RESSA HEALTH
Professional Master Services Agreement
Including Business Associate Agreement and Global Data Processing Addendum
Effective Date: 09/04/2026 | Version 1.3 (Global)
PLEASE READ THIS AGREEMENT CAREFULLY. SECTION 23 CONTAINS A BINDING ARBITRATION CLAUSE, A CLASS ACTION WAIVER, AND A JURY TRIAL WAIVER THAT AFFECT YOUR LEGAL RIGHTS.
SECTION 7 EXPLAINS THAT RESSA DOES NOT VERIFY YOUR PROFESSIONAL LICENSE OR CREDENTIALS, THAT YOU ALONE ARE RESPONSIBLE FOR THE CARE YOU PROVIDE, AND THAT RESSA DOES NOT PRACTICE MEDICINE OR ANY OTHER LICENSED PROFESSION.
SECTION 6 EXPLAINS THAT THE INDIVIDUAL, NOT YOU AND NOT RESSA, CONTROLS WHETHER YOU HAVE ACCESS TO INFORMATION IN THE SERVICE; THAT THE INDIVIDUAL MAY REMOVE YOUR ACCESS AT ANY TIME AND WITHOUT YOUR AGREEMENT; AND THAT YOU WILL HAVE THIRTY (30) DAYS AFTER REMOVAL TO DOWNLOAD WHAT YOU NEED FOR YOUR OWN RECORDS.
SECTION 10 EXPLAINS THAT THE SERVICE USES ARTIFICIAL INTELLIGENCE, THAT ITS OUTPUT IS NOT REVIEWED BY A CLINICIAN BEFORE YOU SEE IT, AND THAT YOU MUST INDEPENDENTLY VERIFY IT BEFORE RELYING ON IT FOR ANY CLINICAL PURPOSE.
SECTION 13 EXPLAINS THAT RESSA MAY DE-IDENTIFY OR ANONYMIZE INFORMATION ONLY AS PERMITTED BY APPLICABLE LAW AND MAY USE, DISCLOSE, AND LICENSE INFORMATION THAT IS NO LONGER PERSONAL DATA OR PROTECTED HEALTH INFORMATION, INCLUDING FOR A FEE.
1. About Ressa and This Agreement
1.1 This Agreement. This Professional Master Services Agreement, together with the exhibits attached to it, any Order Form executed by the parties, and the Ressa Health Privacy Policy (together, this “Agreement”), is a legal agreement between you and Metabolic Terrain Omics, Inc., a Delaware corporation doing business as Ressa Health (“Ressa,” “we,” “us,” or “our”), governing your access to and use of the Professional-facing features of the Ressa Health website, applications, and related services (together, the “Service”). By creating a Professional Account, by clicking to accept this Agreement, by executing an Order Form that references it, or by accessing or using the Service in a Professional capacity, you agree to this Agreement. If you do not agree, do not access or use the Service.
1.2 Who “You” Is. “You,” “your,” and “Professional” mean the individual practitioner, professional entity, practice, clinic, wellness provider, health coach or other organization that holds or is billed for the Professional Account. If you accept this Agreement on behalf of an entity, you represent that you are authorized to bind that entity, and “you” means that entity and each of its Authorized Users. An individual practitioner who holds a Professional Account in their own name is both the Professional and an Authorized User.
1.3 Replacement of Prior Terms. If you held a practitioner account on RootedIQ or another Ressa predecessor platform before the Effective Date, this Agreement replaces and supersedes the terms of service, business associate agreement, and any other agreement you previously accepted for that platform with respect to your Professional use of the Service as of the Effective Date, except that any obligation that by its nature was intended to survive termination of the prior agreement continues in effect. We will give you notice of this Agreement before it takes effect for your existing account, and you may export information under Section 18.5 or close your Professional Account under Section 18.2 if you do not agree.
1.4 Order Forms. Some Professionals, particularly practices and organizations, will enter into a written or electronic ordering document that identifies the Professional, the plan, the number of Authorized Users, the fees, and the term (an “Order Form”). An Order Form is governed by and incorporates this Agreement. If no Order Form exists, your plan selection at sign-up and the then-current published pricing serve the same function and are treated as your Order Form.
1.5 Order of Precedence. In the event of a conflict among the documents that make up this Agreement, the following order controls: (a) any mandatory international-transfer terms incorporated under Exhibit B, but only to the extent they must control under applicable law; (b) Exhibit A (Business Associate Agreement), but only as to PHI and HIPAA obligations; (c) Exhibit B (Global Data Processing Addendum), but only as to Personal Data or Professional Health Data and Applicable Data Protection Law; (d) a mutually executed Order Form; and (e) the body of this Agreement. Exhibit A and Exhibit B may apply at the same time. Where two documents impose different lawful protections on the same Health Information and both can be performed, the provision that gives greater protection to the information controls.
1.6 What Ressa Is. Ressa is a health data platform. The Service lets an individual assemble their own health information, including laboratory results, symptom assessments, health history, genetic results obtained elsewhere, and information from devices and applications they connect, into a private personal health record called a Health Vault, and lets that individual give a Professional of their choosing access to it. On the Professional side, the Service lets you view the Health Vaults of Individuals who have approved you, upload records and results for those Individuals, use assessment and intake tools, and view Insights the Service generates.
1.7 What Ressa Is Not. Ressa is not a physician, clinic, hospital, laboratory, pharmacy, health plan, health care clearinghouse, or any other kind of health care Professional. Ressa does not practice medicine, nursing, nutrition, chiropractic, or any other licensed profession, and it does not practice any unlicensed healing art. Ressa does not provide medical advice, diagnosis, treatment, second opinions, or clinical recommendations, to you or to any Individual. Ressa does not supervise, direct, control, or review the care you provide. Ressa is not your employer, partner, joint venturer, agent, or principal, and nothing in this Agreement creates any of those relationships. Ressa does not bill, and does not assist you in billing, any insurer, health plan, Medicare, Medicaid, national or public health service, governmental reimbursement program, or other third-party payor. Your use of the Service does not create a physician-patient, clinician-patient, or other professional treatment relationship between Ressa and any Individual.
1.8 Not for Emergencies or Monitoring. The Service is not an emergency service, a monitoring service, a critical-value notification service, or an urgent-care service. It does not review Health Information in real time, does not detect dangerous results, does not triage results, and does not alert you, any Individual, or emergency personnel. No clinician at Ressa reviews any Individual’s information. You must not rely on the Service to bring an urgent finding to your attention, and you must not tell any Individual that it will.
2. Definitions
Capitalized terms used in this Agreement have the meanings given where they first appear and the meanings given below. Terms defined in HIPAA and used in Exhibit A have the meanings given in HIPAA. Terms defined in an Applicable Data Protection Law and used in Exhibit B have the meanings given in that law unless Exhibit B states otherwise.
“Authorized User” means an individual you permit to access the Service under your Professional Account, including you if you are an individual Professional, and including your employees, contractors,associates, and administrative staff.
“Connected Individual” means an Individual who has approved you, or an organization or practice account of which you are a part, for access to their Health Vault under Section 6, for so long as that approval remains in effect and for the Post-Removal Window that follows it.
“Health Information” means health, medical, clinical, genetic, biometric, and wellness information about an Individual that is created, received, maintained, or transmitted in the Service, however it arrives, including information an Individual enters or uploads, information you or another Professional uploads, information received from a Laboratory Partner or a connected device or application, and Insights generated from any of it.
“Health Vault” means the personal health record the Service maintains for an Individual.
“HIPAA” means the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations at 45 C.F.R. Parts 160, 162, and 164, each as amended.
“Applicable Data Protection Law” means any privacy, data protection, consumer health data, medical-records, health-information, genetic-information, breach-notification, cybersecurity, or similar law that applies to a party or to the Processing of Health Information under this Agreement, including, where applicable, HIPAA; United States federal and state privacy and consumer health laws; the EU General Data Protection Regulation (“EU GDPR”); the United Kingdom GDPR and Data Protection Act 2018, as amended (“UK GDPR”); Canada’s federal and provincial privacy and health-information laws, including PIPEDA where applicable; Québec privacy and health-information laws; and successor or replacement laws.
“Individual” means a natural person who holds a consumer account on the Service and has accepted the Ressa Health Individual Terms of Service.
“Individual Terms” means the Ressa Health Terms of Service, Individual / Consumer, as amended from time to time, which governs the relationship between Ressa and each Individual.
“Insights” means the output the Service generates by applying algorithmic and artificial-intelligence tools to Health Information, including organization of information, identification of patterns and trends, comparison of values over time, range flagging, summaries, and educational material presented alongside data.
“Laboratory Partner” means an independent third-party laboratory or ordering entity integrated with the Service.
“Post-Removal Window” has the meaning given in Section 6.6.
“Protected Health Information” or “PHI” has the meaning given in 45 C.F.R. § 160.103, limited to information Ressa creates, receives, maintains, or transmits on your behalf.
“Professional Account” means the account through which you and your Authorized Users access the Professional-facing features of the Service.
“Professional Content” means notes, care plans, protocols, templates, assessments, configurations, and other material you or an Authorized User creates in or submits to the Service, other than Health Information about an Individual.
“Professional Health Data” means Health Information about a Connected Individual that Ressa creates, receives, maintains, transmits, or otherwise Processes on your behalf. Professional Health Data may also be PHI. Exhibit A governs it to the extent HIPAA applies, and Exhibit B governs it to the extent any other Applicable Data Protection Law applies; both Exhibits may apply to the same information.
“Professional-Submitted Information” means Health Information that you or an Authorized User uploads, enters, or transmits into the Service about an Individual.
3. Eligibility, Professional Status, and Organization Accounts
3.1 Global Availability. Subject to applicable law, sanctions and export-control restrictions, technical availability, and any country or territory restrictions Ressa publishes or communicates, the Service may be made available to Professionals located and practicing in jurisdictions worldwide and to Individuals located in jurisdictions worldwide. You may use the Service only where your use, your professional activities, and your cross-border provision of services are lawful. You are responsible for determining and complying with all licensing, registration, scope-of-practice, telehealth, laboratory-ordering, professional-recordkeeping, health-data, privacy, cybersecurity, artificial-intelligence, medical-device, and other requirements that apply in each jurisdiction in which you or an Individual is located. You must accurately identify your location and jurisdictions of practice and may not use a virtual private network, proxy, or other tool to disguise them. Ressa may restrict, suspend, or discontinue availability in any jurisdiction where Ressa reasonably determines that legal, regulatory, sanctions, security, or operational requirements make offering the Service impracticable. Health Information is hosted in the United States as stated in Section 12.1(b), and any resulting international transfer is governed by Exhibit B.
3.2 Authority and Capacity. You represent that you have the legal capacity and authority to enter into this Agreement, that your use of the Service does not violate any law or any obligation you owe to a third party, including any employer, health system, group practice, or payor, and that you have obtained any internal approval your organization requires.
3.3 Your HIPAA Status: Representation. If HIPAA applies to you or to the information you place in or access through the Service, you represent and warrant, as of the Effective Date and on an ongoing basis, that you have accurately identified your status under HIPAA in your Professional Account as one of the following:
1) a Covered Entity as defined in 45 C.F.R. § 160.103;
2) a Business Associate of a Covered Entity, with respect to the information you will place in or access through the Service; or
3) neither a Covered Entity nor a Business Associate.
You agree to notify Ressa at support@ressahealth.com within ten (10) business days if your HIPAA status changes. Ressa is entitled to rely on your representation. You are solely responsible for determining your own HIPAA status, and Ressa’s provision of Exhibit A is not, and may not be represented by you as, a determination or endorsement that you are a Covered Entity or Business Associate. A Professional outside the United States ordinarily should select “neither” unless HIPAA independently applies to that Professional or to the relevant activity.
3.4 Which Data Protection Terms Apply to You. Exhibit A applies whenever Ressa is a Business Associate or subcontractor under HIPAA with respect to PHI. Exhibit B applies whenever Ressa Processes Professional Health Data on your behalf and an Applicable Data Protection Law other than HIPAA governs that Processing, including where you act as a controller, business, organization, health information custodian, trustee, responsible person, or processor/service Professional under that law. Exhibit A and Exhibit B are not mutually exclusive and may apply concurrently. If there is uncertainty, Ressa may apply either or both Exhibits contractually to ensure that Health Information is not left without protection, without either party conceding a regulatory status that does not otherwise apply.
3.5 Your Data-Protection Status and Responsibilities. You are responsible for determining the Applicable Data Protection Laws that govern your activities and whether you act as a controller, processor, health information custodian, trustee, responsible organization, or equivalent regulated entity. You must provide any information Ressa reasonably requests to identify the appropriate contractual terms and transfer mechanism. Where Ressa Processes Professional Health Data solely on your behalf, Ressa acts as your processor, service Professional, or equivalent role to the extent recognized by Applicable Data Protection Law. Ressa remains an independent controller or equivalent regulated entity for Professional Account, billing, security, fraud-prevention, and other information it Processes for its own lawful business purposes.
3.6 Organization and Practice Accounts. A practice, clinic, professional entity, or other organization may hold a Professional Account covering multiple Authorized Users. If you hold such an account:
1) you designate one or more administrators, who may add, remove, and set the permissions of Authorized Users, view all information visible under the Professional Account, export data, change the plan, and act on your behalf under this Agreement;
2) you are responsible for each Authorized User’s compliance with this Agreement, and each Authorized User’s act or omission in the Service is treated as yours;
3) you must promptly remove an Authorized User who leaves your organization or whose license, certification, or scope of practice changes in a way that affects their use of the Service; and
4) where an Individual approves your organization rather than a named Professional, every Authorized User whose role includes clinical access may be able to see that Individual’s information, and you are responsible for limiting access within your organization to those with a legitimate need.
3.7 No Account Sharing. Authorized User credentials are personal to the Authorized User. You may not share, sell, transfer, or permit the use of a set of credentials by more than one person. Ressa prices the Service by Authorized User seat and may audit and true-up seats under Section 17.5.
4. The Service
4.1 What the Professional-Facing Service Includes. The features below are the features the Professional side of the Service is designed to offer. Not every feature is available on every plan, to every Professional, or at every time. What you can see and do is determined by your plan tier and by your role, as described in Section 6.3 and the then-current Ressa pricing page and features list.
1) Access to Connected **Individuals’ information.** You may view the Health Information of Individuals who have approved you, to the extent your plan tier permits.
2) Upload. You may upload laboratory results, medical records, imaging reports, notes, and other Health Information about an Individual into the Service.
3) Assessments and intake. You may administer structured symptom assessments, intake questionnaires, and health-history tools.
4) Insights and pattern **analysis.** You may view Insights generated from a Connected Individual’s Health Information, subject to Section 10.
5) Laboratory ordering and **results.** Where the Service offers it, you may request testing from a Laboratory Partner and receive results into the Service, subject to Section 8.
6) Scheduling and telehealth **integrations.** The Service may integrate with calendar and videoconferencing services, subject to Section 17.
7) Export. You may export information you are entitled to see in a human-readable format.
4.2 What the Service Is Not. The Service is not, and you may not use or represent it as, an electronic health record or certified health IT for any regulatory purpose, a practice management system, a billing or claims system, a clinical decision support system intended to direct or substitute for professional judgment, a laboratory information system, or a system of record for any professional recordkeeping obligation you owe. Ressa does not market or provide the Service as a regulated medical device or regulated clinical decision-support product in any jurisdiction. You may not use the Service in a manner that would require Ressa to obtain a regulatory authorization, clearance, certification, conformity assessment, or approval that Ressa has not obtained. You are responsible for maintaining your own patient or client records in a system that satisfies the professional recordkeeping, retention, localization, and availability obligations that apply to you. Do not rely on the Service as your only copy of anything you are required to keep.
4.3 Changes to the Service. We may modify, suspend, or discontinue any part of the Service at any time. Where a change materially and adversely reduces the core functionality of the plan you are paying for, we will give you at least thirty (30) days’ notice, and if the change takes effect during a term you have prepaid, you may terminate under Section 18.2 and receive a pro-rata refund of fees prepaid for the remainder of that term. We will not remove your ability to export information you are entitled to see without notice.
4.4 Availability. Ressa does not guarantee uninterrupted, timely, secure, or error-free access to the Service and does not commit to any service level, uptime percentage, or support response time except as expressly stated in a mutually executed Order Form. Scheduled maintenance, third-party outages, and force majeure events may interrupt access.
4.5 Beta and Pre-Release Features. We may offer features identified as beta, preview, pilot, early access, or similar. Those features are provided as-is, may be changed or withdrawn at any time, may not be covered by any commitment in this Agreement other than our obligations with respect to Health Information under Section 12 and Exhibit A or B, and should not be used for any purpose where an error would matter clinically.
5. Professional Accounts, Authorized Users, and Security
5.1 Registration. You agree to provide accurate, current, and complete information when you register, including your legal name, the legal name of your practice or entity, your professional designation, each country, state, province, territory, or other jurisdiction in which you practice or provide services, your license or certification numbers where you hold them, and your HIPAA and other regulatory status requested by Ressa, and to keep that information current. Health Information is only as useful as it is accurate, and information entered incorrectly may produce misleading Insights.
5.2 Credentials and Multi-Factor Authentication. You and each Authorized User are responsible for keeping login credentials confidential and for all activity under those credentials. The Service requires a second authentication factor. You agree not to share credentials or authentication codes with anyone, including with an Individual, with a colleague, or with Ressa support. Ressa will never ask you for your password.
5.3 Notify Us Promptly. You must notify Ressa at support@ressahealth.com without unreasonable delay, and in any event within twenty-four (24) hours, after you learn or reasonably suspect that any credential to the Professional Account has been lost, stolen, or used without authorization, or that any person has obtained access to Health Information through your Professional Account without authorization. You must cooperate with Ressa’s investigation.
5.4 Devices and Endpoints. You are responsible for the security of the devices, networks, and endpoints your Authorized Users use to access the Service, for maintaining current operating systems and security patches, for screen-lock and encryption on any device on which Health Information is viewed or stored, and for the secure handling and disposal of anything you print, download, screenshot, or export from the Service.
5.5 Support Access. Ressa support cannot open or view an Individual’s Health Information without that Individual’s authorization. Support may view limited Professional Account information, such as an Authorized User’s email address, plan, and login status, for troubleshooting. If resolving a support request requires access to Health Information, we will tell you what access is needed and obtain the necessary authorization first.
5.6 Ressa Workforce Access. Ressa personnel and contractors may access Health Information only where necessary to operate, secure, or support the Service. That access is role-based, limited to job need, logged, and subject to written confidentiality obligations. Section 12 states our commitments in full.
6. Individuals, Connections, and Access to Health Information
6.1 The Individual Controls the Connection. Every Individual holds their own account under the Individual Terms and controls whether you have access to their Health Vault. While you may invite Individuals to access Ressa, you may not create an Individual’s account for them, you do not approve your own access to a Connected Individual, and Ressa does not grant you access to any Individual’s information without that Individual’s approval.
6.2 Two Kinds of Information. Health Information reaches the Service in two ways:
1) Individual-Controlled Information. Information an Individual enters or uploads themselves or that arrives from a Laboratory Partner or a connected device or application at the Individual’s direction, is owned by the Individual and held by Ressa under the Individual Terms. You have no right to access, view, retain, copy, or own such information, except through an approval under this Section, and your limited rights to that information end when the Individual disconnects you as a Professional.
2) Professional-Submitted Information. Information you or an Authorized User uploads, enters, or transmits into the Service about an Individual is created, received, maintained, and transmitted by Ressa on your behalf. From the moment you submit it, it is PHI (or, if Exhibit B applies to you, Professional Health Data), Ressa handles it under Exhibit A or Exhibit B, and it also becomes visible to the Individual in their Health Vault.
3) When Individual-Controlled Information becomes PHI. When you access or request Individual-Controlled Information in your capacity as a health care Professional, Ressa handles that information on your behalf for purposes of that access, and Exhibit A or Exhibit B applies to it for so long as you retain access to it. The same record can therefore be the Individual’s information as to the Individual and PHI as to you, and Ressa maintains both sets of obligations simultaneously.
4) The Individual sees what you submit. You acknowledge and agree that any Professional-Submitted Information you place in the Service is visible to the Individual it concerns, immediately and without redaction, and that the Service has no mechanism to withhold a record from the Individual. Do not place in the Service any note, impression, or record that you are not prepared for the Individual to read. Psychotherapy notes as defined in 45 C.F.R. § 164.501 must not be placed in the Service at all.
6.3 What Approval Gives You. When an Individual approves you, you gain access to all of that Individual’s Health Information, created at any point in time, as determined by your plan tier.
6.4 Professional Acknowledgments. You acknowledge and agree that:
1) You will see **information that predates the connection.** An Individual who approves you exposes information already in their Health Vault, not only information created afterward. You may encounter information you did not ask for, do not need, and would not have requested, including information about substance use disorder treatment, HIV or other sexually transmitted infection status, mental health treatment, reproductive health, and genetic testing. Section 6.7 governs how you must treat it.
2) You may see **information other Professionals uploaded.** Where your tier permits access to the full record, you may see records uploaded by another Professional the Individual has approved.
3) Ressa cannot implement **a granular restriction.** If you are a Covered Entity, you must not agree to a restriction under 45 C.F.R. § 164.522(a) on the use or disclosure of PHI held in the Service unless you have first confirmed with Ressa in writing that the restriction can be implemented in the Service. Ressa will tell you promptly whether a requested restriction can be honored. You are responsible for any restriction you agree to that the Service cannot perform, and Section 22.1 applies.
4) An Individual may **decline to connect, or may disconnect, for any reason.** You may not condition the provision of care on an Individual’s approval of you in the Service, may not require an Individual to keep you connected, and may not represent to an Individual that removing you will affect the care they receive. Any attempt to condition care or the continuity of care to an Individual on their approval of a connection to you in the Service is a material breach of this Agreement.
6.5 The Individual May Disconnect You at Any Time. An Individual may remove you at any time through their account settings. Disconnection is the Individual’s right alone, does not require your agreement, and does not require notice to you beyond what the Service provides. On removal, you immediately lose access to information generated afterward.
6.6 The Post-Removal Window. For thirty (30) days after removal (the “Post-Removal Window”), you retain the ability to view and download the information you could previously see, allowing you to export and retain a copy in your own patient records as professional recordkeeping law requires. At the end of the Post-Removal Window your access to that Individual’s Health Information within the Service ends and cannot be restored except by a new approval from the Individual. <u>Do not wait. Ressa cannot extend the Post-Removal Window or restore access after it closes. Ressa will not proactively notify you before the Post-Removal Window closes, although the Service may do so.</u>
6.7 Sensitive Categories. The Service may hold information subject to protections greater than those ordinarily applicable to health information, including special-category or sensitive personal data, genetic and biometric data, substance-use information, HIV or other sexually transmitted infection status, mental-health information, reproductive and sexual-health information, and information subject to professional secrecy or medical-confidentiality duties. In the United States this may include, where applicable, 42 C.F.R. Part 2 and state health or genetic privacy laws; in other jurisdictions additional restrictions may apply. You are responsible for identifying such information when you encounter it and for complying with every restriction that applies to your collection, access, use, disclosure, transfer, retention, and re-disclosure of it, including any requirement for a separate consent, authorization, lawful basis, or special-category condition. You must not place Part 2 records in the Service unless you have first obtained Ressa’s written confirmation that the Service is configured to receive them and have executed any additional agreement Ressa requires.
6.8 Individual Rights Requests. An Individual may direct a request for access, correction, amendment, deletion, restriction, or an accounting of disclosures to Ressa or to you: Ressa will receive and act on withdrawals of permissions that govern its optional uses, including under the authorization administered in Section 6.10. Referral of a request to you does not permit Ressa to continue an optional use after its authority has ended.
1) For information Ressa holds for the Individual under the Individual Terms, Ressa responds directly and will direct the Individual to make the correction themselves through the Service.
2) For PHI or Professional Health Data Ressa holds or Processes on your behalf, Ressa will route the request to you unless Applicable Data Protection Law requires Ressa to respond directly, and Ressa will provide the assistance required by Exhibit A or Exhibit B.
3) For records you hold outside the Service, the request is entirely yours.
4) You agree to respond to any request routed to you within the time applicable law allows and to notify Ressa of your determination where the Service must act on it. The Service does not provide an Individual with a self-service log of who has viewed or received their information. Where an accounting of disclosures is required, you are the party responsible for providing it, and Ressa will supply the audit-log information you reasonably need.
6.9 No Deletion Through You. You may not delete an Individual’s Health Vault, close an Individual’s account, or remove Individual-Controlled Information from the Service. You may request correction of Professional-Submitted Information you submitted. Where you believe a record must be amended or removed to comply with law, contact <u>support@ressahealth.com</u>.
6.10 Consent and Authorization Administration. You authorize and direct Ressa, on your behalf, to present and administer the patient consents and authorizations used in the Service for the activities described in this Agreement, including the separate Practitioner Health Information Marketing Authorization and applicable state genetic-data forms. This delegation includes presenting the applicable text, receiving an electronic signature or other required completion record, recording the information and purposes covered, identifying the actual practices and any required named recipients, providing copies, retaining the applicable version and evidence of assent, and receiving and administering withdrawals. Ressa will administer those functions in accordance with applicable law, the relevant form and Exhibit A or Exhibit B. You approve the program described in this Section and authorize Ressa to use its standard forms for that program, with changes needed for applicable law that do not expand the authorized purposes.
Your approval of this Agreement and an Individual’s acceptance of the Individual Terms are not substitutes for any required patient consent or authorization. Optional dataset or marketing permissions are not a condition of treatment, payment, health-plan enrollment, eligibility for benefits, the Ressa subscription or the practice connection.
Ressa will make the completed authorization and relevant administration records available to you for the activities it administers on your behalf. Ressa will stop future uses and disclosures relying on a withdrawn or expired permission and promptly communicate a relevant withdrawal to you. You will promptly communicate a withdrawal or restriction received by you that affects Ressa’s processing. Ressa does not need your further approval to stop a use that the Individual has revoked. The Practitioner Health Information Marketing Authorization ends for your practice when the Individual disconnects you, regardless of the Post-Removal Window.
You remain responsible for your own notices, the lawful collection and submission of records, your clinical activities, and consents outside the administration expressly delegated here. Ressa is responsible for the delegated functions it performs. Neither party may direct or perform a use prohibited by law or outside the applicable permission. Where you act for an upstream entity, you represent that you have authority to give these directions and will identify any restriction that limits them.
7. Professional Responsibilities and Professional Independence
7.1 Professional Licensure. Professionals on the Service may include licensed clinicians, nutrition professionals, health coaches, and other wellness Professionals, and not every Professional holds a professional license. Ressa’s acceptance of your registration is not a representation to you, to any Individual, or to anyone else that you are licensed, credentialed, qualified, or fit to provide any service. You may not state or imply otherwise in any marketing, communication, or conversation with an Individual.
7.2 Your Representations Regarding Licensure and Scope. You represent and warrant, as of the Effective Date and on an ongoing basis, that:
1) you and each Authorized User hold every license, certification, registration, authorization, or professional membership required to provide the services you provide in every jurisdiction in which you or the applicable Individual is located, and each is current, unrestricted, and in good standing, or, if you or an Authorized User is not licensed, the services you provide do not require a license or regulated professional status in the applicable jurisdiction;
2) you will act at all times within your lawful scope of practice, and will not diagnose, treat, prescribe, order, interpret, counsel, or otherwise act beyond it;
3) neither you nor any Authorized User is excluded, debarred, suspended, disqualified, or otherwise prohibited from providing the relevant services or participating in an applicable governmental, public, or professional program, is subject to a pending exclusion or disciplinary proceeding that would make use of the Service unlawful, or has been convicted of an offense that would require such exclusion where applicable; and you will notify Ressa at tickets@ressahealth.com within five (5) business days if that changes;
4) you will tell each Individual, plainly, what you are and what you are not, including, where applicable, that you are not a licensed health care Professional, and will not use a title, credential, or description that you are not entitled to use; and
5) you have and will maintain a lawful basis to place each item of Professional-Submitted Information in the Service, including any authorization or consent required by law.
7.3 You Are Responsible for Patient Care. You alone are responsible for every clinical, professional, and wellness decision you make and for every service you provide. That responsibility is not shared with, transferred to, or reduced by Ressa, by any Insight, by any range flag, by any Laboratory Partner, or by anything else in the Service. You must exercise your own independent professional judgment on every occasion, must take into account the physical examination, history, medications, and circumstances that the Service does not know, and must not substitute anything the Service produces for that judgment.
7.4 No Fee-Splitting; No Remuneration for Referrals. The fees you pay Ressa are for access to the Service. They are a flat subscription, are not calculated on a per-patient, per-encounter, per-order, per-test, or per-result basis, and are not a share of, and do not vary with, any fee you charge an Individual or any revenue you receive. Ressa does not pay you, and you may not pay Ressa, anything of value in return for a referral, for the use of any Laboratory Partner or other third party, for recommending the Service to an Individual, or for ordering, arranging, or recommending any item or service. Neither party will structure any arrangement under this Agreement in a way intended to induce unlawful referrals, constitute unlawful fee-splitting or self-referral, or violate any anti-kickback, anti-bribery, professional-independence, or similar law. In the United States, this includes where applicable the federal Anti-Kickback Statute, physician self-referral law, Eliminating Kickbacks in Recovery Act, and applicable state law.
7.5 Professional Subscription; No Payor Billing by Ressa. The Service is offered to Professionals as a subscription service. Ressa does not submit claims, generate reimbursement claims or superbills, verify eligibility, coordinate benefits, or enroll as a health care Professional or payor under any public, national, governmental, or private health reimbursement program. You may not represent the Professional subscription fee as a covered or reimbursable clinical item or service unless applicable law and the applicable payor expressly permit it. Nothing in this Section restricts you from billing an Individual, insurer, public health system, or other payor for the professional services you yourself provide, in accordance with applicable law and your own arrangements.
7.6 Your Own Compliance Program. You are responsible for your own privacy, data-protection, cybersecurity, professional, clinical, and health-records compliance program under Applicable Data Protection Law and the laws governing your profession. This includes, where applicable, risk analyses or privacy impact assessments, policies and procedures, workforce training and sanctions, privacy notices, records-of-processing obligations, data-protection impact assessments, individual-rights procedures, record-retention requirements, breach response, and appointment or registration of any privacy officer, data protection officer, representative, or equivalent role. If HIPAA applies, your responsibilities include your risk analysis under 45 C.F.R. § 164.308(a)(1)(ii)(A), HIPAA policies and procedures, workforce training and sanctions, notice-of-privacy-practices duties, designated-record-set determinations, and HIPAA breach response. Ressa does not provide your compliance program or legal advice. You may not represent that use of the Service by itself makes you compliant with any law or professional rule. Ressa’s completion of any security questionnaire, provision of any assessment report, or statement about its own controls does not constitute legal or compliance advice to you. Ressa performs the consent and authorization administration expressly delegated under Section 6.10 and the obligations assigned to it under Exhibit A or Exhibit B; your remaining compliance responsibilities are yours.
7.7 Communications With Individuals. Any communication you send to an Individual through the Service must relate to the services you provide. You may not use the Service to send marketing or advertising to any Individual, to solicit an Individual on behalf of a third party, or to send any communication for which applicable privacy, direct-marketing, electronic-communications, telemarketing, or anti-spam law requires a consent, authorization, opt-in, or other condition unless you have satisfied it yourself. In the United States this may include HIPAA, the Telephone Consumer Protection Act, and CAN-SPAM; other jurisdictions may impose additional or stricter requirements. You are the sender of every such communication and are solely responsible for it.
7.8 What You May Not Tell an Individual. You may not represent, and must correct any impression, that: the Service monitors results or will alert anyone to an abnormal or urgent finding; the Service diagnoses, treats, or provides medical advice; Ressa has reviewed, verified, or endorsed you, any Insight, or any result; Ressa has verified any Professional’s license or credentials; an Individual can restrict what you see item by item; an Individual’s information is unavailable to you once they approve you; or the Service is a substitute for the Individual’s own records or for emergency care.
8. Laboratory Testing and Results
8.1 Ressa Is Not a Laboratory and Does Not Order Tests. Ressa is not a clinical laboratory, is not CLIA-certified, does not order laboratory tests, does not sign or authorize laboratory orders, does not employ or contract with ordering professionals, does not operate a professional medical entity, and does not perform, interpret, or verify any laboratory result. Where the Service lets you or an Individual request a test, the request is transmitted to a Laboratory Partner, which through its own licensed professionals decides whether to authorize the test, arranges specimen collection, performs or arranges the analysis, and returns the result.
8.2 Your Orders Are Yours. Where you place or request an order through the Service, you do so in your own professional capacity and on your own authority. You represent that you hold the requisite license, registration, authority, and scope of practice to order the test in every jurisdiction whose law applies, including the jurisdiction where the Individual and specimen are located, that the order is appropriate in your independent professional judgment, and that you have obtained every consent, authorization, requisition, or other approval the test requires.
8.3 Your Relationship With the Laboratory Partner. Ressa enables one or more Laboratory Partners to provide an integrated lab-ordering and results solution. Your relationship with each Laboratory Partner is your own, is governed by that partner’s own agreement with you, and is not created, guaranteed, or administered by Ressa. Ressa does not control any Laboratory Partner and is not responsible for its clinical decisions, licensure, turnaround times, accuracy, specimen handling, billing, or compliance with law. Ressa’s role is limited to transmitting requests, receiving results, and displaying them.
8.4 Range Flagging. The Service compares laboratory values against configured ranges and marks values that fall outside them. It uses the reference range supplied by the performing laboratory where one is available, and it also uses functional or optimal ranges that Ressa configures and maintains. Flagging is an automated numerical comparison. It is not generated by artificial intelligence, is not performed or reviewed by a clinician, and is not a diagnosis, a clinical finding, an interpretation, a critical-value determination, or medical advice. The absence of a flag does not mean a result is normal or that nothing requires your attention.
8.5 No Monitoring, No Critical-Value Notification. Ressa does not review results, does not identify results that are medically urgent, does not triage results, and will not contact you, the Individual, or emergency personnel about any result. You are responsible for reviewing the results of Individuals in your care and for initiating follow-up. Do not configure your practice on the assumption that the Service will surface an urgent value to you.
9. Genetic Information
9.1 Scope. This Section applies to information about an Individual’s genes, gene products, or inherited characteristics, including genotype and sequence data and information derived from the analysis of a biological sample for those purposes (“Genetic Information”), however it reaches the Service.
9.2 Ressa Is Not a Genetic Laboratory. Ressa does not perform genetic testing, does not order it, does not interpret it, and does not provide genetic counseling. Genetic Information reaches the Service because an Individual or a Professional uploads results obtained elsewhere, or because you, an Individual, or another Professional orders testing and such results are imported to the Service, by any means available within the Service.
9.3 Biological Samples. Ressa does not hold, control, direct, or retain any biological sample. Any sample is collected and held by the Laboratory Partner or third-party laboratory Professional, which alone controls its retention and destruction. A request to destroy a sample must be directed to that laboratory; Ressa can pass such a request along but cannot honor it and does not warrant that the laboratory will.
9.4 Your Obligations. You are responsible for complying with every law that applies to your collection, access, use, disclosure, transfer, retention, and re-disclosure of Genetic Information, including any special consent, counseling, notice, localization, or secondary-use restriction. In the United States this includes, where applicable, the Genetic Information Nondiscrimination Act and state genetic privacy statutes; other jurisdictions may impose additional protections. Any applicable consent or lawful-basis obligations that attach to Genetic Information are yours to satisfy; the Service does not obtain consent on your behalf, and the Individual’s acceptance of the Individual Terms is not a consent to your use of their Genetic Information.
9.5 Restrictions on Disclosure. Ressa will not disclose Genetic Information, or the fact that an Individual has undergone genetic testing, to any health insurer, life insurer, disability insurer, long-term-care insurer, employer, or educational institution. You agree to the same restriction with respect to Genetic Information you obtain through the Service, except where the Individual has given a valid, specific, written authorization or where an applicable law compels the disclosure.
10. Insights, Artificial Intelligence, and Regulatory Status
10.1 The Service Uses Artificial Intelligence. The Service may apply algorithmic and artificial-intelligence tools, including generative artificial-intelligence and large language models (“AI Tools”), to Health Information in order to parse and extract data from uploaded laboratory and genetic reports, to organize information, to identify patterns and trends, and to generate summaries and educational material.
10.2 How AI Processing Works, and What Is Sent. Ressa’s AI Tools are subject to business associate agreements and agreements that restrict the use of any information sent to such AI Tools for model training with the third-party organizations that create and sell such AI Tools. Ressa does not send Health Information to any public or consumer artificial-intelligence interface. You acknowledge that: (a) parsing any Health Information including laboratory or genetic reports requires transmitting such information to the AI Tool; and (b) Ressa may change or add AI Professionals and will maintain equivalent contractual protections, including a business associate agreement or equivalent written data protection agreement, when it does. Ressa will maintain an up-to-date list of subprocessors that Process Health Information and will provide or make that list available as described in Exhibit B and Applicable Data Protection Law.
10.3 INFORMATIONAL AND EDUCATIONAL PURPOSES ONLY. INSIGHTS ARE PROVIDED FOR INFORMATIONAL AND EDUCATIONAL PURPOSES ONLY. RESSA DOES NOT DIAGNOSE, TREAT, CURE, MITIGATE, OR PREVENT ANY DISEASE OR CONDITION, AND DOES NOT MAKE ANY MEDICAL, CLINICAL, OR THERAPEUTIC DETERMINATION. NO INSIGHT IS MEDICAL ADVICE, A DIAGNOSIS, A CLINICAL OPINION, A TREATMENT PLAN, A CLINICAL DECISION SUPPORT RECOMMENDATION INTENDED TO DIRECT CARE, OR A RECOMMENDATION THAT YOU TAKE OR REFRAIN FROM TAKING ANY ACTION.
10.4 Not Marketed as a Medical Device; No Device Authorization. THE SERVICE AND THE INSIGHTS ARE NOT MARKETED OR PROVIDED BY RESSA AS A MEDICAL DEVICE OR AS REGULATED CLINICAL DECISION-SUPPORT SOFTWARE. RESSA HAS NOT OBTAINED MEDICAL-DEVICE CLEARANCE, APPROVAL, AUTHORIZATION, CERTIFICATION, OR CONFORMITY ASSESSMENT FOR THE SERVICE OR INSIGHTS FROM THE UNITED STATES FOOD AND DRUG ADMINISTRATION, HEALTH CANADA, THE UNITED KINGDOM MHRA, AN EU/EEA COMPETENT AUTHORITY OR NOTIFIED BODY, OR ANY OTHER REGULATORY AUTHORITY. Regulatory classification depends on intended use and applicable law. You must not use or represent the Service in a manner that would cause Ressa to require an authorization it has not obtained, including by relying on an Insight as a substitute for independent professional review of the underlying information.
10.5 Why Insights Can Be Wrong. You acknowledge and agree that:
1) Insights are not reviewed by a licensed clinician before you see them;
2) AI Tools are known to produce output that is fabricated, incorrect, incomplete, outdated, internally inconsistent, or misleading, a phenomenon commonly described as “hallucination”;
3) an extraction or parsing step may misread a value, a unit, a reference range, a date, or an identifier, including by attributing a result to the wrong Individual;
4) Insights may rest on literature that has been superseded and may not reflect current clinical consensus;
5) Insights depend entirely on the completeness and accuracy of the information in the Health Vault, and information that is missing, stale, mistyped, or misfiled will produce unreliable output;
6) two Individuals with similar information may receive different Insights, and the same Individual may receive different Insights at different times; and
7) an Insight could, if acted on without independent verification, contribute to a decision that is unhelpful or harmful to an Individual.
10.6 OBLIGATION TO VERIFY INSIGHTS. YOU MUST INDEPENDENTLY VERIFY EVERY INSIGHT, EXTRACTED VALUE, RANGE FLAG, AND SUMMARY AGAINST THE UNDERLYING SOURCE DOCUMENT AND AGAINST YOUR OWN CLINICAL JUDGMENT BEFORE RELYING ON IT FOR ANY PURPOSE AFFECTING AN INDIVIDUAL. You will not present an Insight to an Individual as a diagnosis, as a clinical finding, or as your own conclusion without having verified it, and you will not represent that an Insight has been reviewed or endorsed by Ressa or by any clinician at Ressa.
10.7 NO WARRANTY AS TO INSIGHTS. ALL INSIGHTS ARE PROVIDED “AS IS” AND “WITH ALL FAULTS.” RESSA MAKES NO REPRESENTATION OR WARRANTY OF ANY KIND THAT ANY INSIGHT IS ACCURATE, COMPLETE, CURRENT, RELIABLE, CLINICALLY VALID, FIT FOR ANY CLINICAL PURPOSE, OR USEFUL, AND EXPRESSLY DISCLAIMS ANY SUCH WARRANTY. YOUR USE OF AND RELIANCE ON ANY INSIGHT IS AT YOUR SOLE RISK. RESSA MAKES NO PROMISE THAT USE OF THE SERVICE WILL IMPROVE ANY INDIVIDUAL’S HEALTH, IDENTIFY OR PREVENT ANY CONDITION, OR PRODUCE ANY PARTICULAR RESULT.
10.8 Model Training. Ressa may use Health Information to operate, maintain, secure, troubleshoot, and improve the Service, including to improve the quality of Insights. Where Ressa uses information to train or refine models, it does so on a de-identified or aggregated basis, in accordance with Section 13.
10.9 Your AI and Automated-Processing Obligations. Jurisdictions may require a health care Professional or other professional to disclose the use of artificial intelligence or automated processing, provide information about automated decision-making, conduct an impact assessment, obtain consent, ensure human review, or comply with professional standards before using AI-generated content in connection with care or communications. Complying with requirements that apply to your own use of the Service is your responsibility, not Ressa’s. Ressa will provide, on request, a plain-language description of how the Service uses AI that you may adapt for your own disclosures.
11. Health Information; Business Associate and Data Protection Addenda
11.1 Exhibit A. Where Section 3.4 makes Exhibit A applicable, Exhibit A is incorporated into and forms part of this Agreement, is executed by the same act by which you accept this Agreement, and governs Ressa’s creation, receipt, maintenance, and transmission of PHI on your behalf. Exhibit A applies only to the extent HIPAA applies and does not displace Exhibit B where another Applicable Data Protection Law also applies.
11.2 Exhibit B. Where Section 3.4 makes Exhibit B applicable, Exhibit B is incorporated into and forms part of this Agreement, is executed by the same act by which you accept this Agreement, and governs Ressa’s Processing of Professional Health Data on your behalf under Applicable Data Protection Law. Exhibit B may apply whether or not Exhibit A also applies.
11.3 Minimum Necessary and Data Minimization. Where HIPAA applies, Ressa will limit its uses, disclosures, and requests for PHI to the Minimum Necessary as required by HIPAA. Where another Applicable Data Protection Law applies, Ressa will Process Professional Health Data only as necessary for the documented purposes and instructions permitted by Exhibit B and will apply applicable data-minimization principles. You acknowledge that parsing an uploaded laboratory, genetic, or other report may require processing the document as submitted, including direct identifiers it contains. You control what you upload. Where a document can be submitted with fewer identifiers without impairing its intended use, you should submit it that way.
11.4 No Sale or Advertising Use of Professional Health Data. Ressa will not sell PHI or Professional Health Data as those terms are defined under applicable law, will not share Professional Health Data for cross-context behavioral advertising or targeted advertising, and will not use or disclose it for marketing or fundraising without a valid authorization, consent, or other lawful basis where one is required. Nothing in this Section expands Ressa’s rights in information that has been lawfully anonymized so that it is no longer PHI or Personal Data under the Applicable Data Protection Law, which is addressed in Section 13.
12. Data Security and Ressa’s Commitments
12.1 Our Commitments. With respect to Health Information in the Service, Ressa will:
1) implement and maintain appropriate administrative, physical, technical, and organizational safeguards designed to protect Health Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including encryption in transit and at rest, role-based access controls, multi-factor authentication, audit logging, vulnerability management, and, where HIPAA applies, safeguards that comply with 45 C.F.R. Part 164, Subpart C;
2) host and store Health Information in the United States unless an Order Form or written notice from Ressa expressly states otherwise; a Professional’s or Individual’s access from another country and any transfer of Professional Health Data to Ressa in the United States is subject to Exhibit B and Applicable Data Protection Law;
3) limit internal access to the minimum necessary for a workforce member to do their job, and require every workforce member and contractor with access to be bound by written confidentiality obligations and to receive privacy and security training;
4) use, disclose, and otherwise Process Health Information only to provide, secure, support, and improve the Service as permitted by this Agreement; to carry out lawful functions on your behalf, including treatment, payment, and health care operations where those concepts apply; as you or the Individual lawfully direct; as permitted by Exhibit A or Exhibit B; as permitted by a valid authorization, consent, or other lawful basis; or as required by law;
5) enter into a business associate agreement or an equivalent written data protection agreement with every vendor, subprocessor, and downstream subcontractor that creates, receives, maintains, or transmits Health Information, and remain responsible for their acts and omissions with respect to Health Information as if they were Ressa’s own;
6) maintain a written incident response plan and a documented security risk analysis; and
7) notify you of a Breach of Unsecured PHI, Personal Data Breach, Security Breach, or other reportable compromise of Professional Health Data within the timeframes stated in Exhibit A or Exhibit B, as applicable, and in any event without unreasonable delay;
12.2 Backups and Business Continuity. Ressa maintains encrypted backups on a rotation. Backups exist to restore the Service, not to serve as your record retention. Ressa does not guarantee that any particular item of information can be recovered, and you should not rely on the Service as your only copy of anything. Deletion requests are honored in the production environment on the timeframes stated in this Agreement; information in encrypted backups is removed on the ordinary backup rotation, which may take longer.
13. De-Identified and Aggregated Information; Research
13.1 Ressa May De-Identify or Anonymize. Ressa may de-identify or anonymize Health Information using a method permitted by the Applicable Data Protection Law governing the information. For PHI, this may include a method recognized under 45 C.F.R. § 164.514. Under laws that distinguish anonymized information from pseudonymized, de-identified, or coded personal data, information is treated as outside those laws only if it has been rendered anonymous to the standard required by that law. You authorize de-identification or anonymization only to the extent you have legal authority to do so. Once information is lawfully anonymous and no longer PHI or Personal Data under the Applicable Data Protection Law, Ressa may use, reproduce, modify, analyze, combine, disclose, distribute, license, and sell it for lawful purposes. Information that remains Personal Data or otherwise regulated after de-identification remains subject to the applicable protections of this Agreement and law.
13.2 Re-Identification Prohibited. Ressa will not attempt to re-identify information treated as anonymous or de-identified under Section 13.1 and will contractually prohibit recipients from attempting to re-identify it or combine it with other information for that purpose, except for Ressa’s internal validation of an anonymization or de-identification method or the work of a qualified expert performing such a determination, in each case under access controls and confidentiality obligations and as permitted by law.
13.3 Effect of Deletion on Anonymous Information. Where information has been lawfully anonymized so that it is no longer PHI, Personal Data, or otherwise regulated information under the Applicable Data Protection Law, termination of this Agreement, closure of your Professional Account, an Individual’s removal of you, or a deletion request does not require Ressa to remove that anonymous information from a dataset, model, publication, or arrangement in which it has already been included, unless applicable law requires otherwise. If information remains regulated despite de-identification, applicable access, deletion, objection, withdrawal, or other rights continue to apply.
14. Intellectual Property, Ownership, and Licenses
14.1 Ownership and License. You retain all rights in Professional Content as between you and Ressa, subject to this Agreement. You grant Ressa a limited, non-exclusive, royalty-free, worldwide license to host, store, reproduce, process, transmit, display, and analyze Professional Content and Professional-Submitted Information solely to: (a) provide, secure, and support the Service for you and for the Individuals you serve; (b) generate Insights; (c) share information as you and the applicable Individual direct; (d) improve and maintain the Service; (e) create de-identified and aggregated information under Section 13; and (f) comply with legal obligations. This license ends when you delete the content or your Professional Account is closed, except for copies retained under Section 18.6 and for de-identified information already created.
14.2 Ownership of the Service. Except for the rights expressly granted to you under this Agreement, Ressa retains all right, title, and interest in and to the Service, and all intellectual property rights therein, including without limitation all source code, databases, functionality, software, designs, AI models, algorithms, and content comprising the Service. This Agreement does not confer on you a license or interest in, or ownership of, any aspect of the Service beyond the limited subscription right set forth in this Agreement.
14.3 Your License to Use the Service. Subject to your compliance with this Agreement and payment of the applicable fees, Ressa grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license, during the Term, to access and use the Service for your internal professional purposes and for the benefit of the Individuals you serve. Any other use is prohibited and terminates this license.
14.4 Health Information Is Not Yours to License. Nothing in Section 14.1 is a representation by you that you own an Individual’s Health Information, and nothing in this Agreement transfers ownership of Health Information to you or to Ressa. Health Information about an Individual belongs to that Individual as against you and Ressa, subject to your rights in the record you maintain as a professional.
14.5 Professional Representations. You represent that you have the right to submit each item of Professional Content and Professional-Submitted Information, that doing so does not violate any law or any third party’s rights, and that you have obtained any authorization, consent, or license required, including any license required to display a proprietary code set, nomenclature, or content you submit, such as CPT, ICD-10-CM, LOINC, SNOMED CT, or a copyrighted assessment instrument. Ressa does not license any such code set or instrument to you. For a consent or authorization that Ressa administers under Section 6.10, Ressa’s completion of that delegated process satisfies the obligation to obtain that permission to the extent the permission is valid and covers the activity. This does not relieve you of an upstream permission, notice or other obligation outside that process.
14.6 Feedback. By submitting suggestions, feedback, or other information to Ressa regarding the Service, you grant Ressa a non-exclusive, royalty-free, perpetual, irrevocable license to use, modify, and incorporate such feedback into the Service without compensation or attribution to you.
14.7 Publicity. Ressa may identify you as a customer, and use your name and logo, in customer lists and general marketing materials, in a manner that does not identify any Individual or state or imply that Ressa endorses your services. You may opt out at any time by notice to support@ressahealth.com, and Ressa will discontinue the use within thirty (30) days. Any other use of your name, and any testimonial, case study, or quotation, requires your prior written consent. You may not use Ressa’s name, logo, or marks except to state factually that you use the Service, and you may not state or imply that Ressa endorses, certifies, verifies, or supervises you.
15. Acceptable Use
You agree, and will ensure that each Authorized User agrees, not to:
-
use the Service for any unlawful purpose or in violation of any applicable law, professional rule, or licensing board requirement;
-
hold yourself out as a licensed practitioner if you are not, or use the Service to practice any profession beyond your lawful scope;
-
access or attempt to access any account, Health Vault, or information you have not been approved to access, or retain access after an Individual has removed you or after the Post-Removal Window has closed;
-
submit false, misleading, or fraudulent information, impersonate any person or entity, or misstate your license, credentials, or HIPAA status;
-
solicit the credentials or personal information of any other user, or use another person’s account;
-
breach or attempt to breach any security or authentication measure, or circumvent any technological measure protecting the Service;
-
reverse-engineer, decompile, disassemble, or attempt to derive the source code, models, prompts, or underlying algorithms of the Service;
-
copy, reproduce, or create derivative works of the Service, or scrape, crawl, harvest, or use automated means to access or extract data from it, except through an interface Ressa expressly provides for that purpose;
-
resell, sublicense, rent, lease, time-share, or provide the Service as a service bureau to any third party, or permit access by anyone other than an Authorized User;
-
use the Service or any output of it to build, train, or improve a competing product, model, or service, or to benchmark it for publication without Ressa’s written consent;
-
upload or transmit any file or code containing viruses, worms, or other destructive features, or interfere with the security, integrity, availability, or performance of the Service;
-
use the Service to market to Individuals, to sell or promote a third party’s products, or to send communications for which you have not obtained the required authorization or consent;
-
use the Service to gather information for the purpose of filing or supporting a legal claim against a third party, or to conduct surveillance of any person;
-
place Health Information in the Service about a person who is not a Connected Individual, or about a person from whom you have not obtained the necessary authorization;
-
defame, abuse, stalk, threaten, intimidate, or harass any user or any employee, contractor, or agent of Ressa; or
-
facilitate or encourage any violation of this Agreement.
Ressa may investigate suspected violations and may suspend or terminate access under Section 18.3 where it reasonably believes a violation has occurred or where continued access presents a risk to Health Information or to any Individual.
16. Third-Party Content, Connected Sources, and Laboratory Partners
16.1 Third-Party Content. The Service may contain or link to information, products, services, websites, and content provided by third parties, including educational material, Laboratory Partners, connected devices and applications, calendar and videoconferencing services, and offerings from Ressa’s partners (“Third-Party Content”). Ressa provides Third-Party Content as a convenience, does not control it, does not endorse it, and makes no representation or warranty about it. You assume all risk arising from your access to and use of it.
16.2 Separate Terms. Third-Party Content and services may be subject to separate terms between you and the third party. Where they conflict with this Agreement, those terms govern solely as to that third party’s offering. You are responsible for reviewing them and for determining whether the third party is a business associate of yours.
16.3 NO WARRANTY AS TO THIRD PARTIES. NEITHER RESSA NOR ITS AFFILIATES MAKES ANY WARRANTY, REPRESENTATION, GUARANTEE, RECOMMENDATION, REFERRAL, OR OPINION REGARDING ANY THIRD PARTY’S QUALIFICATIONS, CREDENTIALS, LICENSING, QUALITY OF WORK, TURNAROUND, ACCURACY, SECURITY, PRIVACY PRACTICES, BILLING, OR COMPLIANCE WITH LAW, INCLUDING ANY LABORATORY PARTNER, ORDERING PROFESSIONAL, SPECIMEN COLLECTION Professional, DEVICE MANUFACTURER, OR TELEHEALTH OR CALENDAR SERVICE. NOTWITHSTANDING ANY DILIGENCE, VETTING, OR CONTRACTING RESSA MAY CONDUCT WITH A THIRD PARTY, RESSA DOES NOT ENDORSE IT.
16.4 Assumption of Risk and Limited Release. To the fullest extent permitted by applicable law, you release Ressa and its affiliates from, and agree not to assert against them, any claim arising out of the acts or omissions of any third party described in this Section, including any claim relating to the collection, handling, transport, or analysis of a specimen; the substance, accuracy, or timing of a result; the availability or security of a connected device or application; and any product a third party manufactures, distributes, or sells. This Section does not release or limit: (a) any claim arising out of Ressa’s own acts or omissions, including any breach of Section 12, Section 13, Exhibit A, or Exhibit B; (b) any liability for Ressa’s gross negligence, willful misconduct, or fraud; (c) any liability or right that cannot be released or limited under applicable law; or (d) any right or remedy you have directly against the third party.
17. Fees, Payment, and Automatic Renewal
17.1 Fees. You will pay the fees listed on the applicable pricing page for the tier you select in your Order Form, or at the point of purchase. Fees are stated in United States dollars. Fees are a flat subscription charge for access to the Service and are not charged on a per-patient, per-encounter, per-order, or per-result basis. Subscription fees are billed at the start of the subscription period and at each renewal. Monthly plans bill monthly; annual plans bill annually in advance. Ressa may change subscription pricing, effective as of your next renewal date, by notifying you at least thirty (30) days prior to your next renewal. If you do not agree, cancel before the renewal date under Section 17.3.
17.2 Payment Processing. Payments are processed by Stripe, Inc. (“Stripe”). By purchasing, you authorize Ressa and Stripe to charge your designated payment method in full for all amounts due, including taxes and fees, and to use another payment method you have provided if one is refused. Ressa transmits to Stripe only the minimal billing identifiers necessary to bill you; card details are entered on Stripe’s own hosted page and do not pass through or reside on Ressa’s systems. Stripe’s own terms and privacy policy govern its handling of that information. Closing your Professional Account does not delete the customer, subscription, or transaction records Stripe maintains, which Stripe may retain to meet its own legal, regulatory, fraud-prevention, and recordkeeping obligations; direct any question about that information to Stripe.
17.3 AUTOMATIC RENEWAL: PLEASE READ. YOUR SUBSCRIPTION AUTOMATICALLY RENEWS AT THE END OF EACH BILLING PERIOD FOR A FURTHER PERIOD OF THE SAME LENGTH, AND YOUR PAYMENT METHOD WILL BE CHARGED AT RESSA’S THEN-CURRENT RATE FOR YOUR PLAN, UNTIL YOU CANCEL. You may cancel at any time, effective at the end of the then-current billing period, through the billing settings in your Professional Account. Ressa will provide a cancellation mechanism in the Professional Account that is at least as easy to use as the mechanism by which you subscribed. Ressa will send a renewal reminder before any renewal for which applicable law requires one. Cancellation takes effect at the end of the billing period in which you cancel, and you retain access until then.
17.4 Trials, Freemium, and Promotions. Ressa may offer a free tier, a free trial, or a promotional rate. Additional terms presented at sign-up form part of this Agreement. A free trial may require a valid payment method and may convert automatically to a paid subscription at the end of the trial period if you do not cancel first. Ressa may modify or discontinue a free tier on thirty (30) days’ notice. Discounted and promotional amounts that require payment are non-refundable.
17.5 Seats and True-Up. Where your plan is priced by Authorized User seat, you will maintain a number of seats at least equal to the number of Authorized Users with access. Ressa may review seat usage and, on notice, invoice you for the additional seats used, prorated to the end of the then-current period. Seats added mid-period are prorated; seat reductions take effect at the next renewal and do not generate a refund.
17.6 Refunds. Except as expressly provided in Section 18.2, fees are non-refundable and there is no refund or credit for a partial billing period, for unused seats, or for periods in which you did not use the Service. There is no early-termination penalty except for recovery of any discounts provided for enrolling in the annual subscription plan; cancelling stops future charges but does not refund amounts already paid for anytime that has already elapsed in the current subscription.
17.7 Late Payment and Suspension. Amounts not paid when due accrue interest at the lesser of one and one-half percent (1.5%) per month or the maximum rate permitted by law. If your payment method fails or an amount remains unpaid for ten (10) days after notice, Ressa may suspend your Professional Account under Section 18.3. Suspension for non-payment does not relieve Ressa of its obligations under Section 12, Exhibit A, or Exhibit B, and Ressa will not withhold your ability to export information you are entitled to see for at least thirty (30) days following suspension.
17.8 Taxes. Fees exclude sales, use, value-added, goods and services, harmonized sales, Québec sales, digital-services, withholding, and similar taxes or governmental charges. Where Ressa determines it must collect a tax, it will add it to the fees or otherwise collect it as applicable. You are responsible for taxes associated with your purchase or use of the Service other than taxes on Ressa’s net income, except to the extent applicable law requires Ressa to bear or remit them.
18. Term, Suspension, Termination, and Data Export
18.1 Term. This Agreement begins on the date you first accept it and continues until terminated (the “Term”) in accordance with its terms. Your subscription term is the billing frequency you select and renews under Section 17.3.
18.2 Termination for Convenience. You may terminate this Agreement by cancelling your subscription under Section 17.3 and closing your Professional Account. Ressa may terminate this Agreement for convenience on thirty (30) days’ notice, in which case Ressa will refund fees prepaid for the period after termination on a pro-rata basis but will charge back any discount provided for an annual subscription.
18.3 Suspension. Ressa may suspend your Professional Account or any Authorized User’s access, with notice where practicable and immediately where not, if: (a) an amount is overdue under Section 17.7; (b) Ressa reasonably believes you or an Authorized User has violated Section 15 or Section 7.2; (c) continued access presents a material risk to Health Information, to the Service, or to any Individual; or (d) a law or a governmental authority requires it. Ressa will limit the scope and duration of a suspension to what is reasonably necessary and will restore access promptly once the cause is resolved.
18.4 Termination for Cause. Either party may terminate this Agreement if the other materially breaches it and fails to cure within thirty (30) days after written notice describing the breach, except that Ressa may terminate immediately, without a cure period, for a breach of Section 15 (acceptable use), or Exhibit A or Exhibit B where the breach presents an ongoing risk to Health Information. Either party may terminate immediately if the other becomes insolvent, makes an assignment for the benefit of creditors, or has a receiver or trustee appointed. You may terminate under Section 4.3 or Section 12 as those Sections provide.
18.5 Your Data Export Window. For thirty (30) days after the effective date of termination or account closure, you will retain the ability to export the information you were entitled to see immediately before termination, so that you can retain what your professional recordkeeping obligations require. Ressa is not obligated to extend this window or to restore access afterward. Where Ressa terminates or suspends under Section 18.3 or Section 18.4, Ressa will either provide you with a copy of the information retained in the Service that you are otherwise entitled to, or provide the export window unless doing so would be unlawful or would present a security risk.
18.6 Effect of Termination. On termination: your license under Section 14.3 ends; your and your Authorized Users’ access to the Service ends, subject to Section 18.5; you must pay all amounts accrued through the effective date; and Exhibit A or Exhibit B governs the return or destruction of PHI or Professional Health Data. Termination of this Agreement does not close, delete, or affect the account of any Individual, whose Health Vault and Individual Terms continue independently, and does not remove Professional-Submitted Information from an Individual’s Health Vault, which the Individual continues to be entitled to see.
18.7 Retention After Closure. Where Ressa retains information after termination as permitted by Exhibit A, Exhibit B, or applicable law, it remains subject to Section 12 and to the applicable Exhibit for as long as Ressa retains it, and Ressa will limit its further uses and disclosures to the purposes that make return or destruction infeasible.
18.8 Survival. Sections 1.7, 5.3, 6.8, 6.9, 7.3, 7.5, 7.6, 9.5, 10.6, 10.7, 12, 13, 14.1, 14.3, 14.5, 16.1, 17.4, 18 (as to amounts accrued), 19, 20, 21, 22, 23, 24, 25, and 26, together with Exhibit A or Exhibit B to the extent stated there, as well as any other clause of this Agreement, which by its nature should survive termination, shall survive termination.
19. Confidentiality
19.1 Confidential Information. “Confidential Information” means: (i) any non-public information of a party; (ii) any non-public information relating to the Service, Ressa’s current or planned products and services, technology, techniques, know-how, research, engineering, designs, finances, accounts, client lists, business forecasts, and marketing plans; (iii) information about you received by Ressa; and (iv) other information of a party disclosed in writing and designated as “Confidential” at the time of disclosure, or disclosed orally and identified as “Confidential” at the time of disclosure. “Confidential Information” shall not include information that: (a) is or becomes generally known through no fault of the receiving party; (b) was in the receiving party’s possession without restriction at the time of disclosure; or (c) is independently developed by the receiving party without use of the disclosing party’s Confidential Information. <u>Health Information is not governed by this Section.</u>
19.2 Obligations. Each party will protect the other’s Confidential Information with at least reasonable care, and will take reasonable steps to hold such Confidential Information in confidence and not use it or disclose it to any other person or entity except those of its personnel and advisors who need it and are bound by confidentiality obligations at least as protective.
19.3 Exclusions. Confidential Information does not include information that is or becomes public without breach, was known to the recipient without restriction before disclosure, is received from a third party without restriction, or is independently developed without use of the Confidential Information.
19.4 Compelled Disclosure. A party may disclose Confidential Information where compelled by law, provided it gives the other party prompt notice where legally permitted and reasonable cooperation in seeking protective treatment.
20. Disclaimers
20.1 NO MEDICAL SERVICES. RESSA DOES NOT PROVIDE MEDICAL ADVICE, DIAGNOSIS, TREATMENT, CLINICAL CONSULTATION, OR ANY FORM OF MEDICAL OPINION, TO YOU OR TO ANY INDIVIDUAL. RESSA IS NOT A LICENSED HEALTH CARE Professional, DOES NOT ENGAGE IN THE PRACTICE OF MEDICINE OR ANY OTHER LICENSED PROFESSION, AND HAS NO EXPERTISE IN DIAGNOSING, EXAMINING, OR TREATING ANY CONDITION. NOTHING IN THE SERVICE IS A SUBSTITUTE FOR YOUR PROFESSIONAL JUDGMENT.
20.2 Disclaimer of Warranties. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICE, ALL INSIGHTS, ALL THIRD-PARTY CONTENT, AND ALL MATERIALS AVAILABLE THROUGH THE SERVICE ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED. RESSA DISCLAIMS ALL WARRANTIES, INCLUDING (A) ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, QUIET ENJOYMENT, OR NON-INFRINGEMENT; (B) ANY WARRANTY ARISING OUT OF COURSE OF DEALING, USAGE, OR TRADE; AND (C) ANY WARRANTY THAT THE SERVICE WILL BE UNINTERRUPTED, TIMELY, SECURE, ACCURATE, COMPLETE, CLINICALLY VALID, OR ERROR-FREE, OR THAT DEFECTS WILL BE CORRECTED. NO ADVICE OR INFORMATION OBTAINED FROM RESSA OR THROUGH THE SERVICE CREATES ANY WARRANTY NOT EXPRESSLY STATED IN THIS AGREEMENT.
20.3 Acknowledgments. The Service is provided to you for informational purposes only. The Service contains tools that you may use in various ways for your own internal business, and your interpretation of any such tool, and use of the Service to make clinical, operational, or business decisions, are solely and exclusively at your discretion. You further acknowledge and agree that: (a) the Service is a documentation and data-analysis tool and does not constitute clinical advice, legal advice, coding advice, reimbursement advice, or a guarantee of regulatory compliance; (b) Insights, including documentation suggestions, records created through AI-assisted import, notices, and calculations, are generated by automated processes and may contain errors, omissions, or inaccuracies that are not apparent on their face; (c) compliance with professional, clinical, privacy, medical-record, billing, reimbursement, public-health-system, insurer, and other regulatory requirements in every jurisdiction that applies to you remains solely your responsibility; (d) you are responsible for verifying the accuracy and completeness of all Insights and for exercising independent professional judgment before signing, finalizing, or relying on any clinical document, treatment schedule, order, or reimbursement calculation; (e) the absence of a notice, scheduling exception, or compliance flag in the Service does not indicate that your documentation is complete, timely, accurate, or compliant; (f) Ressa makes no representation or warranty that use of the Service will prevent regulatory citations, claim denials, professional complaints, or audits, or satisfy any particular regulatory standard; (g) Ressa is not responsible for a difference of coding, clinical, professional, or regulatory opinion or interpretation between Ressa and any other party, nor for a change in law, guidance, or interpretation not known to Ressa; (h) Ressa is not responsible for errors, omissions, illegible text, or false or misleading statements contained in Professional Content, Professional Health Data, or Professional-Submitted Information entered into the Service; and (i) you are responsible for staying informed of the laws, professional standards, payor rules, public-health-system rules, guidance, directives, and interpretive materials that apply to your practice and for all compliance decisions made in reliance on or in connection with Insights. In the United States, these may include CMS, Medicare, Medicaid, carrier, and state-practice requirements; analogous requirements may apply elsewhere.
20.4 Limits on Disclaimers. Nothing in this Section disclaims a warranty or right that cannot be disclaimed under applicable law, and nothing in this Section limits Ressa’s express obligations under Section 12, Section 13.3, Exhibit A, or Exhibit B.
21. Limitation of Liability
21.1 EXCLUSION OF INDIRECT DAMAGES. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, INDIRECT, RELIANCE, OR CONSEQUENTIAL DAMAGES, INCLUDING LOST PROFITS, LOST REVENUE, LOSS OF DATA OR GOODWILL, SERVICE INTERRUPTION, OR THE COST OF SUBSTITUTE SERVICES, ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE SERVICE, WHETHER BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE), PRODUCT LIABILITY, STATUTE, OR ANY OTHER THEORY, AND WHETHER OR NOT THE PARTY HAS BEEN ADVISED OF THE POSSIBILITY, EVEN IF A LIMITED REMEDY IS FOUND TO HAVE FAILED OF ITS ESSENTIAL PURPOSE.
21.2 GENERAL CAP. EXCEPT AS PROVIDED IN SECTION 21.3, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE SERVICE WILL NOT EXCEED THE GREATER OF: (A) THE TOTAL AMOUNT YOU PAID OR OWED RESSA UNDER THIS AGREEMENT IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE LIABILITY; OR (B) TWO THOUSAND UNITED STATES DOLLARS ($2,000).
21.3 Exclusions From the Caps. The cap in Section 21.2 does not apply to: (a) your obligation to pay fees; (b) your indemnification obligations under Section 22.1; (c) either party’s gross negligence, willful misconduct, or fraud; (d) your breach of Section 15 or of Ressa’s intellectual property rights; or (e) any liability that cannot be limited as a matter of law.
21.4 Allocation of Risk. The exclusions and limitations in this Section are a fundamental element of the bargain between the parties, reflect the fees charged, and would be different if they were different. They apply even where a remedy fails of its essential purpose.
21.5 Jurisdictional Limits. Some jurisdictions do not allow the exclusion or limitation of certain damages. Where that is the case, the limitations in this Section apply only to the extent permitted.
22. Indemnification
22.1 Your Indemnity. You will defend, indemnify, and hold harmless Ressa and its affiliates, officers, directors, employees, contractors, licensors, and agents (the “Ressa Parties”) from and against any third-party claim, and all resulting losses, damages, liabilities, settlements, fines, penalties, and reasonable attorneys’ fees, arising out of or relating to: (a) any service, advice, diagnosis, treatment, order, recommendation, or care you or an Authorized User provides or fails to provide, including any decision made in reliance on an Insight, a range flag, or a laboratory result; (b) your breach of Section 7.2, including any absence, restriction, or lapse of a license, or any exclusion or debarment; (c) your breach of this Agreement, Exhibit A, or Exhibit B; (d) any unauthorized access to or acquisition, use, or disclosure of Health Information resulting from a compromise of your credentials, devices, networks, or workforce, or from your act or omission; (e) your handling of information after you download or export it under Section 6.8 or Section 18.5; (f) any Professional Content or Professional-Submitted Information, including any claim that it infringes or misappropriates a third party’s rights or was submitted without a required authorization, consent, or license; (g) any communication you send to an Individual; (h) your violation of any law, professional rule, or third party’s rights; or (i) any representation you make to an Individual that is inconsistent with Section 7.8.
22.2 Ressa’s Indemnity. Ressa will defend, indemnify, and hold harmless you and your officers, directors, employees, and contractors from and against any third-party claim, and all resulting losses, damages, liabilities, settlements, and reasonable attorneys’ fees, arising out of or relating to: (a) a claim that the Service, as provided by Ressa and used in accordance with this Agreement, infringes or misappropriates a United States patent, copyright, trademark, or trade secret; or (b) a Breach of Unsecured PHI, Personal Data Breach, Security Breach, or other breach of the security of Professional Health Data, to the extent caused by Ressa’s breach of Section 12, Exhibit A, or Exhibit B, including the reasonable and documented costs of notifications you are required to make to affected individuals, supervisory authorities, privacy commissioners, health regulators, the Secretary of Health and Human Services, the Federal Trade Commission, other governmental authorities, or the media, as applicable law requires, and of credit monitoring where reasonably provided. Ressa’s obligations under this Section 22.2 are subject to Section 21.
22.3 Infringement Remedies. If the Service becomes, or Ressa reasonably believes it may become, the subject of a claim under Section 22.2(a), Ressa may at its option and expense procure the right for you to continue using it, modify or replace it so that it is non-infringing while materially preserving its functionality, or terminate this Agreement on notice and refund fees prepaid for the period after termination. Ressa has no obligation under Section 22.2(a) for a claim arising from your combination of the Service with anything not provided by Ressa, from your modification of the Service, from Professional Content or Professional-Submitted Information, or from your use of the Service in violation of this Agreement.
22.4 Procedure. The party seeking indemnity will give the indemnifying party prompt written notice of the claim (provided that a delay relieves the indemnifying party only to the extent it is prejudiced), sole control of the defense and settlement (except that no settlement imposing a non-monetary obligation or an admission of liability on the indemnified party may be made without its consent, not to be unreasonably withheld), and reasonable cooperation at the indemnifying party’s expense. The indemnified party may participate with its own counsel at its own expense.
23. Dispute Resolution and Binding Arbitration
PLEASE READ THIS SECTION CAREFULLY. IT REQUIRES THE PARTIES TO ARBITRATE DISPUTES INDIVIDUALLY AND WAIVES THE RIGHT TO A JURY AND TO PARTICIPATE IN A CLASS ACTION.
23.1 Informal Resolution First. Before starting a formal proceeding, the parties will try to resolve the dispute informally. The complaining party will send written notice to the other describing the dispute and the relief sought, to Ressa at support@ressahealth.com, and to you at your account contact address. If the dispute is not resolved within thirty (30) days after receipt, either party may begin a formal proceeding. This requirement does not bar either party from seeking urgent injunctive relief.
23.2 Arbitration. Except as provided in this Section, any controversy, claim, or dispute arising out of or relating to this Agreement or the Service, including the determination of the scope or applicability of this agreement to arbitrate (a “Dispute”), will be resolved by binding arbitration before a single arbitrator rather than in court. JAMS will administer the arbitration under its Streamlined Arbitration Rules and Procedures, or its Comprehensive Arbitration Rules and Procedures where the amount in controversy exceeds $250,000. The seat of arbitration is Pima County, Arizona, and the parties may agree to proceed by videoconference or, for claims under $50,000, on documents only. The arbitrator must apply applicable law, may award any relief a court could award on an individual basis, and must issue a written decision stating the essential findings and conclusions. Each party bears its own attorneys’ fees and an equal share of the arbitrator’s fees, except where a statute or the award provides otherwise. Judgment on the award may be entered in any court of competent jurisdiction. The Federal Arbitration Act governs this Section.
23.3 Exceptions. In the event either party is suffering immediate irreparable injury, such party may seek emergency or other injunctive relief in any court of competent jurisdiction without first complying with the mediation or arbitration procedures above. Additionally, Ressa may, in its sole discretion, elect to resolve collection matters related to fees owed by you in a court of law in accordance with Section 24.
23.4 CLASS ACTION WAIVER. TO THE EXTENT PERMITTED BY LAW, EACH PARTY MAY BRING CLAIMS AGAINST THE OTHER ONLY IN AN INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE PROCEEDING, AND THE ARBITRATOR MAY NOT CONSOLIDATE MORE THAN ONE PARTY’S CLAIMS OR PRESIDE OVER ANY CLASS OR REPRESENTATIVE PROCEEDING. If this Section is found unenforceable as to a particular claim or request for relief, that claim or request will be severed and heard in a court of competent jurisdiction under Section 24, and the remainder of this Section continues to apply in arbitration.
23.5 JURY TRIAL WAIVER. EXCEPT WHERE PROHIBITED BY LAW, EACH PARTY WAIVES ANY CONSTITUTIONAL AND STATUTORY RIGHT TO A TRIAL BEFORE A JUDGE OR JURY AND ELECTS INSTEAD TO HAVE DISPUTES RESOLVED BY ARBITRATION.
23.6 TIME TO FILE. ANY CLAIM ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE SERVICE MUST BE COMMENCED WITHIN ONE (1) YEAR AFTER THE CLAIM ACCRUES, OR THE SHORTEST PERIOD PERMITTED BY APPLICABLE LAW IF LONGER, AFTER WHICH IT IS PERMANENTLY BARRED. This Section does not apply to a claim for which applicable law prohibits a contractual shortening of the limitations period.
23.7 Confidentiality of Proceedings. The existence and content of an arbitration, including any award, are confidential, except as necessary to enforce or challenge the award, to comply with law, or to obtain insurance coverage.
24. Governing Law and Venue
This Agreement is governed by the laws of the State of Delaware, without regard to its conflict-of-laws rules, except that the Federal Arbitration Act governs Section 23. For any claim not subject to arbitration, the parties consent to the exclusive jurisdiction and venue of the state and federal courts located in Pima County, Arizona, and waive any objection to that forum. The Uniform Commercial Code, the Uniform Computer Information Transactions Act, and the United Nations Convention on Contracts for the International Sale of Goods do not apply. Nothing in this Section displaces HIPAA, Applicable Data Protection Law, professional-regulation law, a data-transfer mechanism incorporated under Exhibit B, or any other mandatory law that by its terms cannot validly be displaced by this choice of law or forum. Nothing in Sections 23 or 24 limits the authority of a regulator or supervisory authority, or any non-waivable right of an Individual or data subject, under applicable law.
25. Changes to This Agreement
Ressa may update this Agreement from time to time. If such a change is material, Ressa will notify you through the Service or by email to your account contact at least thirty (30) days before it takes effect and will post the updated Agreement with a new Effective Date. Your continued use of the Service after the effective date of a change constitutes acceptance of it. If you do not agree, you may terminate this Agreement by notice to Ressa before the change takes effect and receive a pro-rata refund of fees prepaid for the remainder of your then-current term.
26. General Provisions
26.1 Entire Agreement. This Agreement, including its exhibits and any Order Form, is the entire agreement between the parties regarding the Service and supersedes all prior and contemporaneous agreements, proposals, and representations on the subject, including any prior terms of service or business associate agreement. No purchase order, vendor portal term, or other document you issue has any effect, and any term in it that conflicts with this Agreement is void.
26.2 No Reliance. Each party acknowledges that it has not relied on any statement, promise, or representation not expressly set out in this Agreement. This Section does not limit liability for fraud.
26.3 Severability. If any provision of this Agreement is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or severed if it cannot be, and the remaining provisions continue in full force. Where a provision would, if read broadly, permit Ressa to control or interfere with your professional judgment or would constitute unlawful fee-splitting or the corporate practice of a profession, it will be read narrowly so that it does not, and severed if it cannot be.
26.4 Titles for Convenience; Waiver. Section titles and references are for convenience only and shall not affect the interpretation or meaning of this Agreement. No failure by a party to insist upon the strict performance of any term or condition, or to exercise any right or remedy hereunder, shall constitute a waiver of any such term, condition, right, or remedy.
26.5 Assignment. You may not assign or transfer this Agreement, in whole or in part, without Ressa’s prior written consent, except to a successor to all or substantially all of your practice or business that assumes this Agreement in writing and is not a competitor of Ressa. Ressa may assign this Agreement in connection with a merger, acquisition, reorganization, or sale of assets, provided the assignee assumes Ressa’s obligations under Section 12 and Exhibit A or Exhibit B and Ressa notifies you. Any attempted assignment in violation of this Section is void.
26.6 No Joint Venture or Partnership. Nothing in this Agreement shall be construed to create a joint venture, partnership, employment, or agency relationship between the parties. The parties are and shall remain independent contractors. Except as otherwise expressly provided herein, neither party shall be liable for the debts or obligations of the other party.
26.7 No Third-Party Beneficiaries. Except for rights expressly granted to data subjects under a mandatory international-transfer mechanism incorporated through Exhibit B, this Agreement is for the benefit of the parties only and creates no enforceable rights in any third party, including any Individual. The Secretary of Health and Human Services has the rights stated in Exhibit A, and supervisory authorities and regulators retain all powers granted by applicable law.
26.8 Notices. Notices to Ressa must be sent to support@ressahealth.com and, for a notice of termination, breach, indemnity claim, or dispute, also by certified mail to Metabolic Terrain Omics, Inc. d/b/a Ressa Health, 2 East Congress Street, Suite 900, Tucson, AZ 85701, Attn: Legal. Notices to you may be given by email to your account contact or by posting in the Service, except that notice of termination, breach, indemnity claim, or dispute must be sent by email to your account contact. Notice is effective when sent or posted.
26.9 Force Majeure. No failure, delay, or default in performance of any obligation under this Agreement will constitute a breach if caused by: strike, fire, shortage of materials, act of a public authority, unavoidable casualty, civil disorder, riot, insurrection, vandalism, war, severe weather, natural disaster or other act of God, failure of the Internet, failure or error of an Internet service Professional, failure of third-party connectivity Professionals or telecommunications carriers, failure of a subprocessor, hacking or electronic vandalism, terrorism, pandemic, public health emergency, or any other cause that is beyond the reasonable control of the party otherwise chargeable, for so long as such cause continues and for a commercially reasonable period thereafter. Nothing in this Section excuses either party’s obligations of confidentiality, its obligations under Exhibit A or Exhibit B, or Ressa’s obligations to maintain security safeguards, or either party’s payment or data return obligations.
-
Counterparts and Electronic Acceptance. This Agreement may be executed in counterparts and by electronic signature or click-through acceptance, each of which has the same effect as an original. Your click-through acceptance of this Agreement constitutes your execution of Exhibit A and/or Exhibit B, as applicable, including any international-transfer terms incorporated through Exhibit B.
-
Language and Local Versions. Ressa may provide translated or jurisdiction-specific versions of this Agreement. Where applicable law requires a contract, standard terms, notice, or related document to be provided in a local language, Ressa and Professional will comply with that requirement before the Professional is bound. Without limiting the foregoing, for a Professional in Québec where the Charter of the French language requires a French version of a contract of adhesion or related document to be provided before acceptance, Ressa will make the French version available before acceptance; after receiving or having access to the French version, the Professional may expressly choose to contract in another language where the law permits. A translation does not reduce any mandatory protection under Applicable Data Protection Law.
EXHIBIT A
BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement (“BAA”) supplements and is made a part of the Ressa Health Professional Master Services Agreement (the “Services Agreement”) between Metabolic Terrain Omics, Inc., a Delaware corporation doing business as Ressa Health (“Business Associate” or “Ressa”), and the Professional identified in the Services Agreement (“Covered Entity”). It is effective on the same date as the Services Agreement and is executed by the same act of acceptance.
This BAA applies where Section 3.4 or Section 3.5 of the Services Agreement makes it applicable. Where Covered Entity is itself a business associate of an upstream covered entity, Ressa is a subcontractor within the meaning of 45 C.F.R. § 160.103, this BAA is the written agreement required by 45 C.F.R. § 164.502(e)(1)(ii), and references to “Covered Entity” are read to mean that business associate.
A.1 Definitions
Capitalized terms used but not defined in this BAA have the meanings given in HIPAA or in the Services Agreement. The following terms have the meanings given in 45 C.F.R. Parts 160 and 164: Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information (“ePHI”), Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
“PHI” means Protected Health Information as defined in 45 C.F.R. § 160.103, limited to information Ressa creates, receives, maintains, or transmits for or on behalf of Covered Entity under the Services Agreement.
“De-Identified Information” means information de-identified in accordance with 45 C.F.R. § 164.514(a)–(b), by the Safe Harbor method or by Expert Determination.
“Privacy Rule,” “Security Rule,” and “Breach Notification Rule” mean, respectively, 45 C.F.R. Part 164 Subpart E, Subpart C, and Subpart D.
A.2 Scope
(a) This BAA governs PHI only. It does not govern: (i) information Ressa creates, receives, maintains, or transmits for an Individual under the Individual Terms and not on behalf of Covered Entity; (ii) De-Identified Information; (iii) information Covered Entity provides to Ressa that is not PHI, including Professional Account and billing information; or (iv) information after Covered Entity downloads or exports it from the Service, which Covered Entity holds in its own right.
(b) Ressa is a Business Associate only to the extent it creates, receives, maintains, or transmits PHI for or on behalf of Covered Entity. Ressa’s separate, direct-to-consumer relationship with each Individual under the Individual Terms is not a business associate relationship with Covered Entity and is not restricted by this BAA. Where the same record is both PHI as to Covered Entity and the Individual’s own information as to the Individual, Ressa performs both sets of obligations, and where they conflict Ressa performs the obligation that gives greater protection to the record.
A.3 Permitted Uses and Disclosures by Ressa
(a) Services. Ressa may Use and Disclose PHI to perform the Service and its other obligations under the Services Agreement, provided the Use or Disclosure would not violate the Privacy Rule if done by Covered Entity, except as permitted by subsections (c) and (d) below.
(b) As Required by Law. Ressa may Use and Disclose PHI as Required by Law.
(c) Management and Administration of Ressa. Ressa may Use PHI for the proper management and administration of Ressa and to carry out Ressa’s legal responsibilities. Ressa may Disclose PHI for those purposes only if the Disclosure is Required by Law, or if Ressa obtains, before making the Disclosure, reasonable assurances from the person to whom the PHI is disclosed that the PHI will be held confidentially and Used or further Disclosed only as Required by Law or for the purpose for which it was disclosed to that person, and that the person will notify Ressa of any instance of which it becomes aware in which the confidentiality of the PHI has been breached. This subsection implements 45 C.F.R. § 164.504(e)(4).
(d) Data Aggregation. Ressa may Use and Disclose PHI to provide Data Aggregation services relating to the Health Care Operations of Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
(e) De-Identification. Ressa may de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(b), as expressly permitted by 45 C.F.R. § 164.504(e)(2)(i)(B). Covered Entity authorizes that de-identification. Once information is de-identified it is no longer PHI, is not subject to this BAA, and is governed by Section 13 of the Services Agreement, which permits Ressa to Use, Disclose, license, and sell it. Ressa will not attempt to re-identify De-Identified Information and will contractually prohibit each recipient from doing so, subject to Section 13.3 of the Services Agreement.
(f) Minimum Necessary. Ressa will limit its Uses, Disclosures, and requests for PHI to the Minimum Necessary to accomplish the intended purpose, consistent with 45 C.F.R. § 164.502(b) and § 164.514(d), and will make reasonable efforts to limit access by its workforce accordingly. Covered Entity acknowledges the determination described in Section 11.3 of the Services Agreement regarding the processing of uploaded documents.
(g) Prohibitions. Ressa will not: Use or Disclose PHI other than as permitted by this BAA, the Services Agreement, or as Required by Law; sell PHI or receive remuneration in exchange for PHI except as permitted by 45 C.F.R. § 164.502(a)(5)(ii); Use or Disclose PHI for marketing as defined in 45 C.F.R. § 164.501 or for fundraising, in each case without a valid authorization complying with 45 C.F.R. § 164.508; or Use or Disclose psychotherapy notes as defined in 45 C.F.R. § 164.501.
(h) Compliance With Covered Entity’s Obligations. To the extent Ressa carries out an obligation of Covered Entity under the Privacy Rule, Ressa will comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of that obligation. This subsection implements 45 C.F.R. § 164.504(e)(2)(ii)(H).
(i) Restrictions and Confidential Communications. Ressa will comply with any restriction on the Use or Disclosure of PHI to which Covered Entity has agreed under 45 C.F.R. § 164.522(a), and with any confidential-communication request Covered Entity has accommodated under 45 C.F.R. § 164.522(b), in each case only to the extent Covered Entity has notified Ressa of it in writing and Ressa has confirmed in writing that it can be implemented in the Service. Covered Entity acknowledges Section 6.4(c) of the Services Agreement and the limits of the Service’s access model.
A.4 Safeguards
(a) Ressa will use appropriate administrative, physical, and technical safeguards, and comply with the Security Rule with respect to ePHI, to prevent Use or Disclosure of PHI other than as provided by this BAA, and to protect the confidentiality, integrity, and availability of ePHI that Ressa creates, receives, maintains, or transmits on behalf of Covered Entity.
(b) Without limiting subsection (a), Ressa will encrypt PHI in transit and at rest, maintain role-based access controls and multi-factor authentication, maintain audit logs of access to PHI, conduct and document a security risk analysis, maintain a written incident response plan, train its workforce on privacy and security and apply sanctions for violations, and obtain an annual independent third-party security assessment. Section 12 of the Services Agreement states these commitments in full and is incorporated here.
(c) Ressa will store and process PHI within the United States and will not transfer PHI outside the United States without Covered Entity’s prior written consent.
A.5 Reporting
(a) Improper Use or Disclosure. Ressa will report to Covered Entity any Use or Disclosure of PHI not permitted by this BAA of which it becomes aware, without unreasonable delay and in no case later than five (5) business days after discovery.
(b) Breach of Unsecured PHI. Ressa will notify Covered Entity of any Breach of Unsecured PHI without unreasonable delay and in no case later than five (5) business days after discovery of the Breach. A Breach is treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to Ressa or to any person other than the individual committing the Breach who is an employee, officer, or agent of Ressa. This timeframe is shorter than the outer limit permitted by 45 C.F.R. § 164.410 because Covered Entity requires time to meet its own obligations under 45 C.F.R. §§ 164.404 and 164.408.
(c) Content of the Notice. Ressa’s notice under subsection (b) will include, to the extent known at the time and with the balance supplied promptly as it becomes available: the identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; a description of what happened, the date of the Breach and the date of discovery; a description of the types of PHI involved; the steps Individuals should take to protect themselves; what Ressa is doing to investigate, mitigate, and protect against further Breaches; and a contact at Ressa. Ressa will supplement its notice as the investigation develops and will provide the information Covered Entity reasonably requires to make its own notifications.
(d) Security Incidents. Ressa will report to Covered Entity any Security Incident of which it becomes aware that results in unauthorized access to, or the unauthorized Use, Disclosure, modification, or destruction of, ePHI, without unreasonable delay and in no case later than five (5) business days after discovery. Unsuccessful Security Incidents, including pings and other broadcast attacks on a firewall, port scans, unsuccessful log-on attempts, denial-of-service attempts that do not result in the Service being taken offline, and malware detected and blocked before it reaches ePHI, that do not result in unauthorized access to ePHI are reported on an aggregate basis on Covered Entity’s written request, and no individual notice is required. This subsection constitutes notice of the ongoing existence and occurrence of unsuccessful Security Incidents.
(e) Mitigation. Ressa will mitigate, to the extent practicable, any harmful effect known to Ressa of a Use or Disclosure of PHI by Ressa in violation of this BAA.
(f) Notification to Individuals and Regulators. As between the parties, Covered Entity is responsible for notifying Individuals, the Secretary, and the media as the Breach Notification Rule requires, and controls the content and timing of those notifications. At Covered Entity’s written request Ressa will make the notifications on Covered Entity’s behalf, in a form Covered Entity approves in advance, and Covered Entity’s request does not relieve Covered Entity of responsibility for compliance. Section 22.2(b) of the Services Agreement governs which party bears the cost.
(g) Cooperation. Each party will cooperate reasonably with the other in investigating a Breach or Security Incident, in responding to an inquiry from the Secretary, a State Attorney General, or another regulator, and in defending a claim arising from it.
A.6 Subcontractors
(a) Ressa will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on Ressa’s behalf agrees in writing, before receiving PHI, to restrictions and conditions at least as protective as those that apply to Ressa under this BAA, as required by 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2).
(b) Ressa remains fully responsible and liable to Covered Entity for the acts and omissions of its Subcontractors with respect to PHI as if they were Ressa’s own.
(c) Ressa’s artificial-intelligence processing is performed by a third-party cloud services Professional under Ressa’s business associate agreement with the Professional, as described in Section 10.2 of the Services Agreement. Ressa will maintain a business associate agreement or equivalent written data protection agreement with any Professional it substitutes or adds.
A.7 Individual Rights
(a) Access under 45 C.F.R. § 164.524. Ressa will make PHI in a Designated Record Set available to Covered Entity, or at Covered Entity’s direction to the Individual or the Individual’s designee, within ten (10) business days of Covered Entity’s written request, in the electronic form and format requested if readily producible and otherwise in a readable electronic form, so that Covered Entity may meet its obligations under 45 C.F.R. § 164.524.
(b) Amendment under 45 C.F.R. § 164.526. Ressa will make PHI in a Designated Record Set available for amendment and will incorporate an amendment directed by Covered Entity within ten (10) business days of Covered Entity’s written request.
(c) Accounting under 45 C.F.R. § 164.528. Ressa will document, and retain for six (6) years, the Disclosures of PHI and the information relating to those Disclosures that Covered Entity would be required to include in an accounting under 45 C.F.R. § 164.528, and will provide that documentation to Covered Entity within ten (10) business days of a written request, so that Covered Entity may respond within the time the rule allows.
(d) Requests Received Directly by Ressa. If Ressa receives a request from an Individual that properly belongs to Covered Entity, Ressa will not respond substantively and will route it to Covered Entity within five (5) business days, together with the information Covered Entity needs to respond. Section 6.8 of the Services Agreement governs the allocation of these requests, and Ressa’s separate obligations to the Individual under the Individual Terms are unaffected.
(e) Designated Record Set. Covered Entity will inform Ressa in writing which categories of information in the Service Covered Entity treats as part of its Designated Record Set. Absent that designation, Ressa will treat all PHI it maintains for Covered Entity in the Service as part of the Designated Record Set for purposes of subsections (a) and (b).
A.8 Availability to the Secretary
Ressa will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary for purposes of determining Covered Entity’s compliance with the Privacy Rule, in the time and manner designated by the Secretary. Ressa will notify Covered Entity of any such request promptly, unless prohibited from doing so, and will provide Covered Entity with a copy of what it produces. This Section implements 45 C.F.R. § 164.504(e)(2)(ii)(I).
A.9 Obligations of Covered Entity
(a) Covered Entity will notify Ressa of any limitation in its Notice of Privacy Practices, and of any change to that notice, to the extent the limitation or change affects Ressa’s permitted Uses or Disclosures.
(b) Covered Entity will notify Ressa of any change in, or revocation of, an Individual’s permission to Use or Disclose PHI, and of any restriction Covered Entity has agreed to under 45 C.F.R. § 164.522, in each case to the extent it affects Ressa’s permitted Uses or Disclosures, and subject to Section A.3(i).
(c) Covered Entity will obtain any consent, authorization, or permission required by law for Ressa’s Uses and Disclosures under this BAA and the Services Agreement.
(d) Covered Entity is responsible for permissions and notices required for its own activities, except that Ressa will obtain and administer the patient permissions expressly delegated under Section 6.10 of the Service Agreement. Each party remains responsible for its assigned functions and for acting within a valid permission. Covered Entity will provide the practice identity, upstream restrictions and other information reasonably required for Ressa to perform the delegated administration.
(e) Covered Entity will not request that Ressa Use or Disclose PHI in a manner that would violate the Privacy Rule if done by Covered Entity, except where Section A.3(c) or A.3(d) permits it.
(f) Covered Entity is responsible for the security of its own systems, credentials, devices, and workforce, and for the PHI it downloads or exports from the Service, as provided in Sections 5 and 6.8 of the Services Agreement.
(g) Covered Entity will not place in the Service records subject to 42 C.F.R. Part 2 except as Section 6.7 of the Services Agreement permits, and will not place psychotherapy notes in the Service.
A.10 Term and Termination
(a) Term. This BAA begins on the Effective Date of the Services Agreement and continues until the later of the termination of the Services Agreement and the date Ressa returns or destroys all PHI, or, where return or destruction is infeasible, indefinitely as to the PHI Ressa retains, in accordance with subsection (d).
(b) Termination for Cause by Covered Entity. Covered Entity may terminate this BAA and the Services Agreement if Ressa materially breaches this BAA and fails to cure the breach within thirty (30) days after written notice, or immediately if cure is not possible. If neither termination nor cure is feasible, Covered Entity will report the violation to the Secretary.
(c) Termination for Cause by Ressa. Ressa may terminate this BAA and the Services Agreement if Covered Entity materially breaches this BAA and fails to cure within thirty (30) days after written notice, or immediately where the breach presents an ongoing risk to PHI.
(d) Return or Destruction of PHI. On termination, Ressa will return or destroy all PHI that Ressa or its Subcontractors still maintain in any form, and retain no copies, within sixty (60) days, subject to the export window in Sections 6.6 and 18.5 of the Services Agreement and to subsection (e). Destruction will be performed in a manner consistent with NIST Special Publication 800-88 or an equivalent standard, and Ressa will certify destruction in writing on Covered Entity’s request.
(e) When Return or Destruction Is Infeasible. Where return or destruction of PHI is infeasible, including PHI in encrypted backups pending ordinary rotation, PHI Ressa is Required by Law to retain, PHI that is subject to Ressa’s retention policy and PHI that is inseparable from an Individual’s own record which the Individual is entitled to keep under the Individual Terms, Ressa will extend the protections of this BAA to that PHI for as long as Ressa retains it, and will limit further Uses and Disclosures of it to those purposes that make the return or destruction infeasible. This subsection implements 45 C.F.R. § 164.504(e)(2)(ii)(J).
(f) De-Identified Information. De-Identified Information created before termination is not PHI, is not returned or destroyed under this Section, and remains subject to Section 13 of the Services Agreement.
(g) Survival. Sections A.3(e), A.5(e), A.6(b), A.8, A.10(d) through (g), and A.11 survive termination.
A.11 Miscellaneous
(a) Regulatory References; Amendment. A reference in this BAA to a section of HIPAA means that section as in effect or as amended. The parties will negotiate in good faith to amend this BAA as necessary for either party to comply with a change in HIPAA or in other applicable law. This BAA may be amended only in a writing signed or electronically accepted by both parties.
(b) Interpretation. Any ambiguity in this BAA is resolved to permit the parties to comply with HIPAA. In the event of a conflict between this BAA and the Services Agreement as to the Use, Disclosure, or safeguarding of PHI, this BAA controls.
(c) Liability. The limitations of liability in Section 21 of the Services Agreement apply to claims arising under this BAA. Nothing in this BAA creates a right of indemnification other than as provided in Section 22 of the Services Agreement.
(d) No Third-Party Beneficiaries. Nothing in this BAA confers any right on any person other than the parties and, as expressly provided in Section A.8, the Secretary.
(e) Notices. Notices under this BAA are given as provided in Section 26.8 of the Services Agreement. Notice of a Breach or Security Incident under Section A.5 must be given by email and by telephone where a telephone contact has been provided.
EXHIBIT B
GLOBAL DATA PROCESSING ADDENDUM
This Global Data Processing Addendum (“DPA”) supplements and is made a part of the Ressa Health Professional Master Services Agreement (the “Services Agreement”) between Metabolic Terrain Omics, Inc. d/b/a Ressa Health (“Ressa”) and the Professional identified in the Services Agreement (“Professional”). It applies whenever Ressa Processes Professional Health Data on Professional’s behalf and an Applicable Data Protection Law other than, or in addition to, HIPAA governs that Processing. It may apply concurrently with Exhibit A. To the extent Ressa acts as a processor, service Professional, contractor, or equivalent regulated recipient for Professional, the subject matter of the Processing is Professional’s use of the Service; the duration is the Term plus any lawful retention period; the nature and purpose are hosting, organization, parsing, analysis, display, transmission, support, security, backup, and other operations needed to provide the Service on Professional’s documented instructions; the data subjects are Connected Individuals and other persons whose information Professional lawfully submits; and the data may include identifiers, contact information, account information, health and medical records, laboratory and genetic information, biometric information, professional notes, device information, and other sensitive or special-category data described in the Services Agreement.
B.1 Nature and Scope of Data Processing Addendum
This DPA is intended to satisfy processor/service-Professional contracting requirements under Applicable Data Protection Law, including, where applicable, the EU GDPR, UK GDPR, Canadian federal and provincial privacy laws, Québec privacy and health-information laws, United States state consumer health and privacy laws, and analogous laws in other jurisdictions. The terminology used by those laws varies; this DPA is to be interpreted to give effect to the legally equivalent role and obligation. If an Applicable Data Protection Law imposes a stricter mandatory requirement, that requirement controls to the extent of the conflict.
B.2 Definitions
“Professional Health Data” has the meaning given in Section 2 of the Services Agreement and includes Personal Data that Ressa Processes on Professional’s behalf.
“Controller,” “Processor,” “Personal Data,” “Process” or “Processing,” and “Data Subject” have the meanings given in the Applicable Data Protection Law, and include legally equivalent concepts such as business/service Professional, organization/service Professional, health information custodian/agent, trustee/contractor, or responsible person/processor.
“Personal Data Breach” or “Security Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Professional Health Data, or any equivalent event that Applicable Data Protection Law requires to be reported or assessed.
“Restricted Transfer” means a transfer or disclosure of Personal Data to a country, territory, organization, or recipient for which Applicable Data Protection Law requires an adequacy decision, standard contractual clauses, transfer addendum, transfer risk assessment, privacy impact assessment, consent, authorization, or other transfer safeguard.
B.3 Processing Instructions and Use Restrictions
Ressa will Process Professional Health Data only on Professional’s documented instructions as set out in the Services Agreement, this DPA, an Order Form, or another written instruction accepted by Ressa, unless Applicable Data Protection Law requires otherwise. If law requires Processing beyond Professional’s instructions, Ressa will inform Professional before the Processing unless law prohibits notice. Ressa will promptly inform Professional if, in Ressa’s reasonable view, an instruction infringes Applicable Data Protection Law. Ressa will not sell Professional Health Data, share it for cross-context behavioral or targeted advertising, use it to build a profile for unrelated commercial purposes, or use it for Ressa’s independent marketing. Ressa may Process Professional Health Data for security, fraud prevention, legal compliance, and service administration only to the extent permitted for a processor, service Professional, contractor, or equivalent recipient under Applicable Data Protection Law.
B.4 Confidentiality, Security, and Subprocessors
Ressa will ensure that personnel authorized to Process Professional Health Data are bound by confidentiality obligations, receive appropriate privacy and security training, and access the data only on a need-to-know basis. Ressa will implement the technical and organizational measures in Section 12 and Section A.4, adapted to Professional Health Data, taking into account the nature, scope, context, purposes, and risks of Processing. Professional gives Ressa general authorization to use subprocessors needed to provide the Service. Ressa will impose written obligations on each subprocessor that are no less protective than the relevant obligations in this DPA, remain responsible for the subprocessor’s Processing to the extent required by law and this Agreement, and maintain an up-to-date subprocessor list. Where Applicable Data Protection Law requires advance notice or an opportunity to object, Ressa will provide at least thirty (30) days’ notice of a material new subprocessor that will Process Professional Health Data, and Professional may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Professional may terminate the affected Service without penalty and receive a pro-rata refund of prepaid fees for the unused affected period.
B.5 Personal Data Breach Notification and Cooperation
(a) Ressa will notify Professional of a Personal Data Breach or Security Breach involving Professional Health Data without undue delay after becoming aware of it and, where reasonably practicable, within forty-eight (48) hours. Ressa may provide information in phases and will not delay the initial notice because all facts are not yet known. The notice will include the information described in Section A.5(c) to the extent known and any additional information reasonably required by Applicable Data Protection Law.
(b) As between the parties, Professional is responsible for determining whether notice to Data Subjects, patients, supervisory authorities, privacy commissioners, health regulators, consumer-protection authorities, or other persons is required for Processing for which Professional is the controller or equivalent regulated entity, and for making those notifications unless Applicable Data Protection Law places the duty directly on Ressa. Ressa will provide reasonable cooperation and information so Professional can meet any deadline, including a seventy-two-hour or shorter regulatory deadline where applicable. Ressa will make any notification that law independently requires Ressa to make and, where legally permitted, will coordinate with Professional before doing so. Section 22.2(b) of the Services Agreement governs cost allocation.
(c) Ressa will take reasonable steps to contain, investigate, mitigate, and remediate a Personal Data Breach or Security Breach, preserve relevant evidence and logs, and provide Professional with reasonable updates. Each party will cooperate with the other in responding to Data Subject requests, complaints, regulatory inquiries, and investigations arising from the incident.
B.6 Anonymization, De-Identification, and Secondary Use
Ressa may anonymize or de-identify Professional Health Data only as permitted by Section 13 and Applicable Data Protection Law and only to the extent Professional has authority to permit that Processing. Information is outside this DPA only when it no longer constitutes Personal Data, PHI, or otherwise regulated information under the Applicable Data Protection Law. Pseudonymized, coded, or HIPAA-de-identified information that remains Personal Data under another applicable law remains protected by this DPA. Professional is responsible for ensuring that any consent, authorization, lawful basis, special-category condition, ethics approval, or other permission required for Professional’s instructions has been obtained. Law. Ressa will not sell identified or identifiable Provider Health Data or disclose identifiable health or genetic information to sponsors or advertising platforms under the optional program. Ressa may administer patient permissions under Section 6.10 and use Provider Health Data for personalized marketing only within the applicable effective patient authorization and law. The creation and licensing of qualifying deidentified datasets are subject to Section 13.
B.7 Data Subject Rights; DPIAs and Regulatory Assistance
Taking into account the nature of the Processing, Ressa will provide reasonable assistance, through appropriate technical and organizational measures where feasible, to enable Professional to respond to requests to access, correct, amend, delete, restrict, object, withdraw consent, obtain a copy of, or port Professional Health Data, and to requests concerning automated processing, as required by Applicable Data Protection Law. Ressa will route to Professional without undue delay any request it receives that properly belongs to Professional and will not respond substantively except on Professional’s documented instruction or where law requires Ressa to respond. Ressa will also provide information reasonably necessary for Professional to conduct a data-protection impact assessment, privacy impact assessment, transfer risk assessment, prior consultation, or comparable assessment concerning the Service, including assessments required for sensitive health information or cross-border transfers.
B.8 Professional’s Instructions and Compliance Obligations
Professional represents and warrants that its instructions to Ressa are lawful and that Professional has identified an appropriate lawful basis for the Processing and, where required, an additional condition for health, genetic, biometric, or other sensitive or special-category data. Professional is responsible for providing required privacy notices; obtaining any consent or authorization that applicable law requires; honoring professional secrecy and confidentiality duties; ensuring data accuracy and minimization; establishing retention periods; maintaining required records; conducting required impact or transfer assessments; and complying with local hosting, localization, medical-record, and professional rules. Ressa does not obtain those Professional-specific permissions on Professional’s behalf, and an Individual’s acceptance of the Individual Terms is not a substitute for a permission Professional is independently required to obtain.
B.9 Term, Return or Deletion, Audit, and Compliance Information
This DPA begins on the Effective Date of the Services Agreement and continues for so long as Ressa Processes Professional Health Data on Professional’s behalf. On termination or on Professional’s lawful written instruction, Ressa will return or delete Professional Health Data as required by Applicable Data Protection Law, subject to the export window and lawful retention exceptions in the Services Agreement and Exhibit A. Ressa will make available to Professional information reasonably necessary to demonstrate compliance with processor/service-Professional obligations under Applicable Data Protection Law and, where required by law, permit and contribute to a reasonable audit or inspection by Professional or an independent auditor bound by confidentiality. Unless a regulator or law requires otherwise, audits must be on reasonable advance notice, no more than once annually, during normal business hours, scoped to relevant controls, and conducted to avoid unreasonable disruption or access to another customer’s information. Professional will first use current third-party audit reports, certifications, and security documentation where they reasonably satisfy the request. If Professional becomes or ceases to be a Covered Entity or Business Associate, the applicability of Exhibit A changes accordingly, but this DPA continues whenever another Applicable Data Protection Law applies.
B.10 International and Cross-Border Transfers
Professional acknowledges that Ressa hosts Professional Health Data in the United States as stated in Section 12.1(b), so use of the Service from another jurisdiction may involve a Restricted Transfer. The parties will use any transfer mechanism required by Applicable Data Protection Law. For transfers subject to the EU GDPR that require safeguards under Article 46 and are not covered by an applicable adequacy decision or another lawful mechanism, the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 (“EU SCCs”) are incorporated by reference: Module 2 (controller to processor) applies when Professional is a controller and Ressa is a processor; Module 3 (processor to processor) applies when Professional is a processor and Ressa is a subprocessor. Clause 7 applies; for Clause 9, Option 2 general authorization applies with the thirty-day notice in Section B.4; the optional language in Clause 11 does not apply; for Clauses 17 and 18, the law and courts of Ireland apply unless the EU SCCs require another eligible Member State. The parties, Processing description, data-subject categories, data categories, sensitive data, frequency, purpose, retention, subprocessors, and security measures are deemed completed by the Services Agreement, the applicable Order Form, this DPA, Section 12, and Ressa’s then-current subprocessor list. For a Restricted Transfer subject to the UK GDPR, the then-current ICO-approved International Data Transfer Addendum to the EU SCCs is incorporated to the extent necessary, with Professional as exporter and Ressa as importer and the same Processing details, and the parties will complete any required data-protection test or transfer risk assessment. For Canadian transfers, Ressa will protect Professional Health Data under this DPA and provide reasonable information to support Professional’s accountability and cross-border risk assessment obligations. For a Québec Professional, Professional remains responsible for any privacy impact assessment and written-agreement requirements applicable before communicating or entrusting personal or health information outside Québec, and Ressa will reasonably cooperate with that assessment. For any other jurisdiction, the parties will execute or incorporate a legally required transfer mechanism or supplemental term where reasonably necessary. If no lawful transfer mechanism can be implemented, Ressa may suspend the affected Processing and Professional may terminate the affected Service without penalty. Mandatory transfer terms control over conflicting terms of the Services Agreement to the extent required by law.
