Terms of Service (EHR SaaS)
Plain-Language Summary (Not Legally Operative)
This Agreement is between AllegianceMD Software, Inc. (“AllegianceMD”) and the healthcare organization or professional using our cloud EHR and related services (the “Service”). During your paid subscription, we grant you a limited, non-exclusive right to use the Service. You are responsible for your users’ actions, all clinical decisions, legal/regulatory compliance, and any third-party integrations you enable (e.g., labs, e-prescribing, clearinghouses, payment processors, telehealth, HIEs). If you are a HIPAA Covered Entity or Business Associate and you request it, we will sign a Business Associate Agreement (“BAA”); the BAA governs our handling of PHI and controls over any conflicting PHI terms here. We use reasonable safeguards to secure and operate the Service, but we can not guarantee 100% perfect security or can we guarantee 100% uninterrupted availability. Fees are non-refundable, and we may suspend service for non-payment or misuse. Our liability is limited, and you agree to indemnify us for claims arising from your data, misuse, or third-party services. Some features may be offered as beta or free trials and are provided “as is.” Disputes will be resolved by binding, individual arbitration. This summary is for convenience only; the full Terms below govern.
Table of Contents
- 1. Parties; Acceptance; Order of Precedence
- 2. Definitions
- 3. Access; License; Restrictions; Third-Party Services
- 4. Clinical & Regulatory Disclaimers
- 5. Business Associate Relationship
- 6. Data; IP; Feedback
- 7. Security; Availability; Support
- 8. Beta Features & Free Trials
- 9. Fees; Taxes; Non-Payment
- 10. Term; Termination; Suspension
- 11. Warranties & Disclaimers
- 12. Indemnification
- 13. Limitation of Liability
- 14. Confidentiality
- 15. Compliance; Export; Anti-Corruption
- 16. U.S. Government Rights
- 17. Publicity; Marks
- 18. Modifications to TOS or Service
- 19. Dispute Resolution; Governing Law; Venue; Class Waiver
- 20. Notices; Assignment; Entire Agreement; Severability; Survival
- 21. API Terms
1 Parties; Acceptance; Order of Precedence
1.1 Parties
These Terms of Service ("TOS") are between AllegianceMD Software, Inc., a Nevada corporation, with principal address at 6914 S. Yorktown ave Ste 200 Tulsa, OK 74136, and the Customer identified on an Order Form. "Customer" includes Customer's Affiliates using the Service under Customer's Order.
1.2 Acceptance
These TOS are accepted when Customer (a) clicks to accept; (b) signs an Order Form referencing these TOS; or (c) accesses or uses the Service. Customer is responsible for its employees, contractors, agents, and other authorized users (each a "User").
1.3 Order of Precedence
If there is a conflict, the following control in this order: (i) the BAA (if executed) solely for PHI-related terms, (ii) the main Order Form/Statement of Work ("Order Form" or "SOW"), (iii) these TOS, (iv) the Data Processing Addendum ("DPA," if separate and applicable to non-PHI personal data), and (v) referenced policies, Documentation, and service descriptions ("Policies"). Terms on Customer purchase orders, vendor portals, or similar forms are rejected and have no effect.
2 Definitions
- P1 (Critical): production outage or loss of a core documented workflow with no reasonable workaround.
- P2 (High): major degradation of a documented workflow; a workaround exists but is burdensome.
- P3 (Medium/Low): minor impact, cosmetic issue, or intermittent error with a reasonable workaround.
3 Access; License; Restrictions; Third-Party Services
3.1 Access Grant
Subject to these TOS and the Order Form, AllegianceMD grants Customer a non-exclusive, revocable, non-transferable right to access and use the Service during the Term solely for Customer's internal healthcare operations.
3.2 Restrictions
Customer shall not, and shall ensure Users do not:
- (a) sublicense, rent, or lease the Service;
- (b) reverse engineer, decompile, disassemble, or attempt to derive source code;
- (c) circumvent access limits, rate limits, or security;
- (d) scrape, harvest, or bulk-export data except via available export tools or documented APIs;
- (e) publish or disclose benchmarks or performance tests without our prior written consent;
- (f) use the Service for high-risk activities outside intended healthcare workflows (e.g., real-time critical infrastructure control);
- (g) introduce Malicious Code; or
- (h) remove proprietary notices.
3.3 Credentials
Customer controls User provisioning and is responsible for maintaining the confidentiality of credentials and all activities under its accounts. Customer must promptly notify AllegianceMD of suspected unauthorized access.
3.4 Third-Party Services
The Service may enable integrations with third-party services (e.g., labs, e-prescribing networks, clearinghouses, payment processors, telehealth platforms, HIEs, registries) ("Third-Party Services"). Third-Party Services are not AllegianceMD products. Customer is solely responsible for selecting, enabling, and using Third-Party Services, for associated fees, and for any data exchange with them. AllegianceMD disclaims all responsibility for Third-Party Services and their acts, omissions, or availability.
4 Clinical & Regulatory Disclaimers
4.1 No Medical Practice
AllegianceMD does not provide medical care, practice medicine, or offer medical advice. The Service is a tool to assist licensed professionals. Customer retains sole clinical judgment and responsibility for diagnosis, treatment, documentation, billing, and outcomes.
4.2 Compliance
AllegianceMD does not guarantee Customer's compliance with HIPAA, HITECH, CMS, OIG, Joint Commission, state laws, 42 C.F.R. Part 2, EPCS requirements, Information Blocking rules, or other regulations. Customer is responsible for configuring and using the Service in a compliant manner and for all consents, authorizations, and notices.
4.3 Content Accuracy
Clinical Content, decision-support, drug databases, formularies, knowledge bases, and any third-party content may be incomplete or outdated. Customer must verify all clinical information from independent sources and current standards of care. Clinical decision support is informational only and not a substitute for professional judgment; Customer agrees to verify all recommendations before use.
4.4 Information Blocking
AllegianceMD will not engage in Information Blocking. Customer is responsible for its own compliance, including configuration and governance. AllegianceMD may rely on applicable exceptions and safe harbors (e.g., preventing harm, privacy, security, infeasibility, content and manner). AllegianceMD may decline or throttle requests that are infeasible, insecure, exceed reasonable rate limits, or would violate law or third-party rights.
4.5 Clinical Interfaces and Results Transmission
Customer acknowledges that clinical interfaces (including HL7/FHIR/LIS/HIE/eRx/clearinghouse feeds and registries) involve third-party systems and networks outside AllegianceMD's control. AllegianceMD is not responsible for delays, failures, duplicates, corruption, or omissions in inbound or outbound messages, orders, prescriptions, claims, or results.
4.6 Verification Duty
Customer will maintain clinical verification workflows (e.g., critical result callbacks, reconciliation queues, downtime procedures) and will not rely solely on the Service or any alert/notification to discover, triage, or act on clinical results.
4.7 Configuration and Mapping
Customer is responsible for test catalogs, code mappings (including LOINC/NCPDP/EDI), routing, and other configuration with its labs, facilities, and payors. AllegianceMD is not responsible for misconfiguration or mapping errors.
5 Business Associate Relationship
5.1 BAA Execution
If Customer is a HIPAA Covered Entity or Business Associate, AllegianceMD will execute its standard BAA upon request. The BAA governs PHI handling and prevails solely for PHI-related conflicts with these TOS.
5.2 No BAA, No PHI
If no BAA is executed, Customer shall not upload PHI to the Service. Customer is liable for violations of this Section.
5.3 De-identified/Aggregated Use
AllegianceMD may create, use, and disclose De-identified Data and Aggregated Data for any lawful purpose, including analytics, R&D, benchmarking, Service improvement, and industry reporting, consistent with HIPAA and applicable law.
6 Data; IP; Feedback
6.1 Ownership
As between the parties, Customer retains all rights in Customer Data. AllegianceMD retains all rights in the Service, software, Content, Usage Data, De-identified Data, Aggregated Data, and all improvements.
6.2 License to AllegianceMD
Customer grants AllegianceMD a worldwide, royalty-free license to host, process, transmit, display, and use Customer Data solely to deliver, maintain, secure, support, and improve the Service; to comply with law; and as permitted in the BAA and these TOS.
6.3 Usage Data
AllegianceMD may collect and use Usage Data to operate, analyze, secure, and improve the Service and for capacity planning. AllegianceMD will not use Usage Data to identify Customer except as required for support, security, billing, or legal compliance.
6.4 Feedback
Feedback is assigned to AllegianceMD, together with all associated IP rights. If assignment is ineffective, Customer grants AllegianceMD a perpetual, irrevocable, worldwide, royalty-free license to use Feedback for any purpose without restriction, attribution, or compensation.
6.5 Reservation
Nothing restricts AllegianceMD from developing, providing, or commercializing products or services that are similar to or compete with those of Customer.
7 Security; Availability; Support
7.1 Safeguards
AllegianceMD implements reasonable and appropriate administrative, technical, and physical safeguards designed to protect Customer Data. AllegianceMD does not guarantee absolute security.
7.2 Availability; Maintenance
The Service may be unavailable during planned maintenance windows and for emergency maintenance. Internet, telecom, and hosting dependencies are outside AllegianceMD's control.
7.3 Service Levels
Unless an Order Form or SLA expressly states Service Levels and credits, no uptime warranty applies. Service credits (if any) are Customer's sole and exclusive remedy for Service Level failures.
7.4 Incidents
AllegianceMD will promptly notify Customer of a security incident impacting Customer Data and will provide updates as reasonably available. For PHI, notifications will be made in accordance with HIPAA/HITECH and the BAA (without unreasonable delay and no later than the applicable statutory deadlines). For non-PHI personal information, AllegianceMD will notify without unreasonable delay and in any event within 30 Business Days after determining that a notifiable breach has occurred under applicable law.
7.5 Maintenance of Alternative Workflows
Customer will maintain reasonable downtime and contingency procedures for prescribing, results review, and other clinical workflows during scheduled or emergency maintenance or third-party outages.
7.6 Interfaces Status Visibility
Any dashboards/queues we provide regarding message status are informational only. Customer remains solely responsible for monitoring and acting on items requiring clinical follow-up.
8 Beta Features & Free Trials
Beta Features and free trials are provided AS-IS, without warranties, support, or indemnities, may be rate-limited, and may be modified or discontinued at any time. Customer must not rely on Beta Features for clinical decisions. Beta Features and trials are excluded from SLAs and credits.
9 Fees; Taxes; Non-Payment
9.1 Fees
Fees are set forth on the Order Form. All fees are non-cancellable and non-refundable except as expressly stated herein.
9.2 Taxes
Fees exclude taxes. Customer is responsible for all sales, use, VAT, GST, and similar taxes (excluding taxes based on AllegianceMD's net income).
9.3 Invoices; Late Fees
Unless otherwise stated, invoices are due net thirty (30) days. Overdue amounts may accrue the lesser of 1.5% per month or the maximum lawful rate. Customer agrees to pay reasonable collection and attorneys' fees.
9.4 Suspension
9.4 Suspension (Non-Payment). We may suspend the Service for unpaid amounts after notice and a ten (10) day cure period. Notwithstanding the foregoing, AllegianceMD will not implement a suspension in a manner that constitutes information blocking or violates applicable law. During any suspension for non-payment, Customer will retain limited, read-only access sufficient to (a) enable an individual’s electronic access to their EHI and (b) perform the certified EHI export capability (45 C.F.R. § 170.315(b)(10)) for switching or patient access. We may throttle or disable non-essential features and charge permitted fees consistent with 45 C.F.R. § 171.302, but we will not charge (i) any fee based on an individual’s electronic access to their EHI or (ii) any fee to perform the certified export for switching or to provide patients their EHI. Service restoration may require payment of past-due amounts and a reasonable reactivation fee.
10 Term; Termination; Suspension
10.1 Term
The initial subscription term is stated in the Order Form and auto-renews for successive terms of equal length unless a party gives at least sixty (60) days' prior written notice of non-renewal (or a longer period if required by applicable law).
10.2 Termination for Cause
Either party may terminate for material breach not cured within thirty (30) days after written notice. AllegianceMD may terminate immediately if continued Service would create material legal or security risk or if Customer becomes insolvent, enters bankruptcy, or ceases operations.
10.3 Suspension
AllegianceMD may suspend access immediately for: (a) security risk; (b) suspected violation of law, these TOS, or the BAA; (c) non-payment; or (d) use that degrades or adversely impacts the platform or other customers.
10.4 Effect; Data Export; Deletion
Upon termination or expiration, Customer's access ends. For thirty (30) days after termination (the "Export Window"), upon request, AllegianceMD will make available Customer Data in a reasonable, standard format via available export tools. Extended or custom exports may incur fees. Following the Export Window, AllegianceMD will delete Customer Data per its retention schedule, subject to legal holds and obligations. For PHI, return/destruction will be performed per the BAA and Customer's documented instructions, and for such periods as required by applicable medical-record retention laws or legal holds.
11 Warranties & Disclaimers
11.1 Limited Warranty (Material Conformity; Module Scope; Workarounds)
During the subscription term, the Service will materially conform to the Documentation under Supported Configurations. Conformity is assessed at the Module level identified on the Order Form, not any individual screen, field, or sub-feature. AllegianceMD may satisfy its re-performance obligation by providing a commercially reasonable workaround that restores Material Conformity. This warranty does not apply to issues caused by:
- (a) Third-Party Services or data sources;
- (b) Customer's configurations, integrations, or use contrary to the Documentation;
- (c) unsupported environments or Customer networks;
- (d) Beta Features or free trials;
- (e) clinical content accuracy or clinical outcomes; or
- (f) internet/telecom/hosting dependencies.
Claims must be submitted within thirty (30) days of discovery with reasonable cooperation and steps to reproduce. Customer's exclusive remedies for breach of this Section are (i) re-performance (including a workaround) or (ii) if AllegianceMD cannot cure within a reasonable time, a pro-rated credit of prepaid fees for the affected Module for the period of nonconformity. Credits under this Section may not be combined with SLA credits for the same event; the greater credit applies.
Credit Ceiling: Total credits issued under this Section in any calendar quarter will not exceed 20% of the fees paid or payable for the affected Module for that quarter.
11.2 DISCLAIMERS
THE SERVICE, CONTENT, BETA FEATURES, AND ALL RELATED MATERIALS ARE PROVIDED "AS IS" AND "AS AVAILABLE." EXCEPT AS EXPRESSLY STATED IN SECTION 11.1, ALLEGIANCEMD AND ITS SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, AND INTEROPERABILITY. ALLEGIANCEMD DOES NOT WARRANT UNINTERRUPTED OR ERROR-FREE OPERATION OR THAT THE SERVICE WILL MEET CUSTOMER'S REQUIREMENTS OR ENSURE CLINICAL OR REGULATORY OUTCOMES.
12 Indemnification
12.1 Customer Indemnity
Customer will defend, indemnify, and hold harmless AllegianceMD and its officers, directors, employees, and agents from and against all third-party claims, damages, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to:
- (i) Customer Data (including PHI) or alleged misuse,
- (ii) Customer's or Users' use of the Service in violation of law, the BAA, or these TOS,
- (iii) disputes with patients, payors, or Third-Party Services,
- (iv) Customer's configurations, integrations, or customizations,
- (v) Customer's failure to obtain required consents, authorizations, or notices, and
- (vi) any alleged Information Blocking or penalties arising from Customer's configurations, access decisions, or failure to provide required notices/authorizations.
12.2 AllegianceMD IP Indemnity
AllegianceMD will defend Customer against third-party claims alleging that the Service, as provided by AllegianceMD and used in accordance with these TOS and the Documentation, directly infringes a U.S. patent, copyright, or trademark, and will pay final judgments or settlements approved by AllegianceMD. If a claim arises, AllegianceMD may, at its option:
- (a) procure the right for Customer to continue using the Service;
- (b) replace or modify the Service to be non-infringing; or
- (c) terminate the affected Service and issue a pro-rated credit for prepaid, unused fees.
This Section is Customer's sole and exclusive remedy for IP infringement. AllegianceMD has no obligation for claims based on:
- Third-Party Services or third-party components,
- Customer Data,
- Customer's use not in accordance with the Documentation,
- combinations with items not provided by AllegianceMD,
- requested changes or configurations, or
- open-source components used under their licenses.
12.3 Procedure
The indemnified party must promptly notify the indemnifying party of the claim, allow control of the defense, and provide reasonable cooperation.
13 Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW: (A) NEITHER PARTY IS LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUES, DATA, GOODWILL, OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THE POSSIBILITY; AND (B) A PARTY'S AGGREGATE LIABILITY FOR ALL CLAIMS WILL NOT EXCEED THE LESSER OF (i) FEES PAID OR PAYABLE BY CUSTOMER IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY OR (ii) US$5,000. THESE LIMITATIONS APPLY TO ALL CAUSES OF ACTION, WHETHER IN CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, STATUTE, OR OTHERWISE, AND SURVIVE TERMINATION. These limitations apply to the maximum extent permitted by law and do not limit liability that cannot legally be limited under applicable law.
14 Confidentiality
14.1 Obligations
Each party will protect the other's non-public information with reasonable care and use it only for this relationship. PHI is governed by the BAA. Confidentiality obligations do not apply to information that is public without breach, independently developed without use of the other's information, or rightfully obtained from a third party.
14.2 Compelled Disclosure
A party may disclose the other's confidential information as required by law or court order, with reasonable advance notice (if legally permitted) to allow the other party to seek protection.
15 Compliance; Export; Anti-Corruption
Customer represents and warrants that it and its Users will comply with applicable healthcare, privacy, and security laws; U.S. and international export control and sanctions laws (including the EAR and OFAC programs); and anti-corruption laws. Customer will not permit access to or use of the Service (a) in any country or region subject to comprehensive U.S. embargo (currently including, without limitation, Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine), (b) by any individual or entity on U.S. or applicable jurisdiction denied or restricted party lists, or (c) for any prohibited end use under the EAR. Customer will not offer, promise, or give anything of value in violation of anti-corruption laws in connection with this Agreement.
16 U.S. Government Rights
If accessed by or on behalf of the U.S. Government, the Service is "commercial computer software" with rights restricted by FAR 12.212 and DFARS 227.7202.
17 Publicity; Marks
We may use Customer's name and logo in customer lists and brief case studies unless Customer opts out by written notice. Use must be reasonable and non-disparaging.
18 Modifications to TOS or Service
We may update the TOS and the Service from time to time. Material changes for paid customers take effect on renewal or thirty (30) days after notice (via email or in-product), whichever is earlier, except changes required by law or for security may take effect immediately. Continued use after effectiveness constitutes acceptance.
19 Dispute Resolution; Governing Law; Venue; Class Waiver
19.1 Governing Law
Nevada law governs, without regard to conflicts rules.
19.2 Arbitration
Any dispute arising out of or relating to these TOS or the Service will be resolved by binding arbitration administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules. The seat and venue will be Clark County, Nevada. One arbitrator, appointed under the Rules. Judgment on the award may be entered in any court of competent jurisdiction.
19.3 Injunctive Relief
Either party may seek temporary or injunctive relief in the state or federal courts located in Clark County, Nevada to protect IP, confidential information, or address security threats.
19.4 Class/Jury Waiver
Disputes must be brought only in an individual capacity and not as a class, representative, or private attorney general action. JURY TRIAL IS WAIVED.
19.5 Severability (Dispute Provision)
If the class or representative action waiver is found unenforceable with respect to a particular claim or party, then only that claim or party will proceed in court and the remainder of the arbitration agreement will remain in force. If a court determines that the entire arbitration agreement is unenforceable for a particular claim or party, then that claim or party will proceed exclusively in the state or federal courts located in Clark County, Nevada, and the parties waive jury trial.
20 Notices; Assignment; Entire Agreement; Severability; Survival
20.1 Notices
Legal notices to AllegianceMD: https://allegiancemd.com/contact-us. We may provide notices to Customer via email to the admin contact and through the Service portal.
20.2 Assignment
Customer may not assign these TOS or any rights without AllegianceMD's prior written consent, except to a successor in interest to all Customer's relevant business and obligations, with prompt notice. AllegianceMD may assign these TOS (including in a merger, sale, or corporate reorganization) upon notice.
20.3 Entire Agreement; Waiver
These TOS, the Order Form, the BAA, the DPA (if any), and Policies are the entire agreement. Waivers must be in writing and are not continuing. Customer acknowledges it has not relied on any representations or statements not expressly set out in this Agreement or the Order Form.
20.4 Severability
If any provision is unenforceable, it will be modified to the minimum extent necessary; the remainder remains in effect.
20.5 Survival
Sections 2, 3.2–3.4, 4, 5.3, 6, 7.3–7.4, 8, 9, 10.4, 11, 12–16, 18–20 survive termination.
21 API Terms
21.1 API Access
Use of APIs is subject to these TOS, Documentation, and fair-use/rate limits we may set.
21.2 Security
API keys are credentials; keep them confidential. Do not embed keys in client-side code or share with third parties.
21.3 Prohibited Uses
No scraping, replication of substantial parts of the Service, or building competing datasets. We may suspend APIs for abuse, security risk, or legal reasons. Excessive or abusive API calls constitute cause for suspension under §10.3(d).
Effective Date: 01/01/2019
Last Updated: 09/19/2025
Privacy Policy (Site, App, and Services)
Plain-Language Summary (Not Legally Operative)
This Policy explains what we collect, how we use it, and when we share it. PHI is handled under our BAA with your healthcare provider; this Policy covers other personal information (e.g., account, device, and usage data). We use data to deliver and secure the Service, support you, improve features, and comply with law. We don't sell or share PHI. We also state that we do not sell or share personal information for cross-context behavioral advertising. You can exercise rights under applicable laws. Security is "reasonable and appropriate," not absolute. We keep data only as long as needed. Details below control.
Table of Contents
- 1. Scope; Audience; Relationship to HIPAA
- 2. Categories of Data Collected
- 3. Sources of Data
- 4. Purposes of Use
- 5. Legal Bases / Regional Notices
- 6. Disclosures to Third Parties
- 7. Cookies & Tracking
- 8. Data Retention
- 9. Security
- 10. International Transfers
- 11. Children's Privacy
- 12. Individual Rights & Requests
- 13. Breach/Incident Notifications
- 14. Changes to this Policy
- 15. Contact Information
1 Scope; Audience; Relationship to HIPAA
1.1 Scope
This Privacy Policy ("Policy") applies to personal information processed by AllegianceMD through our websites, applications (including the patient portal), and cloud services (collectively, the "Services").
1.2 HIPAA vs. This Policy
When we process PHI on behalf of a Covered Entity or Business Associate under a BAA, PHI is governed by HIPAA/HITECH and the BAA, not this Policy. This Policy governs non-PHI personal information (e.g., account and usage data).
1.3 Patient-Facing Portal
Patient portal content may include PHI. For patients, your provider's Notice of Privacy Practices governs PHI; this Policy governs portal account metadata and usage information to the extent it is not PHI.
2 Categories of Data Collected
We collect the following categories (which may overlap):
2.1 Account & Identity
Name, username, password, contact details, role, professional credentials, NPI/license, practice information.
2.2 Patient PHI
Clinical records, demographics, insurance, e-prescribing, orders/results, notes, images, communications—when processed under a BAA.
2.3 Device/Telemetry
IP address, device identifiers, browser, OS, app version, timestamps, cookies, logs, crash reports.
2.4 Usage Analytics
Feature usage, clickstream, session metadata, configuration settings, API calls, performance metrics.
2.5 Support Artifacts
Tickets, chat transcripts, call recordings, screenshots, and logs. Customer must avoid including unnecessary PHI in tickets; if included, PHI is handled under the BAA.
2.6 Payment/Billing
Billing contacts, payment tokens (via PCI-compliant processors), transaction records.
2.7 Sensitive Data
We do not intentionally collect Sensitive Data outside of PHI. If provided (e.g., government IDs for identity verification), we process it only as necessary and permitted by law.
2.8 Cookies/Similar Tech
See Section 7.
2.9 From Integrations
Data exchanged with labs, eRx networks, clearinghouses, HIEs, registries, payment processors, telehealth platforms, and other integrated systems.
3 Sources of Data
- Directly from Users (account setup, forms, portal).
- Automatically via the Services (SDKs, telemetry, logs, cookies).
- From Customer's systems and vendors during onboarding or migration.
- From Third-Party Services enabled by Customer (Section 2.9).
- Public and commercial sources (e.g., NPI registry) for verification.
4 Purposes of Use
We use data to:
4.1 Provide & Operate
Deliver core functionality, EHR workflows, PM/billing, e-prescribing, portal access, APIs, and integrations.
4.2 Secure & Maintain
Authenticate, prevent fraud/abuse, detect incidents, debug, and ensure integrity and availability.
4.3 Support
Provide technical and customer support; train support personnel; improve service quality.
4.4 Improve & R&D
Analyze usage; develop new features; create De-identified and Aggregated Data for analytics and benchmarking.
4.5 Communicate
Send service, security, and transactional communications; provide product updates. Marketing communications are limited and can be controlled via preferences.
4.6 Compliance
Meet legal, regulatory, and audit obligations, including HIPAA/HITECH (for PHI via BAA), Information Blocking, reporting, and responding to lawful requests.
We do not sell or share PHI. For non-PHI personal information, we do not sell and do not share for cross-context behavioral advertising.
5 Legal Bases / Regional Notices
5.1 HIPAA/HITECH (PHI)
PHI is processed as a Business Associate under the BAA for treatment, payment, and healthcare operations and as otherwise permitted by HIPAA.
5.2 Nevada (NRS 603A)
We maintain reasonable security measures to protect personal information and do not sell covered information as "sale" is defined by Nevada law.
5.3 California (CCPA/CPRA)
For California residents, we act primarily as a service provider to our Customers. For our own website/app operations (non-PHI), we collect identifiers, internet activity, and professional information for the purposes in Section 4. We do not sell or share personal information. Rights: access, correction, deletion, portability, and to limit use of Sensitive PI (not applicable as we do not use Sensitive PI beyond permitted purposes). Submit requests via [email protected] or portal form. We will verify and respond within required timelines.
5.4 Virginia/Colorado/Connecticut/Utah
We process personal data as a processor/service provider for our Customers and as a controller for our own operations. Rights: access, correction, deletion, portability, and appeal (VA/CO/CT). Submit requests via [email protected]. Appeals may be submitted to the same address with "Appeal" in the subject.
5.5 GDPR/UK GDPR
For EU/UK personal data not subject to HIPAA, AllegianceMD acts as a processor to Customer (controller) and as a controller for limited operations (account, billing, security). Legal bases include contract performance, legitimate interests (security, improvement), legal obligation, and consent where required. Where applicable, we use EU Standard Contractual Clauses/UK IDTA for international transfers.
6 Disclosures to Third Parties
We disclose data to:
6.1 Subprocessors/Service Providers
Hosting, support, communications, analytics, security, and similar vendors under written contracts with confidentiality and data-protection obligations.
6.2 Third-Party Services Enabled by Customer
Labs, eRx networks, clearinghouses, payment processors, telehealth/HIEs/registries, and other integrations at Customer's direction.
6.3 Legal/Compliance
To comply with law, respond to lawful requests, or protect rights, safety, and security.
6.4 Corporate Transactions
In mergers, acquisitions, financings, or reorganizations, subject to confidentiality.
6.5 With Consent/Instructions
As authorized by Customer or the data subject where applicable.
We do not sell personal information and do not share personal information for cross-context behavioral advertising.
7 Cookies & Tracking
7.1 Types
We use: (a) Essential cookies for login, security, and core functions; (b) Analytics cookies to understand feature usage and performance; and (c) Preference cookies to remember settings.
7.2 Controls
You can manage cookies in your browser and via our Cookie Settings link (where available). Blocking essential cookies may impair functionality.
7.3 Do Not Track
We honor legally required preference signals where applicable.
8 Data Retention
We retain PHI per the BAA/Customer instructions and applicable medical-record retention laws; we do not act as the medical-record custodian. We retain non-PHI personal information no longer than necessary for the purposes in Section 4, typically for the subscription term plus a reasonable period (e.g., up to 24 months) for backup, audit, dispute resolution, and legal compliance, unless a longer period is required by law or contract.
9 Security
We implement reasonable and appropriate administrative, technical, and physical safeguards designed to protect data. No method of transmission or storage is 100% secure. We will notify as required by law and the BAA in the event of certain incidents.
10 International Transfers
Where applicable, we use lawful transfer mechanisms (e.g., EU Standard Contractual Clauses, UK IDTA/Addendum) and implement appropriate safeguards. Details are available upon request.
11 Children's Privacy
The Services are not directed to children under 13. Any minor patient PHI processed via the Service is handled under HIPAA and the BAA at the direction of the Covered Entity.
12 Individual Rights & Requests
12.1 How to Submit
Send requests to [email protected] or through the portal. Specify your relationship (patient, provider staff, website visitor) and the data you seek.
12.2 Verification
We may require information to verify identity and authority (e.g., from a representative). For PHI, requests are handled under HIPAA and directed to the Covered Entity as appropriate.
12.3 Timelines; Appeals
We will respond within applicable statutory timelines. For Virginia/Colorado/Connecticut, you may appeal a denial by emailing [email protected] with "Appeal" in the subject.
13 Breach/Incident Notifications
For PHI, notifications are made in accordance with HIPAA/HITECH and the BAA. For non-PHI, we will notify you as required by applicable law.
14 Changes to this Policy
We may update this Policy. Material changes will be notified via email or in-product notice and will take effect on the Effective Date listed below or as required by law.
15 Contact Information
Privacy inquiries and rights requests: https://allegiancemd.com/contact-us
Postal: AllegianceMD Software, Inc., 6914 S. Yorktown ave Ste 200 Tulsa, OK 74136
General contact: https://allegiancemd.com/contact-us
State-Specific Addenda (Summaries)
Effective Date: 01/01/2019
Last Updated: 09/19/2025