and nothing in this Agreement creates a partnership, joint venture, agency, or employment relationship. This Agreement is only between you and Veradigm and gives no rights or remedies to any other person or entity.
11.6 Force Majeure. Neither Party will be liable for any delay or failure to perform its obligations under this Agreement (other than Customer’s payment obligations) due to causes beyond its reasonable control, including natural disasters, war, terrorism, governmental actions, power or telecommunications outages, cyberattacks, or failures of third-party systems or services.
11.7 Privacy Policy. Your use of the Services is subject to our Privacy Policy, which you acknowledge you have reviewed.
11.8 Entire Agreement; Severability; Waiver; Electronic Acceptance. This Agreement, together with the BAA and the Subscription Services Addendum, is the entire agreement between you and Veradigm regarding the Services and supersedes all prior discussions, understandings, and agreements on that subject matter. If any provision is unenforceable, the remaining provisions remain in effect. A Party’s failure to enforce any provision is not a waiver of its rights. Notices, consents, approvals, and other actions relating to the Services may be provided and accepted electronically.
Business Associate Addendum
This Business Associate Addendum (“BAA”) forms part of and is incorporated into the ePrescribe Subscription Services Agreement (the “Agreement”) between Veradigm LLC (“Veradigm”) and Customer. It governs Veradigm’s (and its agents’ and subcontractors’) Use and Disclosure of Protected Health Information (“PHI”) and implementation of safeguards for the security of Electronic PHI (“EPHI”) disclosed by Customer to Veradigm under the Agreement, and is intended to enable each Party to establish its compliance with HIPAA. Capitalized terms not defined in this BAA or the Agreement have the meanings given under HIPAA.
1.1 General. Veradigm will not Use or Disclose PHI except as permitted or required by this BAA, the Agreement, or applicable law, and, except as otherwise permitted under this BAA, may not Use or Disclose PHI in a manner that would violate HIPAA if done by Customer.
1.2 Performance of Services. Veradigm may Use or Disclose PHI to provide the ePrescribe Services or to perform its obligations under this BAA.
1.3 Performance of Customer’s Obligations. To the extent Veradigm is required by the Agreement to carry out a Customer obligation under HIPAA, Veradigm will comply with the HIPAA requirements that apply to Customer in performing that obligation.
1.4 Minimum Necessary. Veradigm will Use, Disclose, or request only the minimum necessary PHI to accomplish the intended purpose.
1.5 Management and Administration. Veradigm may Use or Disclose PHI for its proper management and administration or to carry out its legal responsibilities, in compliance with 45 C.F.R. § 164.504(e)(4)(ii).
1.6 Other Permitted Uses. Veradigm may: (a) perform data aggregation for Customer’s health care operations; (b) Use and Disclose PHI as permitted by 45 C.F.R. § 164.512; and (c) de-identify PHI in accordance with 45 C.F.R. § 164.514(b) and Use or Disclose (and permit others to Use or Disclose) de-identified information on a perpetual, unrestricted basis.
2.1 Safeguards. Veradigm will use appropriate safeguards to prevent Use or Disclosure of PHI other than as provided by this BAA, including appropriate Administrative, Physical, and Technical safeguards to protect the confidentiality, integrity, and availability of EPHI in compliance with the Security Rule.
2.2 Reporting. Veradigm will report to Customer without unreasonable delay any improper or unauthorized Use or Disclosure of PHI, or any Security Incident, that compromises Customer’s PHI or EPHI and of which Veradigm becomes aware. Veradigm hereby notifies Customer of the ongoing occurrence of Unsuccessful Security Incidents, for which no additional report or notice is required. “Unsuccessful Security Incidents” include pings and other broadcast attacks on Veradigm’s firewall, port scans, unsuccessful log-on attempts, denials of service, and any combination of these, so long as none results in unauthorized Use or Disclosure of Customer’s EPHI.
2.3 Mitigation. Veradigm will mitigate, to the extent practicable, any harmful effect known to Veradigm of a Use or Disclosure of PHI by Veradigm in violation of this BAA.
2.4 Agents and Subcontractors. Veradigm will ensure that any agent or subcontractor that accesses, creates, receives, maintains, or transmits PHI on Veradigm’s behalf agrees in writing to the same restrictions and conditions that apply to Veradigm with respect to that PHI.
2.5 Access and Amendment. If Veradigm is required by the Agreement to maintain Customer’s Designated Record Set (“DRS”), then on reasonable advance written request from Customer, Veradigm will provide Customer access to PHI and EPHI in a DRS and incorporate any amendments Customer agrees to, in accordance with 45 C.F.R. §§ 164.524 and 164.526, respectively.
2.6 Audit and Inspection. Veradigm will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary, in a time and manner reasonably designated by the Secretary during Veradigm’s normal business hours, for purposes of the Secretary determining Customer’s compliance with HIPAA.
2.7 Accounting of Disclosures. Veradigm will document Disclosures of PHI and related information as would be required for Customer to respond to an Individual’s request for an accounting of disclosures under 45 C.F.R. § 164.528, and will provide that information to Customer within 15 days of a reasonable written request in connection with an accounting request from an Individual.
2.8 Breach Notification. Except as provided in 45 C.F.R. § 164.412, Veradigm will notify Customer of any Breach of Unsecured PHI without unreasonable delay and no later than 15 business days after discovery of the Breach. The notice will include, to the extent possible, known, or available, the information required by 45 C.F.R. § 164.410.
3.1 Customer Obligations. Customer will not request Veradigm to Use or Disclose PHI in any manner that would not be permissible under HIPAA. Customer represents and warrants that it has obtained all consents, authorizations, and other permissions necessary under HIPAA for Veradigm to provide the ePrescribe Services, and will take reasonable and appropriate steps to comply with its obligations as a Covered Entity, including maintaining appropriate administrative, physical, and technical safeguards.
3.2 Notices Affecting Use or Disclosure. Customer will notify Veradigm of any limitation in Customer’s notice of privacy practices, any change in or revocation of an Individual’s permission, and any restriction on the Use or Disclosure of PHI to which Customer has agreed, in each case to the extent it may affect Veradigm’s Use or Disclosure of PHI.
On termination of the Agreement, Veradigm will return or destroy all PHI received from, or created or received on behalf of, Customer, or otherwise in Veradigm’s (or its subcontractors’ or agents’) possession, if feasible. If Veradigm determines that return or destruction is infeasible, Veradigm will extend the protections of this BAA to that PHI and limit further Uses and Disclosures to those purposes that make return or destruction infeasible.
Except as expressly modified by this BAA, the Agreement remains in full force and effect, and its provisions on dispute resolution, limitation of liability, indemnification, notices, assignment, and other general terms apply to this BAA unless expressly stated otherwise. If this BAA and the Agreement conflict with respect to PHI or the Parties’ obligations under HIPAA, this BAA controls. Terms used but not defined in this BAA have the meaning given in HIPAA or, if not defined under HIPAA, in the Agreement, and references to HIPAA provisions include any successor provisions and amendments for which compliance is required. The Parties will negotiate in good faith to amend this BAA as reasonably necessary to comply with changes in applicable law, and any ambiguity will be resolved in favor of a meaning that permits the Parties to comply with HIPAA.