These Terms of Service (the “Terms”) are a contract between Passing Lanes Solutions LLC, a California limited liability company (“HIPAAWorks,” “we,” “us,” or “our”), and the organization that accepts these Terms (“Customer”). HIPAAWorks is a product of Passing Lanes Solutions LLC.
The individual accepting these Terms represents that they have authority to bind Customer. If that individual lacks authority, they must not accept these Terms or use the Service on Customer's behalf.
By selecting the checkbox or button indicating acceptance, Customer agrees to these Terms and acknowledges the Privacy Notice and Acceptable Use Policy. Customer may not use the Service unless an authorized representative has affirmatively accepted these Terms.
1. The Service
1.1 Service description
HIPAAWorks is a hosted, business-to-business software service that helps small healthcare practices:
- record organization and technology-profile information;
- complete a questionnaire-based HIPAA Security Rule self-assessment;
- identify and prioritize gaps using a versioned, deterministic control set;
- receive suggested remediation guidance;
- track organization-recorded remediation activity; and
- create organization-attested gap and risk-analysis records.
The Service does not independently examine Customer's systems, facilities, vendors, records, or safeguards.
1.2 Pre-subscription access
HIPAAWorks may permit limited access to onboarding, a technology profile, a Quick Check, and a summary of initially identified gaps before Customer subscribes. Pre-subscription access is not the full assessment. The full assessment and paid-plan features require an active subscription.
1.3 Changes to the Service
We may improve, modify, or discontinue features from time to time. We will not materially reduce the core functionality of a paid subscription during its then- current term without reasonable notice, except when a change is necessary for security, legal compliance, prevention of harm, or a third-party provider change. Features labeled preview, beta, early access, or coming soon are not committed delivery obligations.
2. Eligibility and business use
The Service is offered only for lawful business use by organizations and their authorized workforce members. It is not a patient portal, personal health record, clinical system, emergency service, or consumer medical application.
Users must be at least 18 and capable of entering a binding contract. Customer is responsible for determining which users may access its workspace and for their compliance with these Terms.
3. Accounts, organizations, and users
3.1 Accurate information
Customer and its users must provide accurate account and organization information and keep it reasonably current.
3.2 Account security
Users must safeguard credentials, use required authentication measures, and promptly notify us at [email protected] of suspected unauthorized access. Customer is responsible for activities performed through its accounts except to the extent caused by our breach of these Terms.
3.3 Organization roles
The Service may provide Owner, Admin, Editor, and Viewer roles. Customer controls user invitations and role assignments. Customer is responsible for:
- confirming that each invited person is authorized;
- assigning the least privilege reasonably needed;
- removing access promptly when it is no longer appropriate; and
- maintaining at least one authorized Owner.
An Owner may manage billing and other organization-level settings. Role names describe application permissions and do not create legal duties or professional roles.
3.4 Identity providers
Users may sign in using supported identity providers, including Google or Microsoft. Customer remains responsible for securing its identity-provider accounts and for the provider's terms applicable to Customer.
4. Limited right to use the Service
Subject to these Terms and payment of applicable fees, we grant Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the subscription term to permit its authorized users to access and use the hosted Service for Customer's internal business purposes.
Customer may not:
- copy, modify, distribute, sell, lease, or sublicense the Service;
- reverse engineer or attempt to derive nonpublic source code, except to the limited extent a restriction is prohibited by law;
- bypass access, subscription, tenant-isolation, or security controls;
- use the Service to build or train a competing product;
- use automated means to scrape or extract the Service except through a documented interface we expressly authorize; or
- remove proprietary notices.
No software is sold under these Terms. All rights not expressly granted are reserved.
5. Customer Content
5.1 Definition
“Customer Content” means information Customer or its users submit to the Service, including organization profiles, technology inventories, assessment answers, vendor information, comments, remediation notes, risk-acceptance rationales, uploaded evidence, and instructions for generating reports. Customer Content does not include the Service, control framework, question bank, templates, or our preexisting materials.
5.2 Ownership
As between the parties, Customer retains its rights in Customer Content. Customer grants us a worldwide, non-exclusive license during the applicable retention period to host, copy, process, transmit, display, and create technical or presentational derivatives of Customer Content only as reasonably necessary to:
- provide, secure, support, and improve the Service;
- generate Customer-requested guidance and reports;
- prevent fraud, misuse, or harm;
- comply with law and enforce these Terms; and
- perform other processing described in the Privacy Notice and DPA.
This license does not permit us to sell Customer Content or use it for cross-context behavioral advertising.
When improving the Service, we will use Customer Content only as needed to diagnose or validate the Customer-facing function involved, or in aggregated or de-identified form as described in Section 12. This clause does not authorize us to train a general-purpose AI model on identifiable Customer Content.
5.3 Customer assurances
Customer represents that it has the rights and lawful basis needed to submit and instruct us to process Customer Content. Customer must not submit information belonging to another organization without authorization.
5.4 Sensitive security information
Customer understands that its assessment answers, identified gaps, remediation history, and evidence may reveal sensitive details about its security posture. Customer is responsible for limiting access to authorized users and for handling exported files securely.
6. No protected health information
6.1 The Service is not designed for PHI
The Service is not designed or offered to create, receive, maintain, transmit, or access protected health information on behalf of Customer. Customer must not enter, upload, transmit, or otherwise provide:
- patient names, initials, faces, contact details, record numbers, or other identifiers;
- medical, treatment, diagnosis, prescription, billing, appointment, or insurance information linked to a patient;
- screenshots, photographs, documents, or exports containing patient information; or
- any other PHI as defined by HIPAA.
Customer must review and redact files before uploading them. For photographs, Customer must check screens, charts, labels, sign-in sheets, whiteboards, reflections, and people in the image.
6.2 No Business Associate relationship
The parties do not intend for HIPAAWorks to act as Customer's Business Associate, and these Terms are not a Business Associate Agreement. Customer must not use the Service in a manner that would require HIPAAWorks to enter a Business Associate Agreement. We do not agree to obligations applicable to a Business Associate unless the parties execute a separate written agreement expressly identified as a Business Associate Agreement.
6.3 Suspected PHI
If Customer believes PHI has been submitted, Customer must:
- stop further submission;
- notify us promptly at [email protected] without including the PHI in the notice; and
- identify the affected item using the minimum non-sensitive information needed for us to locate it.
We may restrict access to, quarantine, or delete content we reasonably believe violates this section. We may suspend the affected feature or account while the matter is investigated. We will handle a suspected submission under our incident procedures and applicable law. Nothing in these Terms limits any obligation that applicable law independently imposes.
6.4 Customer responsibility
Customer is responsible for configuring its workflows and training users to keep PHI out of the Service. A prohibition in these Terms does not make an upload safe or lawful.
7. Customer responsibilities and acceptable use
Customer must use the Service in accordance with law, these Terms, and the Acceptable Use Policy. Customer is responsible for:
- the completeness and accuracy of its self-assessment scope and answers;
- deciding whether and how to act on identified gaps and suggested remediation;
- evaluating vendor representations and Customer's own legal obligations;
- reviewing AI-generated or template-generated text before relying on or sharing it;
- maintaining its own copies of records needed for legal, regulatory, insurance, or business purposes; and
- obtaining professional advice appropriate to its circumstances.
8. Assessments, guidance, reports, and AI
8.1 Self-assessment
Findings reflect Customer-provided answers and available Customer Content as of the relevant date. HIPAAWorks does not independently verify Customer's systems, facilities, evidence, implementation, or vendor performance.
8.2 No professional advice or determination
The Service and its outputs are for informational and organizational purposes. They are not legal advice, a legal opinion, a certification, a determination that Customer satisfies HIPAA or another law, or a guarantee of a regulatory, insurance, security, or business outcome. No software product can make an organization compliant on its own.
Severity labels identify the priority assigned to a control by the applicable versioned control set. They are not a compliance score or individualized legal conclusion.
8.3 Artificial intelligence
The Service uses third-party AI services to draft certain remediation guidance, profile summaries, and report narrative. Depending on the feature, the AI provider may receive minimized organization, technology, vendor, assessment, or aggregate finding information as described in the Privacy Notice.
AI does not determine Customer's legal status, assign final severity, decide whether a safeguard is effective, or close a finding. AI output may be incomplete, inaccurate, or unsuitable for Customer's circumstances. Customer must review all output and is responsible for decisions made using it.
Customer must not include PHI, secrets, or unnecessary personal information in fields that may be processed by AI.
8.4 Organization-attested records
“Organization-attested” means that a record reflects information and actions provided or recorded by Customer. It does not mean that HIPAAWorks, a regulator, an auditor, an attorney, or another independent party verified the record.
9. Subscriptions, fees, and taxes
9.1 Orders and plans
The plan, price, billing interval, included features, and other commercial terms presented at checkout or in an order form are incorporated into these Terms. Prices shown in marketing materials do not override the checkout or order form.
9.2 Recurring billing
Subscriptions automatically renew for successive periods equal to the selected billing interval until canceled. Before obtaining payment authorization, checkout must display clearly:
- the amount and currency;
- whether billing is monthly or annual;
- that charges recur until cancellation;
- when the first charge occurs;
- any trial or promotional conditions; and
- how to cancel.
By confirming checkout, Customer authorizes Stripe to charge the selected payment method for recurring fees and applicable taxes.
9.3 Payment processing
Stripe processes payments. Customer's use of Stripe-hosted checkout and billing features may be subject to Stripe's terms and privacy notice. HIPAAWorks does not receive complete payment-card details through the implemented hosted checkout flow.
9.4 Cancellation
Customer may cancel through the Stripe-hosted billing portal or another method we identify at checkout.
Cancellation takes effect immediately. Access to paid features ends at cancellation. Fees already paid are nonrefundable and are not prorated. We will send a renewal-reminder notice 7 days before a subscription renews.
Unless required by law or stated in an order form, fees are nonrefundable.
9.5 Fee changes
We may change fees for a future renewal term by giving reasonable advance notice. The change takes effect at the next renewal after the notice period unless Customer cancels first.
9.6 Taxes and overdue amounts
Fees exclude taxes unless checkout states otherwise. Customer is responsible for applicable sales, use, and similar taxes other than taxes on our net income.
If a payment fails or lapses, we may restrict access to the Service until the account is reconciled. Access is restored once payment is successfully processed.
10. Third-party services
The Service relies on third-party providers for hosting, authentication, database and storage, payments, AI, email, analytics, monitoring, and network security. Our current providers are described in the Privacy Notice and subprocessor list.
Third-party services may change or become unavailable. We are responsible for our selection and use of subprocessors as stated in the DPA, but we do not control third-party products Customer independently chooses to use, including its EHR, email, vendors, or identity-provider account.
11. Confidentiality and security
11.1 Confidential Information
“Confidential Information” means nonpublic information disclosed by one party to the other that a reasonable person would understand to be confidential, including Customer Content and nonpublic security, business, and technical information.
The receiving party will:
- use Confidential Information only to perform or exercise rights under these Terms;
- protect it using reasonable care, and no less than the care used for its own similar information; and
- disclose it only to personnel and providers who need it and are subject to confidentiality obligations.
These duties do not apply to information the recipient can document was lawfully known without restriction, independently developed, lawfully received from another source, or made public without breach.
If law requires disclosure, the recipient may disclose the required amount and, when legally permitted, will give reasonable notice.
11.2 Security
We will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information processed. No service is completely secure, and we do not guarantee that unauthorized access or security incidents will never occur.
11.3 Security incidents
We will investigate confirmed unauthorized access to Customer Content and provide notice as required by applicable law. Any negotiated notification deadline or security commitment must appear in an executed order form or security addendum.
12. Intellectual property
We and our licensors own the Service, software, workflows, design, control and question framework, templates, documentation, generated structure, and related intellectual property, excluding Customer Content.
Subject to Customer's rights in Customer Content, we may use de-identified and aggregated operational information that does not identify Customer, a user, a patient, or Customer-specific security details to operate, secure, and improve the Service. We will not attempt to re-identify it.
13. Feedback
If Customer voluntarily provides suggestions about the Service, Customer grants us a perpetual, irrevocable, worldwide, royalty-free right to use them without restriction or attribution. This does not include Customer Content or Confidential Information embedded in feedback.
14. Beta and preview features
Beta or preview features may be incomplete, change without notice, and contain errors. They are provided for evaluation, may have limited support, and should not be used as Customer's only repository for important records.
A beta or preview feature may be offered free of charge or included in a specific subscription tier for a limited time (for example, made available to Core-tier customers for 30 days before becoming a Pro-tier feature), as stated when the feature is introduced.
15. Suspension
We may suspend access when reasonably necessary to:
- address a security risk or suspected unauthorized access;
- prevent harm to the Service, another customer, or a third party;
- respond to prohibited PHI or other unlawful content;
- comply with law or a binding government request;
- address material nonpayment; or
- investigate a material breach of these Terms.
When practical, we will give notice and limit the suspension to the affected account or feature. We will restore access after the reason is resolved when reasonable.
16. Term and termination
These Terms begin when accepted and continue while Customer uses the Service. Either party may terminate:
- when Customer cancels and the paid term ends;
- for the other party's material breach that remains uncured 7 days after written notice, or immediately for a security issue or violation of Section 6 (PHI) or the Acceptable Use Policy;
- immediately if continued performance would violate law or create a material security risk; or
- as otherwise stated in an order form.
17. Data export, retention, and deletion
Customer should export records it needs before termination. Customer may export supported records, including generated reports, in PDF format through the Service during the subscription.
Upon Customer's written request and cancellation of the subscription, we will delete Customer's data from the Service, subject to the retained-record exceptions below.
We may retain information when reasonably necessary to comply with law, resolve disputes, enforce agreements, prevent fraud or abuse, maintain security, or preserve records that the parties have expressly agreed are append-only. Retained Customer Content remains protected under the applicable confidentiality and security obligations.
Deletion from active systems may not immediately remove residual copies from backups. We will not retain prohibited PHI merely because another category of record is ordinarily retained.
Sections that by their nature should survive termination—including payment obligations, confidentiality, intellectual property, disclaimers, indemnification, liability limits, disputes, and retained-data protections—will survive.
18. Disclaimers
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE, BETA FEATURES, GUIDANCE, AND OUTPUTS ARE PROVIDED “AS IS” AND “AS AVAILABLE.” WE DISCLAIM IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.
WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE, THAT EVERY SECURITY OR REGULATORY ISSUE WILL BE IDENTIFIED, OR THAT CUSTOMER'S USE OR REMEDIATION WILL PRODUCE A PARTICULAR LEGAL, REGULATORY, SECURITY, INSURANCE, OR BUSINESS RESULT.
Some jurisdictions do not allow certain disclaimers, so these exclusions apply only to the extent permitted by law.
19. Indemnification
19.1 Customer indemnity
Customer will defend and indemnify HIPAAWorks and its affiliates, officers, and personnel from third-party claims, damages, and reasonable costs arising from:
- Customer Content that infringes or violates another person's rights;
- Customer's unlawful or prohibited use of the Service;
- Customer's submission of PHI in violation of Section 6; or
- Customer's material breach of the Acceptable Use Policy.
This obligation does not apply to the extent a claim was caused by our breach of these Terms, negligence, or willful misconduct.
19.2 HIPAAWorks indemnity
We will defend Customer against a third-party claim that the unmodified, as-provided paid Service infringes that party's U.S. patent, copyright, or trademark, and will pay resulting damages and costs finally awarded or agreed in settlement. This obligation does not apply to a claim arising from: Customer Content; combination of the Service with a product, service, or data not provided by us; use of the Service other than as authorized by these Terms; or continued use after we provide a non-infringing replacement or modification. If the Service becomes, or we reasonably believe it may become, the subject of an infringement claim, we may, at our option, procure the right to continue use, modify the Service to be non-infringing, or terminate the affected component and refund prepaid, unused fees for it.
19.3 Procedure
The indemnified party must give prompt notice, permit the indemnifying party to control the defense and settlement, and provide reasonable cooperation. A settlement may not admit fault or impose nonmonetary obligations on the indemnified party without its consent.
20. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THE POSSIBILITY.
EACH PARTY'S TOTAL LIABILITY ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER FOR THE SERVICE DURING THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY.
This limitation does not apply to: payment obligations; breach of Section 11 (Confidentiality); a party's indemnification obligations under Section 19; Customer's submission of prohibited PHI in violation of Section 6; fraud; gross negligence; willful misconduct; or another liability that cannot be limited under applicable law.
The limitations allocate risk between the parties and apply to the maximum extent permitted by law regardless of the theory of liability.
21. Governing law and disputes
These Terms are governed by the laws of the State of California, without regard to conflict-of-laws rules.
Disputes not resolved informally will be resolved by binding individual arbitration.
Either party may seek urgent injunctive relief to protect confidential information or intellectual property in a court with jurisdiction.
22. Notices
We may provide operational notices through the Service or by email. Legal notices to HIPAAWorks must be sent by email to:
Passing Lanes Solutions LLC
[email protected]
Notices to Customer may be sent to the account Owner or the billing email on file. Customer must keep those addresses current.
23. Changes to these Terms
We may update these Terms. If a change materially affects Customer's rights or obligations, we will provide reasonable advance notice through the Service, by email, or both. Material changes will apply prospectively on the stated effective date. If applicable law or the nature of the change requires renewed affirmative consent, we will request it.
The version accepted by Customer and any later accepted version should be retained with the acceptance record.
24. General
Neither party may assign these Terms without the other's consent, except in connection with a merger, reorganization, sale of substantially all assets, or assignment to an affiliate, provided the assignee assumes the obligations.
Neither party is liable for delay caused by events beyond its reasonable control, except payment obligations.
These Terms, incorporated policies, any DPA, and any order form are the entire agreement concerning the Service. If they conflict, the order of precedence is:
- an executed order form, only for its commercial terms;
- the DPA, only for personal-data processing;
- these Terms; and
- the Acceptable Use Policy.
Purchase-order terms do not apply unless expressly accepted in a signed writing.
Failure to enforce a provision is not a waiver. If a provision is unenforceable, it will be modified to the minimum extent necessary and the rest remains in effect. Headings are for convenience. “Including” means “including without limitation.”
25. Contact
Questions about these Terms: [email protected]
Privacy questions: [email protected]
Security reports: [email protected]