Terms and Conditions

Last Updated: August 17, 2026 These Terms and Conditions (“Agreement”) govern access to and use of the Hermes Health Unity Platform and related services (the “Services”) offered by Hermes Health Group, Inc. (“Hermes Health”). By entering into an Order Form with Hermes Health, clicking “I Accept,” checking the acceptance box, or otherwise using or accessing the Services, customer (“Customer”) agrees to be bound by this Agreement, including any Order Forms, exhibits, or addenda incorporated herein by reference. If Customer does not agree to all of the terms of this Agreement, do not click “I Accept” (or the equivalent) and do not access or use the Services. 1. Definitions. 1.1. “Affiliate” means any organization (a) which controls, is controlled by, or is under common ownership or control with a Party; or (b) for which a Party directly or indirectly holds or controls fifty percent (50%) or more of the beneficial ownership or voting interest or the power to direct or cause the direction of the management or policies of an entity, whether through the ability to exercise voting power, by contract, or otherwise. 1.2. “Applicable Data Protection Laws” means any applicable U.S. federal or state law or regulation that governs the privacy, security, confidentiality, protection, processing or transfer of the Patient Data or that govern the rights of Patients or other data subjects with regard to that Patient Data, including, as applicable, the Health Insurance Portability and Accountability Act, as amended by the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations (collectively, “HIPAA”). 1.3. “Authorized Purposes” are the purposes and activities for which Customer authorizes Hermes Health to use or disclose Patient Data through the Services. 1.4. “BAA” means a Business Associate Agreement executed by and between the Parties, as applicable. 1.5. “Confidential Information” means any non-public information of either Party relating to its business activities, financial affairs, technology, marketing or sales plans that is disclosed to, and received by, whether orally or in writing, the other Party pursuant to this Agreement, including any information that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure, and the terms and conditions of this Agreement and any associated Order Form. Customer acknowledges and agrees that the technology and computer code underlying the Services is Confidential Information of Hermes Health. 1.6. “Customer Data” means, except as otherwise provided in the applicable Order Form, all Inputs and Outputs submitted or generated by or on behalf of Customer in connection with Customer’s use of the Services. Customer Data includes all Patient Data. 1.7. “Effective Date” means the date Customer first clicks ‘I Accept,’ checks the acceptance box, or otherwise starts using the Services or otherwise executes an Order Form or separate agreement between the Parties. 1.8. “Hermes Health Platform” means the cloud-hosted software-as-a-service (SaaS) platform marketed as the “Hermes Health Unity Platform” that is designed to facilitate access to and exchange of Patient Data. 1.9. “Inputs” means the information input for an individual patient by or on behalf of Customer into the Hermes Health Platform as required to provide the Services. 1.10. “Network Participants” means (a) Provider Network(s) and (b) Customer. 1.11. “Outputs” means the abstracts, summaries, analyses, answers or other information generated by the Hermes Health Platform in response to the Inputs provided by or on behalf of Customer. 1.12. “Patient Authorization” means an express authorization meeting the requirements of Applicable Data Protection Laws from a patient permitting such patient’s Patient Data to be processed by Hermes Health as contemplated by this Agreement. 1.13. “Patient Data” means the data regarding a patient created or received by Hermes Health from or on behalf of Customer through the Services that is identified with an individual patient and includes without limitation the patient’s past, present, or future physical or mental health status, some or all of which may constitute “protected health information” as defined in 45 C.F.R. § 160.103. A patient’s Patient Authorization is also Patient Data. 1.14. “Provider Network” means any third‑party entity or electronic data‑exchange platform—including, without limitation, electronic health‑record (EHR) vendors, release‑of‑information (ROI) vendors, healthcare facilities, real‑world‑data companies, and other clinical‑data intermediaries—with which Hermes Health maintains a contractual relationship or data‑use agreement that authorizes the exchange of Patient Data with Hermes Health for one or more Authorized Purposes. 1.15. “Order Form” means an online or written ordering document generated by Hermes Health that Customer submits (electronically or in writing) and Hermes Health accepts, specifying the Services to be provided and any pricing or usage limits. Order Forms shall be deemed incorporated herein by reference. No Order Form will be binding unless executed by both Parties. 1.16. “Services” means the provision of access to the features and functionality of the Hermes Health Platform, including the services made available via the Hermes Health Platform, and updates and modifications thereto, related support or other professional services, in each case as specified in an Order Form. 1.17. “Users” means any of Customer’s or its Affiliates’ employees, independent contractors and other individuals authorized by Customer to use the Services in accordance with this Agreement. For purposes of this Agreement, where applicable, this may include Customer’s end users. 2. Services. 2.1. Subscription. Subject to the terms of this Agreement and any restrictions set forth in an Order Form, Hermes Health grants Customer and its Users a non-exclusive, non-transferable, non-sublicensable right to have its Users: 2.1.1. access the features and functions of the Services ordered under an Order Form solely for the purposes set forth therein; and 2.1.2. view, download and use the Patient Data requested by Customer from Provider Networks, which are made available to Customer through the Services solely in accordance with the terms of this Agreement. 2.2. Users. Customer shall be responsible for granting and revoking User authorizations in accordance with Hermes Health’s reasonable security and user-credentialing requirements as may be communicated by Hermes Health from time to time. Customer shall ensure that its Users’ access to and use of the Services are in accordance with this Agreement. Customer is solely responsible for each of its Users’: (a) use of the Services, (b) training, (c) compliance with this Agreement, and (d) compliance with Applicable Data Protection Laws (including, without limitation, the HIPAA Minimum Necessary Requirements described in 45 C.F.R. §§ 164.502(b) and 164.514(d) (the “Minimum Necessary Requirements”)). 2.3. Artificial Intelligence Tools. As part of the provision of the Services, Hermes Health leverages certain proprietary and third-party artificial intelligence tools (collectively, the “AI Tools”). The AI Tools leverage large language models and artificial intelligence algorithms to receive Inputs and generate Outputs. The AI Tools will use and process Customer Data only as necessary to provide Customer with the Services, comply with applicable law, and as otherwise set forth herein. CUSTOMER AND NOT HERMES HEALTH SHALL BE SOLELY RESPONSIBLE FOR ITS AND ITS AUTHORIZED USERS’ INPUTS AND USE OF THE OUTPUTS, INCLUDING ANY DECISIONS MADE OR ACTIONS TAKEN BASED ON THE OUTPUTS. 2.4. Restrictions. Customer and its Users may use the Services only in accordance with applicable law and the terms of this Agreement. Except as expressly authorized by this Agreement, Customer will not, and will not allow any User or other third party under its control, to (a) permit any non-User to access or use the Services; (b) decompile, disassemble, reverse engineer, or otherwise attempt to derive the trade secrets embodied in the Services; (c) use any Services, or allow the transfer, transmission, export, or re-export of any Services or portion thereof in violation of any export control laws or regulations administered by the U.S. Commerce Department or any other government agency; (d) bypass or breach any security device or protection used by the Services or access or use the Services other than through the use of a User’s own then-valid access credentials; (e) input, upload, transmit, or otherwise provide to or through the Services any information or materials that are unlawful or injurious or which contain, transmit, or activate any harmful or destructive code; (f) remove any copyright, trademark, proprietary rights, disclaimer, or warning notice included on or embedded in any part of the Services, including any screen displays, etc., or any other products or materials provided by Hermes Health hereunder; or (g) access the Services with any automated or other process such as screen scraping, by using robots, web-crawlers, spiders or any other sort of bot or tool, for the purpose of extracting data, monitoring availability, performance, functionality, or for any other benchmarking or competitive purpose. 2.5. Connectivity. As between Hermes Health and Customer, Customer is solely responsible for all telecommunication and internet connections required to access the Services, as well as all hardware and software at Customer’s site(s). In addition to other third-party costs that may apply, Customer agrees to pay for all telecommunications services required for Customer and its Users to access the Services. Hermes Health hereby disclaims all liabilities and makes no warranties of any kind with respect to Customer’s use of products or services provided by a third party to access or use the Services (e.g., computers, operating systems, internet connections, EMRs (if applicable)). 2.6. Services Ownership and Feedback. Except for the limited rights expressly provided to Customer herein, Hermes Health retains all rights, title, and interest (including, without limitation, all patent, copyright, trademark, trade secret, and other intellectual property rights) in and to the Services, and all copies, modifications, improvements, trained models, enhancements, analytics, benchmarks, insights, and derivative works thereof. Customer acknowledges that Hermes Health makes available to all of its Network Participants and other customers on a regular basis improvements to the Services which may be based in whole or in part on feedback provided by its Network Participants and customers and their Users (including Customer and its Users) and Customer hereby grants to Hermes Health a worldwide, perpetual, irrevocable, royalty-free license to use and incorporate into the Services any suggestion, enhancement request, recommendation, correction, or other feedback which is provided to Hermes Health by Customer or its Users. 2.7. Customer Ownership and License of Patient Data. 2.7.1. Ownership. As between Customer and Hermes Health, and subject to the rights and licenses granted herein, Customer shall retain ownership of its Patient Data and, to the extent permitted by applicable law, retains all rights to the Inputs and owns all Outputs. Customer acquires no right, title, or interest, except for the limited right expressly granted to Customer herein, in Hermes Health’s proprietary format or display of same through the Services. 2.7.2. Customer Responsibilities. Customer is solely responsible for (a) the accuracy, legality, sufficiency, and completeness of Customer Data, including all Inputs and (b) obtaining and maintaining all authorizations, consents, and notices required by Applicable Data Protection Laws for Hermes Health’s use of Customer Data as set forth herein. 2.7.3. License to Hermes Health. Customer hereby grants to Hermes Health a non-exclusive, non-transferable, non-sublicensable license to: 2.7.3.1. Run the Services. Use, reproduce, host, display, transmit, and disclose Customer Data as reasonably necessary to provide, maintain, support, and secure the Services and to comply with Customer’s lawful instructions and applicable law; 2.7.3.2. Improve Hermes Health Operations and Offerings. Use Customer Data to monitor performance, fix defects, train algorithms needed for the Services, test enhancements, develop new features, and otherwise improve the quality, speed, and security of the Services; 2.7.3.3. Develop Value‑Added Offerings. Use Customer Data to design, test, and deliver analytics, benchmarks, clinical abstractions, predictive insights, or other value‑added solutions for Customer and other authorized Network Participants; and 2.7.3.4. Comply with Law. Use Customer Data as required to satisfy applicable legal, regulatory, or accreditation obligations. 2.7.4. Safeguards. Hermes Health will protect all identified Customer Data in accordance with any BAA, if applicable, and Applicable Data Protection Laws. Hermes Health will not sell Patient Data to third parties or use it for marketing to individuals without Customer’s prior written consent. 2.7.5. No Other Rights. Except for the licenses expressly granted above, this Agreement conveys no ownership or other rights (by implication, estoppel, or otherwise) to either Party in the other Party’s data or intellectual property. 3. Legal Compliance and Data Use and Disclosure. 3.1. Customer Attestation. The Hermes Health Platform is designed to enable Customer and its Users to access and share electronically Patient Data with Provider Networks for the Authorized Purposes. As a precondition to using these Services, Customer certifies that it meets one of the following legal statuses and will maintain that status throughout the Term: 3.1.1. Covered Entity under 45 C.F.R. § 160.103; 3.1.2. Business Associate of one or more Covered Entities, as defined in 45 C.F.R. § 160.103; or 3.1.3. Authorized third party that has valid Patient Authorizations or other legally effective patient consents permitting it to obtain, use, and disclose the relevant Patient Data through the Services for the Authorized Purposes. 3.1.4. Customer further agrees to (a) keep documentary evidence of such status and authorizations on file, (b) provide that evidence to Hermes Health upon reasonable request, and (c) promptly notify Hermes Health in writing if Customer no longer satisfies the requirements above. Any misrepresentation—or later loss—of the attested status constitutes an incurable material breach of this Agreement, entitling Hermes Health to immediate suspension or termination of the Services. 3.2. Patient Authorizations. Where HIPAA authorizations or equivalent patient consents (i.e., Patient Authorizations) are required for the Authorized Purposes, Customer represents and warrants that it has obtained—and will maintain for the duration of this Agreement—a valid authorization or consent from each affected patient to perform the Services and that complies with applicable law. Without limiting the foregoing, Customer is solely responsible for: 3.2.1. Securing and documenting all licenses, consents, notices, and regulatory approvals necessary under Applicable Data Protection Laws to permit Hermes Health to receive, store, process, and disclose Patient Data as set forth herein; 3.2.2. Ensuring that all instructions provided to Hermes Health regarding the use or disclosure of Patient Data are lawful and do not cause Hermes Health to violate Applicable Data Protection Laws; and 3.2.3. Promptly informing Hermes Health in writing if any Patient Authorization is revoked, expires, or is otherwise rendered invalid. 3.2.4 If any Patient Authorization or legal basis lapses or becomes defective, Customer will immediately cease transmitting the affected data through the Services and will instruct Hermes Health on the lawful disposition of such data. 3.3. Use & Disclosure of Information by Customer and Customer’s Contractors. 3.3.1. Subject to the terms of this Agreement, Customer may use and disclose Customer Data via the Services for the Authorized Purposes. As between Customer and Hermes Health, Customer is solely responsible for ensuring that Customer’s use and disclosure of Patient Data via the Services (a) is limited to Authorized Purposes; (b) is permissible under any applicable privacy policy and/or HIPAA privacy notice; (c) is not required to be authorized or consented to by any person, including any individual to whom it pertains, or if authorization or consent of any person is required, that it has been obtained; (d) is not subject to an agreed upon or required restriction which would prohibit the disclosure; and (e) is limited to individuals with whom Customer has a direct relationship for treatment, payment, or health care operations purposes, or for whom Customer is permitted by applicable law to access Patient Data. Furthermore, Customer hereby represents that its access to, use of, and disclosure of Customer Data via the Services shall be consistent with all applicable federal and state laws, including, without limitation, the Minimum Necessary Requirements. 3.3.2. If Customer engages an individual or entity as a business associate of Customer to provide services on Customer’s behalf which services require access to Patient Data via the Services (each a “Contractor”), Customer shall restrict such Contractor’s use and disclosure of Patient Data to the applicable Authorized Purposes and in all cases consistent with the Minimum Necessary Requirements. Customer will also ensure that such Contractor has entered into a HIPAA business associate agreement. To the extent that Customer requests that Hermes Health directly deliver Customer’s Patient Data to Customer’s Contractor, via the Services or otherwise, and Hermes Health agrees to do so, then Customer shall deliver an authorization letter to Hermes Health which identifies the specific subset of Patient Data necessary to fulfill the request. Such authorization letter shall include the following Customer representations: (a) that Customer has executed a services contract and a valid HIPAA business associate agreement with the Contractor; (b) that the Patient Data which Customer instructs Hermes Health to deliver to the Contractor is being delivered to Contractor on behalf of Customer and is consistent with the Authorized Purposes and with the Minimum Necessary Requirements; (c) that the Contractor has provided Customer with assurances to Customer’s reasonable satisfaction with respect to the Contractor’s information-security practices and related compliance, and that Customer understands and acknowledges that Hermes Health will not be performing its own security or compliance assessments of the Contractor; (d) that Customer will not hold Hermes Health responsible for, and shall indemnify Hermes Health from and against, the Contractor’s use or disclosure of, or changes to, the Patient Data or for any other activity of Customer’s Contractor; and (e) that Customer will immediately notify Hermes Health upon termination of Customer’s services contract or business associate agreement with the Contractor or upon any change of the scope of such agreements such that a change to the Contractor’s access to Customer’s Patient Data is merited. 3.4. Use and Disclosure of Customer Data by Hermes Health. Hermes Health may use and disclose Customer Data including Patient Data (a) for the Authorized Purposes, (b) as permitted under the license granted by Customer to Hermes Health under Section 2.7.3, and (c) as otherwise authorized in this Agreement or the BAA; provided that any onward disclosure of identified data is limited to Authorized Purposes under this Agreement and/or a separate written agreement between Hermes Health and Customer. 3.5. Use and Disclosure of Administrative Data, Transaction Data, and Derived Data by Hermes Health. 3.5.1. Administrative Data. “Administrative Data” means information identifying and pertaining to Customer and its Users, such as User contact information, but which does not contain Patient Data or Customer’s Confidential Information, which Hermes Health uses to manage and administer the Services and provide support to Customer and its Users. Hermes Health may use and disclose Administrative Data for purposes of providing the Services to Network Participants, for Hermes Health’s proper management and administration, and as required by law. 3.5.2. Transaction Data. “Transaction Data” means information and statistics about Customer’s interactions with and usage of the Services, but which does not contain Patient Data, Administrative Data, or Customer’s Confidential Information. Customer hereby acknowledges and agrees that the Transaction Data is owned by, and is the exclusive property of Hermes Health, and that Hermes Health may use and disclose Transaction Data for any lawful purpose, including, by way of illustration and not limitation, (a) for the analysis, development, improvement, and provision of the Services and other Hermes Health products and services; (b) for recordkeeping, fee calculation, internal reporting, support, and other internal business purposes; (c) to report the number and type of transactions and other statistical information concerning the Services; and (d) to otherwise administer and facilitate the Services. 3.5.3. Derived Data. “Derived Data” means any data, information or insights that Hermes Health derives from Customer Data, Administrative Data, or Transaction Data that does not include Customer’s Confidential Information or Patient Data or other personally identifiable information. Customer hereby acknowledges and agrees that the Derived Data is owned by, and is the exclusive property of Hermes Health, and that Hermes Health may use, disclose, market, license, distribute, sell, receive remuneration for, create derivative works of, and otherwise commercialize the Derived Data for any legally permissible purpose. 4. Fees and Payment. 4.1. Subscription Fees. Customer shall pay all fees as specified in the applicable Order Form. Except as otherwise specified herein or in an Order Form, payment obligations are non-cancelable and fees paid are non-refundable. 4.2. Invoicing and Payment. Fees shall be invoiced in advance and otherwise in accordance with the relevant Order Form. Unless otherwise stated in the Order Form, fees are due net thirty (30) days from the receipt of invoice date, provided that if an invoice is sent electronically to the email address provided by Customer for billing, then it shall be deemed received by Customer as of the date it was sent. Hermes Health shall submit invoices to Customer as set forth in the applicable Order Form or Customer’s billing admin console. 4.3. Overdue Charges. Subject to Section 4.5, if any invoiced amount is not received by Hermes Health by the due date, then without limiting Hermes Health’s rights or remedies, those charges may accrue late interest at the rate of 1.5% of the outstanding balance per month, or the maximum rate permitted by law, whichever is lower. 4.4. Suspension of Service. Subject to Section 4.5, if any charge owing by Customer is thirty (30) days or more overdue, Hermes Health may, without limiting its other rights and remedies, suspend Services until such amounts are paid in full. 4.5. Payment Disputes. Hermes Health shall not exercise its rights under Sections 4.3 (Overdue Charges) or 4.4 (Suspension of Service) if Customer is disputing the applicable charges reasonably and in good faith and is cooperating diligently to resolve the dispute. 4.6. Taxes. Hermes Health’s fees do not include any taxes, levies, duties or similar governmental assessments of any nature, including, for example, value-added, sales, use or withholding taxes, assessable by any jurisdiction whatsoever (collectively, “Taxes”). Customer is responsible for paying all Taxes associated with its purchases hereunder. If Hermes Health has, or is later determined to have, the legal obligation to pay or collect Taxes for which Customer is responsible under this Section 4.6, Hermes Health shall invoice Customer and Customer shall pay that amount unless Customer provides Hermes Health with a valid tax exemption certificate which is authorized by the appropriate taxing authority. 5. Disclaimers. 5.1. EXCEPT AS EXPRESSLY SET FORTH HEREIN, THE SERVICES ARE PROVIDED ON AN AS-IS BASIS ONLY. WITHOUT IN ANY WAY LIMITING THE GENERALITY OF THE FOREGOING, HERMES HEALTH DOES NOT REPRESENT OR WARRANT THAT THE SERVICES WILL MEET THE REQUIREMENTS OF ANY PERSON OR WILL OPERATE ERROR-FREE OR CONTINUOUSLY, AND HERMES HEALTH MAKES NO OTHER REPRESENTATIONS OR WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OR REPRESENTATIONS CONCERNING MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. CUSTOMER AGREES THAT HERMES HEALTH HAS MADE NO AGREEMENTS, REPRESENTATIONS, OR WARRANTIES OTHER THAN THOSE EXPRESSLY SET FORTH IN THIS AGREEMENT, AND THAT NO OTHER STATEMENT ABOUT THE INFORMATION OR SERVICES PROVIDED UNDER THIS AGREEMENT SHALL BE DEEMED TO BE A WARRANTY EXCEPT TO THE EXTENT EXPRESSLY STATED AS SUCH A WARRANTY IN A MUTUALLY EXECUTED AMENDMENT TO THIS AGREEMENT. THE INFORMATION AVAILABLE THROUGH THE SERVICES DOES NOT REPRESENT HERMES HEALTH’S RECOMMENDATIONS. CUSTOMER ACKNOWLEDGES THAT THE SERVICES ARE NOT DESIGNED OR INTENDED TO BE RELIED UPON IN ANY ENVIRONMENT IN WHICH THE UNAVAILABILITY OF THE SERVICES COULD LEAD TO DEATH, PERSONAL INJURY, OR PHYSICAL OR ENVIRONMENTAL DAMAGE. HERMES HEALTH ASSUMES NO RESPONSIBILITY FOR THE ACCURACY, UP-TO-DATE STATUS, OR COMPLETENESS OF THE PATIENT DATA, NOR FOR SUCH PATIENT DATA’S SUFFICIENCY WITH ANY LEGAL STANDARD. CUSTOMER ACKNOWLEDGES THAT THE FULL AVAILABILITY OF CERTAIN FUNCTIONALITY OR CONTENT OF THE SERVICES DEPENDS, IN PART, UPON THE ACCURACY AND COMPLETENESS OF THE PATIENT DATA PROVIDED BY OR ON BEHALF OF CUSTOMER TO HERMES HEALTH. ACCORDINGLY, SUCH UNAVAILABILITY OF THE SERVICES SHALL NOT BE DEEMED TO BE A FAILURE BY HERMES HEALTH TO PROVIDE THE SERVICES. CUSTOMER AGREES THAT IT SHALL HOLD HERMES HEALTH HARMLESS FROM ANY AND ALL ADVERSE EXPENSES, DAMAGES, OR LOSSES WHICH MAY RESULT FROM ANY SUCH UNAVAILABILITY OF THE SERVICES. 5.2. CUSTOMER ACKNOWLEDGES AND UNDERSTANDS THAT ACCESS TO AND USE OF THE HERMES HEALTH PLATFORM AND/OR SERVICES DEPENDS IN PART ON ACCESS TO PATIENT DATA AND OTHER INFORMATION OR DATA PROVIDED BY PROVIDER NETWORKS OR OTHER THIRD PARTIES (“THIRD PARTY DATA”). THE PARTIES ACKNOWLEDGE AND AGREE THAT THE ACCURACY OF THE PATIENT DATA OR ANY OUTPUTS BASED THEREON MADE AVAILABLE TO CUSTOMER THROUGH THE SERVICES ARE DEPENDENT ON THE ACCURACY AND COMPLETENESS OF THIRD PARTY DATA AND THIRD PARTY DATA MAY BE DERIVED FROM HISTORICAL DATA THAT MAY BE OUTDATED AND NO LONGER ACCURATE AT THE TIME OF USE. ACCORDINGLY, HERMES HEALTH IS NOT RESPONSIBLE FOR THE ACCURACY, QUALITY, CURRENCY, TIMELINESS, OR COMPLETENESS OF THIRD PARTY DATA OR ANY OUTPUTS BASED ON THIRD PARTY DATA AND MAKES NO REPRESENTATIONS OR WARRANTIES REGARDING THIRD PARTY DATA OR ANY OUTPUTS BASED THEREON AND CUSTOMER USES THE OUTPUTS AT ITS OWN RISK. IN ADDITION, HERMES HEALTH CANNOT GUARANTEE THIRD PARTY DATA WILL ALWAYS BE AVAILABLE. IF A PROVIDER NETWORK OR OTHER THIRD PARTY BECOMES UNAVAILABLE OR HERMES HEALTH’S ACCESS TO SUCH PROVIDER NETWORK OR THIRD PARTY IS TERMINATED BY THE PROVIDER NETWORK OR THIRD PARTY, THEN THIRD PARTY DATA WILL NO LONGER BE AVAILABLE TO BE MADE TO CUSTOMER AND THE SERVICES WILL BE AFFECTED ACCORDINGLY. 5.3. Customer acknowledges and agrees that the Services and Patient Data are not intended to be medical advice or instructions for medical diagnosis, treatment, or care of persons by Hermes Health and that the Services are not a substitute for professional medical advice, examination, diagnosis, or treatment and should not be used to diagnose, treat, cure, or prevent any disease without the supervision of a doctor or qualified healthcare provider. Customer acknowledges and agrees that Hermes Health does not operate or control the internet and that: (a) viruses, worms, trojan horses, or other undesirable data or malware; or (b) unauthorized users (e.g., hackers) may attempt to obtain access to and damage data, websites, computers, or networks and that Hermes Health will not be responsible for such activities except to the extent that such activities are caused by Hermes Health’s breach of its information security obligations hereunder. In no event shall Hermes Health be liable to Customer or any third party for damages caused by a zero-day security event. 6. Limitations on Liability Relating to Performance of Services. Neither Party shall be liable to the other Party or to any third party for any indirect, incidental, special, consequential, or punitive damages arising out of or related to this Agreement, including without limitation loss of revenue, loss of profits, loss of business, or loss of data, even if advised of the possibility of such damages. Except with respect to (a) liability arising from a Party’s indemnification obligations, (b) Customer’s payment obligations, (c) Customer’s breach of Section 2.4 (Restrictions) or Section 9 (Mutual Confidentiality), or (d) either Party’s gross negligence or willful misconduct, each Party’s aggregate liability to the other for all damages, losses, and causes of action, whether in contract, tort (including negligence), or otherwise shall not exceed the total fees paid or payable to Hermes Health on behalf of Customer during the twelve (12) month period immediately preceding the event giving rise to such liability. Notwithstanding the foregoing, in no event shall a Party be responsible for any penalties, damages, or other losses incurred by the other Party as the result of any event, occurrence, or failure to perform which was materially caused or contributed to by such other Party’s failure to comply with an obligation under any applicable requirement of this Agreement or with any law or regulation. 7. Indemnification. To the extent permitted by applicable law, and subject to the limitations set forth in this Agreement, each Party will indemnify, hold harmless, and defend the other Party from and against any and all third-party claims, losses, deficiencies, damages, liabilities, costs, and other expenses (including but not limited to reasonable attorneys’ fees) incurred as a result of a third-party claim which arises out of the indemnifying Party’s grossly negligent act or omission or willful misconduct. Customer will indemnify, hold harmless, and defend Hermes Health from and against any third-party claims arising out of or relating to (a) Customer’s or its Users’ use of the Services in violation of this Agreement or Applicable Data Protection Laws, (b) Customer’s failure to obtain or maintain required Patient Authorizations or other consents, or (c) Customer Data, including any claim that Customer Data infringes or misappropriates any third-party right. Hermes Health will indemnify, hold harmless, and defend Customer with respect to any third-party claims, demands, awards, judgments, actions, and proceedings made by any person or organization based on a claim that the Services, without modification and without combination with any third-party’s intellectual property, infringe upon a United States patent, copyright, trade secret, or other proprietary right of a third party. Notwithstanding the foregoing, Hermes Health will have no obligation with respect to any claim of infringement that is based upon or arises out of (i) the use or combination of the Services with any software, products, data, or other materials not provided by Hermes Health, (ii) modification or alteration of the Services by anyone other than Hermes Health, (iii) use of Services in excess of the rights granted in this Agreement, or (iv) any specifications, content, Patient Data or intellectual property provided by Customer. The indemnification obligations set forth in this Section are contingent upon the indemnified Party promptly notifying the indemnifying Party in writing of such claim, loss, liability, etc. and permitting the indemnifying Party sole authority to control the defense or settlement of such claim and providing such indemnifying Party reasonable assistance (at such indemnifying Party’s sole expense) in connection therewith. 8. Term & Termination of Agreement. The term of this Agreement shall commence on the Effective Date and continue until terminated in accordance with this Agreement (“Term”). Except as set forth on the applicable Order Form, the initial term of each Order Form shall be one (1) year commencing on the effective date of the Order Form (the “Order Form Initial Term”), after which the Order Form shall automatically renew for successive one (1) year terms (each an “Order Form Renewal Term” and, together with the Order Form Initial Term, the “Order Form Term”) unless either Party provides written notice to the other Party of its intent not to renew the Order Form at least sixty (60) days prior to the expiration of the Order Form Initial Term or Order Form Renewal Term, as applicable. This Agreement or an Order Form, and Customer’s corresponding access to the Services, may be terminated as follows: 8.1. Termination for no Outstanding Order Forms. Either Party may terminate this Agreement upon written notice to the other Party in the event there are no outstanding Order Forms for a continuous period of ninety (90) days. 8.2. Termination for Insolvency or Bankruptcy. Either Party may terminate this Agreement immediately upon written notice to the other Party in the event of the other Party’s bankruptcy or insolvency, or the proper commencement of proceedings under bankruptcy or insolvency code or similar law, whether voluntary or involuntary, by or against such other Party, or in the event that such other Party is dissolved or liquidated. 8.3. Termination for Breach. Except as otherwise specified in this Agreement, either Party may terminate this Agreement, effective upon written notice to the other Party, if the other Party breaches this Agreement, and such breach: (a) is incapable of a cure; or (b) being capable of cure, remains uncured thirty (30) days after the non-breaching Party provides the breaching Party with written notice of the breach (or, if the breach by its nature is not reasonably susceptible to cure within thirty (30) days, fails to commence and diligently pursue a cure within such time period). If the breach is a failure by Customer to pay fees due under the applicable Order Form, Hermes Health may require a reasonable advance fee deposit or other assurance of future payments by Customer. 8.4. Effect of Termination on Services. Upon termination of this Agreement for any reason, Customer and its Users shall no longer be authorized to use the Services, access to the Services and user names and security tokens shall be terminated, and any further access by or on behalf of Customer shall be prohibited unless otherwise agreed in writing by Hermes Health, provided that unless this Agreement is terminated by Hermes Health pursuant to Section 8.3, Hermes Health will allow Customer to access the Services for thirty (30) days following termination or expiration solely to permit Customer to download any Patient Data and other Customer Data in an industry-standard format. 8.5. Effect of Termination on Patient Data. Upon termination of this Agreement for any reason, unless requested otherwise by Customer or required by the terms of this Agreement, the applicable BAA, or Applicable Data Protection Laws including satisfaction of certain audit requirements thereunder, Hermes Health will delete any Patient Data in its possession in connection with the Services. Notwithstanding the foregoing, Patient Authorizations may be maintained by Hermes Health for a minimum of six (6) years from submission regardless of any termination or expiration of this Agreement. Upon written request from Customer, Hermes Health will certify the deletion. 9. Mutual Confidentiality. 9.1. Protection. Each Party agrees (a) to exercise the same degree of care and protection with respect to the other Party’s Confidential Information as each Party exercises with respect to its own Confidential Information, but in no event less than a reasonable degree of care and protection; and (b) not to disclose such Confidential Information to any third party or use it for any purposes other than in connection with fulfilling its obligations under, or enjoying the rights granted to it, under this Agreement; provided, however, that each Party may disclose Confidential Information to its employees and third parties performing services for such Party related to the purposes of this Agreement who have a need to know such Confidential Information and who have agreed in writing to comply with the restrictions set forth herein with respect to such Confidential Information. The receiving Party shall be responsible for any breaches of this Section 9.1 by any such employees or third parties. 9.2. Exceptions. If Customer is a government entity, then the obligations set forth in this Section 9 shall apply only to the extent legally permissible. Furthermore, these obligations shall not apply to Confidential Information which (a) is known by the receiving Party prior to its receipt, as evidenced by written documentation, (b) is now or hereafter becomes publicly known by acts not attributable to the receiving Party, (c) is disclosed to a Party by a third party who has the legal right to make such disclosure, or (d) is disclosed by a Party with the other Party’s separate written consent. Notwithstanding the above, the receiving Party may disclose certain Confidential Information of the disclosing Party, without violating the obligations of this Agreement, to the extent such disclosure is required by a valid order of a court or other governmental body having jurisdiction, provided that the receiving Party provides the disclosing Party with reasonable prior written notice of such disclosure and makes a reasonable effort to obtain, or to assist the disclosing Party in obtaining, a protective order preventing or limiting the disclosure and/or requiring that the Confidential Information so disclosed be used only for the purposes for which the law or regulation required, or for which the order was issued. 10. Miscellaneous. 10.1. Access to Records. If required for purposes of 42 CFR §420.300, or any other applicable state or federal law, upon written request Hermes Health shall make any necessary books, records, and documents available to the U.S. Department of Health and Human Services Comptroller General, their duly authorized representatives, or other governmental authority, for purposes of verifying the nature and extent of any costs incurred by Customer for services furnished by Hermes Health for which payment may be or have been made under Medicare, Medicaid, or other applicable federal or state reimbursement programs. Hermes Health’s obligation to provide access to records under this Section 10.1 shall survive the termination of this Agreement for such periods required by applicable law. 10.2. Force Majeure. No Party will be liable for any failure to perform its obligations hereunder where such failure results from force majeure, meaning any cause beyond the reasonable control of the Party and which could not have been prevented through the exercise of reasonable care and precautions, including acts of god, fire, strike, lockout, labor disputes, accidents, war, civil insurrection, riots, embargoes, pandemic, epidemic, public health emergency, internet or telecommunications failures, cyberattacks, power outages, actions or inactions of third-party service providers (including Provider Networks), or the demands, restrictions, or delays of any government. For the avoidance of doubt, Customer’s payment obligations shall not be excused by any force majeure event. 10.3. Applicable Law. This Agreement shall be interpreted consistently with applicable federal law and with the state laws of Delaware, without regard to such state’s choice-of-law principles. 10.4. Dispute Resolution. In the event of any dispute between the Parties arising out of this Agreement, the Parties shall use their best efforts to resolve the dispute through face-to-face, good faith negotiations. Disputes not resolved within thirty (30) days following written notice of the dispute shall be submitted to binding arbitration by a single arbitrator selected by both Parties pursuant to the Commercial Expedited Procedures of the American Arbitration Association, and judgment upon the award rendered by the arbitrator may be entered in any court having jurisdiction over the Parties. The arbitrator may award the prevailing Party the costs and reasonable attorneys’ fees expended in such arbitration. Notwithstanding the foregoing, either Party shall have the right to seek injunctive or equitable relief in any court of competent jurisdiction. Further, either Party may bring a claim or action in the Federal and state courts of Los Angeles County, California to enforce such Party’s rights in its intellectual property. 10.5. Amendment. Hermes Health reserves the right to revise the terms of this Agreement for any reason required by Applicable Data Protection Laws, in which case Hermes Health will notify Customer in writing either directly or via posting the revised Terms and updating the ‘Last updated’ date at the top of this Agreement. All other revisions to the terms of this Agreement shall be made pursuant to a writing signed by both Parties. 10.6. Assignment. Neither Party may assign any of its rights or obligations hereunder, whether by operation of law or otherwise, without the other Party’s prior written consent (not to be unreasonably withheld); provided, however, that either Party may assign this Agreement in its entirety (including all Order Forms) without the other Party’s consent to its Affiliate or to its legal successor in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets to which this Agreement relates, provided written notice shall be provided to the other Party within thirty (30) days of any such assignment. Subject to the foregoing, this Agreement shall bind and inure to the benefit of the Parties, their respective successors, and permitted assigns. 10.7. Notices. The Parties hereby consent to the giving and receipt of notices as follows, and such notices shall be deemed to be effectively given upon receipt of the receiving Party if (a) hand delivered, (b) sent postage prepaid via certified mail, return receipt requested, (c) mailed for overnight delivery, or (d) delivered via email, provided that, in each case, the sending Party utilizes the notice address(es) indicated in Customer’s profile. Furthermore, in the case of a notice via email, the sending Party shall ensure that the transmission of such notice is time-stamped and that the original notice document is reasonably protected against alteration. Electronic notice is deemed delivered when sent, provided no bounce-back is received. Each Party may change its address(es) for notices by providing notice thereof to the other Party in accordance with this Section. 10.8. Severability. If any portion of this Agreement is declared void or ineffective by a court of competent jurisdiction, such portions shall be ineffective only to the extent of such invalidity or unenforceability, and the remaining portions shall remain valid, enforceable, and in full effect. 10.9. No Waiver. No failure or delay on the part of either Party in exercising any right, power, or remedy under this Agreement will operate as a waiver thereof, nor will any single or partial exercise of any such right, power, or remedy preclude any other or further exercise thereof or the exercise of any other right, power, or remedy hereunder. The rights and remedies provided in this Agreement are cumulative, and are not exclusive of any other rights, powers, or remedies, now or hereafter existing, at law or in equity or otherwise. 10.10. Third Party Beneficiaries. Except as may be expressly set forth in an addendum or attachment hereto, neither this Agreement nor any attachment hereto is intended for the benefit of any third party, and no third party shall have any cause of action arising from or pertaining to it. 10.11. Survival. Sections 1, 2.3, 2.4, 2.6, 2.7, 3.5.3, 5, 6, 7, 8.4, 8.5, 9, and 10 and any other section whose survival is implied shall survive the termination of this Agreement for any reason. Certain sections of the BAA may also survive the termination of this Agreement, as set forth therein. 10.12. Authority. Customer hereby represents and warrants that (a) Customer has the legal right and authority to enter into this Agreement and to use the Services, (b) Customer will use the Services only in compliance with this Agreement and all Applicable Data Protection Laws, (c) all Patient Authorizations and other consents required for Customer’s use of the Services have been validly obtained and remain in effect, and (d) Customer Data does not and will not infringe or misappropriate any third-party intellectual property rights or violate any applicable law. 10.13. Entire Agreement; Interpretation. Except where expressly stated otherwise, references to this Agreement shall be interpreted as referring to the main body of this Agreement as well as all other schedules, exhibits, attachments, SOWs, addendums, and amendments hereto, including, without limitation, the BAA. This Agreement constitutes the sole and entire agreement of the Parties with respect to the subject matter hereof and supersedes all prior and contemporaneous understandings, agreements, representations, and warranties, both written and oral, with respect to the subject matter hereof. In the event of any inconsistency or ambiguity between any of the provisions of this Agreement, it shall be resolved according to the following order of priority: (a) the BAA, (b) the Order Form(s), with respect to each individual Order Form only, (c) the main body of this Agreement, (d) all other documents incorporated herein by reference.