Legal
Terms of Service
Effective date: July 23, 2026
These Terms of Service (“Terms”) are a legally binding agreement between you (“Customer”) and Medera, Inc. (“Medera”) governing your access to and use of Medera’s AI-powered behavioral health platform and all related services (the “Services”). By accessing the Services, executing an Order Form that references these Terms, or clicking “I Agree,” you agree to be bound by these Terms, our Privacy Policy, and any applicable BAA, DPA or SLA incorporated by reference. If you enter these Terms on behalf of an organization, you represent that you have authority to bind it.
Definitions
- “Services” means Medera’s AI-powered behavioral health platform, including all software, APIs, mobile applications, documentation and related professional services.
- “Healthcare Provider” means any licensed medical professional, behavioral health clinician or authorized representative of a healthcare organization that accesses the Services.
- “PHI” has the meaning ascribed under HIPAA (45 CFR § 160.103), including individually identifiable health information created, received, maintained or transmitted through the Services.
- “Covered Entity” means a health plan, healthcare clearinghouse or healthcare provider that transmits health information electronically, as defined in 45 CFR § 160.103.
- “BAA” means the Business Associate Agreement between Medera and the Covered Entity governing PHI, as required by HIPAA.
- “Order Form” means the document specifying the Services purchased, subscription tier, pricing and term, incorporating these Terms.
- “Customer Data” means all data, including PHI, that Customer or its authorized users upload, transmit or create through the Services.
- “De-identified Data” means data processed to meet the HIPAA Safe Harbor (45 CFR § 164.514(b)) or Expert Determination (45 CFR § 164.514(a)) standard.
- “SLA” means the Service Level Agreement setting forth uptime commitments, performance benchmarks, support response times and service credit remedies.
Eligibility & account
Access to clinical features is restricted to licensed healthcare providers, behavioral health clinicians and authorized staff of healthcare organizations. You represent and warrant that you hold all licenses, certifications and credentials required to practice in your jurisdiction and to use the Services as contemplated.
Account security
- Use multi-factor authentication as required by the platform
- Do not share credentials or allow unauthorized access to your account
- Notify Medera immediately upon discovery of any unauthorized use or security breach
- Ensure all users under your organization's account comply with these Terms
Enterprise accounts must designate at least one administrator authorized to manage user access, configure settings and serve as the primary contact for security and compliance matters.
Acceptable use & prohibited conduct
You agree to use the Services only for lawful purposes and in accordance with all applicable laws, regulations and professional standards, including HIPAA and applicable medical practice acts: solely for authorized clinical, administrative or operational purposes; with proper patient consent or authorization for all PHI; in compliance with published usage policies, rate limits and fair-use guidelines; and reporting any discovered vulnerabilities promptly through responsible disclosure.
You shall not, and shall not permit any third party to:
- Reverse engineer, decompile or attempt to derive the source code of any Medera software or algorithms
- Use the Services to develop a competing product, or for benchmarking without prior written consent
- Access or attempt to access any other customer's data, accounts or systems
- Introduce malicious code or harmful technology into the Services
- Use bots, scrapers or crawlers except through authorized APIs
- Circumvent or interfere with security, authentication or access controls
- Use the Services in any manner that violates HIPAA or other healthcare regulations
- Resell, sublicense or make the Services available to third parties without prior written consent
Clinical use & medical disclaimer
- Healthcare providers retain full and sole responsibility for all patient care decisions, diagnoses and treatment plans
- AI-generated outputs must be independently validated by a qualified clinician before use in patient care
- The Services do not constitute medical advice, diagnosis or treatment, and are not a substitute for professional consultation
- Medera does not practice medicine; no provider-patient relationship is created between Medera and any patient
- In a clinical emergency, providers must follow established emergency protocols and not rely solely on platform outputs
HIPAA & Business Associate Agreement
Where Customer is a Covered Entity or Business Associate under HIPAA, the parties shall execute a BAA before Customer transmits any PHI to Medera. The BAA is incorporated into these Terms by reference. Key provisions include:
- Permitted uses and disclosures of PHI limited to performing the Services and as required by law
- Administrative, physical and technical safeguards compliant with the HIPAA Security Rule
- Prompt reporting of security incidents and breaches of unsecured PHI per regulatory timelines
- Subcontractor flow-down: all subcontractors with PHI access must agree to equivalent obligations
- Return or destruction of PHI upon termination, with certification of destruction upon request
- Availability of internal practices, books and records to the HHS Secretary for compliance assessment
- Obligation to mitigate any harmful effect of impermissible use or disclosure of PHI
Data privacy & security
Medera maintains an enterprise-grade security program validated by independent third-party evaluation:
- Encryption. AES-256-GCM at rest with HSM-backed key management and 90-day rotation; TLS 1.3 in transit with forward secrecy.
- Access controls. Role-based access with least privilege, MFA for all users, just-in-time provisioning for administrative operations.
- Infrastructure. Zero-trust architecture, WAF, DDoS mitigation, IDS/IPS, micro-segmentation and tenant isolation at all layers.
- Monitoring. 24/7/365 SOC monitoring, automated vulnerability scanning, annual independent penetration testing and a responsible disclosure program.
For details, see our Privacy Policy and Compliance & Safety pages. Where required by applicable data protection law, Medera will enter into a Data Processing Addendum covering the subject matter and duration of processing, sub-processor management, Standard Contractual Clauses for international transfers, and data return and deletion. Request our standard DPA at hi@medera.info.
Service Level Agreement
- Availability. 99.9% monthly uptime commitment for production environments, excluding scheduled maintenance windows.
- Maintenance. At least 72 hours advance notice; performed off-peak (Saturday 02:00 to 06:00 ET) whenever possible.
- Support response. Severity 1 (production down): 15-minute initial response with continuous effort. Severity 2: 1 hour. Severity 3: 4 hours. Severity 4: 1 business day.
- Service credits. Uptime below 99.9%: 10% credit. Below 99.0%: 25%. Below 95.0%: 50%. Credits apply to the next invoice; maximum credit 50% of monthly fees.
- Recovery objectives. RTO of four (4) hours for critical services; RPO of one (1) hour for all Customer Data and PHI; disaster recovery tested at least annually.
SLA commitments do not apply to downtime caused by factors outside Medera’s reasonable control, Customer’s equipment or network failures, Customer’s breach of these Terms, scheduled maintenance, or features designated beta or preview.
Intellectual property
- Medera IP. Medera and its licensors retain all right, title and interest in the Services, platform, algorithms, models, documentation and all improvements. Nothing in these Terms transfers Medera intellectual property to Customer.
- Customer Data. Customer retains all right, title and interest in Customer Data, and grants Medera a limited, non-exclusive license to use it solely to provide the Services and as permitted under the BAA.
- De-identified data. Medera may create De-identified Data in accordance with HIPAA standards and retains all rights to it for product improvement, research and other lawful purposes. De-identified Data will not be re-identified.
- Feedback. Medera may use suggestions and feature requests without restriction; feedback is not Customer Confidential Information.
Payment terms
- Subscription fees are specified in the Order Form and billed in advance, monthly or annually, in U.S. dollars
- Invoices are payable Net 30 unless the Order Form specifies otherwise; late payments accrue interest at the lesser of 1.5% per month or the maximum lawful rate
- Renewal pricing adjustments require at least sixty (60) days written notice before the renewal period
- Fees are exclusive of taxes; Customer is responsible for all taxes except taxes on Medera's net income
- Fees are non-refundable except as provided in the SLA, in the event of material breach by Medera, or as required by law
Confidentiality
Each party protects the other’s Confidential Information with at least the care it uses for its own, and never less than a reasonable standard. Confidential Information is used only to perform obligations under these Terms, disclosed only to those with a need to know under equivalent obligations, and never disclosed to third parties without consent except as required by law with prompt notice.
Standard exclusions apply (publicly available information, prior knowledge, independent development, lawful third-party receipt). Confidentiality obligations survive termination for five (5) years; obligations for PHI and trade secrets survive indefinitely or as required by law.
Indemnification
By Medera
Medera will defend and indemnify Customer against third-party claims arising from: infringement of third-party intellectual property rights by the Services as provided; Medera’s material breach of confidentiality obligations or the BAA; or Medera’s gross negligence or willful misconduct in handling PHI.
By Customer
Customer will defend and indemnify Medera against third-party claims arising from: Customer Data or use of the Services in violation of these Terms or law; failure to obtain required patient consents; or clinical decisions made by Customer’s providers. The indemnified party must give prompt notice, grant sole control of defense, and cooperate reasonably; no settlement may impose obligations on the indemnified party without consent.
Limitation of liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, including lost profits, revenue, data or business interruption, regardless of the theory of liability.
- Aggregate cap. Except for indemnification obligations, breach of confidentiality, or willful misconduct, each party’s total liability shall not exceed the greater of (a) fees paid or payable in the twelve months preceding the event, or (b) one hundred thousand U.S. dollars ($100,000).
- Super cap. For claims arising from breach of the BAA, unauthorized disclosure of PHI, or breach of confidentiality, each party’s aggregate liability shall not exceed two times (2x) the fees paid or payable in the preceding twelve months.
- Exclusions. Nothing limits liability for fraud or intentional misrepresentation, death or personal injury caused by negligence, liability that cannot be excluded by law, or Customer’s obligation to pay fees.
Warranties & disclaimers
Medera warrants that the Services will materially conform to the applicable documentation during the subscription term; will be provided in a professional and workmanlike manner consistent with industry standards; that Medera will maintain commercially reasonable security measures consistent with HIPAA and industry best practices; and that Medera will comply with applicable law in providing the Services.
Except as expressly provided, the Services are provided “as is” and “as available.” Medera disclaims all other warranties, express, implied or statutory, including merchantability, fitness for a particular purpose, title and non-infringement, and does not warrant that the Services will be uninterrupted, error-free or completely secure.
Term & termination
- Term & renewal. The initial term is specified in the Order Form and renews automatically for successive periods (equal to the initial term or one year, whichever is shorter) unless either party gives sixty (60) days notice of non-renewal.
- For convenience. Either party may terminate on sixty (60) days written notice; pre-paid fees for the remaining term are non-refundable if Customer terminates for convenience.
- For cause. Either party may terminate immediately for uncured material breach (thirty days to cure; ten days for payment defaults), insolvency, or where continued performance would violate law.
- Effect. Licenses terminate immediately; Customer Data including PHI is returned in a standard machine-readable format or securely destroyed, at Customer’s election, within thirty (30) days, with a certificate of destruction on request; surviving sections (confidentiality, indemnification, limitation of liability, governing law) and outstanding payment obligations survive.
Audit rights
- Enterprise customers may audit Medera's compliance with the BAA, these Terms and applicable law once per twelve-month period (more if a breach has occurred), on thirty (30) days notice
- Audits occur during business hours, at Customer's expense, minimizing disruption to operations
- Medera will provide its current SOC 2 Type II audit status (and report upon completion), penetration test executive summary and other compliance documentation as a reasonable alternative to on-site audits
- Audit findings are Medera Confidential Information
- Material non-compliance triggers a remediation plan within thirty (30) days and corrective action on a mutually agreed timeline
Dispute resolution
These Terms are governed by the laws of the State of Delaware, without regard to conflict-of-law principles. The parties will first attempt good-faith negotiation for thirty (30) days, then executive escalation for a further thirty (30) days. Any unresolved dispute is finally settled by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, before a single arbitrator in Wilmington, Delaware. Either party may seek injunctive relief in any court of competent jurisdiction to prevent irreparable harm, including for breaches of confidentiality, intellectual property or unauthorized disclosure of PHI.
Force majeure & insurance
Neither party is liable for failure or delay caused by circumstances beyond its reasonable control, including natural disasters, pandemics, war, government actions, power failures or telecommunications failures. The affected party must give prompt notice and mitigate. If a force majeure event continues more than ninety (90) consecutive days, either party may terminate the affected Order Form without liability. Force majeure does not excuse payment for Services already delivered and does not relieve either party of its obligations to protect PHI.
Insurance
- Commercial General Liability: not less than $2,000,000 per occurrence and $4,000,000 aggregate
- Professional Liability / Errors & Omissions: not less than $5,000,000 per claim and aggregate
- Cyber Liability / Technology E&O: not less than $5,000,000 per claim and aggregate, covering breach response, regulatory proceedings and network security liability
- Workers' Compensation: as required by applicable law; certificates of insurance available upon request
General provisions
- Entire agreement. These Terms, together with all Order Forms, the BAA, DPA, SLA and executed amendments, constitute the entire agreement and supersede all prior understandings.
- Amendment. Amendments require a signed writing, except that Medera may update these Terms for non-material changes with thirty (30) days written notice.
- Assignment. Neither party may assign without consent, except in connection with a merger, acquisition or sale of substantially all assets.
- Severability & waiver. Invalid provisions are reformed minimally; failure to enforce is not a waiver; waivers must be written.
- Notices. Legal notices in writing by certified mail, overnight courier or email with confirmation, effective on receipt.
- Relationship. The parties are independent contractors; no partnership, joint venture, employment or agency is created, and there are no third-party beneficiaries.
- Export & anti-corruption. Customer complies with export control and sanctions laws; each party complies with applicable anti-corruption laws including the U.S. FCPA.
SMS Terms & Conditions
Medera Health Care-Team Notifications, effective July 23, 2026. These terms govern the Medera Health text messaging program, which helps patients verify insurance coverage and coordinate care with their clinical team, including California Medi-Cal members and other patients. See also the SMS program page.
- 1. Program description. Opted-in patients receive care-related messages: secure insurance-card verification links, appointment reminders and follow-ups, and care-team notifications. The program does not send marketing or promotional messages.
- 2. Opting in. Consent is given either (a) verbally during a call with our care team, where permission is asked, the mobile number is read back, and required disclosures are stated before any message is sent; or (b) by texting START to (681) 432-3260. Consent is not a condition of receiving care or any service.
- 3. Message frequency. Frequency varies, typically 1 to 4 messages per care interaction; this is not a recurring subscription.
- 4. Cost. Message and data rates may apply per your carrier plan.
- 5. Opting out. Text STOP to (681) 432-3260 at any time; one final message confirms unsubscription. Text START to rejoin.
- 6. Help. Reply HELP, or reach us at (681) 432-3260 or hi@medera.info.
- 7. Carriers. Carriers are not liable for delayed or undelivered messages.
- 8. Privacy. See our Privacy Policy. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
Contact
For questions regarding these Terms, contact our legal team at hi@medera.info or visit our contact page. Our legal team is available to discuss any aspect of these Terms, negotiate enterprise agreements, or provide additional documentation.
Questions about this document?
Our privacy and legal team responds to verified requests within thirty days, and usually much sooner.