Including Business Associate Agreement at Article 14
ilumenIQ LLC
Please read this agreement carefully before creating an account or accessing the ilumenIQ platform. By typing your full legal name and clicking “I agree” or an equivalent control during account creation, the individual completing registration: (1) accepts this agreement on behalf of the practice or organization identified during account creation; (2) represents and warrants that he or she has legal authority to bind that practice or organization; (3) executes the business associate agreement set forth in Article 14 on behalf of that practice or organization as a covered entity under HIPAA; and (4) acknowledges that this agreement is a legally binding contract. This agreement contains a mandatory arbitration provision and class action waiver at Article 16 and a limitation of liability at Article 12. If you do not have authority to bind the practice or organization, or if it does not agree to these terms, do not complete account creation.
Article 1 — Formation, Acceptance, and Precedence
1.1 Parties. This Master Subscription and License Agreement (this “Agreement”) is entered into as of the date Customer completes account creation and accepts it (the “Effective Date”) by and between ilumenIQ LLC, a North Carolina limited liability company having its principal office at 1235 East Blvd, Suite E519, Charlotte, North Carolina 28203 (“ilumenIQ”), and the practice or organization identified during account creation (“Customer”). ilumenIQ and Customer are each a “Party” and together the “Parties.”
1.2 Manner of Acceptance. Customer accepts this Agreement by causing an authorized individual to type that individual’s full legal name in the signature field presented during account creation and to click the acceptance control. That typed name constitutes the electronic signature of Customer within the meaning of N.C. Gen. Stat. § 66-312 and the Electronic Signatures in Global and National Commerce Act, 15 U.S.C. § 7001 et seq., and originates from an affirmative act evidencing acceptance and execution. ilumenIQ maintains a record of each acceptance, including the typed name, the identity of the accepting individual, the date and time of acceptance, and the version of this Agreement accepted.
1.3 Authority. The individual accepting this Agreement represents and warrants that Customer is a validly existing legal entity, that the individual is authorized to bind Customer, and that Customer’s acceptance and performance of this Agreement violate no law and no agreement to which Customer is a party.
1.4 Business Associate Agreement. Article 14 of this Agreement constitutes a business associate agreement required by 45 C.F.R. §§ 164.308(b) and 164.504(e). By accepting this Agreement, Customer, as a Covered Entity, simultaneously executes that business associate agreement with ilumenIQ as its Business Associate. ilumenIQ will not receive, create, maintain, or transmit Protected Health Information on Customer’s behalf before this Agreement has been accepted.
1.5 Order of Precedence. This Agreement, together with the Subscription Plan selected at account creation, Exhibit A, the End User License Agreement, and the Privacy Policy published at ilumeniq.com/legal/privacy-policy, constitutes the entire agreement between the Parties. In the event of conflict, the order of precedence is: (a) Article 14 of this Agreement, as to Protected Health Information; (b) the remainder of this Agreement, including Exhibit A; (c) the Subscription Plan selected at account creation; (d) the Privacy Policy; and (e) the End User License Agreement.
1.6 Revisions. ilumenIQ may revise this Agreement. If ilumenIQ makes a material revision, ilumenIQ will notify Customer by email and through the Platform not less than thirty (30) days before the revision takes effect and will require Customer to accept the revised Agreement at next administrator login. If Customer declines a material revision, Customer may terminate this Agreement effective on the date the revision would take effect. ilumenIQ may revise Article 14 as necessary to conform to changes in HIPAA upon reasonable prior notice, and such revisions take effect without further action by Customer. No revision applies retroactively to any claim that has accrued.
Article 2 — Definitions
2.1 “Authorized User”. means an individual employee, contractor, owner, or agent of Customer whom Customer designates to access the Platform on Customer’s behalf and who has accepted the End User License Agreement.
2.2 “Client Data”. means the data records maintained on the Platform relating to Customer’s individual clients and patients, comprising the elements listed in Part I of Exhibit A.
2.3 “Connected System”. means any third-party electronic health record, practice management, scheduling, billing, accounting, payroll, or other system of Customer from which data is transmitted to, or retrieved by, the Platform.
2.4 “Customer Data”. means all data, content, and information submitted to, retrieved for, or processed through the Platform by or on behalf of Customer, including Client Data and PHI.
2.5 “Documentation”. means the user guides, help materials, in-product instructions, and usage policies made available by ilumenIQ describing the operation and permitted use of the Platform.
2.6 “HIPAA”. means the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act of 2009, and the regulations promulgated thereunder at 45 C.F.R. Parts 160 and 164, each as amended.
2.7 “PHI”. means Protected Health Information as defined at 45 C.F.R. § 160.103, as applied to information created, received, maintained, or transmitted by ilumenIQ on behalf of Customer.
2.8 “Platform”. means ilumenIQ’s proprietary software-as-a-service application for practice data aggregation, dashboarding, reporting, and analytics, together with all updates, enhancements, and modifications made available to Customer, and the Documentation.
2.9 “Services”. means access to and use of the Platform and any support furnished by ilumenIQ under this Agreement.
2.10 “Subscription Fees”. means the fees for the Subscription Plan selected by Customer at account creation, as displayed on the plan selection screen at signup and as adjusted under Section 5.6.
2.11 “Subscription Plan”. means the subscription tier, billing cycle, and feature set selected by Customer at account creation, as displayed on the plan selection screen at signup, which is incorporated into this Agreement by reference.
2.12 “Subscription Term”. means the period commencing on the Effective Date and continuing for the billing cycle selected at account creation, together with each renewal term.
Article 3 — Access and License
3.1 License Grant. Subject to Customer’s compliance with this Agreement and payment of Subscription Fees, ilumenIQ grants Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable right and license to access and use the Platform during the Subscription Term solely for Customer’s internal business operations and in accordance with the Documentation.
3.2 Authorized Users. Customer may permit Authorized Users to access the Platform. Each Authorized User must have unique credentials and must accept the End User License Agreement at first login. Customer is responsible for the acts and omissions of its Authorized Users as if they were Customer’s own, and shall promptly revoke access for any individual who ceases to be employed by or affiliated with Customer or who violates this Agreement or the End User License Agreement.
3.3 Restrictions. Customer shall not, and shall not permit any Authorized User or third party to: (a) sublicense, sell, resell, rent, lease, transfer, assign, or otherwise make the Platform available to any third party; (b) modify, translate, adapt, or create derivative works of the Platform; (c) reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, data model, or metric methodologies of the Platform, except to the extent this restriction is unenforceable under applicable law; (d) access or use the Platform to build, improve, market, or benchmark a competing product or service; (e) use the Platform to store or transmit infringing, defamatory, unlawful, or tortious material, or malicious code; (f) interfere with or disrupt the integrity or performance of the Platform or the data of any other customer; (g) attempt to gain unauthorized access to the Platform or its related systems or networks, or to circumvent tenant isolation, authentication, rate limiting, or audit logging; or (h) use any bot, scraper, crawler, script, or other automated tool to access or interact with the Platform except as expressly authorized in writing by ilumenIQ.
3.4 Reservation of Rights. ilumenIQ reserves all rights not expressly granted. No license is granted by implication, estoppel, or otherwise.
Article 4 — Connected Systems and Credentialed Automated Access
4.1 Connection Methods. The Platform obtains Customer Data from Connected Systems by one or more of the following methods, as configured by Customer: (a) an application programming interface or native data connection published or licensed by the operator of the Connected System; (b) a file or report exported by Customer and uploaded by Customer to the Platform; or (c) Credentialed Automated Access, as described in Section 4.2.
4.2 Credentialed Automated Access Defined. Where the operator of a Connected System does not make an application programming interface or native data connection available to Customer, Customer may direct ilumenIQ to obtain Customer Data by “Credentialed Automated Access,” meaning an automated, scheduled process by which ilumenIQ authenticates to the Connected System using credentials and access rights furnished by Customer, navigates the Connected System’s user interface, generates or retrieves the reports Customer has configured, and transmits them to the Platform. Credentialed Automated Access is a fallback method used only where a published interface is unavailable.
4.3 Appointment of Agent; Customer Authorization. Customer grants Credentialed Automated Access authorization on a per-Connected-System basis through a separate in-product confirmation completed at connection setup. By completing that confirmation, Customer:
(a) appoints ilumenIQ as Customer’s limited agent and attorney-in-fact for the sole purpose of accessing the identified Connected System on Customer’s behalf, using Customer’s credentials and Customer’s own access rights, and retrieving the configured reports;
(b) represents and warrants that Customer has reviewed the terms of service, license agreement, acceptable use policy, and any applicable business associate agreement governing the identified Connected System, and has determined in Customer’s own judgment that Credentialed Automated Access as described in Section 4.2 is permitted thereunder;
(c) acknowledges that all activity conducted by ilumenIQ pursuant to that authorization is conducted at Customer’s direction and on Customer’s behalf, is deemed Customer’s own activity under the terms governing the Connected System, and is authorized access within the meaning of 18 U.S.C. § 1030 and comparable state law; and
(d) agrees to revoke the authorization promptly through the Platform if the determination in clause (b) ceases to be accurate, if Customer’s rights under the agreement governing the Connected System are modified, suspended, or terminated, or if the operator of the Connected System objects to the access.
4.4 No Representation of Authorization or Affiliation. ilumenIQ makes no representation, warranty, or determination that Credentialed Automated Access to any Connected System is permitted by the operator of that Connected System, and ilumenIQ does not independently assess the terms governing any Connected System. ilumenIQ is not affiliated with, sponsored by, endorsed by, certified by, or a partner of any operator of a Connected System, and Customer shall not represent otherwise. Any reference by ilumenIQ to the name or mark of a Connected System operator is nominative and made solely to identify compatibility.
4.5 Credential Handling. Credentials furnished by Customer for Credentialed Automated Access are stored in encrypted form, are used only to perform the report retrievals Customer has configured and at the frequency Customer has configured, and are not used for any other purpose. Customer shall, where the Connected System permits, furnish credentials for a dedicated service account holding only the least privilege necessary to generate the configured reports, and shall not furnish credentials associated with a clinician’s personal account. Customer is responsible for rotating credentials and for deprovisioning them upon revocation.
4.6 Minimum Necessary. ilumenIQ performs Credentialed Automated Access using the minimum access and frequency necessary to deliver the Services, limited to the report types and schedules configured by Customer. Customer, as the Covered Entity, is responsible for determining that each configured report is consistent with 45 C.F.R. § 164.502(b).
4.7 Revocation and Suspension. Customer may revoke any Credentialed Automated Access authorization at any time through the Platform’s connection management settings, effective promptly upon Customer’s action. Revocation does not affect data already retrieved. ilumenIQ may suspend Credentialed Automated Access to any Connected System immediately and without liability if the operator of that Connected System objects to the access, if the access appears to violate applicable law, or if the access presents a security risk.
4.8 Effect of Loss of a Connection. Customer acknowledges that a Connected System operator may at any time modify, restrict, or block access, that such action is outside ilumenIQ’s control, and that no service level, credit, or remedy arises from it. If Credentialed Automated Access to a Connected System is suspended under Section 4.7 or blocked by the operator and is not restored within thirty (30) days, either Party may terminate this Agreement upon written notice, and ilumenIQ shall refund Subscription Fees prepaid and allocable to the unexpired portion of the then-current Subscription Term. This is Customer’s sole and exclusive remedy for loss of a connection.
4.9 Indemnity. Customer’s indemnification obligation with respect to Connected Systems is set forth in Section 13.2.
Article 5 — Subscription Plan, Fees, and Payment
5.1 Plan Selection. At account creation Customer selects a Subscription Plan specifying features, billing cycle, and Subscription Fees. The Subscription Plan so selected is incorporated into this Agreement. Customer may change its Subscription Plan subject to availability and applicable pricing, effective at the start of the next billing cycle.
5.2 Subscription Fees. Customer shall pay the Subscription Fees associated with its Subscription Plan. All fees, except as expressly provided in Sections 1.6 and 4.8, are non-refundable.
5.3 Billing. Subscription Fees for annual plans are billed in advance at the commencement of each Subscription Term and each renewal term. Subscription Fees for month-to-month plans are billed in advance at the commencement of each monthly cycle. Payment is due upon billing. Customer authorizes ilumenIQ to charge the payment method on file for all Subscription Fees as they become due and shall maintain a valid payment method.
5.4 Taxes. Subscription Fees exclude sales, use, value-added, gross receipts, and similar taxes. Customer is responsible for all such taxes other than taxes on ilumenIQ’s net income.
5.5 Late Payment and Suspension. Amounts not paid when due accrue interest at one and one-half percent (1.5%) per month or the maximum rate permitted by applicable law, whichever is more, from the due date until paid. ilumenIQ may suspend access to the Platform upon thirty (30) days’ written notice if undisputed amounts remain past due. Suspension does not relieve Customer of accrued payment obligations and does not extend the Subscription Term.
5.6 Fee Adjustments. ilumenIQ may adjust Subscription Fees for any renewal term upon not less than sixty (60) days’ prior written notice. If Customer does not accept an adjustment, Customer may elect not to renew under Article 6.
Article 6 — Subscription Term and Renewal
6.1 Annual Subscriptions. Annual subscriptions renew automatically for successive one-year terms at the then-current Subscription Fees unless either Party gives written notice of non-renewal not less than thirty (30) days before the end of the then-current Subscription Term.
6.2 Month-to-Month Subscriptions. Month-to-month subscriptions renew automatically for successive monthly periods at the then-current Subscription Fees unless either Party gives written notice of non-renewal not less than thirty (30) days before the end of the then-current monthly period.
6.3 Renewal Reminder. ilumenIQ may send Customer written notice of each impending automatic renewal of an annual subscription, together with the applicable fees and the deadline for non-renewal, not less than thirty (30) and not more than sixty (60) days before the renewal date.
6.4 Early Termination of Annual Subscriptions. Customer may not terminate an annual subscription for convenience before the end of the applicable Subscription Term. If Customer terminates an annual subscription early for any reason other than ilumenIQ’s uncured material breach, or if ilumenIQ terminates for Customer’s uncured material breach, Customer remains liable for all Subscription Fees through the end of the then-current Subscription Term.
6.5 Switching Plans. Customer may switch between billing cycles or plan tiers effective at the start of the next billing cycle. A switch from an annual to a month-to-month plan mid-term is subject to Section 6.4.
Article 7 — Customer Responsibilities
7.1 Account Security. Customer is responsible for maintaining the confidentiality of all account credentials, for administering user provisioning and deprovisioning, for enforcing multi-factor authentication where available, and for all activity occurring under its account. Customer shall notify ilumenIQ promptly upon becoming aware of any unauthorized access to its account.
7.2 Data Accuracy and Lawful Acquisition. Customer is responsible for the accuracy, quality, and legality of Customer Data and for the means by which Customer acquired it. Customer acknowledges that Platform outputs are derived from Customer Data and from Connected Systems and are only as accurate, complete, and current as those sources.
7.3 HIPAA Compliance. Customer, as a Covered Entity, is solely responsible for its own compliance with HIPAA, including maintenance of its Notice of Privacy Practices, obtaining any necessary authorizations, performing its own risk analysis, honoring individual rights requests, and satisfying its own breach notification obligations. ilumenIQ’s status as Business Associate does not relieve Customer of any obligation.
7.4 Compliance With Other Law. Customer is responsible for compliance with all other applicable federal, state, and local law governing its practice and its client records, including any state statute governing the confidentiality of mental health records, professional licensure requirements, and any law of a state in which Customer operates that is more stringent than HIPAA.
7.5 Notification of Special Categories. Customer shall notify ilumenIQ in writing before transmitting to the Platform any data that is subject to (a) 42 C.F.R. Part 2, including any record of the identity, diagnosis, prognosis, or treatment of a patient of a federally assisted substance use disorder program; (b) any state statute imposing restrictions on the disclosure of records more stringent than HIPAA that would apply to ilumenIQ; or (c) any court-ordered restriction or individual-requested restriction to which Customer has agreed under 45 C.F.R. § 164.522. Customer represents that as of the Effective Date it has given no such notice and transmits no such data. If Customer becomes subject to any of the foregoing, the Parties shall execute an appropriate addendum before Customer transmits the affected data, and ilumenIQ may decline to receive it.
7.6 Connected Systems. Customer is solely responsible for ensuring that its use of every Connected System in connection with the Services, including every export, integration, and Credentialed Automated Access authorization, complies with the terms governing that Connected System and with applicable law.
Article 8 — ilumenIQ Obligations and Security
8.1 Availability. ilumenIQ will use commercially reasonable efforts to make the Platform available at all times, excepting scheduled maintenance for which ilumenIQ gives reasonable advance notice, and unavailability caused by circumstances beyond ilumenIQ’s reasonable control, including failures of Connected Systems, hosting providers, and telecommunications networks. ilumenIQ offers no service level commitment and no service credits under this Agreement.
8.2 Security Program. ilumenIQ maintains a written information security program.
8.3 Risk Analysis. ilumenIQ will conduct and document an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic PHI it holds, as required by 45 C.F.R. § 164.308(a)(1)(ii)(A), not less than annually and upon any material change to its systems, and will implement security measures sufficient to reduce identified risks to a reasonable and appropriate level.
8.4 Audit Logging. ilumenIQ may implement and maintain hardware, software, and procedural mechanisms that record and examine activity in systems containing PHI, as required by 45 C.F.R. § 164.312(b). Such logging records authentication events, administrative actions, and access to and viewing of records containing PHI, may be retained for not less than six (6) years.
8.5 Certification Not Provided. ilumenIQ does not hold, and does not represent that it holds, SOC 2 attestation, HITRUST certification, certification under the ONC Health IT Certification Program, or any other third-party audit, attestation, or certification, and has not undergone third-party penetration testing. Customer acknowledges that it has evaluated ilumenIQ’s security posture on the basis of the representations in this Article 8 and not on the basis of any certification. ilumenIQ will notify Customer if this Section ceases to be accurate.
8.6 Updates. ilumenIQ may update, modify, or enhance the Platform. ilumenIQ will use commercially reasonable efforts to give advance notice of any change that materially degrades functionality Customer is then using.
Article 9 — Data Ownership, Minimization, and De-Identified Data
9.1 Customer Ownership. As between the Parties, Customer retains all right, title, and interest in and to Customer Data. Customer grants ilumenIQ a limited, non-exclusive, non-transferable license to access, retrieve, store, process, and display Customer Data solely to provide the Services and as permitted by Article 14.
9.2 Data Minimization. ilumenIQ reduces each client record at ingestion and retains only the elements listed in Part I of Exhibit A. The elements listed in Part II of Exhibit A are not retained. Client names are held only transiently in memory during a synchronization and are discarded on completion; the durable match key is the record identifier assigned by the Connected System.
9.3 The Retained Data Set Is PHI.
The reduced data set described in Section 9.2 and Exhibit A is Protected Health Information. ilumenIQ maintains it as Protected Health Information, subject in full to Article 14 and to the HIPAA Privacy Rule and Security Rule. ilumenIQ makes no representation that the reduced data set is de-identified within the meaning of 45 C.F.R. § 164.514, and neither Party shall treat it as de-identified. The reduction described in Section 9.2 is a data minimization measure undertaken in furtherance of 45 C.F.R. § 164.502(b) and is not a de-identification methodology.
9.4 De-Identified and Aggregated Data. ilumenIQ may create de-identified data from Customer Data and may use, disclose, and commercialize such data, and any aggregated benchmarks derived from it, for any lawful purpose, including improvement of the Services, development of new features, research, and publication of comparative benchmarks, subject to each of the following conditions:
(a) the data must first be de-identified in accordance with 45 C.F.R. § 164.514(b), either by removal of all identifiers enumerated in § 164.514(b)(2) with no actual knowledge that the residual information could be used alone or in combination to identify an individual, or by a determination made and documented by a qualified expert in accordance with § 164.514(b)(1);
(b) ilumenIQ shall document the methodology applied and, in the case of an expert determination, shall retain the expert’s written analysis and shall furnish a summary of it to Customer upon written request;
(c) ilumenIQ shall not attempt to re-identify any de-identified data, shall not disclose any re-identification code or mechanism, and shall contractually prohibit re-identification by any recipient;
(d) no benchmark, report, or other output derived from de-identified data may identify Customer, any Authorized User, any clinician, or any individual client or patient, or may be presented in a manner from which Customer’s identity is reasonably ascertainable, without Customer’s prior written consent; and
(e) no minimum cell size of fewer than eleven (11) individuals or fewer than three (3) contributing practices may be published in any comparative benchmark.
Subject to and conditioned upon satisfaction of the foregoing, ilumenIQ owns all de-identified and aggregated data it creates. This Section 9.4 states a conditional right; ilumenIQ acquires no right to use any data for the purposes described in this Section unless and until the conditions in clauses (a) through (e) are satisfied as to that data.
9.5 Retention and Destruction Schedule. ilumenIQ retains data as follows: (a) Customer Data, including Client Data, is retained for the duration of the Subscription Term and for the thirty (30) day wind-down period described in Section 15.4, and is thereafter deleted or destroyed in accordance with Section 14.17; (b) audit and security logs are retained for six (6) years in accordance with 45 C.F.R. § 164.316(b)(2)(i); (c) backups containing Customer Data are purged on a rolling cycle not exceeding thirty-five (35) days, and Customer Data present in a backup after deletion under clause (a) remains subject to Article 14 until the backup is purged; and (d) account, billing, and contract records are retained as necessary to comply with applicable law and to enforce this Agreement. ilumenIQ maintains a written retention and destruction policy consistent with this Section and will furnish it to Customer upon written request.
9.6 Feedback. If Customer or any Authorized User provides ilumenIQ with any suggestion, idea, or feedback regarding the Services, ilumenIQ may use it without restriction and without obligation to Customer.
Article 10 — Confidentiality
10.1 Definition. “Confidential Information” means non-public information disclosed by one Party to the other that is designated confidential or that reasonably should be understood to be confidential given its nature and the circumstances of disclosure. Customer Data is Customer’s Confidential Information. ilumenIQ’s pricing, platform architecture, data model, metric methodologies, roadmap, and technical documentation are ilumenIQ’s Confidential Information.
10.2 Obligations. Each Party shall: (a) use the other’s Confidential Information only as necessary to perform under or exercise rights under this Agreement; (b) protect it with not less than the degree of care it uses for its own confidential information and in no event less than reasonable care; and (c) not disclose it to any third party without prior written consent, except to employees, contractors, and advisors who have a need to know and who are bound by confidentiality obligations at least as protective as these.
10.3 Exceptions. These obligations do not apply to information that (a) is or becomes public through no fault of the receiving Party; (b) was rightfully known to the receiving Party without restriction before disclosure; (c) is rightfully received from a third party without restriction; or (d) is independently developed without use of or reference to the disclosing Party’s Confidential Information. If disclosure is compelled by law or legal process, the receiving Party shall, to the extent legally permitted, give prompt prior written notice and reasonable cooperation in seeking protective treatment, and shall disclose only what is legally required.
10.4 PHI. The use and disclosure of PHI is governed exclusively by Article 14, which controls over this Article 10 in the event of any conflict.
Article 11 — Representations, Warranties, and Disclaimer
11.1 Mutual. Each Party represents and warrants that it has full power and authority to enter into and perform this Agreement, that this Agreement has been duly authorized and constitutes its binding obligation, and that its execution and performance violate no law and no agreement to which it is a party.
11.2 By ilumenIQ. ilumenIQ represents and warrants that (a) the Platform will perform materially in accordance with the Documentation; (b) ilumenIQ will comply with the requirements of HIPAA applicable to Business Associates in providing the Services; and (c) the statements in Sections 8.2 through 8.5 are accurate as of the Effective Date. Customer’s sole and exclusive remedy for breach of clause (a) is correction of the nonconformity or, if ilumenIQ does not correct it within thirty (30) days of written notice, termination and refund of Subscription Fees prepaid and allocable to the unexpired portion of the then-current Subscription Term.
11.3 By Customer. Customer represents and warrants that (a) it has all rights, authorizations, and consents necessary to submit Customer Data to the Platform and to permit ilumenIQ to process it as described in this Agreement; (b) it will comply with all applicable law in connection with its use of the Services, including HIPAA as a Covered Entity; (c) its use of the Services, including every Connected System integration and Credentialed Automated Access authorization, complies with all applicable third-party terms; and (d) the representations in Section 7.5 are and remain accurate.
11.4 Disclaimer.
Except as expressly set forth in Section 11.2, the platform and services are provided “as is” and “as available.” ilumenIQ disclaims all other warranties, express, implied, and statutory, including the implied warranties of merchantability, fitness for a particular purpose, title, accuracy, and non-infringement. ilumenIQ does not warrant that the services will be uninterrupted, error-free, or completely secure, that any connected system will remain accessible, or that any defect will be corrected. ilumenIQ does not warrant that customer’s use of the services will result in customer’s compliance with HIPAA or any other law.
Article 12 — Limitation of Liability
12.1 Exclusion of Consequential Damages.
In no event will either party be liable to the other for any indirect, incidental, special, consequential, exemplary, or punitive damages, including loss of profits, loss of revenue, loss of data, loss of goodwill, regulatory fines or penalties assessed against the other party, business interruption, or cost of substitute services, arising out of or related to this agreement or the services, whether in contract, tort, strict liability, or otherwise, and whether or not the party has been advised of the possibility of such damages.
12.2 Cap on Liability.
ilumenIQ’s total aggregate liability to CUSTOMER arising out of or related to this agreement or the services, whether in contract, tort, strict liability, or otherwise, shall not exceed the total subscription fees paid by customer to ilumenIQ in the three (3) months immediately preceding the event giving rise to the claim.
12.3 Exceptions. The limitations in Sections 12.1 and 12.2 do not apply to (a) Customer’s payment obligations under Article 5; (b) Customer’s indemnification obligations under Section 13.2; (c) either Party’s breach of Article 10; (d) damages arising from Customer’s gross negligence, willful misconduct, or fraud; or (e) any liability that cannot be limited under applicable law.
12.4 Basis of the Bargain. The Parties acknowledge that the limitations in this Article 12 are an essential basis of the bargain, that the Subscription Fees reflect this allocation of risk, and that these limitations apply notwithstanding the failure of essential purpose of any limited remedy.
Article 13 — Indemnification
13.1 By ilumenIQ. ilumenIQ shall defend Customer against any third-party claim alleging that the Platform, as furnished by ilumenIQ and used in accordance with this Agreement, infringes a United States patent, copyright, or trademark or misappropriates a trade secret, and shall pay damages and costs finally awarded or agreed in settlement. This obligation does not apply to the extent the claim arises from (a) modification of the Platform by anyone other than ilumenIQ; (b) combination of the Platform with products, data, or services not furnished by ilumenIQ; (c) Customer Data or any Connected System; or (d) use of the Platform in violation of this Agreement. If the Platform becomes, or in ilumenIQ’s judgment is likely to become, the subject of such a claim, ilumenIQ may at its option procure the right to continue use, modify or replace the Platform, or terminate this Agreement and refund Subscription Fees prepaid and allocable to the unexpired portion of the then-current Subscription Term. This Section states ilumenIQ’s entire liability and Customer’s sole remedy for intellectual property infringement.
13.2 By Customer. Customer shall defend, indemnify, and hold harmless ilumenIQ and its members, managers, officers, employees, agents, and affiliates from and against any claim, loss, liability, damage, fine, penalty, cost, and expense, including reasonable attorneys’ fees, arising out of or relating to (a) Customer’s breach of this Agreement or of any representation or warranty in it; (b) use of the Services by Customer or any Authorized User in violation of applicable law; (c) any Connected System, including any claim by the operator of a Connected System that Customer’s integration or Credentialed Automated Access authorization violated its terms of service, license agreement, or acceptable use policy, or any claim under 18 U.S.C. § 1030 or comparable state law arising from access conducted pursuant to a Credentialed Automated Access authorization granted by Customer; (d) Customer’s failure to comply with HIPAA as a Covered Entity, including any failure to obtain a necessary authorization or to notify ilumenIQ under Section 7.5; (e) the accuracy, quality, or legality of Customer Data or the means by which Customer acquired it; or (f) any clinical, financial, employment, or operational decision made by Customer or any Authorized User in reliance on a Platform output.
13.3 Procedure. The indemnified party shall promptly notify the indemnifying party in writing of the claim, shall give the indemnifying party sole control of the defense and settlement, and shall provide reasonable cooperation at the indemnifying party’s expense. Failure to give prompt notice relieves the indemnifying party only to the extent it is materially prejudiced. The indemnifying party shall not settle any claim in a manner that imposes any obligation or admission on the indemnified party without prior written consent, not unreasonably withheld.
13.4 No Other Indemnity.
Section 13.1 states the only indemnity given by ilumenIQ under this agreement. ilumenIQ gives no indemnity with respect to any breach of unsecured protected health information, security incident, unauthorized access, or violation of HIPAA, and customer’s remedies for any such matter are limited to those set forth in article 12 and article 14.
Article 14 — Business Associate Agreement
This Article 14 constitutes the business associate agreement between Customer, as Covered Entity, and ilumenIQ, as Business Associate, required by 45 C.F.R. §§ 164.308(b) and 164.504(e). By accepting this Agreement, Customer simultaneously executes this business associate agreement.
14.1 Definitions. Capitalized terms used in this Article 14 and not otherwise defined have the meanings given them in HIPAA. Without limitation: “Breach” has the meaning at 45 C.F.R. § 164.402; “Business Associate” means ilumenIQ; “Covered Entity” means Customer; “Designated Record Set” has the meaning at 45 C.F.R. § 164.501; “Electronic Protected Health Information” or “ePHI” has the meaning at 45 C.F.R. § 160.103; “Individual” has the meaning at 45 C.F.R. § 160.103 and includes a personal representative under 45 C.F.R. § 164.502(g); “Privacy Rule” means 45 C.F.R. Part 160 and Part 164, Subparts A and E; “Required by Law” has the meaning at 45 C.F.R. § 164.103; “Security Incident” has the meaning at 45 C.F.R. § 164.304; “Security Rule” means 45 C.F.R. Part 160 and Part 164, Subparts A and C; and “Unsecured PHI” has the meaning at 45 C.F.R. § 164.402. Any ambiguity in this Article 14 shall be resolved in favor of a meaning that permits compliance with HIPAA.
14.2 Acknowledgment of Maintenance of PHI. The Parties acknowledge that Business Associate creates, receives, maintains, and transmits PHI on behalf of Covered Entity, and that Business Associate stores PHI on a persistent basis in the form described in Section 9.2 and Exhibit A. Business Associate does not warrant that any data it holds is de-identified.
14.3 Permitted Uses and Disclosures. Business Associate may use and disclose PHI only: (a) as necessary to perform the Services described in this Agreement; (b) as Required by Law; (c) for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided that any disclosure for such a purpose is either Required by Law or made only after Business Associate obtains reasonable written assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality; and (d) to create de-identified data in accordance with 45 C.F.R. §§ 164.502(d) and 164.514(a) through (c) and Section 9.4 of this Agreement. Business Associate shall not use or disclose PHI in any manner that would violate the Privacy Rule if done by Covered Entity, except as permitted by clause (c).
14.4 Prohibited Uses. Business Associate shall not: (a) sell PHI or receive remuneration in exchange for PHI except as permitted by 45 C.F.R. § 164.502(a)(5)(ii); (b) use or disclose PHI for marketing or fundraising; (c) use PHI to train any machine learning or artificial intelligence model other than a model used solely to provide the Services to Covered Entity, unless the data has first been de-identified in accordance with Section 9.4; or (d) transmit or store PHI outside the United States.
14.5 Safeguards. Business Associate shall implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, and shall comply with Subpart C of 45 C.F.R. Part 164 and with the applicable HITECH provisions. The safeguards described in Article 8 are incorporated into this Article 14.
14.6 Minimum Necessary. Business Associate shall request, use, and disclose only the minimum PHI necessary to accomplish the purpose of the request, use, or disclosure, consistent with 45 C.F.R. §§ 164.502(b) and 164.514(d).
14.7 Subcontractors. Business Associate shall require each subcontractor that creates, receives, maintains, or transmits PHI on its behalf to agree in writing to restrictions and conditions at least as protective as those in this Article 14, as required by 45 C.F.R. § 164.502(e)(1)(ii). Business Associate shall maintain and, upon written request, furnish to Covered Entity a current list of such subcontractors.
14.8 Reporting and Breach Notification. Business Associate shall report to Covered Entity: (a) any use or disclosure of PHI not permitted by this Article 14; (b) any Security Incident of which it becomes aware, provided that unsuccessful attempts that do not result in unauthorized access, use, disclosure, modification, or destruction and that are of a routine nature, such as pings, port scans, and unsuccessful log-on attempts, are hereby reported on an ongoing basis and require no separate notice; and (c) any Breach of Unsecured PHI, without unreasonable delay and in no event later than ten (10) business days after discovery. Notification of a Breach shall include, to the extent then known: the identification of each Individual whose Unsecured PHI has been or is reasonably believed to have been accessed, acquired, used, or disclosed; a description of what happened, including the date of the Breach and the date of discovery; a description of the types of PHI involved; a description of the investigation, mitigation, and remediation undertaken; and any other information Covered Entity requires to satisfy its obligations under 45 C.F.R. §§ 164.404 through 164.408. Business Associate shall supplement its notification as additional information becomes available and shall cooperate reasonably with Covered Entity’s investigation and notification efforts. A Breach shall be treated as discovered on the first day on which it is known to, or by exercising reasonable diligence would have been known to, Business Associate.
14.9 Mitigation. Business Associate shall mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of this Article 14.
14.10 Individual Access. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall, within ten (10) business days of Covered Entity’s written request, make such PHI available to Covered Entity, or as directed by Covered Entity to the Individual, in the form and format requested if readily producible, so as to permit Covered Entity to satisfy 45 C.F.R. § 164.524.
14.11 Amendment. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall make any amendment to such PHI directed by Covered Entity within ten (10) business days, so as to permit Covered Entity to satisfy 45 C.F.R. § 164.526.
14.12 Accounting of Disclosures. Business Associate shall document and, within ten (10) business days of Covered Entity’s written request, provide to Covered Entity information sufficient to permit Covered Entity to respond to a request for an accounting of disclosures in accordance with 45 C.F.R. § 164.528.
14.13 Requests Received Directly. If Business Associate receives directly from an Individual a request for access to, amendment of, an accounting of disclosures of, or a restriction on the use or disclosure of PHI, Business Associate shall not respond substantively and shall forward the request to Covered Entity within five (5) business days.
14.14 Governmental Access. Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the United States Department of Health and Human Services for purposes of determining Covered Entity’s compliance with the Privacy Rule, and shall notify Covered Entity of any such request unless prohibited by law.
14.15 Credentialed Automated Access. Where Covered Entity has granted a Credentialed Automated Access authorization under Article 4, Business Associate’s access to and processing of PHI pursuant to that authorization is a function performed on behalf of and at the direction of Covered Entity, is an authorized use under this Article 14, and is subject to all safeguards and restrictions of this Article 14. Covered Entity is responsible for determining that each such authorization is consistent with its own obligations under HIPAA, including the minimum necessary standard.
14.16 Minors, Personal Representatives, and Restrictions. Covered Entity acknowledges that Client Data may relate to Individuals under the age of eighteen, that under N.C. Gen. Stat. § 90-21.5 and comparable law in other states a minor may consent to certain mental health and related services on the minor’s own behalf, and that in those circumstances a parent or guardian may not be the minor’s personal representative under 45 C.F.R. § 164.502(g). Covered Entity is solely responsible for determining who is the personal representative of any Individual and for all decisions regarding disclosure to a parent, guardian, or family member. Business Associate shall not make any such determination or disclosure and shall refer all such requests to Covered Entity under Section 14.13.
14.17 State Law. The Parties acknowledge that state law more stringent than HIPAA may apply to the records of Covered Entity, including N.C. Gen. Stat. § 122C-52 et seq. and N.C. Gen. Stat. § 8-53.3, and that HIPAA does not preempt such law. Covered Entity is responsible for identifying every state whose law applies to it and for notifying Business Associate under Section 7.5 of any requirement that would impose an obligation on Business Associate beyond those set forth in this Article 14. Business Associate shall comply with any such requirement of which it is so notified and to which it agrees in writing.
14.18 Covered Entity Obligations. Covered Entity shall: (a) notify Business Associate in writing of any limitation in its Notice of Privacy Practices, any change to or revocation of an Individual’s authorization, and any restriction to which it has agreed under 45 C.F.R. § 164.522, in each case to the extent the limitation, change, or restriction may affect Business Associate’s use or disclosure of PHI; (b) not request Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy Rule if done by Covered Entity, except as permitted by Section 14.3(c); (c) transmit to Business Associate only the minimum PHI necessary for Business Associate to perform the Services; and (d) obtain and maintain any authorization or consent required for Business Associate to perform the Services.
14.19 Term and Termination of This Article. This Article 14 takes effect on the Effective Date and terminates when all PHI has been returned or destroyed under this Section. Covered Entity may terminate this Agreement immediately upon written notice if Business Associate materially breaches this Article 14 and fails to cure within thirty (30) days of written notice. Upon termination or expiration of this Agreement, and following the thirty (30) day wind-down period described in Section 15.4, Business Associate shall return or destroy all PHI it maintains, and shall retain no copies, within thirty (30) days. To the extent return or destruction is infeasible, including PHI residing in backup media pending purge under Section 9.5(c) and PHI contained in audit logs retained under Section 9.5(b), Business Associate shall extend the protections of this Article 14 to that PHI and limit further use and disclosure to the purposes that make return or destruction infeasible, for so long as it is retained. Business Associate shall certify destruction in writing upon Covered Entity’s written request.
14.20 Survival and Precedence. The obligations of Business Associate under this Article 14 survive termination of this Agreement for so long as Business Associate retains any PHI. To the extent any other provision of this Agreement conflicts with this Article 14 with respect to PHI, this Article 14 governs.
Article 15 — Term, Termination, and Data Return
15.1 Term. This Agreement commences on the Effective Date and continues until the Subscription Term expires or this Agreement is terminated as provided herein.
15.2 Termination for Cause. Either Party may terminate this Agreement upon written notice if the other Party (a) materially breaches this Agreement and fails to cure within thirty (30) days after written notice describing the breach in reasonable detail, or (b) becomes insolvent, makes a general assignment for the benefit of creditors, or becomes the subject of any bankruptcy, receivership, or similar proceeding not dismissed within sixty (60) days.
15.3 Effect of Termination. Upon termination or expiration: (a) all licenses granted to Customer terminate; (b) Customer shall cease all use of the Platform following the wind-down period; (c) each Party shall return or destroy the other’s Confidential Information, subject to Section 9.5 and Section 14.19; and (d) accrued payment obligations survive.
15.4 Data Return Wind-Down. For thirty (30) days following termination or expiration, ilumenIQ will make the Platform available to Customer in a limited, read-only export mode so that Customer may export Customer Data in a commercially reasonable machine-readable format. ilumenIQ shall not delete Customer Data during that period. ilumenIQ is not responsible for Customer Data that Customer fails to export during the wind-down period. This Section does not apply where the Agreement is terminated by ilumenIQ for Customer’s failure to pay undisputed Subscription Fees, in which case the wind-down period commences upon payment in full.
15.5 Survival. Articles 2, 9, 10, 12, 13, 14, 16, and 17, and Sections 3.4, 11.4, 15.3, 15.4, and 15.5, survive termination or expiration of this Agreement.
Article 16 — Binding Arbitration and Class Action Waiver
16.1 Pre-Arbitration Conference. Before commencing arbitration, the Parties shall attempt in good faith for thirty (30) days to resolve the dispute through discussion between senior representatives. This Section does not toll any statute of limitations and does not bar either Party from commencing arbitration to preserve a claim that would otherwise become time-barred.
16.2 Agreement to Arbitrate. All controversies or claims arising out of or relating to this Agreement shall be settled exclusively through binding arbitration administered by the American Arbitration Association in accordance with the Expedited Procedures of the Commercial Arbitration Rules. The arbitration hearing shall take place before a single arbitrator in Mecklenburg County, North Carolina, via video conference, and such arbitrator shall ensure the following procedural requirements govern the arbitration: the arbitration shall be decided based solely upon the submission of documents, and no witness testimony shall be elicited or heard; there shall be no written discovery, interrogatories, requests for production of documents, or requests for admissions; there shall be no depositions taken; all information exchanged and elicited through the arbitration shall be kept strictly confidential by the parties and shall not be shared with anyone other than the parties themselves and the arbitrator; and the arbitration hearing shall not exceed one (1) day. Customer agrees that ilumenIQ’s members, managers, officers, employees, agents, and affiliates are intended beneficiaries of this arbitration clause. This agreement to arbitrate shall be enforceable under and subject to the Federal Arbitration Act. In addition, no arbitration proceeding hereunder shall be filed or pursued as a class action or proceed as a class action, or on a basis involving claims brought in a purported representative capacity on behalf of the general public, other customers or potential customers or persons similarly situated. Moreover, no arbitration proceeding hereunder shall be consolidated with, or joined in any way with, any other arbitration proceeding.
The parties agree to arbitrate on an individual basis and each waives the right to participate in a class action.
16.3 Delegation. The arbitrator shall have exclusive authority to resolve any dispute concerning the interpretation, applicability, enforceability, or formation of this Article 16, except that a court of competent jurisdiction shall determine the enforceability of the class action waiver.
16.4 Class Waiver Not Severable. If the class action waiver in Section 16.2 is held unenforceable as to any claim or request for relief, that claim or request for relief, and only that claim or request for relief, shall be severed from the arbitration and litigated in the state or federal courts located in Mecklenburg County, North Carolina, and all remaining claims shall proceed in arbitration. In no event shall any class, collective, consolidated, or representative claim be arbitrated.
16.5 Role of the Courts. Judgment on the award may be entered in any court of competent jurisdiction. The state and federal courts located in Mecklenburg County, North Carolina have exclusive jurisdiction over any proceeding to compel arbitration, to confirm, vacate, modify, or enforce an award, or to adjudicate any claim severed under Section 16.4, and each Party consents to the personal jurisdiction of those courts and waives any objection to venue in them.
16.6 Survival. This Article 16 survives termination or expiration of this Agreement.
Article 17 — Miscellaneous
17.1 Miscellaneous. This Agreement, together with the documents identified in Section 1.5, constitutes the entire agreement between the Parties with respect to its subject matter and supersedes all prior and contemporaneous agreements, negotiations, representations, and understandings, whether written or oral, with respect thereto. Except as provided in Section 1.6, this Agreement may be amended only by a written instrument executed by authorized representatives of both Parties. This Agreement shall be governed by and construed in accordance with the laws of the State of North Carolina, without regard to its conflict of laws principles. Subject in all respects to Article 16, venue for any permitted proceeding shall lie exclusively in the state and federal courts located in Mecklenburg County, North Carolina. In the event of any suit, action, proceeding, or arbitration arising out of or relating to this Agreement, the prevailing Party shall be entitled to recover from the non-prevailing Party its reasonable attorneys’ fees and expenses, this provision being reciprocal and applicable to all Parties and made pursuant to N.C. Gen. Stat. § 6-21.6 and, in arbitration, pursuant to the authority of the arbitrator. No failure or delay by either Party in exercising any right under this Agreement shall constitute a waiver of that right, and no waiver shall be effective unless in writing. This Agreement shall be construed according to its fair meaning and shall not be construed against either Party as the drafter. If any provision of this Agreement is held invalid or unenforceable, that provision shall be modified to the minimum extent necessary to render it enforceable, or if modification is not possible, severed, and the remaining provisions shall continue in full force and effect.
17.2 Notices. Legal notices shall be in writing and are effective when (a) delivered personally, (b) sent by certified mail, return receipt requested, or (c) sent by nationally recognized overnight courier. Operational and billing notices may be delivered by email to the address associated with Customer’s account or by posting within the Platform. Notices to ilumenIQ shall be addressed to ilumenIQ LLC, Attn: Legal, 1235 East Blvd, Suite E519, Charlotte, North Carolina 28203, with a copy to legal@ilumeniq.com. Notices to Customer shall be addressed to the administrative contact of record.
17.3 Assignment. Customer may not assign this Agreement, in whole or in part, by operation of law or otherwise, without ilumenIQ’s prior written consent, which shall not be unreasonably withheld in connection with a merger, reorganization, or sale of all or substantially all of Customer’s assets or equity, provided the assignee assumes this Agreement in writing. ilumenIQ may assign this Agreement without consent in connection with a merger, reorganization, or sale of all or substantially all of its assets or equity, upon written notice to Customer. Any purported assignment in violation of this Section is void.
17.4 Independent Contractors. The Parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, franchise, or employment relationship. The limited agency created by Section 4.3 is expressly limited to the purpose stated therein.
17.5 No Third-Party Beneficiaries. Except for the persons identified as intended beneficiaries in Section 16.2 and the indemnified persons identified in Section 13.2, this Agreement confers no rights on any person other than the Parties and their permitted successors and assigns.
17.6 Force Majeure. Neither Party is liable for any delay or failure in performance, other than a payment obligation, caused by circumstances beyond its reasonable control, including acts of God, natural disaster, epidemic, war, terrorism, civil unrest, labor disturbance, governmental action, utility failure, internet or telecommunications outage, or failure of a Connected System or hosting provider.
17.7 Publicity. Neither Party shall use the name, mark, or logo of the other in any advertising, press release, customer list, or public statement without the other’s prior written consent.
17.8 Electronic Acceptance. This Agreement may be accepted electronically as provided in Section 1.2, and such acceptance has the same legal effect as a signature on a paper document.
Exhibit A — Data Minimization Schedule
I. Elements Retained for Each Client Record. Initials; birth year, without month or day; the first three digits of the postal ZIP code; gender identity; race and ethnicity; preferred language; relationship status; employment status; an indicator of whether the individual is a minor; intake date; last attended date; billing type, meaning self-pay or insurance; the name of the insurance company, without any member or subscriber identifier; treating clinician; outstanding account balance; referral source; the record identifier assigned by the Connected System, used as the durable match key; and the individual’s appointment history, including the date and time of each appointment, the applicable service or procedure code, the duration, and whether the appointment was in-office or by telehealth.
II. Elements Not Retained. Name; full date of birth; full postal ZIP code; street address; telephone number; electronic mail address; insurance member or subscriber number; Social Security number; medical record number; clinical note or other clinical documentation of any kind; and diagnosis code.
III. Characterization. The elements listed in Part I constitute Protected Health Information and are maintained as such. Part I does not describe a de-identification methodology and no element of it should be understood as a representation that the retained data set satisfies 45 C.F.R. § 164.514.
IV. Retention Periods. Client Data: the Subscription Term plus the thirty (30) day wind-down period described in Section 15.4, then deleted or destroyed under Section 14.19. Audit and security logs: six (6) years, in accordance with 45 C.F.R. § 164.316(b)(2)(i). Backup media containing Customer Data: purged on a rolling cycle not exceeding thirty-five (35) days. Account, billing, and contract records: as necessary to comply with applicable law and to enforce this Agreement.
V. Amendment of This Exhibit. ilumenIQ may amend this Exhibit A to reflect a reduction in the elements retained without notice. ilumenIQ shall give Customer not less than thirty (30) days’ prior written notice before adding any element to Part I, and Customer may terminate this Agreement without penalty if it objects, with a refund of Subscription Fees prepaid and allocable to the unexpired portion of the then-current Subscription Term.