Terms of Service
Mediphant Guardian Platform
Last Updated: October 20, 2025
Version: 1.0
These Terms of Service ("Terms" or "Agreement") constitute a legal agreement between the healthcare organization or practice ("Organization," "you," or "Customer") and Mediphant Corporation ("Mediphant," "we," "our," or "us") and govern your use of the Mediphant Guardian platform, including our website, web application, mobile applications, and all related services (collectively, the "Service" or "Platform").
Effective Date: For electronic acceptance, these Terms become effective on the date you click "I Agree," check the acceptance box, or first access the Service. For traditional signature execution, these Terms become effective on the date of the last signature. The effective date of your agreement will be recorded and provided to you upon request.
By clicking "I Agree," "Accept," or similar button, by checking a box indicating acceptance, by executing an Order Form, or by accessing or using the Service, you represent that you have the authority to bind your Organization to these Terms and the accompanying Business Associate Agreement, and you agree to be bound by both documents. If you do not agree to these Terms and the BAA, do not use the Service.
1. Definitions
"Authorized User" means any individual authorized by the Organization to access and use the Service, including but not limited to healthcare providers, administrative staff, and other personnel.
"BAA" means the Business Associate Agreement attached hereto as Exhibit A or otherwise executed between the parties.
"Connected Patient" means an individual patient who has granted the Organization access to their health data through the Service.
"Order Form" means the ordering document executed between you and Mediphant that specifies the subscription term, pricing, number of Authorized Users, and other commercial terms.
"PHI" means Protected Health Information as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended.
"Service Level Agreement" or "SLA" means the service level commitments provided by Mediphant as set forth in Section 12 or as otherwise specified in an Order Form.
2. Eligibility & Account Creation
2.1 Organization Requirements
To use the Service, you must be:
- A licensed healthcare organization, medical practice, or healthcare provider operating in the United States
- Authorized to provide healthcare services in your jurisdiction
- Capable of entering into legally binding contracts
- In compliance with all applicable healthcare laws and regulations, including HIPAA
2.2 Account Registration
When creating an Organization account, you agree to:
- Provide accurate, complete, and current information about your Organization
- Maintain and promptly update this information
- Maintain the security and confidentiality of your administrative account credentials
- Promptly notify us of any unauthorized access or security breaches
- Accept responsibility for all activities that occur under your Organization's account
2.3 Authorized Users
You are responsible for:
- Managing access credentials for all Authorized Users
- Ensuring that each Authorized User complies with these Terms
- All actions taken by Authorized Users under your Organization's account
- Promptly deactivating access for any individual who is no longer authorized to use the Service
3. About Mediphant Guardian
Mediphant Guardian is a platform that enables healthcare organizations to securely send, receive, organize, and manage patient health records shared by individuals using the Mediphant consumer application. The Service facilitates patient-provider data sharing, care coordination, and secure health information management. Mediphant Guardian does not provide medical advice, diagnosis, or treatment, and does not replace clinical judgment or professional medical services.
4. Scope of Service
4.1 Service Features
Subject to these Terms and payment of applicable fees, Mediphant grants you a non-exclusive, non-transferable, revocable right to access and use the Service for your internal business purposes, which includes:
- Receiving and accessing health records shared by Connected Patients and Organization
- Securely storing and organizing patient health information
- Facilitating communication with patients regarding their shared health data
- Generating insights and summaries to support clinical workflows
4.2 Service Modifications
We reserve the right to modify, update, or discontinue features of the Service at our discretion. We will provide reasonable notice for material changes that negatively impact functionality. Continued use of the Service after such changes constitutes acceptance of the modified Service.
5. Acceptable Use & Restrictions
5.1 Permitted Use
You may use the Service only for lawful purposes and in accordance with these Terms. You agree to use the Service in compliance with all applicable federal, state, and local laws, including but not limited to HIPAA, HITECH, state privacy laws, and FDA regulations where applicable.
5.2 Prohibited Activities
You and your Authorized Users agree not to:
- Use the Service for any unlawful purpose or in violation of any applicable laws or regulations
- Access or attempt to access accounts, data, or systems not intended for you
- Interfere with or disrupt the integrity or performance of the Service
- Reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code of the Service
- Remove, modify, or obscure any proprietary notices on the Service
- Use the Service to transmit viruses, malware, or other malicious code
- Share access credentials or allow unauthorized individuals to use the Service
- Use the Service to harass, abuse, threaten, or violate the rights of others
- Scrape, spider, or use automated means to access the Service except through authorized APIs
- Resell, sublicense, or otherwise commercialize access to the Service without our written consent
- Use the Service in a manner that violates any patient's privacy rights or consent limitations
5.3 Consequences of Violation
We reserve the right to investigate violations of these Terms and take appropriate action, including suspension or termination of access to the Service, without refund or credit.
6. Data Ownership, Use & Protection
6.1 Organization Data Ownership
You retain all ownership rights to PHI and other data provided to or generated through your use of the Service ("Organization Data"). By using the Service, you grant Mediphant a limited, non-exclusive license to process Organization Data solely to:
- Provide, maintain, and improve the Service
- Comply with legal obligations
- Enforce these Terms
- Perform other functions as reasonably necessary to deliver the Service
6.2 Data Use Restrictions
Mediphant will not:
- Sell Organization Data or PHI to third parties
- Use PHI to train general-purpose AI models
- Access or use Organization Data except as necessary to provide the Service, ensure security, or comply with legal obligations
- Retain Organization Data longer than necessary for the purposes outlined in these Terms and our Privacy Policy, except as required by law
6.3 De-identified Data
We may de-identify Organization Data in accordance with HIPAA standards and use such de-identified data for research, analytics, product improvement, and other lawful business purposes. De-identified data cannot reasonably be used to identify any individual or Organization.
6.4 Organization Responsibilities
You are responsible for:
- Ensuring you have appropriate legal authority and patient consent to collect, use, and share data through the Service
- The accuracy, quality, and legality of Organization Data
- Ensuring your use of the Service complies with all applicable laws and regulations
- Implementing appropriate administrative, physical, and technical safeguards within your own organization
- Training Authorized Users on proper data handling and privacy practices
- Reporting any suspected security incidents or privacy breaches to Mediphant promptly
7. HIPAA Compliance & Business Associate Agreement
7.1 Business Associate Relationship
The parties acknowledge that Mediphant is a Business Associate of the Organization under HIPAA. The parties shall execute a separate Business Associate Agreement (the "BAA") that governs the creation, receipt, maintenance, transmission, and disclosure of PHI by Mediphant on behalf of the Organization.
7.2 BAA Incorporation
The BAA is incorporated into and made part of these Terms. In the event of any conflict between these Terms and the BAA with respect to the handling of PHI, the BAA shall control.
7.3 Organization's HIPAA Obligations
You represent and warrant that:
- You are a Covered Entity or Business Associate subject to HIPAA
- You will comply with all applicable HIPAA requirements
- You have obtained all necessary patient authorizations and consents
- You will use and disclose PHI only as permitted by HIPAA and applicable state laws
7.4 Breach Notification
Each party will notify the other promptly upon discovery of any breach of unsecured PHI, and in any event no later than required by applicable law. Mediphant will cooperate with you to investigate and remediate any such breach.
8. Billing, Payment & Subscription Terms
8.1 Fees & Payment
You agree to pay all fees specified in your Order Form. Unless otherwise specified, fees are based on:
- The number of Authorized Users with access to the Platform
- The number of Connected Patients
- Any additional services or features purchased
8.2 Billing Model
Credit Card on File: You must maintain a valid credit card on file with Mediphant. By providing credit card information, you authorize Mediphant to charge your card for all fees incurred under your account.
Invoicing: We will issue invoices on a monthly or other agreed-upon basis reflecting:
- Subscription fees for Authorized Users
- Usage-based fees calculated on the number of Connected Patients during the billing period
- Any applicable taxes, surcharges, or additional service fees
Invoices are due upon receipt unless otherwise specified in your Order Form. We will charge your credit card on file on or after the invoice date.
8.3 Usage Calculation & Pro-Ration
Connection Activation: A Connected Patient is considered "active" only when both conditions are met:
- The patient has granted your Organization access to their health data through the Mediphant consumer application, AND
- Your Organization has accepted the connection request
Pro-Rated Billing: Connected Patients are billed on a pro-rated basis from the date the connection becomes active. Pro-ration is calculated on a daily basis for the billing period.
8.4 Payment Terms
- Fees are non-refundable except as expressly provided in these Terms or required by law
- You are responsible for all taxes, duties, and government charges except for taxes based on Mediphant's net income
- Late payments may incur interest at the rate of 1.5% per month or the maximum rate permitted by law, whichever is lower
9. Subscription Term & Termination
9.1 Subscription Term
Your initial subscription term begins on the Effective Date and continues for the period stated in your Order Form or, if no period is specified, on a month-to-month basis. Unless either party provides written notice of non-renewal at least 30 days before the end of the then-current term, your subscription will automatically renew.
9.2 Termination for Cause
Either party may terminate this Agreement for cause if the other party materially breaches these Terms and fails to cure such breach within 30 days of written notice.
9.3 Termination for Convenience
You may terminate this Agreement for convenience by providing 30 days' written notice. You will remain responsible for all fees through the end of your then-current term.
9.4 Data Retrieval & Deletion
Following termination:
- Immediate Disconnection: All Connected Patient connections are immediately terminated and access to the Service is disabled
- Organization Data Export: You may submit a written request to compliance@mediphant.ai within 30 days of termination to request an export of your user-generated content
- No Patient Data Provided: Patient health records shared through Connected Patient relationships will not be included in any data export
- Data Deletion: After 30 days, user-generated content files will be permanently deleted. Account records and compliance data will be retained in accordance with our Privacy Policy
10. Intellectual Property Rights
Mediphant retains all right, title, and interest in and to the Service, including all software, technology, content, branding, trademarks, and other intellectual property rights. These Terms do not grant you any ownership rights in the Service.
11. Confidentiality
Each party agrees to protect the other party's Confidential Information using at least reasonable care and to use such information solely for purposes of performing under this Agreement.
12. Representations, Warranties & Disclaimers
EXCEPT AS EXPRESSLY SET FORTH IN THESE TERMS, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED BY LAW, MEDIPHANT DISCLAIMS ALL WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY.
THE SERVICE IS FOR ADMINISTRATIVE AND COORDINATION PURPOSES ONLY. MEDIPHANT DOES NOT PROVIDE MEDICAL ADVICE, DIAGNOSIS, OR TREATMENT.
13. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, MEDIPHANT'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT SHALL NOT EXCEED THE TOTAL FEES PAID BY YOU TO MEDIPHANT DURING THE 12 MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO LIABILITY.
14. Indemnification
Each party agrees to indemnify and hold harmless the other party from claims arising from their respective breaches, violations of law, or acts and omissions as specified in the full Terms of Service.
15. Dispute Resolution; Binding Arbitration
Any disputes shall be resolved through binding arbitration administered by the American Arbitration Association in Dallas, Texas. You may opt out of arbitration within 30 days by contacting hello@mediphant.ai.
16. General Provisions
Electronic Acceptance & Signatures
Pursuant to the ESIGN Act and UETA, electronic signatures and records have the same legal force and effect as handwritten signatures and paper records. Your electronic acceptance creates a legally binding agreement.
We will maintain records of your electronic acceptance, including:
- The Effective Date (date and time of acceptance)
- The identity of the person accepting (name and email)
- The version of these Terms accepted
- The IP address from which acceptance occurred
- The Organization name
17. Contact Information
Mediphant Corporation
539 W Commerce St. #7718
Dallas, TX 75208
Email: hello@mediphant.ai
Website: https://mediphant.ai
ACCEPTANCE AND BINDING AGREEMENT
BY CLICKING "I AGREE" OR "ACCEPT," YOU ACKNOWLEDGE THAT:
- You have read and understood these Terms of Service and the Business Associate Agreement in their entirety;
- You have the authority to bind your Organization to these Terms and the BAA;
- Your Organization agrees to be bound by these Terms and the BAA; and
- Electronic acceptance creates a legally binding contract equivalent to a handwritten signature.
If you do not have the authority to bind your Organization, or if you do not agree to these Terms and the BAA, you must not accept these Terms or use the Service.