Last updated: July 13, 2026
This Vim Applications Description sets forth further Application-specific terms and conditions that may apply to Vim’s provision and Covered Provider’s use of Vim Connect or the Services. Capitalized terms not defined herein shall have the meanings assigned to them in the Provider Terms of Service.
- 1. Diagnosis Gaps (Dx Gaps) Application allows Covered Provider to view data from the Data Source regarding potential chronic conditions of a patient. Covered Provider may, in its sole discretion, respond to the information presented on the Dx Gaps Application, and such response will be shared back to the Data Source. In supported EHRs, (i) the Dx Gaps Application may allow Covered Provider to add the chronic conditions ICD-10 codes into its EHR, or, alternatively, if the Covered Provider already coded the relevant ICD-10 codes in the encounter assessments, the Dx Gaps Application will automatically detect that, and resolve the applicable gaps; and/or (ii) where Covered Provider has enabled the CDE Application, if requested by the Data Source, following each use of the Dx Gaps Application, the updated encounter record along with the recorded use of the Dx Gaps Application will be extracted from the EHR and promptly delivered to the Data Source.
- 2. Care Gaps Application Application presents to Covered Provider and patients’ Gaps in Care data provided to Vim by a Data Source. Covered Provider may, under their sole discretion, respond to the information presented in the Care Gaps Application, and Vim will then share these responses back to the Data Source. In supported EHRs, (i) the Care Gaps Application may allow Covered Provider to add the relevant CPT codes to the EHR, and or/ (ii) where Covered Provider has enabled the CDE Application, if requested by the Data Source, following each use of the Care Gaps Application, the updated encounter record along with the recorded use of the Care Gaps Application will be extracted from the EHR and promptly delivered to the Data Source.
-
- Care Insights Application: By using Care Insights, the following terms apply to you and Your Authorized Users’ use of Care Insights. While some features of Care Insights may be optional, these terms apply to all features you and Your Authorized Users may access in connection with Care Insights.
3.1. Care Insights Functionality.
3.1.1. Insight Categories. To the extent that one or more Data Sources is connected, Care Insights presents to the Covered Provider gaps in patient care data and/or various insights provided to Vim by such Data Source(s), which may include one or more of the following data categories (“Insight Categories”):
(a) Diagnosis Gaps – undocumented conditions affecting risk adjustment
- includes writeback capabilities.
(b) Risk – high-risk flags, predictive scoring, or adverse likelihood
- Does not include writeback capabilities.
(c) Quality – measure-based insights related to quality programs (e.g. HEDIS, STAR).
- May include writeback capabilities.
(d) Rx – medication adherence or prescribing patterns
- Does not include writeback capabilities.
(e) Utilization – ER, inpatient, and general usage trends.
- Does not include writeback capabilities.
(f) Care Management – Chronic management, follow-ups
- Does not include writeback capabilities.
(g) SDOH – Social determinants like housing, income.
- Does not include writeback capabilities.
(h) ADT – notification of admissions, discharge and transfer
- does not include writeback capabilities.
(i) Clinical Insights – all uncategorized but relevant insights, as determined by a Data Source. any potential chronic conditions, provided to Vim by a Data Source.
3.1.2. Insight Categories and their respective content and actions may vary depending on configurations selected by a Data Source, and content provided by it. Covered Provider may, in its sole discretion, respond to the information presented, and Vim will then share Covered Provider’s responses back to the Data Source.
3.2. ICD-10 Codes / CPT Codes. In supported EHRs, (i) the Care Insights Application may allow Covered Provider to add the relevant CPT codes and/or the chronic conditions ICD-10 codes into the EHR, or, alternatively, with respect to the ICD-10 codes, if the Covered Provider already coded the relevant ICD-10 codes in the encounter assessments, Care Insights will automatically detect that, and resolve the applicable gaps; and/or (ii) where the Covered Provider enables the CDE Application, if requested by the Data Source, following activity of the Care Insights Application, the updated encounter record along with the recorded use of the Care Insights Application, will be extracted from the EHR and promptly delivered to the Data Source.
3.3. AMA CPT Terms. Vim Connect and the Services may include the Current Procedural Terminology (“CPT”) code set, maintained by the American Medical Association (the “AMA”). The use of the CPT code is subject to the AMA CPT End User Agreement Terms.
3.4. Permissions in Care Insights. Through the Insight Categories, Data Sources may include and share certain “Sensitive Health Information” or other information which some Authorized Users may not be entitled or eligible to view in your organization. Vim is not obligated to monitor information or materials available through Care Insights, or to review or edit any such information or materials. It is your responsibility to manage permissions of your Authorized Users for the Care Insights Application, through the Vim Console including but not limited to any access control as set forth in Section 5 of the Provider Terms of Service. All organizations are created with the organization default of “Action” to each category (meaning the user can see the insights and also take action accordingly such as “agree”, “dismiss” or auto-resolve). When an organization changes the default setting, it applies to new users and existing users whose permissions haven’t been specifically and manually overridden.
3.5. Patient Matching within Care Insights. To the extent that one or more Data Source(s) is connected, Covered Provider acknowledges that Vim Connect matches patient-related data presented in Covered Provider’s EHR with Data Source Content using automated processes. In order to determine whether relevant Data Source Content exists for such a patient, Covered Provider authorizes Vim to transmit limited patient identifiers and related information to applicable Data Sources for the purpose of querying, matching, and, if applicable, retrieving Data Source Content. Covered Provider acknowledges that such queries may not result in a match and may result in Data Source Content that is incorrect, incomplete, or associated with a patient other than the intended individual, and that Vim does not independently verify the accuracy, completeness, or clinical relevance of any Data Source Content returned. Covered Provider and its Authorized Users are solely responsible for reviewing and validating Data Source Content prior to reliance or use.
3.6. Vim Scribe Module within Care Insights. The Care Insights Application may include an ambient scribe module, if selected by You (“Vim Scribe”), which is an AI-powered clinical documentation tool which enables Authorized Users to record and process patient-provider interactions in real time through audio capture embedded within the Care Insights interface. You must choose to add the Vim Scribe feature to Care Insights via a designated landing page or order form, whereby you may review all the pricing and order details and conduct your purchase, together with your review and access to these terms. By using Vim Scribe, together with Care Insights, You are directing Vim, as your business associate, to process Provider Data, including Data Source Content and audio recordings, through the Vim Scribe to support documentation, gap assessment, and gap addressing workflows.
3.6.1. Vim Scribe Functionality. Vim Scribe may generate transcripts, summaries, and other documentation outputs, and may analyze such interactions against Insight Categories and patient-specific gaps in care as the encounter occurs. To the extent a Data Source is connected to Covered Provider, Vim Scribe may present real-time or near real-time updates to Insight Categories based on the content of the interaction, including indications that a gap has been discussed, requires documentation, or may be resolved, and may provide supporting excerpts, rationale, or confidence indicators. To the extent a Data Source is connected to Covered Provider, following an encounter, Vim Scribe may present summaries of gaps that were addressed, not addressed, or under-documented, and may identify potential diagnoses, conditions, or coding opportunities, including Hierarchical Condition Categories (HCCs). Vim Scribe may also generate structured clinical documentation, including SOAP notes and, in supported EHRs, may enable the inclusion or writeback of such content into the patient record. To the extent that a Data Source is connected, Vim Scribe may also generate suggested codes.
3.6.1.1. Supported Languages; Language Detection and Translation. Vim Scribe is designed to detect and process patient-provider interactions conducted in any of the languages identified in Appendix A to these Terms (“Supported Languages”). Vim Scribe automatically detects the spoken language during an encounter using automated language detection technology. All documentation outputs generated by Vim Scribe—including transcriptions, SOAP notes, summaries, and gap assessments —are produced in English, regardless of the language in which the underlying encounter was conducted. If a patient-provider interaction is conducted in a language not identified in Appendix A, Vim Scribe will not capture, process, or generate any output for such interaction, and no Vim Scribe services will be provided with respect to that encounter. Covered Provider is solely responsible for verifying, prior to any patient encounter, whether the language(s) spoken during such encounter are Supported Languages, and for informing patients accordingly. Vim makes no representation that the Supported Languages list is complete, error-free, or will not change, and Vim reserves the right to add or remove Supported Languages at any time upon notice to Covered Provider.
3.6.4. Data Handling and Storage.
3.6.4.1 VIM SCRIBE IS NOT INTENDED TO SERVE AS A “SYSTEM OF RECORD” OR PRIMARY DATA REPOSITORY FOR ANY INFORMATION, INCLUDING, BUT NOT LIMITED TO, PATIENT HEALTH INFORMATION. Vim does not serve as a permanent storage system for clinical records and should not be used as a record-keeping or storage repository for any purpose. It is Your responsibility to save, maintain, and store all final documentation, including any generated using Vim Scribe in Your EHR or other designated system of record. You and Your Authorized Users remain solely responsible for maintaining complete and accurate patient records in Your EHR or other designated system of record in accordance with all applicable laws and regulations, including but not limited to HIPAA and state law record retention requirements.
3.6.4.2 Temporary Data Retention. While neither Vim Scribe nor Care Insights is a system of record, recordings, transcriptions, insights, and AI-generated summaries may be retained temporarily solely to facilitate the processing and delivery of the services. This temporary retention does not alter Your obligation to maintain official records in Your designated system of record and should not be relied upon for any purpose.
3.6.4.3 Data Upon Service Termination. Upon termination or discontinuation of Care Insights and/or Vim Scribe, Vim may delete content and AI-generated content in accordance with Vim’s data retention policies and any applicable law. You are solely responsible for ensuring all necessary documentation has been saved to Your EHR or other system of record prior to termination.
3.6.5. Care Insights Disclaimers.
3.6.5.1 No Medical Advice. CARE INSIGHTS, INCLUDING ALL OF ITS FEATURES, IS A DOCUMENTATION TOOL ONLY. VIM DOES NOT PROVIDE MEDICAL, CLINICAL, DIAGNOSTIC, CODING, BILLING, OR TREATMENT ADVICE OF ANY KIND THROUGH CARE INSIGHTS. AUTHORIZED USERS REMAIN SOLELY RESPONSIBLE FOR ALL CLINICAL DECISIONS AND PATIENT CARE. WITHOUT LIMITING THE FOREGOING, ANY IDENTIFICATION OF CONDITIONS, DIAGNOSES, OR HCCS IS INFORMATIONAL ONLY AND MUST BE INDEPENDENTLY VALIDATED BY COVERED PROVIDER PRIOR TO SUBMISSION OR USE. VIM SHALL NOT BE RESPONSIBLE OR LIABLE FOR ANY DECISIONS MADE OR ACTIONS TAKEN IN RELIANCE ON CARE INSIGHT OUTPUTS.
3.6.5.2 Vim Scribe Disclaimers.
3.6.5.2.1. Covered Provider acknowledges that Vim Scribe relies on automated technologies to process audio and generate outputs that may be incomplete, inaccurate, delayed, or misleading, and that such outputs may not be verbatim and may include summarized, reformatted, or interpreted content. Real-time outputs may be partial or subject to change during the encounter. Vim does not independently verify the accuracy, completeness, or clinical or coding appropriateness of any output generated by Vim Scribe.
3.6.5.2.2. Vim Scribe outputs are provided for documentation support purposes only and do not constitute clinical, diagnostic, coding, or billing advice. Without limiting the foregoing, any identification of conditions, diagnoses, or HCCs is informational only and must be independently validated by Covered Provider prior to submission or use. Vim shall not be responsible or liable for any decisions made or actions taken in reliance on Vim Scribe outputs.
3.6.5.2.3 AI-Generated Content Accuracy. VIM MAKES NO GUARANTEE, WARRANTY, OR REPRESENTATION REGARDING THE ACCURACY, COMPLETENESS, OR RELIABILITY OF ANY AI-GENERATED TRANSCRIPTIONS, NOTES, SUMMARIES, OR CONTENT. AI-GENERATED TRANSCRIPTIONS, NOTES AND SUMMARIES MAY CONTAIN ERRORS, OMISSIONS, INACCURACIES, OR MISINTERPRETATIONS. AUTHORIZED USERS MUST EXERCISE PROFESSIONAL JUDGMENT AND CAREFULLY REVIEW ALL AI-GENERATED CONTENT BEFORE INCORPORATING IT INTO PATIENT RECORDS.
3.6.5.2.4. Reliance on AI-Generated Content. YOU AND YOUR AUTHORIZED USERS SHOULD EXERCISE PROFESSIONAL JUDGMENT AND DISCRETION IN RELYING ON INFORMATION GENERATED BY CARE INSIGHTS. VIM SHALL NOT BE HELD LIABLE FOR ANY DECISIONS MADE OR ACTIONS TAKEN IN RELIANCE ON AI-GENERATED TRANSCRIPTIONS, NOTES OR SUMMARIES.
3.6.5.2.5. Translation and Language Processing Disclaimer. VIM SCRIBE INCORPORATES AUTOMATED LANGUAGE DETECTION AND TRANSLATION CAPABILITIES TO PROCESS PATIENT-PROVIDER ENCOUNTERS CONDUCTED IN THE SUPPORTED LANGUAGES LISTED IN APPENDIX A. VIM MAKES NO GUARANTEE, WARRANTY, OR REPRESENTATION REGARDING THE ACCURACY, COMPLETENESS, OR RELIABILITY OF ANY LANGUAGE DETECTION OR TRANSLATION PERFORMED BY VIM SCRIBE, INCLUDING WITH RESPECT TO ANY OUTPUTS GENERATED FROM NON-ENGLISH ENCOUNTERS, INCLUDING SOAP NOTES, TRANSCRIPTIONS, SUMMARIES, OR GAP ASSESSMENTS. ENCOUNTERS CONDUCTED IN A LANGUAGE OTHER THAN ENGLISH ARE SUBJECT TO AUTOMATED DETECTION AND TRANSLATION PROCESSES THAT MAY INTRODUCE ERRORS, OMISSIONS, INACCURACIES, OR MISINTERPRETATIONS IN THE RESULTING DOCUMENTATION. VIM SHALL NOT BE LIABLE FOR ANY ERRORS, INACCURACIES, OR CLINICAL CONSEQUENCES ARISING FROM OR RELATED TO THE LANGUAGE DETECTION OR TRANSLATION FEATURES OF VIM SCRIBE. WITHOUT LIMITING THE FOREGOING: (A) LANGUAGE DETECTION MAY FAIL OR MAY MISIDENTIFY THE LANGUAGE SPOKEN, WHICH MAY RESULT IN INACCURATE PROCESSING OR NO CAPTURE OF AN ENCOUNTER; (B) TRANSLATION ERRORS MAY DISTORT THE CLINICAL CONTENT OF AN ENCOUNTER, INCLUDING SYMPTOMS, DIAGNOSES, MEDICATIONS, OR OTHER CLINICALLY SIGNIFICANT INFORMATION; AND (C) ALL VIM SCRIBE OUTPUTS DERIVED FROM NON-ENGLISH ENCOUNTERS MUST BE INDEPENDENTLY VERIFIED BY COVERED PROVIDER AND ITS AUTHORIZED USERS PRIOR TO USE IN CLINICAL DOCUMENTATION OR PATIENT RECORDS. COVERED PROVIDER AND ITS AUTHORIZED USERS ARE SOLELY RESPONSIBLE FOR REVIEWING AND VERIFYING THE ACCURACY OF ALL VIM SCRIBE OUTPUTS, REGARDLESS OF THE LANGUAGE OF THE UNDERLYING ENCOUNTER. NOTHING IN THIS SECTION LIMITS ANY OTHER DISCLAIMER OR LIMITATION OF LIABILITY SET FORTH IN THESE TERMS OR THE AGREEMENT.
3.6.5.5. Service Availability. Vim may perform maintenance, upgrades, or discontinue the Vim Scribe feature without notice. Vim reserves the right to suspend or terminate access to the Vim Scribe feature for any violation of these terms or the Agreement. Outputs may vary based on audio quality, speaker clarity, background noise, accents, and other environmental or technical factors.
3.6.5.6. Underlying Technologies. Vim Scribe relies on third-party service providers and underlying technologies, including cloud infrastructure and automated processing systems, to deliver its functionality. Vim does not control and is not responsible for the performance, availability, or output of such third-party services. You acknowledge that Vim Scribe outputs may be affected by the performance, limitations, or changes in such underlying technologies, including variations in processing, latency, or output quality. Vim does not guarantee the continuous availability, consistency, or performance of any such third-party services.
3.7. Covered Provider Obligations.
3.7.1. HIPAA Compliance and Patient Authorizations. In addition to Covered Provider’s obligations set forth in 1.7.2-1.7.4 below, You are solely responsible for ensuring that Your and Your Authorized Users’ use of Care Insights including as applicable, Vim Scribe, complies with HIPAA and all other applicable federal and state privacy and security laws. This includes, but is not limited to:
3.7.1.1. Ensuring that recordings and transcriptions are created and maintained only for appropriate clinical purposes;
3.7.1.2. Implementing reasonable and appropriate administrative, physical, and technical safeguards to protect PHI and other sensitive information processed through Care Insights; and
3.7.1.3. Training Authorized Users on proper use of Care Insights in compliance with HIPAA, Your organization’s policies, and any other applicable laws.
3.7.2. Content Responsibility and Clinical Judgment. You and Your Authorized Users are solely responsible for:
3.7.2.1. All clinical decisions and patient care;
3.7.2.2. If Vim Scribe is used – reviewing, verifying, and editing all AI-generated transcriptions, summaries, gap updates, and documentation for accuracy and completeness before incorporating them into the patient’s medical record;
3.7.2.3. Determining whether any gaps in care have been appropriately addressed or resolved;
3.7.2.4. All clinical, coding, billing, and compliance decisions, including with respect to any diagnoses, conditions, or codes identified or suggested by Care Insights;
3.7.2.5 Ensuring all documentation is accurate, complete, and complies with all applicable laws, regulations, and standards of care;
3.7.2.6. The final content of all documentation incorporated into the EHR or patient record;
3.7.2.7 Determining the appropriateness of using Care Insights for any particular patient encounter; and
3.7.2.8. Compliance with all applicable laws, regulations, and ethical guidelines.
3.7.3. Recording Consent. Vim Scribe enables the recording and processing of patient-provider interactions. Covered Provider acknowledges and agrees that Covered Provider and its Authorized Users are solely responsible for determining whether notice, consent, authorization, or any other permission is required prior to recording or processing any interaction through Vim Scribe and for obtaining and maintaining any such notice, consent, authorization, or permission in accordance with applicable law, professional obligations, and organizational policies, including, but not limited to, any state recording consent requirements, consumer protections, surveillance and/or wiretapping laws. Vim may display notices, reminders, acknowledgements, or other prompts relating to recording consent requirements. Such notices are provided solely as a convenience and do not create any obligation on Vim to determine whether notice, consent, authorization, or any other permission is required or has been obtained. Covered Provider and its Authorized Users remain solely responsible for obtaining and maintaining any such notice, consent, authorization, or permission
3.7.4. Prohibited Uses. You and Your Authorized Users shall not use Vim Scribe to:
3.7.4.1. Use Care Insights for emergency or time-sensitive clinical situations where immediate action is required;
3.7.4.2. Rely on AI-generated content without appropriate review and verification;
3.7.4.3. Input or process data in violation of applicable law, these Terms, and all other Agreements between You and Care Insights;
3.7.4.4. Use Care Insights for any unlawful, harmful, or unauthorized purpose; or
3.7.4.5. Attempt to access data or recordings to which you are not authorized.
3.8. De-Identification and Use of Data. You authorize Vim to de-identify data from Care Insights (including usage patterns, metadata, and de-identified transcription data) in accordance with the de-identification standards set forth in 45 C.F.R. § 164.514(a)-(b) and to use such de-identified data for Vim’s business purposes, including, without limitation: Improving and developing Care Insights and other Vim products and services; conducting research and analytics, and creating aggregated benchmarking and statistical reports.
3.9 Indemnification. In addition to your indemnification obligations under the Provider Terms of Service, You agree to defend, indemnify, and hold harmless Vim and Vim’s affiliates, licensors, directors, officers, employees, agents and contractors against any and all claims, demands, losses, costs, and expenses, including reasonable attorney’s fees and litigation expenses, arising out of or relating to (i) any claims arising from the recording of patient encounters without proper consent or authorization; (ii) any inaccuracy in clinical documentation resulting from failure to properly review and verify AI-generated content; or (iii) any clinical decisions or patient care based on AI-generated content from Care Insights.
3.10. Termination.
3.10.1. You may discontinue use of Care Insights at any time by disabling the application through Vim Console or contacting Vim.
3.10.2. Upon termination of Your access to Care Insights:
3.10.2.1. You and Your Authorized Users will no longer be able to access or use Care Insights;
3.10.2.2. Recordings, transcriptions, and AI-generated content may be deleted in accordance with Vim’s data retention policies. You are solely responsible for ensuring all necessary documentation has been saved to Your EHR prior to termination; and
3.10.2.3. Your obligations under these terms that by their nature should survive termination (including, but not limited to, Your indemnification obligations and Vim’s right to use de-identified data) shall survive.
APPENDIX A
VIM SCRIBE SUPPORTED LANGUAGES
This Appendix A lists the languages currently supported by Vim Scribe for automated language detection and translation, as referenced in Section 1.6.1.1 of these Terms. Vim Scribe will not capture or process patient-provider encounters conducted in any language not included in this list. All documentation outputs are generated in English regardless of the source language. Vim reserves the right to modify this list at any time upon notice to Covered Provider.
Supported Languages (109 total):
Afrikaans (af), Albanian (sq), Amharic (am), Arabic (ar), Armenian (hy), Assamese (as), Azerbaijani (az), Basque (eu), Belarusian (be), Bengali (bn), Bosnian (bs), Bulgarian (bg), Catalan (ca), Cebuano (ceb), Chinese (Simplified and Traditional) (zh), Corsican (co), Croatian (hr), Czech (cs), Danish (da), Dhivehi (dv), Dutch (nl), English (en), Esperanto (eo), Estonian (et), Filipino/Tagalog (fil), Finnish (fi), French (fr), Frisian (fy), Galician (gl), Georgian (ka), German (de), Greek (el), Gujarati (gu), Haitian Creole (ht), Hausa (ha), Hawaiian (haw), Hebrew (iw), Hindi (hi), Hmong (hmn), Hungarian (hu), Icelandic (is), Igbo (ig), Indonesian (id), Irish (ga), Italian (it), Japanese (ja), Javanese (jv), Kannada (kn), Kazakh (kk), Khmer (km), Korean (ko), Krio (kri), Kurdish (ku), Kyrgyz (ky), Lao (lo), Latin (la), Latvian (lv), Lithuanian (lt), Luxembourgish (lb), Macedonian (mk), Malagasy (mg), Malay (ms), Malayalam (ml), Maltese (mt), Maori (mi), Marathi (mr), Meiteilon/Manipuri (mni-Mtei), Mongolian (mn), Myanmar/Burmese (my), Nepali (ne), Norwegian (no), Nyanja/Chichewa (ny), Odia/Oriya (or), Pashto (ps), Persian (fa), Polish (pl), Portuguese (pt), Punjabi (pa), Romanian (ro), Russian (ru), Samoan (sm), Scots Gaelic (gd), Serbian (sr), Sesotho (st), Shona (sn), Sindhi (sd), Sinhala/Sinhalese (si), Slovak (sk), Slovenian (sl), Somali (so), Spanish (es), Sundanese (su), Swahili (sw), Swedish (sv), Tajik (tg), Tamil (ta), Telugu (te), Thai (th), Turkish (tr), Ukrainian (uk), Urdu (ur), Uyghur (ug), Uzbek (uz), Vietnamese (vi), Welsh (cy), Xhosa (xh), Yiddish (yi), Yoruba (yo), and Zulu (zu).
Note: The above list reflects the languages currently supported by the underlying AI model technology used by Vim Scribe as of the effective date of these Terms. Vim does not independently verify translation accuracy for any Supported Language. The inclusion of a language in this list does not constitute a warranty or representation that Vim Scribe will accurately process or translate encounters conducted in that language. Language detection and translation are performed by automated systems and are subject to the disclaimers set forth herein.
- 4. Order Assist (f/k/a Referral Guidance or Referral Navigations) Application allows Covered Providers to access certain lists of Referred Providers which Data Sources recommended for referrals (“Referred Providers”). In addition, Covered Providers may request Vim to present their own physicians at the top of the search results list in the Order Assist Application. On supported EHRs, Covered Providers may use the Order Assist Application to write Data Source recommended referrals back into the EHR. The Data Source provides Vim with the Covered Providers search results logic. Vim is unaware of, nor has any control or discretion over, the factors and considerations under which these search results are generated and therefore shall not be held responsible by Covered Providers for any damages that arise from referrals made by Covered Providers through Vim the Order Assist Application.
- 5. Eligibility Application presents Covered Provider with patients’ insurance eligibility information, the name of their insurance company, and other information that may be relevant for the patient and Covered Provider. This data is provided by a Data Source. Vim has no discretion or influence over patients’ insurance information, including eligibility for treatment.
- 6. Patient Health History Application presents patients’ health history data to Covered Provider. Health history data is provided to Vim by Data Sources. “Health History” means a record, or a portion thereof, of the patient’s health, including, without limitation to, past visits with medical providers, past illnesses, chronic illnesses, allergies, prescribed medications, surgeries, injuries, mental health condition, blood tests results, administered vaccines and imaging results. Subject to Vim’s or the Data Source’s sole discretion, some types of Health History data may not be presented. Health History will not be recorded in the Covered Provider’s EHR unless incorporated by an Authorized User.
- 7. Pre-Authorization Application presents to Covered Provider information regarding any pre-authorizations required by the patient’s insurance company for certain medical treatments. Information entered into the Pre-Authorization Application is provided by Data Sources. Vim has no discretion or influence over the patient’s insurance information, including any information required by the Pre-Authorization Application for services. Prior authorization is not a guarantee of payment. Only the applicable Data Source can determine payment based on the submission of a claim by Covered Provider to such Data Source. Vim has no responsibility or liability regarding such Data Source’s payment processes or decisions.
- 8. Case Submission Application allows, for certain patients, to submit a pre-authorization case by allowing Covered Provider to access the Data Source’s submission portal directly from the Covered Provider’s EHR. The Data Source, and not Vim, has full and sole discretion to either approve or reject submitted cases.
- 9. Clinical Data Exchange (CDE) Application streamlines the retrieval of patients’ finalized encounter data and any attachments thereof (“Clinical Data”) from your EHR and securely transmits the Clinical Data to the designated entity requesting such Clinical Data (“Data Requestor”). Clinical Data may also include ancillary data associated with the patient, encounter identifiers file, the provider, and metadata in the form of a CSV or txt.Upon enabling the CDE Application, the following terms apply to your, and your Authorized Users’ use of the CDE Application:
-
- The Covered Provider or Admin may identify one or more Authorized Users, which shall be responsible for (a) accessing and reviewing Clinical Data retrieval requests sent to Covered Provider; (b) rejecting, if needed, any Clinical Data retrieval requests received through the CDE Application (“Data Exchange Admin(s)”). In addition, Covered Provider or Admin must provide a valid email address for receipt of email notifications regarding new Clinical Data retrieval requests. Covered Provider shall be solely responsible and liable to ensure the review and/or rejection of Clinical Data retrieval requests sent to Covered Provider.
- Upon receiving a Clinical Data retrieval request from a Data Requestor, the CDE Application will use a live EHR session of any active Authorized User to access and retrieve the requested Clinical Data from the EHR through such Authorized User’s EHR account (“Retrieved Clinical Data”). Retrieved Clinical Data will only contain Clinical Data that such Authorized User had access to in the Covered Provider’s EHR. If a Clinical Data retrieval request has not been rejected by a Data Exchange Admin, and the retrieval has been successful, Vim will securely transfer the Retrieved Clinical Data to the Data Requestor.
- Covered Provider hereby authorizes Vim to retrieve Clinical Data using any Authorized User’s EHR account, according to these CDE Application terms, unless a Clinical Data request has been rejected by a Data Exchange Admin.
- Covered Provider hereby authorizes Vim to retrieve Clinical Data using any Authorized User’s EHR account, according to these CDE Application terms, unless a Clinical Data request has been rejected by a Data Exchange Admin.
- Note that your EHR is expected to generate audit trails or logs documenting all instances in which the Clinical Data has been accessed, retrieved and/or transmitted under the applicable Authorized User. Covered Provider is responsible for retaining these audit logs in accordance with HIPAA’s record retention requirements.
- The CDE Application does not store or maintain the Retrieved Clinical Data. Vim does not assume any responsibility for the retention of any data, including audit trail/logs data. Covered Provider is solely responsible for maintaining all records of Clinical Data in accordance with HIPAA’s record retention requirements.
- Covered Provider represents and warrants that the Authorized Users are authorized to access and retrieve the Clinical Data on the Covered Provider’s behalf, and that Authorized Users have access only to Clinical Data of individuals who are current patients of Covered Provider or for whom Covered Provider has a legitimate medical purpose to access the information. This access must align with the applicable laws, regulations, and ethical guidelines governing patient confidentiality and data privacy. Vim shall not be held responsible by Covered Provider for any claims, fines or damages associated with unauthorized access to the requested Clinical Data by the Authorized Users. Vim further disclaims all liability for errors or omissions in the EHR audit trails or log, or any consequences arising from such errors or omissions. Covered Provider shall promptly notify Vim of any unauthorized access or other security incidents involving the CDE Application. Covered Provider shall be responsible for complying with HIPAA Breach Notification Rule requirements, including notifying affected individuals and the Department of Health and Human Services if necessary. Covered Provider agrees to indemnify and hold harmless Vim against any claims, losses or damages arising from a breach of Clinical Data, except where such breach is caused by Vim’s negligence or willful misconduct.
- Vim is not in the business of “assembling or evaluating [information] for the purpose of furnishing consumer reports to third parties”, as is required to qualify as a consumer reporting agency (“CRA”).
- Clinical Data Requestors may collect Clinical Data as subcontractors on behalf of authorized third parties such as health and life insurance companies, governmental entities, workers’ compensation insurers, and law firms with valid legal or contractual grounds to receive the Clinical Data (“Ultimate Data Recipients”).
- To provide the services described herein, You authorize Vim to (1) retrieve, obtain and store the Retrieved Clinical Data through the CDE Application using the EHR sessions of any Authorized Users, and (2) transmit the Retrieved Clinical Data to the Data Requestor. You may withdraw this authorization at any time by disabling the CDE Application; however, such withdrawal will not affect any actions taken in reliance on the above authorization before disabling the CDE Application.
- You agree to defend, indemnify, and hold harmless Vim and Vim’s affiliates, licensors, directors, officers, employees, agents and contractors against any and all third-party claims, demands, losses, costs and expenses, including reasonable attorney’s fees and litigation expenses, arising out of or relating to any action taken by Vim which has been authorized by you under Section 9.10 above.
- VIM SHALL NOT BE HELD LIABLE FOR ANY ERRORS, BUGS, OR SYSTEM MALFUNCTIONS THAT MAY ARISE DURING THE CLINICAL DATA RETRIEVAL PROCESS, WHICH COULD RESULT IN ALTERATIONS OR CHANGES TO THE RETRIEVED DATA, OR ANY OTHER DAMAGES THAT MAY ARISE IN CONNECTION WITH THE USE OF THE CDE APPLICATION.
- THE CDE APPLICATION RETRIEVES CLINICAL DATA FROM THE EHR “AS IS”. COVERED PROVIDER MUST EXERCISE DUE CARE AND JUDGMENT IN ITS USE OF THE CDE APPLICATION AND THE CLINICAL DATA. COVERED PROVIDER REPRESENTS AND WARRANTS THAT IT HAS VALID LEGAL OR STATUTORY GROUNDS TO DISCLOSE CLINICAL DATA TO THE ULTIMATE DATA RECIPIENTS AND THE DATA REQUESTORS. VIM SHALL NOT BE HELD RESPONSIBLE BY THE CLINIC FOR ANY DATA ACCURACY OR DATA QUALITY ISSUES, INCLUDING ANY CLAIMS OR DAMAGES THAT RESULTED FROM THE CLINICAL DATA RETRIEVAL OR USES THEREOF.
- VIM ACKNOWLEDGES THAT IT IS ACTING AS A BUSINESS ASSOCIATE OF THE DATA REQUESTOR UNDER HIPAA AND THAT IT HAS ENTERED INTO A BUSINESS ASSOCIATE AGREEMENT WITH EACH SUCH DATA REQUESTOR.
-
- 10. Rx Assist Application presents to Covered Providers the Data Source’s recommendations regarding the patient’s drug prescriptions, including without limitation, generic alternatives, doses, and necessary replacements. ALL RECOMMENDATIONS CONCERNING ALL TYPES OF MEDICATIONS, WHETHER PRESCRIBED OR NOT, ARE PROVIDED BY THE DATA SOURCE AND VIM SHALL NOT BE RESPONSIBLE FOR ANY INJURY OR DAMAGES CAUSED BY USING THE RX ASSIST APPLICATION.
- 11. Care Collaboration Application (beta version) (“CCA”) identifies patients from your EHR who may be eligible to (1) participate in various care management and specialty programs (“Private Programs”), which have partnered with Vim (“Care Partners”), and/or (2) various services covered by Medicare Part B (“Medicare Programs”, together with Private Programs, collectively, “Programs”). CCA further allows Authorized Users to enroll or request to enroll eligible patients in such Programs.
Upon enabling CCA, the following terms apply to you and your Authorized Users’ use of CCA:- Beta Application. CCA is currently a beta release that is provided for evaluation and feedback purposes only. CCA is not a generally available product and may change substantially before commercial release, or may never be released.
- Medicare Program Management Services.
- For Medicare Programs only, Vim has partnered with LiveCare Corp. d/b/a Clinii (“Clinii”), a technology care management platform that will support your clinical workflows, documentation, patient engagement, and billing-related activities in connection with any Medicare Programs to which you enroll your patients through CCA (“Clinii Services”).
- You may choose to provide care services covered by the Medicare Program through your in-house clinical staff (“Insource Model”) or to outsource such services (“Outsource Model”) using a third-party call center that Vim has partnered with (“Call Center”). The Call Center is integrated with Clinii, but isn’t part of Clinii. Under the Outsource Model, you will be receiving both the Clinii Services, and the Call Center will deliver the care services covered by Medicare to your patients (“Call Center Services”).
- All Clinii Services are subject to and governed by Clinii’s Terms and Conditions (“Clinii Terms”). By enrolling patients in Medicare Programs supported by Clinii, you agree to be bound by the Clinii Terms. Clinii is a third-party vendor, independent of Vim, and Vim is not responsible for the Clinii Services.
- All Call Center Services are subject to and governed by the Call Center Coverage Guide (“Call Center Terms”). By opting to use the Outsource Model, you agree to be bound by the Call Center Terms. The Call Center is a third-party vendor, independent of Vim and Clinii, and neither Vim nor Clinii is responsible for the Call Center Services.
- CCA Functionality.
- Once enabled, CCA scans your EHR records, specifically ICD-10 codes, for relevant chronic conditions, including potential unmet chronic conditions, and identifies patients with ICD-10 codes that may be relevant to one or more Programs, and with respect to Medicare Programs, whether the patient is covered by Medicare Part B (such patients, “Identified Patient(s)”).
- For Private Programs, Vim securely shares the patient information detailed under Annex A with the applicable Care Partners to return potential identification of an Identified Patient’s eligibility for each Care Partner program.
- For Medicare Programs, no data is shared until the patient is enrolled, as further described in the following section, and all Identified Patients shall be considered eligible.
- Authorized Users will determine whether enrollment is appropriate for each Identified User, and may, subject to the Authorized User’s obligations set forth below, submit an enrollment request on behalf of the Identified Patient to enroll with the relevant Program(s).
- The fact that the CAA displays one or more Programs for which a patient may be eligible does not mean that no other similar or alternative programs exist for such a patient, within CAA or generally, or that the patient is not eligible for other programs that are not displayed in CAA. Vim does not represent or warrant that the CAA provides a complete, exhaustive, or exclusive list of all Programs for which a patient may be eligible.
- You remain responsible for independently identifying, evaluating, and discussing alternative programs or care options with patients, whether or not such programs are available through CAA.
- Following submission of an enrollment request by an Authorized User:
- Private Programs:
- Vim will share the patient information detailed in Annex A below with the applicable Care Partner, and the Care Partner will contact the patient to complete the enrollment.
- Authorized Users will be notified once the enrollment has been completed by the Care Partner (“Completed Enrollment”). You may be eligible to receive a payment for Completed Enrollments, as further described in the Payments section below.
- Medicare Programs:
- Vim will share the patient information detailed in Annex A with Clinii.
- Clinii will create the care plan and provide the Clinii Services.
- If you opted to use the Outsource Model, the Call Center will provide the Call Center Services.
- CPT codes for the relevant care services will be issued by Clinii and will be made available to you through CCA. It is your responsibility to submit the claims to Medicare Part B and receive any applicable reimbursement.
- For each enrolled patient, CCA will capture existing actions you and your Authorized Users already perform which could potentially be issued a CPT code (“Auto Capture”). Vim delivers the Auto Capture to Clinii to issue CPT codes, if applicable. The Auto Capture will contain the patient information detailed in Annex A.
- You are required to pay the fees as further described in the Payments section below
- Private Programs:
- Eligibility and Enrollment. Eligibility criteria are solely determined by each Authorized User, and by the Care Partner and/or by Clinii, as applicable. Enrollment is completed solely by the Care Partner and/or Clinii, as applicable. Vim does not influence, validate, or confirm such eligibility requirements or enrollment. Vim does not make eligibility and enrollment decisions. Vim, through CCA, simply transmits eligibility and enrollment requests to the Care Partners and/or Clinii, as applicable, and displays their responses to the Covered Provider.
- Covered Provider Obligations.
- With respect to Private Programs, by enabling CCA, you authorize Vim to share Protected Health Information (“PHI”) of your patients with Care Partners, for screening for Identified Patients and facilitating their enrollment in Care Partners’ programs.
- You are solely responsible for obtaining and maintaining any consents, authorizations, or permissions (including, as applicable, a patient authorization pursuant to 45 C.F.R. § 164.508) required from patients or their authorized representatives as may be necessary to search for unmet chronic conditions, identify potential Care Partner program eligibility, and share patients’ PHI with Care Partners as described herein. For your convenience, you can use our sample Patient Authorization Form.
- You will immediately inform Vim of any patient who has declined or revoked their consent, authorization, or permission to participate in CCA. You may do so by “opting” a patient out via the CCA by toggling the opt-out button by the patient’s name. Once a patient is opted out, Vim may delete and remove any prior identifications for eligibility with respect to such a patient.
- You shall maintain documentation of any consents, authorizations, or permissions as described in this Section for as long as CCA is enabled on your account, or as otherwise required by law, whichever is greater, and you shall provide evidence thereof to Vim and Care Partners upon Vim’s reasonable written request.
- Before submitting an enrollment request on behalf of a patient, you or the Authorized User must verify that enrollment is clinically appropriate for the patient and obtain the patient’s consent to enroll in and be contacted by the applicable Program.
- You acknowledge that you and your Authorized Users are solely responsible for obtaining appropriate patient consent prior to submitting an enrollment request on behalf of a patient.
- You are solely responsible for ensuring that all patient consents, authorizations, or permissions comply with applicable state and federal laws (including HIPAA) and your organization’s policies.
- You are solely responsible for compliance with billing requirements and compliance with law for patients hereunder.
- Payments and Fees. Unless agreed otherwise in a signed Order Form between you and Vim, the following payments and fees will apply to your use of CCA:
- Private Programs: You may be eligible to receive payment for your care coordination and collaboration services provided through CCA, subject to the applicable payment terms of the applicable Care Partner. Such payment information will be made available to you through CCA.
- Medicare Programs:
- For your use of the Insource Model through CAA, you will be charged $10 per Active Patient per month. “Active Patient” means a patient for whom at least one CPT code has been issued to you through CCA, in a given calendar month.
- For your use of the Outsource Model through CAA, you will be charged a fee per each issued CPT code, in accordance with the fee table under Annex B.
- All fees will be charged monthly and are due and payable within 30 days of the invoice date.
- Indemnification. You agree to defend, indemnify, and hold harmless Vim and Vim’s affiliates, licensors, directors, officers, employees, agents and contractors (“Vim Indemnitees”) against any and all claims, demands, losses, costs, and expenses, including reasonable attorney’s fees and litigation expenses, arising out of your or your Authorized Users’ breach of the obligations under these CCA terms.
- Disclaimers.
- Private Programs are provided by Care Partners. You acknowledge that Care Partners’ services, decisions, rules, and communications are the sole responsibility of the Care Partner, and Vim does not (a) guarantee enrollment, (b) set or interpret eligibility criteria or evaluate eligibility, (c) execute enrollments, (d) provide medical or clinical services or clinically evaluate patient records, or (e) verify the accuracy of Care Partner information. You agree to hold harmless Vim and Vim indemnitees for any: (a) eligibility outcomes, including the failure to identify potential eligibility, (b) enrollment results or delays, (c) Care Partner and/or their program performance or communications, (d) changes to Care Partner’s program requirements, or (e) consequences of patient participation or nonparticipation in any Care Partner program.
- Medicare Programs are supported by Clinii, and, if you opt to use the Outsource Model, care is delivered by the Call Center. Clinii Services and Call Center Services are not part of the services provided by Vim, and both Clinii and the Call Center are independent parties of Vim. When you enroll a patient in a Medicare Program supported by Clinii, or use the Clinii Services, you are contracting directly with Clinii, under the Clinii Terms. When you opt to use the Outsource Model or use the Call Center Services, you are contracting directly with the Call Center under the Call Center Terms. Your use of the Clinii Services and/or the Call Center Services remains at your own risk and responsibility. Vim has no control over the content or processes of Clinii, the Call Center, the Clinii Services, the Call Center Services, the Clinii Terms, or the Call Center Terms, and Vim shall not be liable for any damages that may arise from your or your Authorized Users’ use of the Clinii Services and/or the Call Center Services. Vim does not undertake any obligation to monitor Clinii Services, Call Center Services, Clinii’s content, or the Call Center’s content, and Vim is not responsible for, and does not endorse, any Clinii Services, the Call Center Services, or any content made available by such third parties through CCA. Vim is not a party to the Clinii Terms between you and Clinii or to the Call Center Terms between you and the Call Center. Clinii and the Call Center are each solely responsible for their content and warranties, as well as any claims that you may have related to the Clinii Services and/or the Call Center Services, as applicable. Clinii is solely responsible for providing maintenance and support for the Clinii Services.
- You remain responsible for any patient communication, care coordination, or documentation associated with enrollment.
- CCA IS PROVIDED “AS IS”. CCA IS NOT A CLINICAL TOOL AND DOES NOT PROVIDE ANY MEDICAL, DIAGNOSTIC, OR TREATMENT ADVICE, AND COVERED PROVIDER AND ITS AUTHORIZED USERS MUST EXERCISE DUE CARE AND JUDGMENT IN ITS USE OF THE CCA AND COMPLY WITH ALL APPLICABLE CLINICAL, LEGAL, AND REGULATORY DUTIES.
- To the maximum extent permitted by law, Vim disclaims all liability arising from: eligibility evaluations or errors, enrollment outcomes, data inaccuracies, technical or transmission issues, reliance on information provided through the CCA, and any actions, errors, or omissions of Care Partners.
- Feedback and Fair Use
- By providing feedback or suggestions (“Feedback”), you grant Vim a perpetual, royalty-free, transferable license to use such Feedback without restriction.
- Vim may limit usage to ensure system performance during beta.
- Termination. Vim may suspend or terminate access to CCA at any time. You may discontinue use at any time.
Annex A – Information Shared with Partners:
- Eligibility: for eligibility check, the following patient data is extracted by CCA from your EHR and shared with the applicable Care Partner:
- Medical Record Number (MRN) – Unique patient identifier from EHR
- Patient’s first name and last name from the
- Patient’s Date of Birth
- Patient’s zip code
- ICD-10 Diagnosis Codes – All diagnosis codes from the patient’s problem list
- Enrollment: for enrollment completion, the following patient data is extracted by CCA from your EHR and shared with the applicable Care Partner/Clinii:
- Medical Record Number (MRN) – Unique patient identifier from EHR
- Patient’s first name and last name from the
- Patient’s Date of Birth
- Patient’s Phone Number (if available)
- Patient’s Email
- ICD-10 Diagnosis Codes – All diagnosis codes from the patient’s problem list
- Auto Capture: for generating the Auto Capture, the following patient data is extracted by CCA from your EHR and shared with Clinii:
– Care coordination
– Care plan review and update
– Chart preparation
– Clinical review
– Monthly Chart Review
– Create a patient note
– Diagnosis review
– Following up on patient orders/referrals
– Lab correspondences
– Medical Record Review
– Monthly Clinical Review
– Encounter Documentation
– Patient Assessment
– Patient education
– Patient preparation
– Pharmacy correspondences
– Prescription refill
– Provider order for labs
– Provider order for pharmacist consult
– Referrals
– Review care plan
– Review medication
– Update medication
– Scheduling appointments and services
– Updating patient health record
– Provider review of patient labs
– Daily Chart Review
– Prescription transfers
– Prescription process
– +Follow-up on medication status
– Prescription verification
Annex B – Fee per issued CPT Code under Outsource Model
CPT Code Service Description Fee G0506 ONE-TIME onboarding, consent, and care plan development fee $50 99490 CCM, first 20 minutes of staff time $45 99439 CCM, each additional 20 minutes of staff time $35 99487 Complex CCM, 60 minutes with moderate/high complexity care planning $95 99489 Complex CCM, each additional 30 minutes $55 G0557 APCM Level 2: 2 or more chronic conditions $40 G0558 APCM Level 3: Qualified Medicare Beneficiaries, 2+ chronic conditions $75 99424 Base PCM $56 99426 PCM, first 30 minutes for a single high-risk condition $45 99427 PCM, each additional 30 minutes $35 99453 ONE-TIME device setup and patient education $18 99445 RPM device supply and data transmission – 2 to 15 days of readings $35 99454 RPM device supply and data transmission – 16+ days of readings $40 99470 RPM management, 10 to 19 minutes per month $21 99457 RPM management, first 20 minutes of staff time $35 99458 RPM management, each additional 20 minutes $32 - 12. Vim Direct Application is available to all Authorized Users on Vim Connect and enables Authorized Users to send secure messages to other Authorized Users within Vim Connect. Vim Direct allows messaging between Authorized Users within the same healthcare organization or to Authorized Users at different organizations who have Vim Connect. Authorized Users may also use Vim Direct to send invitations to healthcare providers who do not currently use Vim Connect (“Invitation Feature”). Messages may include text and file attachments. By using Vim Direct, the following terms apply to you and your Authorized Users’ use of Vim Direct:
-
- Vim Direct Functionality.
- Messaging Capabilities. Vim Direct allows Authorized Users to:
- Send and receive messages to and from other Authorized Users within their organization;
- Send and receive messages to and from Authorized Users at other healthcare organizations that have the Vim Platform installed;
- Attach files to messages, subject to file size and type restrictions as determined by Vim in its sole discretion; and
- Send invitations to healthcare providers who do not currently have the Vim Platform, inviting them to join and enabling future communication through Vim Direct.
- Message Delivery. Vim will use commercially reasonable efforts to deliver messages, but does not guarantee delivery or timing of message delivery. Authorized Users are solely responsible for confirming receipt of messages.
- Messaging Capabilities. Vim Direct allows Authorized Users to:
- Data Handling and Storage
- Not a System of Record. VIM DIRECT IS A MESSAGING TOOL AND IS NOT INTENDED TO SERVE AS A “SYSTEM OF RECORD” OR PRIMARY DATA REPOSITORY FOR ANY INFORMATION, INCLUDING, BUT NOT LIMITED TO, PATIENT HEALTH INFORMATION. Vim does not store or maintain any information and should not be used as a record-keeping or storage repository for any purpose. It is your responsibility to save, maintain, and store any information, data, and messages. Vim does not store or maintain any Protected Health Information (“PHI”), including, but not limited to, PHI contained in messages as part of any patient’s designated record set. You and your Authorized Users remain solely responsible for maintaining complete and accurate patient records in your EHR or other designated system of record in accordance with all applicable laws and regulations, including but not limited to HIPAA and state law record retention requirements. You and your Authorized Users are solely responsible for including messages in the Designated Record Set.
- Temporary Message Retention. While Vim Direct is not a system of record, message content and attachments may be retained temporarily solely to facilitate the messaging functionality and may be accessible to active Authorized Users who are parties to a conversation. This temporary retention does not alter your obligation to maintain official records in your designated system of record and should not be relied upon for any purpose.
- Conversation History Upon User Departure. If an Authorized User’s organization discontinues use of Vim Connect or if an individual Authorized User’s access to Vim Direct is terminated, but another Authorized User who was party to the same conversation(s) remains an active user of Vim Connect, the conversation history may remain available to the Authorized User(s) who continue to use Vim Connect. You acknowledge and agree that Vim is not required to delete conversation histories solely because one party to a conversation has discontinued use of Vim Direct, provided that at least one party to the conversation remains an active user.
- Covered Provider Obligations
- HIPAA Compliance and Patient Authorizations. You are solely responsible for ensuring that your and your Authorized Users’ use of Vim Direct complies with HIPAA and all other applicable federal and state privacy and security laws. This includes, but is not limited to:
- Obtaining any necessary patient authorizations prior to communicating any information, including, but not limited to, PHI through Vim Direct;
- Ensuring that messages containing PHI are sent only to appropriate recipients who have a legitimate treatment, payment, or healthcare operations purpose;
- Implementing appropriate administrative, physical, and technical safeguards to protect PHI communicated and any other sensitive or personal information through Vim Direct; and
- Training Authorized Users on proper use of Vim Direct in compliance with HIPAA, your organization’s policies, and any other applicable laws.
- Patient Right to Restrict Disclosures. You and your Authorized Users are solely responsible for honoring patients’ rights under HIPAA to request restrictions on the use and disclosure of their PHI, including PHI communicated through Vim Direct. This includes, without limitation:
- Implementing processes to receive, evaluate, and respond to patient requests to restrict disclosures of their PHI;
- Ensuring that Authorized Users do not use Vim Direct to communicate PHI about a patient when such patient has requested restrictions that would prohibit such communication;
- Maintaining documentation of patient restriction requests and your organization’s responses; and
- Promptly communicating restriction requirements to relevant Authorized Users.
Vim has no visibility into, control over, or responsibility for managing patient restriction requests or ensuring Authorized User compliance with such restrictions. Vim shall not be held responsible or liable for any unauthorized disclosure of PHI resulting from an Authorized User’s or any other person’s or entity’s failure to honor a patient’s restriction request.
- Content Responsibility. You and your Authorized Users are solely responsible for:
- The content of all messages sent through Vim Direct;
- Determining the appropriateness of communicating PHI through Vim Direct for any particular purpose;
- Verifying the identity and authorization of message recipients prior to sending PHI;
- Ensuring that attachments do not contain malware, viruses, or other harmful content; and
- Compliance with all applicable laws, regulations, and ethical guidelines.
- Prohibited Uses. You and your Authorized Users shall not use Vim Direct to:
- Communicate emergency or time-sensitive clinical information where immediate response is required;
- Send unsolicited marketing or advertising communications;
- Transmit information in violation of any applicable law, regulation, or patient restriction;
- Share login credentials or access Vim Direct using another Authorized User’s account; or
- Attempt to access messages or conversations to which you are not a party.
- HIPAA Compliance and Patient Authorizations. You are solely responsible for ensuring that your and your Authorized Users’ use of Vim Direct complies with HIPAA and all other applicable federal and state privacy and security laws. This includes, but is not limited to:
- Invitation Feature
- When using the Invitation Feature to invite healthcare providers who do not have Vim Connect, you represent and warrant that:
- You have a legitimate professional or treatment-related reason to contact the invited provider;
- You are not sending unsolicited marketing communications; and
- You will not abuse the Invitation Feature by sending excessive or inappropriate invitations.
- Vim reserves the right to limit, suspend, or terminate your access to the Invitation Feature if Vim determines, in its sole discretion, that you are not appropriately using this feature.
- When using the Invitation Feature to invite healthcare providers who do not have Vim Connect, you represent and warrant that:
- Fees and Payment. The base functionality of Vim Direct is currently provided at no charge. Vim reserves the right to introduce fees in the future. Prior to implementing any such fees, Vim will provide notice in accordance with Section 13.6 of the Provider Terms of Service. You will not be charged for any features unless you affirmatively opt in to enable such features.
- De-Identification and Use of Data
- De-Identified Data. You authorize Vim to de-identify messaging data (including message metadata, usage patterns, and message content) in accordance with the de-identification standards set forth in 45 C.F.R. § 164.514(a)-(b) and to use such de-identified data for Vim’s business purposes, including, without limitation: Improving and developing Vim Direct and other Vim products and services; Conducting research and analytics; and Creating aggregated benchmarking and statistical reports.
- You acknowledge that this Section survives termination of your use of Vim Direct.
- Security and Access
- Security Measures. Vim implements reasonable administrative, physical, and technical safeguards designed to protect the security and confidentiality of messages transmitted through Vim Direct, as further described in Vim’s Business Associate Agreement with you.
- Access Controls. You are responsible for:
- Implementing appropriate access controls to limit which Authorized Users have access to Vim Direct;
- Promptly deactivating access for Authorized Users who no longer require access or whose employment or relationship with your organization has terminated;
- Monitoring Authorized User activity for unauthorized or inappropriate use; and
- Reporting any suspected security incidents to Vim promptly.
- Breach Notification. In the event of a breach of unsecured PHI transmitted through or stored by Vim Direct, the parties’ respective obligations shall be governed by the Business Associate Agreement between you and Vim. You remain responsible for complying with HIPAA Breach Notification Rule requirements with respect to notifications to affected individuals, the Secretary of Health and Human Services, and, where applicable, the media.
- Disclaimers and Limitations of Liability
- No Guarantee of Delivery or Availability. VIM DOES NOT GUARANTEE THAT VIM DIRECT WILL BE AVAILABLE AT ALL TIMES OR THAT MESSAGES WILL BE DELIVERED SUCCESSFULLY OR IN A TIMELY MANNER. VIM SHALL NOT BE LIABLE FOR ANY DAMAGES ARISING FROM DELAYS IN MESSAGE DELIVERY, FAILED MESSAGE DELIVERY, OR UNAVAILABILITY OF VIM DIRECT.
- No Clinical Advice. VIM DIRECT IS A COMMUNICATION TOOL ONLY. VIM DOES NOT PROVIDE MEDICAL, CLINICAL, OR PROFESSIONAL ADVICE OF ANY KIND THROUGH VIM DIRECT. AUTHORIZED USERS REMAIN SOLELY RESPONSIBLE FOR ALL CLINICAL DECISIONS AND PATIENT CARE.
- Third-Party Providers. VIM HAS NO CONTROL OVER AND SHALL NOT BE LIABLE FOR THE ACTIONS, OMISSIONS, OR CONTENT OF AUTHORIZED USERS AT OTHER ORGANIZATIONS. YOU ACKNOWLEDGE THAT WHEN YOU COMMUNICATE WITH AUTHORIZED USERS AT OTHER ORGANIZATIONS THROUGH VIM DIRECT, YOU ARE DOING SO AT YOUR OWN RISK.
- Reliance on Messages. YOU AND YOUR AUTHORIZED USERS SHOULD EXERCISE PROFESSIONAL JUDGMENT AND DISCRETION IN RELYING ON INFORMATION RECEIVED THROUGH VIM DIRECT. VIM SHALL NOT BE HELD LIABLE FOR ANY DECISIONS MADE OR ACTIONS TAKEN IN RELIANCE ON MESSAGES RECEIVED THROUGH VIM DIRECT.
- Indemnification. You agree to defend, indemnify, and hold harmless Vim and Vim’s affiliates, licensors, directors, officers, employees, agents and contractors against any and all claims, demands, losses, costs, and expenses, including reasonable attorney’s fees and litigation expenses, arising out of or relating to:
- Your or your Authorized Users’ use of Vim Direct;
- Any breach of these Vim Direct terms or the Agreement;
- Any violation of HIPAA or other applicable laws arising from your or your Authorized Users’ use of Vim Direct;
- Any failure to honor a patient’s right to restrict disclosure of PHI;
- The content of any messages sent by you or your Authorized Users through Vim Direct; or
- Any claim that you or your Authorized Users failed to maintain appropriate records in your designated system of record.
- Termination
- Vim may suspend or terminate access to Vim Direct at any time, with or without notice, for any reason or no reason, including but not limited to suspected violations of these terms or suspected security incidents.
- You may discontinue use of Vim Direct at any time by disabling the application through Vim Console.
- Upon termination of your access to Vim Direct:
- You and your Authorized Users will no longer be able to access or send messages through Vim Direct;
- Conversation histories in which you or your Authorized Users were participants may remain accessible to other Authorized Users who continue to use Vim Direct, as described in Section 12.2.3 above; and
- Your obligations under these terms that by their nature should survive termination (including, but not limited to, your indemnification obligations and Vim’s right to use de-identified data) shall survive.
- Vim Direct Functionality.
-