Platform Agreement

OMNIPACS PLATFORM AGREEMENT

Terms of Use, End User Agreement and Business Associate Agreement

Version: Version 1.0
Effective Date of this Version: September 1, 2026
Last Updated: September 9, 2026
Structure: Part A (Universal Terms) · Part B (Professional and Organizational Users) · Part C (Business Associate Agreement) · Part D (Patients and Individuals) · Part E (Definitions, Precedence and General Provisions)


Which parts apply to you

This is one agreement covering everyone who uses OmniPACS — hospitals, imaging centers, radiology groups and the clinicians who work for them, and patients looking at their own medical images. It is a single document that you accept with a single click, but it does not give everyone the same obligations, so the first thing it does is tell you which parts are yours.

The router — find yourself here

  • Are you a patient, or an individual looking at your own images, or the images of someone you are legally allowed to act for?
    → Read Part A and Part D. Parts B and C do not apply to you at all. That is roughly 5,000 words of plain English.

  • Are you using OmniPACS for work — at a hospital, imaging center, radiology group, teleradiology practice, or any other practice or organization, whether or not you pay us anything?
    → Read Parts A, B and C. Part D does not apply to you.

  • Everyone reads Part E, which holds the definitions, the order of precedence and the general provisions.

Nobody reads the whole document, and you are not expected to. That is the point of the structure. Reading a Part that does not apply to you will only mislead you about what you have agreed to. If you are unsure which description fits you, Part A, Section A.3 has a table that settles it, and you can email support@omnipacs.com and ask.

Summary for patients — a summary, not the agreement

This box is a plain-language summary written for patients. It is a reading aid only. It is not the agreement, it is not a substitute for Part A and Part D, and if anything in this box differs from Part A or Part D, Part A and Part D govern.

Four things worth knowing before you read anything else.

1. This is not a diagnosis. OmniPACS stores and displays medical images. Nobody here reads your scan or forms an opinion about it. What you see on a phone or laptop is not what your radiologist sees on a calibrated medical display. Ask your treating doctor what your images mean. In an emergency, call 911.

2. You are never charged. Access to your own images is free. There is no plan, no invoice, no auto-renewal, and no card required.

3. You do not sign a HIPAA contract. The Business Associate Agreement in Part C is between OmniPACS and your provider. You are the person it protects, never a party to it.

4. Part D is written for you. Your rights, our promises, what we owe you if something goes wrong, and how disagreements are handled are all in Part D, in plain English.

 
 

The Privacy Policy is a separate document

The OmniPACS Privacy Policy is not part of this Agreement. It is a notice, not a contract, it applies to everyone who uses the Platform or our website in any capacity, and it is published separately at https://omnipacs.com/legal/privacy. Nothing in this Agreement replaces it, and nothing in it replaces this Agreement.


PART A — UNIVERSAL TERMS

Part A binds every person who accesses or uses the OmniPACS Platform, in every capacity, whether or not you pay anything, whether or not you have an account of your own, and whether you reach the Platform through your own credentials, through an invitation from an administrator, or through a shared-study link.

Part A is written to be read start to finish in about ten minutes. It is deliberately plainer than Part B, because a patient and a radiologist are both bound by it and both have to be able to follow it.


A.1 Who we are, and what this covers

A.1.1 The parties. This Agreement is between OmniPACS Healthcare Technologies LLC, a New Jersey limited liability company with its principal place of business at 17 Griffin Street, Monmouth Beach, New Jersey 07750, United States (“OmniPACS,” “we” or “us”) and you, the person or entity accessing or using the Platform.

A.1.2 What the Platform is. The “Platform” is the OmniPACS software, websites, applications and hosted services for storing, transferring, converting, routing, indexing, distributing, viewing and sharing medical images and their associated records, together with the locally installed components that connect to it. Defined terms used across this Agreement are collected in Part E, Section E.2.

A.1.3 What this covers. This Agreement governs your access to and use of the Platform. It is one instrument made of five Parts, and no Part is incorporated into it by reference from somewhere else — they are all in this document.


A.2 How this becomes binding

A.2.1 Assent by click. This Agreement becomes binding on you when you click a button or check a box presented with a statement telling you that clicking or checking constitutes agreement to it (your “Acceptance Date”). That is the only way we bind you to it.

A.2.2 No browsewrap. We do not, and will not, rely on the passive posting of terms to bind anyone. Merely visiting a page where this Agreement is available is not acceptance. Assent is captured only by an affirmative click or checkbox, from a screen that tells you the click is your agreement.

A.2.3 If you do not agree, do not access or use the Platform. If you have already been given credentials or a share link, close it and tell the person who sent it.

A.2.4 Age and authority. By accepting, you represent that you are at least eighteen (18) years old, or that you meet the age and authority rules in Part D, Section D.1; that if you are accepting for an organization you are authorized to bind it, in which case “you” means both you and that organization; and that the information you give us at registration is accurate. Part C, Section C.2 relies on that same authority.

A.2.5 How your acceptance is recorded. What we record when you accept, how long we keep it, and how you can obtain your own copy are set out in Part E, Section E.4.


A.3 Who is bound, and which Parts apply

A.3.1 The rule. Part A binds everyone. Part E applies to everyone. Whether Part B, Part C or Part D reaches you depends on the capacity in which you use the Platform. The router at the front of this document is the plain-language face of the table below; the table is the operative version.

A.3.2 Applicability table.

User typeWho this isPart A (Universal)Part B (Professional / Organizational)Part C (BAA)Part D (Patients and Individuals)
Subscriber / account ownerThe entity, or individual practitioner, that holds the account, selects a plan and is billed — imaging center, mobile or portable imaging provider, radiology or teleradiology group, hospital or health system, or their affiliated professional entitiesApplies in fullApplies in full, at the plan level for the accountApplies, and becomes a binding BAA automatically on acceptance or first PHI ingestion. No separate signature is required (Part C, Section C.1)Does not apply
Authorized Clinical UserAnyone given credentials by a Subscriber — radiologists, technologists, PACS administrators, schedulers, front-desk and billing staffApplies in fullApplies through the Subscriber’s account: you must comply with it, and the Subscriber owes the Fees. If you cause an upload, Part B, Section B.1 also makes you responsible for Fees on that accountApplies through your Organization’s Part C obligationsDoes not apply
Referring or Shared-Study RecipientA referring physician, external reader, second-opinion consultant or other professional recipient given access through a share from a Subscriber’s accountApplies in fullDoes not apply unless you upload, transmit, route or cause the ingestion of Customer Data, or administer an account that does — then Part B, Section B.1 appliesApplies in your professional capacity: you must be a Covered Entity or Business Associate with authority to receive the PHIDoes not apply
Free or Legacy Account HolderAny holder of a free, evaluation, trial, pilot, sandbox, grandfathered or otherwise unpriced accountApplies in fullApplies, but without the fee, service-level and entitlement provisions — see Part B, Section B.2Applies if PHI is involved. Free access is not an exception to HIPAADoes not apply unless you use the Platform solely as a patient
Patient or IndividualA person accessing their own images, or those of someone they hold legal authority for, however the access startedApplies in full, and is written to be readable by youDoes not apply at allDoes not apply at all. A patient is never a party to a BAA (Part C, Section C.5)Applies in full, in plain English

A.3.3 One person may be more than one type. A single individual can fall into more than one row at different times — a physician who is an Authorized Clinical User in her own practice’s account, a Shared-Study Recipient of a study sent by another facility, and a patient looking at her own knee MRI. The Parts attach to each capacity separately. Which Parts apply to a given act is judged by what you were actually doing, not by how your account was originally labelled. So the same physician is governed by Parts A, B and C when she reads her patients’ studies, and by Parts A and D when she looks at her own.

A.3.4 Three things you will not find in Part A. So that no reader concludes a term went missing:

    (a) Part A contains no limitation of liability and no liability cap. For professional and organizational users the cap is in Part B, Section B.7. For patients and individuals it is in Part D, Section D.7, which sets a fixed dollar cap and states affirmatively that a patient owes us no indemnity.

    (b) Part A contains no warranty disclaimer. For professional and organizational users the warranties and disclaimers are in Part B, Section B.6. For patients and individuals what we do and do not promise is in Part D, Section D.6.

    (c) Part A contains no dispute-resolution clause, no governing-law clause, no arbitration clause and no jury or class waiver. For professional and organizational users those are in Part B, Section B.12. For patients and individuals they are in Part D, Section D.8 — and Part D deliberately contains no arbitration, no jury waiver and no class waiver.

These three subjects are left out of the universal core because they differ too much between a health system and a patient to be written once. Nothing is missing; it is located by capacity.


A.4 Your right to use the Platform

A.4.1 The grant. Subject to your continuing compliance with this Agreement, OmniPACS grants you a limited, revocable, non-transferable, non-exclusive, non-sublicensable right to access and use the Platform solely for the Permitted Purposes in Section A.5, and solely in accordance with this Agreement, the Documentation and the clinical-safety limits in Section A.9.

A.4.2 What kind of right this is. It is a right to use a hosted service. It is not a sale, transfer or assignment of software, and it gives you no ownership of anything. It is limited to the Permitted Purposes and to the functions your account and role make available; revocable if you breach this Agreement or when the account through which you reach the Platform closes or expires (enforcement and suspension mechanics for professional users are in Part B, Section B.3 and Part B, Section B.9); non-transferable and non-sublicensable, so you may not sublicense, lease, rent, time-share, transfer or assign it, in whole or part, by operation of law or otherwise, without our prior written authorization; non-exclusive, since we grant the same rights to others; and conditional, existing only while you comply.

A.4.3 Everything we did not grant, we kept. All rights not expressly granted in Section A.4.1 are reserved to OmniPACS and its licensors. You receive no source code, no right to create derivative works, and no rights by implication or estoppel — you cannot argue that because we did not forbid something, we must have allowed it.

A.4.4 Rights that are not in Part A. An organization’s right to install and operate local components across its own network, and the licence for those components, are not universal; they are in Part B, Section B.5. A patient or individual receives hosted access through a browser or app and nothing more.

A.4.5 Some limits outlive your access. When your access ends, your right to use the Platform ends with it, but Sections A.4 through A.9 continue to bind you afterwards, as do the provisions of Parts B, D and E that by their nature survive. See Part E, Section E.3.

A.4.6 Supported browsers, and the equipment you bring. The Platform is a browser-based hosted service, and it is built, tested and supported against a defined set of browsers.

    (a) Supported Browsers. OmniPACS officially supports the current major version and the immediately preceding major version of Google Chrome and of Microsoft Edge, running on a currently supported release of Microsoft Windows or Apple macOS. For access from a mobile device, OmniPACS supports the current major version of Google Chrome on Android and the current major version of Apple Safari on iOS and iPadOS, which is the browser engine every iOS browser uses. Those are the “Supported Browsers.”

    (b) Everything else is unsupported. Any other browser, browser version, browser engine or operating system — including Mozilla Firefox, Opera, Brave, Vivaldi, Samsung Internet, embedded or in-application webviews, kiosk and appliance browsers, browsers on end-of-life or unsupported operating systems, and any browser running in a compatibility, legacy or emulation mode — is not supported. It may work, and OmniPACS does not block it, but OmniPACS makes no representation that the Platform will function correctly on it, and is under no obligation to correct, investigate, work around or reproduce any issue that does not occur on a Supported Browser.

    (c) Configuration you must maintain. The Platform requires JavaScript, cookies and browser local storage to be enabled, and requires TLS 1.2 or higher. You are responsible for your own equipment, operating system, browser, browser version, security updates, extensions, connectivity, bandwidth and display, and for the effect of any extension, plug-in, ad blocker, script blocker, privacy tool, enterprise browser policy, content filter, proxy or inspection appliance you or your organization deploys. Those tools can and do break browser-based clinical software, and OmniPACS is not responsible when they do.

    (d) This list can change. OmniPACS may add or remove Supported Browsers as browser vendors release and retire versions, and will not treat a browser as unsupported without a reasonable transition period where the change is within its control.

    (e) Two things this Section never does. It never limits the retrieval and export path in Part B, Section B.9.16.4, and it is never a basis for refusing, delaying or conditioning an individual’s access to their own health information. If a Supported Browser is not available to you and you need your own images, contact support@omnipacs.com and OmniPACS will provide a reasonable alternative means of access at no charge. Display and viewing limits for clinical purposes are separate, and are in Section A.9.

    (f) Diagnostic reading is different. Nothing in this Section makes any browser suitable for Primary Diagnostic Interpretation. No browser is. See Section A.9.


A.5 What you may use it for

A.5.1 Permitted Purposes. “Permitted Purposes” means, and is limited to:

    (a) for a professional or organizational user — the storage, management, routing, distribution, sharing and review of medical imaging Studies and their associated records, including ingestion, indexing, search, worklist management, report attachment, export and media production, in the course of lawful health care activities: providing, arranging for, paying for, or giving administrative and quality support to health care, by or on behalf of a health care provider, health plan or health care clearinghouse. Clinical review and triage, referral, second opinions, care coordination, responding to a patient’s request for their own records, teaching and quality assurance on your own data, and ordinary imaging-practice administration are inside the purpose; and

    (b) for a patient or individual — getting to medical images and records that are yours, or that belong to someone you hold legal authority for: viewing them, downloading your own copy, uploading your own prior imaging and related records into the access your health care provider gave you, keeping your own records, and sharing them with people you choose. Nothing more, and nothing less.

A.5.2 Any other use is unlicensed. Using the Platform for anything other than a Permitted Purpose falls outside the right granted in Section A.4.1, is unlicensed, and is a material breach of this Agreement. It may also infringe our and our licensors’ intellectual property and may be an unauthorized access to a protected computer system under other law. We reserve every right and remedy.

A.5.3 The purpose limit does not move with your role or your bill. It applies identically to a hospital, a solo radiologist, a share-link recipient, a free-account holder and a patient. Paying for the Platform does not widen the purpose. Paying nothing does not narrow your obligations.


A.6 What you may not do

A.6.1 Prohibited conduct. You will not, and will not permit or enable anyone else to:

    (a) use the Platform for anything other than a Permitted Purpose;
    (b) look at, or try to look at, any Study, record or account you are not authorized to access;
    (c) resell, sublicense, rent, lease, time-share, assign, transfer, or run the Platform as a service for other people without our prior written authorization;
    (d) upload or transmit unlawful, infringing, defamatory or harassing material, material violating someone else’s privacy or publicity rights, images or records you have no right to hold, malicious code, or non-medical content unrelated to a Permitted Purpose;
    (e) interfere with or disrupt the integrity, security, availability or performance of the Platform, or the data of any other user or account;
    (f) conduct penetration testing, vulnerability scanning, load testing, red-teaming or security research against the Platform without our prior written authorization and within an agreed scope and window. OmniPACS does not operate a published vulnerability disclosure program and grants no standing authorization for security testing. Reporting a suspected vulnerability to us at support@omnipacs.com with the subject line “SECURITY” is welcome and is not itself a breach of this paragraph;
    (g) modify, adapt, translate or create derivative works of the Platform, any local component or the Documentation, or copy, frame or mirror any of them;
    (h) reverse engineer, decompile, disassemble, or otherwise try to derive the source code, underlying ideas, algorithms, file formats, protocols or structure of the Platform or any local component;
    (i) bypass, disable, tamper with or circumvent any security, authentication, licensing, metering, rate-limiting, audit-logging or access-control mechanism;
    (j) perform bulk or automated extraction of data — bots, scripts, crawlers — outside the published APIs and the ordinary download and export functions;
    (k) try to re-identify de-identified or limited-data-set information;
    (l) remove, obscure, alter or fail to reproduce any copyright, trademark, trade secret, confidentiality, regulatory, intended-use, labelling, safety or other proprietary notice, legend, watermark or marking appearing in or on the Platform, any local component, the Documentation, or any exported report, disc, media or other output — and where you make a permitted copy, reproduce every such notice on it;
    (m) use the Platform inconsistently with Section A.9, including using a non-diagnostic viewing path for Primary Diagnostic Interpretation;
    (n) impersonate anyone, including a clinician or a family member, or use the Platform to give other people medical advice;
    (o) use the Platform, or anything you learn from it, to build or improve a competing product, or benchmark it for publication without our prior written consent;
    (p) share, lend or transfer credentials, or use another person’s credentials, contrary to Section A.8; or
    (q) upload imaging or records you have no right to upload. If you are a patient or individual, you may upload imaging and related records only where you are the subject of that imaging, or you hold legal authority to act for its subject, and by uploading you represent that you have the right to do so. Uploading another person’s imaging without that authority is a prohibited use. If you are a professional or organizational user, the equivalent obligation is in Part B, Section B.3.1.

A.6.2 The statutory interoperability carve-out. Where applicable law gives you a non-waivable right to decompile or otherwise analyze software for interoperability or another specified purpose, Section A.6.1(g)–(i) does not stop you from doing exactly what that law permits. First write to us at support@omnipacs.com, tell us what you need, and give us a reasonable chance to hand you the interoperability information instead, and use anything you obtain only for the purpose the law allows.

A.6.3 Consequences. Breach of Section A.6 is a material breach. We may suspend or end your access, with or without advance warning depending on the seriousness. Where we believe someone is at risk or a law has been broken, we may notify your provider, your organization, or the authorities. Professional users are also subject to Part B, Section B.3.


A.7 Who owns what

A.7.1 We own the Platform. The Platform — all software, source and object code, models, algorithms, weights, data structures, schemas, interfaces, designs, workflows, Documentation, trademarks, logos, and every improvement or derivative work of any of them — is and remains the exclusive property of OmniPACS and its licensors. Your right to use it is only what Section A.4 grants. No title, ownership interest or proprietary right in the Platform passes to you at any time, however long you use it. Any purported transfer, pledge or encumbrance of the Platform or of your access to it is void.

A.7.2 You own your data and your health information. As between us, you own and keep all right, title and interest in your own Customer Data — Studies, images, reports and metadata — and a patient or individual owns their own health information, except that images your provider placed here are part of your provider’s medical record about you. Either way, OmniPACS acquires no ownership interest in it. The limited licence we need to run the service for you, and its strict limits, are in Part B, Section B.5; for PHI, Part C controls.

A.7.3 Your name and marks. We acquire no right in your names, marks or logos except as Part E, Section E.3 expressly permits. We will never use a patient’s name, face, images or story in marketing, a press release or a customer list.

A.7.4 Survival. Section A.7 survives the end of your access and of any account through which you reached the Platform.


A.8 Your account and your credentials

A.8.1 Credentials are personal. Access the Platform only with credentials assigned to you. Never share your password, passcode or one-time code with anyone — not a colleague, not a family member, not a caregiver, and not someone claiming to be from OmniPACS. We will never ask you for your password. Never use another person’s credentials. Shared, generic, service-desk or role-based human logins are prohibited.

A.8.2 Basic hygiene. Use a password you do not use anywhere else, sign out on shared or public computers, and do not leave an authenticated session open where others can reach it. Authentication is performed through Firebase Authentication using signed JSON Web Tokens. OmniPACS requires verification by a one-time passcode, sent to the email address or mobile number on file, when an account is created and when a password is reset. OmniPACS does not currently enforce multi-factor authentication on every routine sign-in. Subscribers remain responsible for evaluating whether that is sufficient for their environment and for applying compensating controls, including device management, network controls and session policy, where their own risk assessment requires them.

A.8.3 Share links. Treat a share link like a key. If you create a share you are responsible for who receives it, what it exposes and how long it lasts, and — if you are acting professionally — for confirming the disclosure is lawful first. Do not forward a share link to anyone who was not meant to have it. Once someone downloads, saves, forwards, prints or screenshots an image, that copy is out of our hands and out of yours; switching a link off stops future viewing and nothing more. OmniPACS does not warrant that a recipient of a share link must authenticate, that any share link expires, or that any particular expiry period applies. Treat every share link you create as capable of being used by anyone who obtains it, and share it only with people who are entitled to the images.

A.8.4 You are responsible for activity under your credentials, and a Subscriber for activity under its account, whether or not you authorized it — except for activity resulting from our own breach of this Agreement or of Part C.

A.8.5 Tell us immediately if something is wrong. Notify us at once, and in any event within twenty-four (24) hours of discovery, if you suspect your credentials have been compromised, that someone else has been in your account, or that any other security incident has affected the Platform or your connection to it: write to support@omnipacs.com with the subject line “SECURITY”, or call 813-590-0846. Professional users have additional incident obligations in Part B, Section B.3.

A.8.6 When our support team looks at your account. Where necessary to fix a problem you reported, our support staff may access your account using a support-impersonation function. That access is limited to the minimum necessary, is logged in OmniPACS’ internal access logs, and is subject to Part C where PHI is involved. Support-impersonation events are not currently surfaced in a customer-visible or patient-visible audit log, and OmniPACS makes no commitment to surface them.

A.8.7 Provisioning is a professional obligation. The duties to provision, review and promptly deprovision users and to assign minimum-necessary roles sit with organizations, in Part B, Section B.3. If your provider created your access, your provider may also be able to change or switch it off.


A.9 Clinical safety — this is not a diagnosis

This is the most important section in this Agreement. It applies to every user, including users who never pay anything. Read the shared statement, then read the paragraph written for you.

A.9.1 The shared statement. OmniPACS is an image management, storage, communication and display system: it stores, transfers, converts, routes, indexes, distributes and displays medical images and their associated records. The Platform does not provide, and is not intended to provide, image interpretation, diagnosis, treatment recommendations, or any other clinical conclusion. No one at OmniPACS reads your images or forms a clinical opinion about them.

THE PLATFORM IS A PLACE TO STORE, VIEW AND SHARE MEDICAL IMAGES. IT IS NOT A DIAGNOSIS AND IT IS NOT MEDICAL ADVICE. IMAGES DISPLAYED BY OMNIPACS’ OWN VIEWING PATHS MAY NOT BE SUITABLE FOR DIAGNOSTIC INTERPRETATION.

 
 

THE PLATFORM IS NOT CLEARED, APPROVED OR AUTHORIZED BY THE US FOOD AND DRUG ADMINISTRATION OR BY ANY OTHER REGULATORY AUTHORITY, AND IS NOT MARKETED FOR PRIMARY DIAGNOSTIC INTERPRETATION. That statement applies to the Platform, to every local component, and to any AI feature. You must not tell anyone that we hold a clearance, approval or authorization. OmniPACS’ Intended Use statement is available on request at support@omnipacs.com.

A.9.2 If you are a professional user — non-diagnostic display, calibration, and your own judgment.

    (a) Non-diagnostic display. Image rendering, thumbnails, preview panes, embedded viewing, patient-facing viewing, and any browser-based or mobile image display provided by the Platform, EPS-Pi or UDE are provided for non-diagnostic review, triage, verification, quality assurance, clinical reference, patient access and administrative purposes only, and must not be used for Primary Diagnostic Interpretation. No OmniPACS-native viewer configuration is intended, labeled or supported for Primary Diagnostic Interpretation. Diagnostic reading of Studies stored in the Platform is performed in the CHILI viewer, a third-party product supplied by CHILI GmbH, launched from the Platform by means of time-limited, cryptographically signed ticket URLs. The CHILI viewer is not part of the Platform. OmniPACS makes no warranty of any kind as to the CHILI viewer and disclaims all liability arising from it. Its intended use, regulatory status and display requirements are those stated by its manufacturer, and you are responsible for obtaining, distributing and complying with that manufacturer’s labelling.

    (b) Displays and reading environment. Where anyone performs Primary Diagnostic Interpretation of Studies retrieved from the Platform, providing and maintaining calibrated, diagnostic-grade displays appropriate to the anatomy, modality and pathology is your responsibility, not ours — including acceptance and constancy testing, calibration to the DICOM Grayscale Standard Display Function, control of ambient lighting, and verifying that the display chain renders full bit depth and geometry without unintended scaling or windowing. We cannot detect, and do not verify, the calibration state of any display any user uses. Mobile phones, tablets and consumer laptops are for reference and non-diagnostic review only. The full obligations, including lossy compression and mammography restrictions, are in Part B, Section B.4.

    (c) Clinical decisions remain the practitioner’s. All diagnoses, interpretations, reports, referrals, prioritization decisions and patient-management decisions are made solely by licensed practitioners exercising independent professional judgment. The Platform does not replace the education, skill and judgment of a properly trained medical practitioner. Only properly trained, licensed people acting within the scope of their licensure may use the Platform clinically, and they must know its capabilities and limitations. Where an AI feature is available, AI outputs are informational aids only, are not a diagnosis, may be wrong, and must be independently verified against the source images and the clinical record by a qualified practitioner who makes the ultimate decision. Do not treat the Platform as the sole record of a Study’s existence, completeness or integrity.

A.9.3 If you are a patient or an individual — this is your record, not an interpretation.

    (a) This is your record, not an interpretation. OmniPACS shows you your images. It does not tell you what they mean. Nothing you see here tells you whether you are healthy or sick. Your radiologist reads your images; your doctor explains them. This platform is built for access, personal record-keeping and sharing with people you choose — it is not designed or intended for self-diagnosis.

    (b) What you see is not what your radiologist sees. Radiologists read on medical-grade monitors, in dark rooms, with calibrated brightness and contrast, in diagnostic software. You are probably on a phone, a laptop or a tablet. On an ordinary screen, brightness and contrast are not calibrated, so faint findings can vanish or seem to appear; small details can be lost; and images may be compressed or resized to load faster. What looks alarming to you may be completely normal, and what looks normal may not be.

    (c) Ask your treating provider. Do not use this platform to diagnose yourself, to rule anything out, to change your medicine, or to make any decision about your treatment. If a report is available to you here, it was written for your doctor in medical language and may use words that sound worse than they are — please bring it to your appointment rather than interpreting it alone.

    (d) In an emergency, call 911.

IF YOU THINK YOU ARE HAVING A MEDICAL EMERGENCY, CALL 911 OR GO TO YOUR NEAREST EMERGENCY ROOM NOW. DO NOT SEND A MESSAGE THROUGH THIS PLATFORM AND DO NOT WAIT FOR A REPLY. THIS PLATFORM IS NOT MONITORED FOR EMERGENCIES AND NO ONE HERE IS WATCHING FOR URGENT MESSAGES.

 
 

    (e) Do not rely on us as your only copy. A link can expire, an account can close, a provider can remove a study. Keep your own copy of anything you need long term. See Part D, Section D.5.

A.9.4 Safety reporting. Tell us promptly about any suspected malfunction, image-integrity defect, patient-misidentification event, data-loss event, or any event in which the Platform may have contributed to patient harm or a near miss, by writing to support@omnipacs.com with the subject line “URGENT — PATIENT SAFETY”, or by calling 813-590-0846. Professional users must report such events within two (2) Business Days and owe the cooperation duties in Part B, Section B.4.


A.10 Third-party components

A.10.1 The Platform works with other companies’ products — including the CHILI viewer supplied by CHILI GmbH, which is not part of the Platform, your own PACS, RIS, EHR and modality vendors, and the app stores from which you download our mobile applications.

A.10.2 We are not responsible for third-party products. Your use of them is governed by your agreements with those third parties, not by this Agreement, and we do not warrant the continued availability of any third-party product or integration. Where you obtained an OmniPACS application through an app store, that store’s own terms also apply to your download and to your device, and the store is not a party to this Agreement.


A.11 Privacy and security, in outline

A.11.1 The Privacy Policy. How we collect, use, share and protect information generally is described in the OmniPACS Privacy Policy — a separate document that applies to everyone and is not part of this Agreement. It is published at https://omnipacs.com/legal/privacy.

A.11.2 Where to look for the substance. Part A duplicates none of it:

    (a) Protected Health Information — permitted uses and disclosures, safeguards, breach and security-incident reporting, subcontractors, individual access, amendment, accounting, and return or destruction at termination — is governed by Part C, which controls over every other Part as to PHI (Part E, Section E.1).
    (b) Patient-specific privacy rights, including the rights no contract can take away, are in Part D, Section D.5.
    (c) Security, hosting, infrastructure and subprocessors for professional users are in Part B, Section B.11.

A.11.3 Nothing here permits an unlawful use of PHI. No provision of this Agreement is to be read as permitting a use or disclosure of PHI that Part C or the HIPAA Rules do not permit.

A.11.4 Privacy contact. Write to support@omnipacs.com with the subject line “PRIVACY REQUEST”. Individual access, amendment and accounting requests from a Covered Entity go through Part C; requests from a patient go through Part D, Section D.5.


A.12 Feedback

If you send us a suggestion, idea, bug report or complaint about how the Platform works, we may use it to improve the Platform, without restriction and without owing you anything. We will not identify you publicly as the source without your consent. If your message contains your health information, we do not treat that information as free-to-use feedback — we handle it under the Privacy Policy and, for PHI, under Part C.


A.13 Changes to the Platform

A.13.1 The Platform changes. We may add, modify or discontinue features. Software changes over time.

A.13.2 Notice before a material degradation. We will not materially degrade the core functionality of ingestion, storage, retrieval, viewing or export for a paying Subscriber during a paid subscription term without at least thirty (30) days’ prior notice; the consequences of such a change for that Subscriber are in Part B, Section B.9.

A.13.3 Free, legacy, beta and pre-release access. Where we provide the Platform at no charge we may change, limit, suspend or discontinue it on notice, given at least thirty (30) days in advance where the account holds stored data, with a reasonable opportunity to export it first. Beta, preview, pilot, early-access and pre-release builds are provided as is and must not be used for Primary Diagnostic Interpretation or for any purpose on which patient care depends. UDE is distributed through Apple TestFlight as a pre-release build. UDE is not generally available, is provided for evaluation only, and carries no warranty, no availability target and no support commitment. Full provisions in Part B, Section B.2.

A.13.4 If we remove something you rely on and you are a patient or individual, we will give you notice where we reasonably can, and your right to obtain your own records from your provider is unaffected by anything we do to the Platform.


A.14 Changes to this Agreement

A.14.1 Versioning and archive. This Agreement is versioned. Every version carries a version identifier and an effective date and is published at https://omnipacs.com/legal/agreement. We maintain a public archive of all prior versions with their effective dates at https://omnipacs.com/legal/agreement/archive, so that any user can determine which version applied at any point in time. Because this is one instrument, all Parts are versioned together — no Part is versioned separately.

A.14.2 Non-material changes. Clarifications, typographical corrections, updated contact details, and reorganization that does not change substance take effect on publication, and we will update the “Last updated” date at the top. Continued use may evidence acceptance of a non-material change.

A.14.3 Material changes — 30 days’ notice, for everyone. A material change includes any change to fees or fee structure, to metering or Study counting, to the service levels, to suspension or termination, to the licence and its limits in Sections A.4 through A.7, to clinical safety in Section A.9, to Part C, to limitation of liability in Part B, Section B.7 or Part D, Section D.7, to dispute resolution in Part B, Section B.12 or Part D, Section D.8, or to a new use of your information or a new category of recipient. For any material change we will give affected users at least thirty (30) days’ advance notice before it takes effect, by in-product notice and, where we have your email address, by email — to account administrators and the billing contact for a Subscriber, and to the address on file for everyone else — and the notice will identify what is changing and where the new version is published.

A.14.4 How a change is accepted. The same rule applies to every user, professional and patient alike.

    (a) Notice plus continued use. After the thirty (30) days’ notice in Section A.14.3, if you keep accessing or using the Platform once the change has taken effect, that is your acceptance of the changed Agreement. We may also re-present the updated Agreement for click-acceptance, and where we do, acceptance is recorded under Part E, Section E.4.

    (b) If you do not want to accept, stop using the Platform. A professional or organizational user that does not accept may terminate or decline renewal on the notice required by Part B, Section B.9; refunds are governed by Part B, Section B.9 and are not expanded by this Section. Where a non-paying professional user does not accept, that user’s access ends, but we will first give the notice and export opportunity in Part B, Section B.2. A patient or individual who does not want to accept can stop using the Platform and, where the feature exists, close their account (Part D, Section D.5), and can always obtain their records from their provider.

    (c) Where the change affects Part C, we may require confirmation from a person authorized to bind the Organization — see Part C, Section C.2.

    (d) Where the law requires consent, we ask for consent. We will not treat an updated page as your permission when the law says permission must be sought.


A.15 Notices

A.15.1 Notices to you. We may give notice by email to the addresses on file for you — for a Subscriber, the account administrators and billing contact — by in-product notice, or by courier or mail. Email notice is effective on transmission absent a bounce. Keep your contact details current: a notice sent to a stale address on file is still effective.

A.15.2 Notices to us. Formal notices — termination, cancellation, non-renewal, an indemnification claim, a dispute, a claim of breach, or a privacy request you want on the record — must be in writing to:

OmniPACS Healthcare Technologies LLC
Attention: Legal
17 Griffin Street, Monmouth Beach, New Jersey 07750, United States
With a copy by email to support@omnipacs.com

 
 

A.15.3 Everyday problems. For a broken link, a login issue, or a question about which Part applies to you, support@omnipacs.com or in-product support is fine and you will get a human answer. A support ticket or chat message is not written notice for the formal purposes in Section A.15.2.

A.15.4 Professional formalities. Delivery, receipt and business-day counting rules, and the in-product cancellation mechanism, are in Part B, Section B.9 and Part B, Section B.12. Those formalities are not applied to patients and individuals; a patient gives valid notice by writing to the addresses in Part D, Section D.10.

A.15.5 Security, vulnerability and safety notices go to the addresses in Section A.8.5 and Section A.9.4, not to legal notices. In an emergency, do not use notices at all — call 911.

A.15.6 Our published contact points. Support and general questions: support@omnipacs.com or 813-590-0846. Sales, orders and plan changes: sales@omnipacs.com. Privacy requests: support@omnipacs.com, subject line “PRIVACY REQUEST”. Security incidents and vulnerability reports: support@omnipacs.com, subject line “SECURITY”. Patient-safety and malfunction reports: support@omnipacs.com, subject line “URGENT — PATIENT SAFETY”, or 813-590-0846. Formal legal notice: the address in Section A.15.2.


PART B — ADDITIONAL TERMS FOR PROFESSIONAL AND ORGANIZATIONAL USERS

This Part applies only if you use the Platform in a professional or organizational capacity. If you are a patient or individual using OmniPACS to look at your own images, this Part does not apply to you — go to Part D.


Numbering convention used in this Part

Read this before checking a cross-reference. Part B uses one numbering scheme, stated here:

  1. Sections B.1 through B.8 and B.10 through B.12 are numbered sequentially within this Part, with sub-sections numbered under each Section number — for example, Section B.3.4, Section B.4.5, Section B.7.2A and Section B.12.7.

  2. Section B.9 (Subscription Terms) carries its own internal numbering under the B.9 prefix — for example, Section B.9.15.5, Section B.9.16.4 and Section B.9.18.4. Section B.9 contains no Section B.9.17; the service level provisions are a Section of this Part in their own right at Section B.10.

  3. Sections B.5 and B.11 each carry more than one subject, so they take one additional level of numbering — for example, Section B.5.1.2, Section B.5.2.6, Section B.11.1.4 and Section B.11.3.3.

  4. Every cross-reference carries its Part letter. A reference stated with a Part-B number (for example, “Section B.9.16.4”) is internal to this Part B.

  5. “these Terms” means this Agreement as a whole.


B.1 WHO THIS PART BINDS; THE TWO TRIGGERS

This Section is the hinge of this Part. Read it before you upload anything and before you use the Platform in a professional capacity.

B.1.1 Who this Part binds

This Part B binds every person who uses the Platform in a professional or organizational capacity — a Subscriber or account owner, an Authorized Clinical User, a Referring or Shared-Study Recipient, and a holder of a free or legacy account used for professional purposes. The applicability table, the dual-capacity rule and the definitions of those user types are in Part A, Section A.3, and are not restated here. A Patient or Individual is not bound by this Part B in any circumstance (Part A, Section A.3 and Part D).

Professional capacity is judged functionally, and what else binds you depends on what you actually do: the two triggers in Sections B.1.2 and B.1.3 are evaluated by reference to your conduct, not by reference to how your account was originally labeled.

B.1.2 Upload and storage trigger — you become a Subscriber

If you upload, store, transmit, route, or cause the ingestion of any Study or other Customer Data into the Platform, or if any account you administer does, then:

    (a) you are a Subscriber for purposes of these Terms, whether or not you have selected a plan, signed an Order Form, or previously been billed;
    (b) the Subscription Terms in Section B.9 apply to you and to that account, at the subscription plan level applicable to that account as set out in the Order Form for the account or, where there is none, in OmniPACS’ then-current published price list;
    (c) you are responsible for all Fees arising from that account, including Fees for Studies ingested by any other person using that account, jointly and severally with any other person who is a Subscriber in respect of the same account; and
    (d) you represent that you have the authority, rights, consents and authorizations necessary to upload, store, transmit and disclose that Customer Data through the Platform.

    (e) Ingestion caused indirectly still counts. Causing ingestion includes configuring or operating a modality, DICOM router, gateway, OmniRouter, EPS-Pi or other Local Component, an API client, or an inbound share or forwarding rule that results in a Study reaching the Platform, whether or not you personally touched the Platform’s interface.

    (f) Exception — Patients and Individuals. A Patient or Individual who uploads or directs the transfer of their own images, or the images of a person for whom they hold legal authority, into their own patient-facing account does not become a Subscriber and is not charged under Section B.9. That activity is governed by Part D. A Patient’s or Individual’s access to the Platform arises only through a health care provider relationship, and imaging a Patient or Individual uploads into that access is handled as PHI under Part C, as described in Part C, Section C.6 and Part D.

B.1.3 Professional and PHI trigger — Part C attaches

If you use the Platform in a professional or organizational capacity involving Protected Health Information — including any clinical, diagnostic, administrative, billing, research-support or operational use on behalf of a health care provider, health plan, health care clearinghouse, or a business associate of any of them — then:

    (a) you represent and warrant that you are a HIPAA Covered Entity or a Business Associate of a Covered Entity, or are acting for one, and that you have the authority to disclose that PHI to OmniPACS;

    (b) Part C (the Business Associate Agreement) applies to you and to your Organization. Part C is part of this Agreement. It is not a separate document, it is not incorporated by reference, and it does not have to be signed;

    (c) the business associate agreement HIPAA requires is already in place. Part C becomes a binding business associate agreement between OmniPACS and your Organization automatically, on the earlier of your acceptance of this Agreement or the first ingestion of PHI into an account held by or administered for your Organization, in accordance with Part C, Section C.1. No separate signature, countersignature or second acceptance step is required, and none will be requested. There is no period in which you may hold PHI in the Platform without a business associate agreement in force, because acceptance of this Agreement forms one;

    (d) a Patient or Individual is never a party to Part C. A business associate agreement is an agreement between a Covered Entity and a Business Associate. An individual whose PHI it is, is the subject and a beneficiary of that protection, never a party to it, and OmniPACS will not ask a patient to sign one. See Part C, Section C.5 and Part D, Section D.4;

    (e) professional capacity is judged functionally. Viewing a shared Study as a referring physician, an external reader or a consulting specialist is professional use, even if you never upload anything and never pay anything;

    (f) you represent that you are authorized to bind your Organization to Part C. If you are not, Part C, Section C.3 governs what happens, including that OmniPACS’ own obligations under Part C bind OmniPACS regardless, from first receipt of PHI; and

    (g) if you want a signed business associate agreement, you can have one. OmniPACS will negotiate and execute a business associate agreement on your paper or on its own, and an executed agreement replaces Part C in full for your Organization under Part C, Section C.4. Requesting one does not delay your access to the Platform and carries no charge.

Free and trial accounts. Free, evaluation, trial, pilot, sandbox, demonstration, grandfathered and legacy access does not relieve you of anything in this Section B.1.3. There is no free-tier exception to HIPAA. Part C attaches to a free account on exactly the same terms and at exactly the same moment as to a paid one.

B.1.4 Additional licence rights for professional and organizational users

These rights extend the licence granted in Part A, Section A.4 and are available only to professional and organizational users. They do not apply to a Patient or Individual.

B.1.4(a) Entity-wide installation and internal deployment. Where you are an entity, you may install and operate the Platform’s Local Components and access the Platform across your own network, including at multiple sites and on multiple devices, for those of your employees, contractors, medical-staff members and credentialed practitioners who need access to perform their duties, provided that: (i) each such individual is provisioned with unique credentials under Part A, Section A.8; (ii) each such individual is bound by and complies with this Agreement; (iii) you remain responsible for their acts and omissions and, where Section B.9 applies, for all Fees attributable to them; and (iv) you do not thereby make the Platform available to any person outside your organization other than as expressly permitted in this Agreement.

B.1.4(b) Local Components. OmniPACS grants you a limited, non-exclusive, non-transferable right to install and operate the Local Components in your own environment solely to connect to and use the Platform. You will install updates within a commercially reasonable period after they are made available and in any event within thirty (30) days for updates OmniPACS designates as security updates. UDE is distributed through Apple TestFlight as a pre-release build. UDE is not generally available, is provided for evaluation only, and carries no warranty, no availability target and no support commitment. See Section B.2.1(f).


B.2 FREE, TRIAL AND LEGACY ACCOUNTS

B.2.1 Free, evaluation, trial and legacy accounts

Where OmniPACS makes the Platform available to you at no charge — free accounts, evaluation and trial accounts, pilots, sandbox or demonstration tenants, grandfathered or legacy accounts, and view-only access granted to a Shared-Study Recipient:

    (a) Part A and this Part B apply to you in full. Every obligation in them — the licence limits (Part A, Section A.4), the permitted purpose (Part A, Section A.5), the prohibited uses (Part A, Section A.6), the intellectual-property restrictions (Part A, Sections A.6 and A.7), the credential rules (Part A, Section A.8), the intended-use and non-diagnostic limits (Part A, Section A.9), the Acceptable Use Policy (Section B.3), the disclaimers (Section B.6), the liability limits (Section B.7) and the indemnity (Section B.8) — binds you exactly as it binds a paying Subscriber;
    (b) the Platform is provided to you without the subscription commitments in Section B.9 and without the service levels in Section B.10. There is no availability target, no service credit of any kind (OmniPACS offers none to any user), no support commitment, no professional-services entitlement, no retention entitlement and no post-termination retrieval-window commitment for free access, except where OmniPACS states otherwise in writing;
    (c) free access is provided as is, and OmniPACS may change, limit, suspend or discontinue it on notice, which OmniPACS will give at least thirty (30) days in advance where the account contains stored Customer Data, together with a reasonable opportunity to export that data before access ends. OmniPACS will not destroy stored PHI without the notice and export opportunity described in Section B.5.2 and, where a BAA applies, without complying with Part C’s return-or-destroy provisions;
    (d) free access does not relieve you of the Part C (BAA) requirement. If your use involves PHI, Section B.1.3 applies in full and Part C must be in effect before any upload. There is no “free tier exception” to HIPAA; and
    (e) free access does not survive the upload trigger. If you upload, store, transmit, route or cause the ingestion of any Study or other Customer Data, Section B.1.2 applies and Section B.9 attaches to the account, unless OmniPACS has expressly agreed in writing that a specified volume of ingestion is included at no charge and stated the duration of that arrangement.

    (f) Beta, preview and pre-release features. Features designated beta, preview, pilot, evaluation, early access, or distributed through a pre-release channel (including Apple TestFlight) are provided “AS IS” and “AS AVAILABLE,” without warranty of any kind, without any availability target and without any support commitment, may be modified or withdrawn at any time, and must not be used for Primary Diagnostic Interpretation or for any purpose on which patient care depends unless OmniPACS confirms otherwise in writing. UDE is distributed through Apple TestFlight as a pre-release build and is not generally available.


B.3 PROFESSIONAL ACCEPTABLE USE

You will comply with this Acceptable Use Policy, and a Subscriber will ensure that its Authorized Clinical Users comply with it. Breach of this Section B.3 is a material breach of these Terms.

B.3.1 Authority and lawfulness of uploads and disclosures

    (a) Where Section B.1.3 applies to you, you represent and warrant that you are a HIPAA Covered Entity or a Business Associate of a Covered Entity, and that you have all authority, rights, consents and authorizations necessary to upload, store, use, disclose, transmit and share each Study and all other Customer Data through the Platform.
    (b) You represent that each transmission, share or disclosure you initiate through the Platform to a third party — including a referring provider, an external reader, a second-opinion physician, another facility, a payer, an attorney, or a patient — is a use or disclosure permitted by the HIPAA Privacy Rule and by all other applicable law, including any state law imposing heightened protection for substance use disorder, reproductive health, behavioral health, HIV, genetic or minors’ records.
    (c) No PHI may be uploaded before Part C (the BAA) is in effect (Section B.1.3(c)).
    (d) You will use the Platform only for the Permitted Medical Purposes described in Part A, Section A.5 and in accordance with all applicable laws.

B.3.2 Minimum necessary and access discipline

    (a) You will limit user access, sharing scope and share duration to the minimum necessary.
    (b) A Subscriber will review user entitlements at least quarterly and remove access that is no longer necessary.
    (c) You will not use the Platform to access, or facilitate access to, records unrelated to a Permitted Medical Purpose, and a Subscriber will investigate suspected inappropriate access by its own personnel.

B.3.3 Patient identity and data accuracy

    (a) The Subscriber is solely responsible for verifying patient identity before uploading, merging, linking, reconciling, correcting or sharing any Study, and for detecting and resolving duplicate, overlaid, merged or mis-assigned patient records and medical record numbers.
    (b) Any patient-matching, duplicate-detection, name-normalization or reconciliation aid provided by the Platform is a convenience only and is not a substitute for that verification. OmniPACS does not warrant that such aids will identify all duplicates or prevent all mismatches.
    (c) The Subscriber is responsible for correct patient demographics, accession numbers, institution names, modality codes and DICOM tag values, including the correctness and uniqueness of Study Instance UIDs generated by its modalities.
    (d) You will not upload Studies with knowingly incorrect, placeholder, test or fabricated patient identifiers to a production account.

B.3.4 Credentials

    (a) Unique credentials per individual; no sharing of credentials for any reason; no use of another person’s credentials; no shared or generic human accounts (Part A, Section A.8).
    (b) Multi-factor authentication, or equivalent compensating controls, for administrative and remote access. The Platform requires one-time passcode verification at account creation and at password reset, and does not enforce multi-factor authentication on every routine sign-in (Section B.9.20.1A). You are responsible for implementing and maintaining the authentication and access controls your own risk analysis requires.
    (c) Prompt deprovisioning of departed or reassigned personnel.
    (d) Immediate notification of suspected credential compromise (Part A, Section A.8).

B.3.5 Your environment, integrations and Local Components

    (a) You are solely responsible for the procurement, configuration, patching, monitoring, hardening and security of your own environment, including modalities and acquisition devices, workstations, OmniRouter, EPS-Pi, UDE devices, OmniMonitor, DICOM routers and gateways, VPN and site-to-site tunnels, firewalls, DNS, certificates and internet connectivity.
    (b) You are responsible for your own PACS, VNA, RIS, EHR, dictation and billing integrations and for the correctness of the data those systems send to and receive from the Platform.
    (c) You will confirm successful transmission of each Study and will maintain local store-and-forward capability sufficient to survive a connectivity interruption (Section B.4.2).
    (d) You will apply OmniPACS-issued updates to Local Components and will not run unsupported versions beyond the end-of-support date stated in the Documentation.
    (e) You will not modify, reverse engineer, decompile, repackage or redistribute any Local Component (Part A, Section A.6).

B.3.6 Professional-user restriction

Clinical and diagnostic use of the Platform is limited to professional medical personnel licensed to provide diagnosis, referral or clinical viewing services and acting within the scope of their licensure. You will not make the Platform available to the general public or to patients as a diagnostic tool. Patient access is provided under Part D.

B.3.7 Prohibited uses

The prohibitions in Part A, Section A.6 are part of this AUP and are enforceable as such.

B.3.8 Security incident notification

Your notification obligation is in Part A, Section A.8. Where you fail to provide the information OmniPACS reasonably requires to investigate and contain an incident, OmniPACS may isolate the affected connection, account or Local Component as a security containment measure only, subject always to Section B.5.2.5 and Section B.9.16.4.

B.3.9 Enforcement

OmniPACS may suspend or restrict an offending user, credential, connection or Platform function, and may revoke the right granted in Part A, Section A.4, where you breach this AUP. No enforcement action under this Section B.3 will block, disable or degrade the ability of any Subscriber or Covered Entity to retrieve, view or export previously stored Customer Data, including PHI, except to the narrow extent genuinely required to contain an active security incident. See Section B.5.2.5 and Section B.9.16.4.


B.4 MEDICAL IMAGING OBLIGATIONS

B.4.1 Responsibility for Customer Data. You are solely responsible for the accuracy, quality, integrity, completeness, legality and appropriateness of the Customer Data you upload or generate and the means by which you acquired it, including patient demographics, accession numbers, DICOM tag hygiene, and the lawfulness of every upload, disclosure and share.

B.4.2 Data that does not reach the Platform. Transmission of Studies from your environment to the Platform depends on your modalities, routers, gateways, network and connectivity. OmniPACS is not responsible for Customer Data that does not reach the Platform. You represent that you maintain and have adequately tested your own local backup and store-and-forward processes, so that your on-site data is protected against disaster or equipment malfunction and remains available if it does not reach the Platform.

B.4.3 Migration verification. Where legacy data is migrated to the Platform, you are responsible for verifying that the legacy data has been migrated properly and completely — including study counts, patient and accession identifiers, series and instance counts, and image integrity — and for reporting discrepancies within thirty (30) days of migration completion. You will not decommission or delete your source archive until you have completed that verification.

B.4.4 Deletion. The Platform provides administrative deletion functions. Deletion initiated by you or by a user of your account is your instruction to OmniPACS and may be irreversible. You are responsible for ensuring that your deletion practices comply with the medical-record retention requirements applicable to you. OmniPACS is not liable for the consequences of user-initiated deletion.

B.4.5 Retention is your determination. Medical-record retention obligations vary by state, licensure, accreditation, payer and modality, and are longer for mammography. You warrant that you have determined the retention period required of you and are responsible for ordering and configuring retention sufficient to meet it. OmniPACS does not advise on retention periods. OmniPACS’ retention commitments to Subscribers, and its no-silent-deletion covenant, are in Section B.5.2.6 and Section B.9.23.

B.4.6 Minimum-necessary configuration. OmniPACS provides role-based access controls, sharing controls and audit logging. You own the configuration: you will configure roles, permissions, sharing recipients, external share durations and retention so that access to PHI is limited to the minimum necessary for the intended purpose.

B.4.7 De-identification. OmniPACS reserves no right to de-identify Customer Data for its own purposes. OmniPACS will not de-identify Customer Data except on your documented instruction or as expressly permitted by Part C and the HIPAA Rules. You acknowledge that DICOM objects carry identifiers in the header and may carry burned-in annotation in pixel data, and that any de-identification workflow must address both.

B.4.8 Clinical escalation remains yours. Nothing in the Platform — including worklist ordering, notifications, or any AI Feature — relieves you of your own obligations to review every Study within your turnaround-time policies and to identify and escalate urgent or critical findings under your own protocols.
B.4.9 Not a substitute for verification against source. You will not rely on the Platform as the sole record of a Study’s existence, completeness or integrity. A Subscriber will verify against its acquisition systems that Studies transmitted to the Platform were received completely and accurately, and will reconcile counts and content periodically.

B.4.10 Complaint, malfunction and adverse-event cooperation. You will notify OmniPACS promptly, and in any event within two (2) Business Days, of any suspected malfunction, image-integrity defect, patient-misidentification event, data-loss event, or any event in which the Platform may have contributed to or been associated with patient harm or a near miss. You will cooperate reasonably with OmniPACS’ investigation, including by providing relevant identifiers, logs and timelines, and you acknowledge that OmniPACS may be required to report such events to a regulatory authority. You will also make any report required of you, as a user or purchaser of a medical device, to the manufacturer and to the competent authority having jurisdiction. Reports go to support@omnipacs.com with the subject line “URGENT — PATIENT SAFETY,” and may also be made by telephone to 813-590-0846. The clinical-safety and intended-use limitations this Section supports are in Part A, Section A.9.

B.4.11 Cybersecurity materials. On written request under Section B.9.14, and to the extent such materials exist, OmniPACS will make available under a non-disclosure agreement (a) a software bill of materials for the Platform components OmniPACS supplies, (b) a description of its vulnerability-reporting process, and (c) a description of its security-patch and end-of-support practices. OmniPACS does not represent that a software bill of materials or a published vulnerability disclosure policy exists, and OmniPACS commits to no patch cadence and to no remediation timeframe. Suspected vulnerabilities are reported to support@omnipacs.com with the subject line “SECURITY.”


B.5 CUSTOMER DATA, DICOM AND METERING

B.5.1 Customer Data — ownership and limited licence to OmniPACS

B.5.1.1 Ownership — see Part A, Section A.7. Ownership of Customer Data is stated in Part A, Section A.7: as between the parties, the Subscriber (and, as to a Patient’s or Individual’s own data under Part D, that Patient or Individual) owns and retains all right, title and interest in and to Customer Data, including all Studies, images, reports and metadata, and OmniPACS acquires no ownership interest in Customer Data. That provision is not restated here. This Section B.5.1 states the licence granted to OmniPACS and the limits on OmniPACS’ use.

B.5.1.2 Limited licence to OmniPACS. You grant OmniPACS and its subprocessors a non-exclusive, worldwide licence to host, copy, transmit, store, cache, index, compress, transcode, render, back up and display Customer Data solely to the extent necessary to provide, secure, support, monitor and maintain the Platform for you and as permitted by Part C. This licence terminates on deletion or return of the Customer Data in accordance with Section B.9.18 and Part C.

B.5.1.3 No other use. OmniPACS will not use, access, disclose or process Customer Data for any other purpose, including marketing, resale, benchmarking against third parties, or model training, except as expressly permitted by Part C or by a separate written agreement with you. OmniPACS does not use Customer Data or PHI to train artificial intelligence or machine-learning models (Section B.9.21.1).

B.5.1.4 Aggregated service data. OmniPACS may compile and use aggregated technical and operational metrics about the performance and use of the Platform (for example, request latency, ingestion throughput, error rates, feature-usage counts) provided such metrics do not contain PHI, do not identify you or any individual, and are not derived from image pixel data.

B.5.1.5 PHI is governed by Part C. Where Section B.1.3 applies, the parties’ obligations with respect to the use, disclosure, safeguarding, breach notification, return and destruction of PHI are set out exclusively in Part C, which controls over the rest of this Agreement as to PHI under Part E, Section E.1. Nothing in these Terms is intended to, and nothing will be construed to, permit a use or disclosure of PHI that Part C or the HIPAA Rules do not permit.

B.5.1.6 Privacy law other than HIPAA. Where Customer Data includes personal data subject to a comprehensive state privacy law, each party will comply with that law as it applies to it, and the parties will execute a data processing addendum where that law requires one. The Platform is offered for use in the United States only. OmniPACS does not offer the Platform for the processing of personal data subject to non-US data protection law, and makes no representation regarding compliance with any non-US data protection law.

B.5.1.7 Scope of the data OmniPACS holds. OmniPACS holds Customer Data only on behalf of a Covered Entity or a Business Associate of a Covered Entity, as a Business Associate under Part C. A Patient’s or Individual’s access arises only through a health care provider relationship, and imaging and related records a Patient or Individual uploads into that access are received and held as PHI under Part C. OmniPACS does not offer a standalone, patient-controlled or direct-to-individual account, and holds no data for a Patient or Individual otherwise than as Customer Data held under Part C. See Part C, Section C.6 and Part D.

B.5.2 Data access, portability and non-interference

B.5.2.1 Standing export right. At any time while your access is active, and during the post-termination retrieval window in Section B.9.18.4, a Subscriber may retrieve and export all of its Customer Data, including:

    (a) all Studies in unmodified DICOM Part 10 format, preserving the original transfer syntax and the complete DICOM header, without transcoding, re-compression or tag stripping;
    (b) a machine-readable manifest or index sufficient to reconstitute the archive, including patient identifiers, accession numbers, Study Instance UIDs, study dates, modalities, institution names and study descriptions;
    (c) attached reports and documents in their stored formats; and
    (d) worklist, sharing and audit metadata to the extent exportable.

A Patient’s or Individual’s own download and export rights are described in Part D.

B.5.2.2 No punitive export fees. OmniPACS will not charge a fee for standard self-service export or for a single standard bulk DICOM export per account in any twelve (12) month period. Fees may be charged only for extraordinary, defined services — for example, physical media production, forensic reconstruction, custom-format transformation, or repeated full-archive extractions — and only at cost-based rates disclosed in advance in writing.

B.5.2.3 Interoperability. OmniPACS supports the interfaces described in its Documentation and in its DICOM Conformance Statement, each of which is available from OmniPACS on request at support@omnipacs.com. OmniPACS does not warrant support for any particular interface, transaction, transfer syntax or integration profile except as stated in the Documentation or in an Order Form.

B.5.2.4 Non-interference covenant (information blocking). OmniPACS acknowledges that a Subscriber may be subject to the information blocking provisions of 45 CFR Part 171 and that OmniPACS may itself be a health information network or health information exchange for those purposes. OmniPACS will not engage in any practice that it knows or should know is likely to interfere with, prevent, or materially discourage the access, exchange or use of EHI, and will not impose unreasonable technical, contractual, procedural or fee-based barriers to lawful access, exchange or use of Customer Data. OmniPACS will cooperate reasonably with a Subscriber’s own compliance under 45 CFR Part 171 and will provide information the Subscriber reasonably requires to respond to an information blocking inquiry or complaint.

B.5.2.5 No kill switch. OmniPACS will not, under any circumstances — including any payment dispute, commercial disagreement, expiry of a term, or termination — block, disable, encrypt against you, throttle to unusability, degrade, or terminate the ability of a Subscriber or a Covered Entity to access, retrieve or export Customer Data, including PHI, except (i) as required by law or by a governmental order, (ii) as a temporary and narrowly scoped measure genuinely necessary to contain an active security incident, or (iii) after the expiry of the post-termination retrieval window in Section B.9.18.4, in accordance with Part C’s return-or-destroy provisions. No such measure will be used as leverage in a commercial dispute. This Section controls over any conflicting provision anywhere in the contract stack (Part E, Section E.1).

B.5.2.6 Retention; no silent deletion. OmniPACS will retain Customer Data for the duration of the subscription and for any longer retention period stated in an Order Form. Absent an Order Form specifying a longer period, OmniPACS has no obligation to retain Customer Data beyond the Subscription Term, subject to the post-termination retrieval window in Section B.9.18.4. During the Subscription Term, OmniPACS will not purge, tier out, archive to an inaccessible state, or destroy Customer Data without at least thirty (30) days’ prior written notice and an opportunity to export. For free and legacy access, Section B.2.1(c) applies. Your own retention determination is your responsibility under Section B.4.5, and extended retention is available only as ordered under Section B.9.23.1.

B.5.2.7 Individual access support. OmniPACS will make Customer Data available to a Subscriber as and when necessary for the Subscriber to satisfy its obligations to provide individuals with access to PHI under 45 CFR § 164.524, and to respond to amendment, accounting-of-disclosures and records-request obligations, in accordance with Part C. OmniPACS will not charge a Subscriber for standard support of individual access requests, and will not charge a Patient or Individual for access to their own images under these Terms.

B.5.2.8 Migration off the Platform. OmniPACS will not impose contractual or technical restrictions on a Subscriber’s right to migrate Customer Data to another platform, and will provide reasonable cooperation with a Subscriber-directed migration at OmniPACS’ then-current professional-services rates for any effort beyond standard export.


B.6 WARRANTIES AND DISCLAIMERS

This Section states the warranties and disclaimers applicable to professional and organizational users. Part A carries no warranty disclaimer of its own. The warranties and disclaimers applicable to a patient or individual are in Part D, Section D.6.

B.6.1 Mutual warranties. Each party warrants that it has the legal power and authority to enter into these Terms and that these Terms are duly authorized.

B.6.2 The only warranties OmniPACS gives. OmniPACS warrants that, during the Subscription Term of an account for which Fees are paid:

    (a) OmniPACS will provide the Platform and support with reasonable skill and care, using appropriately qualified personnel; and
    (b) OmniPACS will not materially decrease the core functionality of the Platform — the ingestion, storage, retrieval, viewing and export of Customer Data — during a paid Subscription Term.

THESE ARE THE ONLY WARRANTIES OMNIPACS MAKES. They are made only to a Subscriber paying Fees for the affected account, and they do not apply to free, evaluation, trial, pilot, sandbox, demonstration, legacy, share-link, view-only or pre-release access. Nothing in this Section B.6.2 limits OmniPACS’ obligations under Part C or the PHI access floor in Section B.9.16.4, each of which applies to all Customer Data OmniPACS holds, including data held in a free or legacy account.

B.6.3 Remedy for warranty breach. For a breach of Section B.6.2, OmniPACS will use commercially reasonable efforts to correct the non-conformity; if it does not do so within thirty (30) days of your written notice describing the non-conformity in reasonable detail, you may terminate the affected Order Form and receive a pro-rata refund of prepaid, unused Fees for the terminated period. THIS IS YOUR SOLE AND EXCLUSIVE REMEDY FOR BREACH OF SECTION B.6.2. It does not limit remedies for a breach of Part C or for any claim within Section B.7.4.

B.6.4 Your warranties. You warrant that: (a) you have all authority, rights and authorizations necessary for your use of the Platform and for every upload, disclosure and share of Customer Data; (b) you will comply with all laws applicable to your use of the Platform, including HIPAA, state medical-records and privacy law, professional licensure requirements and medical-record retention requirements; (c) you will comply with Part A, Sections A.4 through A.9 and Sections B.3 and B.4 of this Part; and (d) all information you provide to OmniPACS, including billing information and Institution Name configuration, is accurate.

B.6.5 Disclaimer. EXCEPT FOR THE LIMITED EXPRESS WARRANTIES IN SECTION B.6.2 AND OMNIPACS’ OBLIGATIONS UNDER PART C, THE PLATFORM — INCLUDING ALL LOCAL COMPONENTS, DOCUMENTATION, SUPPORT, AI FEATURES AND ANY OTHER MATERIAL OR SERVICE OMNIPACS PROVIDES — IS PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTIES, CONDITIONS OR REPRESENTATIONS OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY OR OTHERWISE. OMNIPACS DISCLAIMS ALL IMPLIED WARRANTIES AND CONDITIONS, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, SYSTEM INTEGRATION AND QUIET ENJOYMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING, COURSE OF PERFORMANCE OR USAGE OF TRADE. OMNIPACS DOES NOT WARRANT THAT THE PLATFORM WILL BE UNINTERRUPTED, TIMELY, SECURE OR ERROR-FREE, THAT ANY DEFECT WILL BE CORRECTED, THAT CUSTOMER DATA WILL NOT BE LOST, ALTERED OR CORRUPTED, THAT THE PLATFORM WILL MEET YOUR REQUIREMENTS, OR THAT THE PLATFORM WILL MEET ANY REGULATORY, ACCREDITATION, LICENSURE OR PAYER REQUIREMENT APPLICABLE TO YOU. OMNIPACS MAKES NO WARRANTY REGARDING ANY THIRD-PARTY PRODUCT, INCLUDING THE CHILI VIEWER, OR REGARDING BETA, TRIAL, PREVIEW, PILOT, FREE, LEGACY OR PRE-RELEASE FEATURES AND ACCOUNTS.

B.6.6 Supported Browsers. The limited warranties in Section B.6.2, the availability target in Section B.10, and OmniPACS’ support obligations apply only to access from a Supported Browser, as defined in Part A, Section A.4.6, in a configuration meeting the requirements of that Section. OMNIPACS MAKES NO WARRANTY OF ANY KIND AS TO THE OPERATION OF THE PLATFORM ON ANY BROWSER, BROWSER VERSION, BROWSER ENGINE OR OPERATING SYSTEM THAT IS NOT A SUPPORTED BROWSER, AND HAS NO OBLIGATION TO INVESTIGATE, REPRODUCE, CORRECT OR WORK AROUND ANY ISSUE THAT DOES NOT OCCUR ON A SUPPORTED BROWSER. OmniPACS may require a Subscriber to reproduce a reported issue on a Supported Browser before OmniPACS accepts it for investigation. The Subscriber is responsible for deploying and maintaining Supported Browsers across its workforce, and for the effect of any extension, enterprise browser policy, content filter, proxy or inspection appliance it deploys. This Section does not limit Section B.9.16.4, and is never a basis for refusing, delaying or conditioning an individual’s access to their own health information under Part A, Section A.4.6(e).

OMNIPACS MAKES NO WARRANTY, REPRESENTATION OR GUARANTEE REGARDING THE CLINICAL ACCURACY, DIAGNOSTIC ADEQUACY OR CLINICAL SUFFICIENCY OF ANY IMAGE, RENDERING, MEASUREMENT, AI OUTPUT OR REPORT, OR REGARDING ANY CLINICAL OUTCOME. THE PLATFORM DOES NOT PROVIDE MEDICAL ADVICE, DIAGNOSIS OR TREATMENT AND IS NOT A SUBSTITUTE FOR THE CLINICAL JUDGMENT OF A LICENSED PRACTITIONER.

B.6.7 No other warranties; no warranty by statement. NO ORAL OR WRITTEN STATEMENT, INFORMATION OR ADVICE GIVEN BY OMNIPACS OR ANY OF ITS EMPLOYEES, AGENTS OR RESELLERS CREATES A WARRANTY OR OTHERWISE EXPANDS THE SCOPE OF SECTION B.6.2. The availability target in Section B.10 is a target and not a warranty. Nothing in this Section B.6 limits OmniPACS’ obligations under Part C, the non-interference covenant in Section B.5.2.4, the no-kill-switch covenant in Section B.5.2.5, or the PHI access floor in Section B.9.16.4.


B.7 LIMITATION OF LIABILITY

This Section states the limitation of liability applicable to professional and organizational users. Part A carries no liability cap of its own. The limits applicable to a patient or individual are in Part D, Section D.7, and are different.

B.7.1 Exclusion of indirect damages. EXCEPT AS PROVIDED IN SECTION B.7.4, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST BUSINESS OPPORTUNITY, LOSS OF GOODWILL, BUSINESS INTERRUPTION, THE COST OF SUBSTITUTE SERVICES, OR THE LOSS OR CORRUPTION OF DATA (EXCEPT TO THE EXTENT SECTION B.7.3(a) TREATS A COST AS DIRECT DAMAGES), WHETHER IN CONTRACT, TORT, STRICT LIABILITY OR OTHERWISE, AND WHETHER OR NOT THE PARTY WAS ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

B.7.2 General cap. EXCEPT AS PROVIDED IN SECTIONS B.7.2A, B.7.3 AND B.7.4, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS WILL NOT EXCEED THE TOTAL FEES ACTUALLY PAID BY THE SUBSCRIBER TO OMNIPACS IN RESPECT OF THE RELEVANT ACCOUNT IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO THE CLAIM.

B.7.2A Cap where no Fees are paid. WHERE NO FEES HAVE BEEN PAID IN RESPECT OF THE RELEVANT ACCOUNT IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO THE CLAIM — INCLUDING FREE, EVALUATION, TRIAL, PILOT, SANDBOX, DEMONSTRATION, LEGACY, SHARE-LINK AND VIEW-ONLY ACCESS — OMNIPACS’ TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS WILL NOT EXCEED ONE THOUSAND US DOLLARS ($1,000) IN THE AGGREGATE. The limits applicable to a Patient or Individual are stated in Part D, Section D.7.

B.7.3 PHI cap. FOR ALL CLAIMS ARISING FROM A BREACH OF UNSECURED PHI CAUSED BY OMNIPACS’ FAILURE TO MEET ITS OBLIGATIONS UNDER PART C, OMNIPACS’ TOTAL AGGREGATE LIABILITY WILL NOT EXCEED THE LESSER OF (i) THREE (3) TIMES THE TOTAL FEES ACTUALLY PAID BY THE SUBSCRIBER TO OMNIPACS IN RESPECT OF THE RELEVANT ACCOUNT IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO THE CLAIM AND (ii) FIVE HUNDRED THOUSAND US DOLLARS ($500,000). THIS IS THE ONLY CAP IN THESE TERMS THAT EXCEEDS THE CAP IN SECTION B.7.2, AND NO OTHER CLAIM, THEORY OR CATEGORY CARRIES A HIGHER CAP.

    (a) Breach-notification and regulatory-response costs are direct damages. The parties agree that costs of investigation, forensic analysis, notification of individuals and regulators, call-center support, credit monitoring or identity-protection services where reasonably provided, and reasonable regulatory response costs, arising from a security incident or breach of unsecured PHI caused by a party’s breach of these Terms or of Part C, are direct damages and are not excluded by Section B.7.1. Such costs are subject to the cap in this Section B.7.3.

B.7.4 Uncapped and unexcluded matters. The limitations in Sections B.7.1, B.7.2, B.7.2A and B.7.3 do not apply to:

    (a) death or bodily injury caused by a party’s negligence;
    (b) a party’s gross negligence, willful misconduct or fraud;
    (c) each party’s indemnification obligations under Section B.8 and Section B.9.19;
    (d) a Subscriber’s obligation to pay Fees, including accrued overage fees; and
    (e) any liability that cannot be limited or excluded under applicable law.

B.7.5 All caps are aggregate. MULTIPLE CLAIMS DO NOT ENLARGE A CAP. THE CAPS IN SECTIONS B.7.2, B.7.2A AND B.7.3 ARE AGGREGATE AND NOT PER-CLAIM, AND APPLY ACROSS ALL CLAIMS, ALL EVENTS AND ALL THEORIES OF LIABILITY, WHETHER IN CONTRACT, TORT, STATUTE OR OTHERWISE. AMOUNTS PAID UNDER SECTION B.7.2 OR SECTION B.7.2A COUNT TOWARD THE CAP IN SECTION B.7.3, AND THE CAP IN SECTION B.7.3 IS NOT ADDITIONAL TO THEM.

B.7.6 Basis of the bargain; failure of essential purpose. The parties agree that the allocation of risk in this Section B.7, together with the limited warranties in Section B.6, the indemnities and the Fees charged (or the absence of Fees), is an essential element of the basis of the bargain. THE EXCLUSIONS AND LIMITS IN THIS SECTION B.7 APPLY EVEN IF A LIMITED REMEDY STATED IN THESE TERMS FAILS OF ITS ESSENTIAL PURPOSE.

B.7.7 Limitations period. Except for claims for non-payment and for indemnified claims, neither party may bring a claim arising out of or relating to these Terms more than one (1) year after the claim accrued, and any such claim not brought within that period is permanently barred, in each case to the maximum extent permitted by applicable law.


B.8 INDEMNITY

B.8.1 You will defend, indemnify and hold harmless OmniPACS and its officers, directors, employees and agents against any third-party claim, and all damages, losses, liabilities, settlements, penalties, costs and reasonable attorneys’ fees arising from or relating to:

    (a) Customer Data you upload, generate, share or disclose, including its accuracy, quality, integrity and legality and the means by which you acquired it;
    (b) any allegation that you lacked the authority, right, consent or authorization to upload, store, use, disclose, transmit or share any Customer Data or PHI, or that a share or disclosure you initiated was impermissible;
    (c) your or your practitioners’ clinical use of the Platform and all diagnoses, interpretations, reports, prioritization decisions and patient-management decisions made by or on behalf of you;
    (d) patient misidentification, record merging, overlay or mismatching attributable to you or your environment;
    (e) your failure to use diagnostic-grade, calibrated displays and validated reading environments as required by Part A, Section A.9, your use of lossy-compressed images for Primary Diagnostic Interpretation contrary to Part A, Section A.9, or your diagnostic use of a non-diagnostic viewing path contrary to Part A, Section A.9;
    (f) your use of an AI Feature without the practitioner review required by Part A, Section A.9, or your failure to make a disclosure for which you are responsible under Section B.9.21;
    (g) your breach of Part A, Sections A.4 through A.9 and Sections B.3 and B.4 of this Part, including the licence limits, the Permitted Medical Purposes restriction, the prohibited uses, the intellectual-property, reverse-engineering and notices restrictions, the credential rules and the AUP;
    (h) upload of PHI before Part C (the BAA) was in effect (Section B.1.3(c)); and
    (i) your own environment, including any security incident originating in it.

B.8.2 Procedure (mutual). The indemnified party will give the indemnifying party prompt written notice of the claim (though delay relieves the indemnifying party only to the extent it is prejudiced), reasonable cooperation at the indemnifying party’s expense, and sole control of the defense and settlement — provided that the indemnifying party will not settle any claim in a way that imposes a non-monetary obligation, an admission of liability, or an unindemnified payment on the indemnified party without its written consent. The indemnified party may participate at its own expense with its own legal representatives.

B.8.3 Patients and Individuals — no indemnity. This Section B.8 does not apply to a Patient or Individual acting in that capacity, and no Patient or Individual owes OmniPACS any indemnity. The obligations that apply to a Patient or Individual — providing accurate identity information, not misusing the Platform, and not accessing another person’s records without authority — are stated in Part D.

B.8.4 OmniPACS’ indemnities. OmniPACS’ indemnification obligations, including its intellectual-property indemnity, are set out in Section B.9.19.


B.9 SUBSCRIPTION TERMS

This Section B.9 applies only to Subscribers. You are a Subscriber if you hold an account under an Order Form, or if Section B.1.2 has made you one. Section B.9 is layered on top of Part A and the remainder of this Part B: Part A continues to apply to you in full, and where Section B.9 conflicts with Part A, Section B.9 controls for Subscribers (Part E, Section E.1).

Note on plan names and prices. This Section deliberately does not name subscription plans or state prices. Wherever it refers to “the subscription plan applicable to your account,” it means the plan identified in the Order Form for your account or, where there is none, the plan applicable to your account in OmniPACS’ then-current published price list. Plan names, base subscription fees, included volumes, overage rates and storage rates live in the Order Form and the price list so that they can change under Section B.9.10 without re-papering these Terms.

B.9.1 APPLICATION OF THIS SECTION

B.9.1.1 Who this Section binds. Section B.9 binds (a) the entity or individual in whose name a subscription account is held, (b) any person who becomes a Subscriber under Section B.1.2, and (c) jointly and severally, any other person who is a Subscriber in respect of the same account.

B.9.1.2 Authorized Clinical Users. An Authorized Clinical User is bound by Part A and this Part B directly and must comply with Section B.9 as it applies to the account they use, but the Subscriber owes the Fees unless Section B.1.2(c) makes that user responsible for them.

B.9.1.3 Free and legacy accounts. Section B.9 does not apply to a free, evaluation, trial or legacy account unless and until Section B.1.2 is triggered or a plan is selected or assigned. See Section B.2.1.

B.9.1.4 Affiliates. An Order Form may extend a subscription to named Affiliates of the Subscriber. The Subscriber remains responsible for its Affiliates’ compliance and for all Fees attributable to them, and each Affiliate that accesses the Platform is bound by Part A and this Part B directly.

B.9.2 ORDER FORMS, PLANS AND PLAN CHANGES

B.9.2.1 Order Forms. Subscriptions are ordered by Order Form. Each Order Form identifies the subscription plan applicable to the account, the base subscription fee, the Included Volume, the overage rate, any storage entitlement and rate, the Initial Term, the Billing Period, the sites or data sources covered, and any negotiated deviation from these Terms. An Order Form controls over Part A and over this Section B.9 where it expressly identifies the provision it is amending (Part E, Section E.1).

B.9.2.2 Self-serve accounts. Where an account is created through self-serve signup rather than a countersigned Order Form, the plan selected at signup, together with the base subscription fee, Included Volume and overage rate applicable to that plan in OmniPACS’ then-current published price list as at the date of signup, constitute the Order Form for that account, and OmniPACS will send the Subscriber a retainable acknowledgment of those terms under Part E, Section E.4.

B.9.2.3 Plan changes. A Subscriber may move to a plan with a higher Included Volume at any time, effective at the start of the next Billing Period or, at OmniPACS’ discretion, immediately with the base subscription fee prorated for the remainder of the Billing Period. A move to a plan with a lower Included Volume takes effect at the start of the next Renewal Term unless OmniPACS agrees otherwise in writing.

B.9.2.4 No unilateral upward reassignment. OmniPACS may propose but may not unilaterally move a Subscriber to a plan with a higher base subscription fee during a Subscription Term. Volume above the Included Volume is handled as overage under Section B.9.7, not by forced plan reassignment.

B.9.2.5 Multiple sites and data sources. Where an Order Form identifies multiple sites or data sources, Studies are attributed among them under Section B.9.6.6. Unless the Order Form states otherwise, the Included Volume is a single pooled entitlement for the account, not a per-site entitlement.

B.9.2.6 Discontinued features. If OmniPACS discontinues or materially degrades a feature that the Order Form expressly identifies as material to the Subscriber, or that is necessary for the core functions of ingestion, storage, retrieval, viewing or export, the Subscriber may terminate the affected Order Form on written notice given within thirty (30) days of OmniPACS’ notice under Part A, Section A.13, and the post-termination retrieval window in Section B.9.18.4 applies in full. No refund or proration of prepaid Fees arises from a termination under this Section B.9.2.6 (Section B.9.15.6).

B.9.3 ACTIVE SUBSCRIPTION AND VALID PAYMENT METHOD

This Section states the Subscriber’s core payment obligations. Read it carefully.

B.9.3.1 Continuous active subscription required. Access to and use of the Platform as a Subscriber requires, at all times, an active subscription under a current Order Form. A Subscriber will maintain an active subscription for the entire period during which its Customer Data is stored in the Platform, other than during the post-termination retrieval window in Section B.9.18.4.

B.9.3.2 Valid payment method required. A Subscriber must at all times maintain a current, valid and chargeable payment method on file with OmniPACS or its billing processor — a credit card, debit card, or ACH/bank debit authorization, or, where OmniPACS has approved invoiced billing in writing, an approved purchase-order and remittance arrangement.

B.9.3.3 Continuing authorization to charge. The Subscriber authorizes OmniPACS and its payment processors (currently Stripe and Maxio/Chargify) to charge the payment method on file, without further authorization, for all Fees when due — including base subscription fees, overage fees, storage fees, true-up amounts, taxes, late charges, and any other amounts owed under these Terms or any Order Form. This is a continuing authorization and remains in effect until all amounts owed are paid in full and the Subscription Term has ended.

B.9.3.4 Keeping the payment method current. The Subscriber will promptly update the payment method on file whenever it expires, is replaced, is cancelled, has insufficient funds or credit, or otherwise becomes invalid. The Subscriber authorizes OmniPACS and its processors to use card-updater and account-verification services to keep the payment method current, and to re-attempt a declined charge.

B.9.3.5 Failure to maintain a payment method is a material breach. Failure to maintain a valid, chargeable payment method on file is a material breach of these Terms and, after notice and the cure period in Section B.9.16.2, permits OmniPACS to suspend new activity under Section B.9.16 and to terminate under Section B.9.18.2 — in each case subject to the absolute preservation of the Subscriber’s access to and export of previously stored Customer Data under Section B.9.16.4 and Section B.5.2.5.

B.9.3.6 Subscription is not free of charge. For the avoidance of doubt, and notwithstanding any prior version of OmniPACS’ terms, a subscription under this Section B.9 is not provided free of charge, and the legacy statement that “subscriptions are provided free of charge and as is” is deleted and of no effect. Free, evaluation, trial and legacy access is a separate arrangement governed by Section B.2.1 and is granted only by written Order Form or express written statement identifying its duration and terms.

B.9.4 FEES GENERALLY

B.9.4.1 What the Subscriber pays. The Subscriber will pay, for each Billing Period, the base subscription fee for the subscription plan applicable to its account as set out in its Order Form or in OmniPACS’ then-current published price list, plus overage fees for Billable Studies in excess of the Included Volume, plus any storage, professional services, media-production or other fees stated in the Order Form.

B.9.4.2 Currency. All Fees are stated and payable in US dollars.

B.9.4.3 Non-refundable. Except as expressly stated in these Terms, Fees are non-refundable and payment obligations are non-cancellable. Amounts already invoiced or charged for a Billing Period that has begun are not refunded on cancellation (Section B.9.15.6).

B.9.4.4 Minimum commitment. The Subscriber pays, for each Billing Period, the greater of (i) the base subscription fee for the plan applicable to its account, or (ii) that base subscription fee plus overage fees for Billable Studies above the Included Volume. There is no reduction, credit or refund of the base subscription fee if actual usage is below the Included Volume.

B.9.5 THE BILLING UNIT — BILLABLE STUDY

B.9.5.1 One Billable Study = one unique DICOM Study Instance UID. A “Billable Study” is one Study — that is, one unique value of the DICOM attribute Study Instance UID (0020,000D) — first ingested into the Subscriber’s tenant during the Billing Period, determined by the Platform’s recorded ingestion timestamp (import time) for that Study.

B.9.5.2 Re-transmission is not a new Study. Re-transmitting, re-sending, resuming, completing or adding instances to a Study already ingested under the same Study Instance UID does not create an additional Billable Study, regardless of how many DICOM objects, series, instances or transmissions are involved and regardless of the Billing Period in which they arrive.

B.9.5.3 Corrections and amendments are not a new Study. Correcting demographics, correcting DICOM tags, adding a report, adding a corrected or addended report, or adding key images to a Study under the same Study Instance UID does not create an additional Billable Study.

B.9.5.4 Delete-and-reupload does create a new Study. If a Study is deleted from the tenant and subsequently re-ingested, the re-ingestion is a new Billable Study, whether or not the Study Instance UID is the same. The Subscriber should use correction and amendment functions rather than delete-and-reupload where possible.

B.9.5.5 Retrieval, viewing, sharing and export are not metered. Retrieval, viewing, worklist access, search, sharing to external recipients, and standard export of Studies already ingested are not additional Billable Studies and carry no per-event charge. Storage is charged only as stated in the Order Form.

B.9.6 COUNTING RULES AND METERING MECHANICS

B.9.6.1 Import-time basis. Billable Study counts are determined by the Platform’s recorded import time for each Study — the timestamp at which the Study was first ingested into the tenant — and not by study date, acquisition date, accession date, report date or any other date in the DICOM header.

B.9.6.2 Modalities excluded from billing. The following DICOM Modality (0008,0060) values are non-billable and are excluded from Billable Study counts (matched case-insensitively):

Excluded modality codeMeaning
SRStructured Report
OTOther
PRPresentation State
DOCDocument
DODocument (legacy/variant code)
SCSecondary Capture

B.9.6.3 Blank or absent modality values are counted. A Study whose Modality attribute is null, empty or missing is a Billable Study. The Subscriber is responsible for correct modality tagging by its modalities and routers; OmniPACS does not infer modality from other attributes.

OmniPACS may change the excluded-modality list only as provided in Section B.9.10.4.

B.9.6.4 The billing window — America/New_York. Billable Study counts are computed on a month-to-date basis for each calendar month, with the beginning and end of the month determined in the America/New_York time zone (Eastern Time, observing daylight saving time), regardless of the time zone of the Subscriber’s facilities, the ingesting device, or the hosting region. A Study ingested at 11:45 p.m. Eastern on the last day of a month is counted in that month; a Study ingested at 12:15 a.m. Eastern on the first day of the following month is counted in the following month.

B.9.6.5 Deduplication scope. Uniqueness of a Study Instance UID is evaluated within the Subscriber’s tenant. The same Study Instance UID ingested into two different tenants is a Billable Study in each.

B.9.6.6 Attribution. A Study is attributed to the Subscriber’s tenant and, where an Order Form identifies multiple sites or data sources, to a site or data source, on the basis of the ingesting data source and the DICOM Institution Name (0008,0080) value, as configured in the Order Form or in the Platform. The Subscriber is responsible for the correctness of its Institution Name configuration and for notifying OmniPACS of changes.

B.9.6.7 No circumvention. Manipulating Study Instance UIDs, modality codes, institution names or import timestamps for the purpose of reducing Billable Study counts is prohibited under Part A, Section A.6 and is a material breach.

B.9.7 CHARGES ABOVE THE BASE SUBSCRIPTION — OVERAGE

This Section states the Subscriber’s obligations for charges above the base subscription. It is the provision most likely to produce a billing surprise, and it is written to be read before that happens.

B.9.7.1 Overage accrues above the Included Volume. Billable Studies in excess of the Included Volume for the subscription plan applicable to the account in a Billing Period are charged at the overage rate stated in the Order Form or the then-current published price list, per Billable Study, with no free grace band and no soft cap unless the Order Form states one.

B.9.7.2 Ingestion is never blocked at a commercial threshold. OmniPACS does not block ingestion when the Included Volume is exceeded. Studies continue to be accepted and stored, and overage fees accrue. The Subscriber acknowledges that this design is deliberate — refusing clinical images at a commercial threshold would be unacceptable — and that the Subscriber is therefore responsible for monitoring and controlling its own volume.

B.9.7.3 Usage visibility. OmniPACS will make the account’s month-to-date Billable Study count available to the Subscriber’s account administrators in the Platform where that function is available and, in any event, on request at support@omnipacs.com. The Subscriber remains responsible for monitoring and controlling its own volume, and OmniPACS does not warrant the availability, timeliness or accuracy of any in-product usage display.

B.9.7.4 Threshold notices. OmniPACS will use reasonable efforts to notify the Subscriber’s administrators by email when the account’s month-to-date Billable Study count reaches eighty percent (80%) and one hundred percent (100%) of the Included Volume. These notices are a courtesy; failure to send a threshold notice does not waive overage fees or relieve the Subscriber of the obligation to monitor its own usage.

B.9.7.5 Persistent overage. If actual volume consistently exceeds the Included Volume, either party may propose a plan change under Section B.9.2.3. OmniPACS may propose but cannot unilaterally impose a higher-priced plan during a Subscription Term (Section B.9.2.4).

B.9.7.6 Other charges above the base subscription. In addition to overage fees, the following may be charged above the base subscription fee, and only where the Order Form or published price list states them: storage above any included storage entitlement (Section B.9.12.1); professional services and implementation work (Section B.9.11); physical media production and extraordinary export services (Section B.9.12.2 and Section B.5.2.2); taxes and governmental fees (Section B.9.9.4); late charges (Section B.9.9.3); and any reactivation fee (Section B.9.16.6). No other charge above the base subscription fee is payable unless it is stated in an Order Form or in the published price list in force when it is incurred.

B.9.8 INVOICING, TRUE-UP AND USAGE RECORDS

B.9.8.1 Monthly invoicing in arrears. Overage fees and any other usage-based charges are invoiced monthly in arrears, promptly after the close of each Billing Period, based on the final Billable Study count for that Billing Period.

B.9.8.2 Base subscription fees. Base subscription fees are invoiced in advance, at the start of each Billing Period.

B.9.8.3 Invoice content. Each invoice will state the Billing Period, the Included Volume, the Billable Study count, the number of Billable Studies over the Included Volume, the overage rate applied, and the resulting overage fee.

B.9.8.4 True-up and reconciliation. OmniPACS will reconcile Billable Study counts after the close of each Billing Period. Where a count is subsequently found to be incorrect — because of a metering defect, a data-source misconfiguration, a duplicate-UID condition, a late-arriving ingestion record, or a correction of modality or institution attribution — OmniPACS will issue a true-up on the next invoice, being an additional charge or a credit as applicable, with a written explanation of the adjustment.

B.9.8.5 Look-back limit. Neither party may raise a true-up for a Billing Period more than ninety (90) days after the close of that Billing Period, except in the case of fraud, deliberate metering circumvention under Part A, Section A.6, or a legal or regulatory requirement.

B.9.8.6 Undercharges. Where OmniPACS undercharged, OmniPACS may recover the shortfall by true-up within the look-back period. OmniPACS will not apply late charges to a true-up undercharge for any period before the true-up invoice date.

B.9.8.7 Overcharges. Where OmniPACS overcharged, OmniPACS will credit the excess on the next invoice or, at the Subscriber’s election, refund it within thirty (30) days.

B.9.8.8 Usage records. OmniPACS will retain per-Study metering records sufficient to substantiate each invoice for at least twenty-four (24) months and will make a per-Study detail report available to the Subscriber on request at no charge. Such records exclude PHI to the extent practicable and are made available in accordance with Part C where they do not.

B.9.8.9 Negotiated counting exceptions. OmniPACS may agree, in a specific Order Form, to a different counting basis for a specific Subscriber or legacy data source. Any such exception applies only to the Order Form in which it is stated and is not a general term of these Terms.

B.9.9 PAYMENT TERMS, TAXES, LATE CHARGES AND DISPUTES

B.9.9.1 Payment due dates.
    (a) Card and ACH accounts. For accounts with a card or bank debit on file, all Fees are charged to the payment method on the invoice date, under the continuing authorization in Section B.9.3.3.
    (b) Invoiced accounts. Where OmniPACS has approved invoiced billing in writing, payment is due net thirty (30) days from the invoice date.

B.9.9.2 Failed payment cure. If a charge to the payment method on file is declined or reversed, OmniPACS will notify the Subscriber’s billing contact and the Subscriber will cure the failure — by updating the payment method or paying by another approved means — within ten (10) Business Days of that notice. OmniPACS may re-attempt the charge during that period.

B.9.9.3 Late charges. Overdue amounts accrue interest from the due date until paid at the lesser of (i) one and one-half percent (1.5%) per month, or (ii) the maximum rate permitted by applicable law. OmniPACS may also recover its reasonable costs of collection, including reasonable attorneys’ fees and court costs. No interest or late charge accrues on any amount disputed in good faith in accordance with Section B.9.9.6, for so long as the Subscriber is cooperating in the dispute-resolution process and has paid all undisputed amounts.

B.9.9.4 Taxes. All Fees are exclusive of sales, use, excise, gross receipts, value-added, withholding and similar taxes and of any governmental fees or surcharges. The Subscriber is responsible for all such amounts, other than taxes on OmniPACS’ net income. Where the Subscriber claims an exemption, it will provide a valid exemption certificate before the applicable invoice date; OmniPACS will apply the exemption prospectively from receipt. If OmniPACS is required to collect a tax the Subscriber has not paid, the Subscriber will reimburse OmniPACS on demand.

B.9.9.5 Payment processors; card data never reaches the Platform. Payments are processed by third-party processors (currently Stripe and Maxio/Chargify). The Subscriber’s use of those processors is subject to their terms.

Payment card transactions are processed by Stripe, Inc., a PCI DSS Level 1 certified service provider. OMNIPACS DOES NOT COLLECT, TRANSMIT, PROCESS OR STORE FULL PAYMENT CARD NUMBERS, CARD VERIFICATION VALUES OR MAGNETIC-STRIPE DATA, and cardholder data does not traverse or reside on the Platform. OMNIPACS DOES NOT ITSELF HOLD A PCI DSS ATTESTATION OF COMPLIANCE AND MAKES NO REPRESENTATION THAT IT DOES. OmniPACS receives from Stripe only limited transaction metadata, such as the card brand, the last four digits, the expiration date, the billing contact and the transaction result.

B.9.9.6 Disputed charges — thirty (30) day window.
    (a) The Subscriber may dispute an invoice or a charge, in whole or in part, by giving OmniPACS written notice at sales@omnipacs.com within thirty (30) days after the invoice date, stating the amount disputed and the basis for the dispute in reasonable detail.
    (b) The Subscriber will pay all undisputed amounts when due.
    (c) The parties will work in good faith to resolve the dispute within thirty (30) days of the notice. OmniPACS will provide the per-Study metering detail supporting the disputed charge.
    (d) OmniPACS will not suspend or terminate for non-payment of an amount disputed in good faith under this Section while the dispute is being resolved, provided the Subscriber is paying undisputed amounts.
    (e) A charge not disputed within the thirty-day window is deemed accepted for purposes of the billing process only. This deemed acceptance does not waive any other right or remedy the Subscriber may have under these Terms or at law, does not waive any claim arising from fraud or from a systemic metering defect, and does not limit the true-up mechanism in Section B.9.8.4.

B.9.9.7 No set-off by the Subscriber. The Subscriber will not withhold or set off Fees against amounts OmniPACS may owe, except amounts finally determined to be owed or agreed in writing.

B.9.10 PRICE CHANGES

B.9.10.1 Changes at renewal. OmniPACS may change the base subscription fee, Included Volume, overage rate, storage rates and other Fees applicable to a plan effective at the start of a Renewal Term, by giving the Subscriber written notice at least thirty (30) days before the renewal date.

B.9.10.2 Right to reject. If the Subscriber does not accept a price change, it may (a) elect not to renew under Section B.9.15.4, or (b) terminate for convenience under Section B.9.15.5, in either case by notice given before the price change takes effect. The Subscriber will not be charged the increased Fees for any period after the effective date of that termination or non-renewal. No penalty or early-termination charge applies to a termination or non-renewal made in response to a price increase.

B.9.10.3 Mid-term changes. OmniPACS will not increase Fees during an Initial Term or a Renewal Term, except: (a) where the Subscriber changes its plan or adds services; (b) for pass-through increases in taxes or governmental fees; (c) for a third-party pass-through cost that the Order Form expressly identifies as passed through; or (d) as the parties otherwise agree in writing.

B.9.10.4 Material changes to billing mechanics. A change to the definition of a Billable Study in Section B.9.5, to the excluded-modality list in Section B.9.6.2, or to the billing window in Section B.9.6.4 is a material change and will be made only at renewal, on at least thirty (30) days’ notice, with the right to reject in Section B.9.10.2 and the re-acceptance mechanic in Part A, Section A.14.

B.9.10.5 Published price list. Where these Terms refer to OmniPACS’ then-current published price list, that list is the price list in force at the relevant time, a copy of which is available on request at sales@omnipacs.com. A change to the published price list does not alter the Fees for an account with a countersigned Order Form during that Order Form’s then-current term.

B.9.11 IMPLEMENTATION, DATA MIGRATION AND PROFESSIONAL SERVICES

B.9.11.1 Scope. Implementation, configuration, interface build, training and legacy-data migration are provided only as stated in an Order Form or statement of work, at the rates stated there. Nothing in these Terms obligates OmniPACS to perform professional services not so ordered.

B.9.11.2 Cooperation. The Subscriber will provide timely access to the personnel, credentials, network access, modality inventory, DICOM tag documentation, sample data and decision-makers reasonably required. OmniPACS is not responsible for delay or failure caused by the Subscriber’s failure to do so, and dates in a project plan are estimates unless the Order Form states otherwise.

B.9.11.3 Legacy-data migration. Where OmniPACS migrates Studies from a prior archive:
    (a) the Subscriber is responsible for obtaining the data from the incumbent vendor, for the completeness and accuracy of what it delivers, and for any incumbent-vendor extraction fees;
    (b) the Subscriber is responsible for verifying, promptly after migration, that the legacy data has been migrated properly and completely, including study counts, patient and accession identifiers, series and instance counts, and image integrity, and for reporting discrepancies within thirty (30) days (Section B.4.3);
    (c) the Subscriber will not decommission or delete its source archive until it has completed that verification;
    (d) OmniPACS will migrate Studies in DICOM form, preserving the original transfer syntax where the source permits, and will not apply additional irreversible compression to migrated Studies; and
    (e) unless the Order Form expressly states otherwise, Studies ingested through a migration are Billable Studies and are counted in the Billing Period in which they are ingested.

B.9.11.4 Ownership of deliverables. Configuration, interfaces, templates and documentation produced in professional services are OmniPACS’ property and are licensed to the Subscriber under Part A, Section A.4 for use with the Platform. Customer Data and the Subscriber’s own content remain the Subscriber’s (Part A, Section A.7).

B.9.11.5 Local Components. Installation, operation, patching and decommissioning of OmniRouter, EPS-Pi, UDE and any other Local Component are governed by Part A, Section A.4, Section B.1.4(b) and Section B.3.5 and by the applicable Documentation.

B.9.12 STORAGE, MEDIA AND EXTRAORDINARY SERVICES

B.9.12.1 Storage fees. Storage is charged only where the Order Form or the then-current published price list states a storage entitlement and a storage rate. Where storage is metered, storage is measured as the average of daily peak stored bytes over the Billing Period, unless the Order Form states another basis.

B.9.12.2 Media production and extraordinary export services. Standard self-service export and one standard bulk DICOM export per account in any twelve (12) month period are provided at no charge under Section B.5.2.2. Fees may be charged only for extraordinary, defined services — physical media production (CD/DVD/ISO), forensic reconstruction, custom-format transformation, or repeated full-archive extractions — and only at cost-based rates disclosed in advance in writing.

B.9.12.3 Rate limits. OmniPACS may apply documented rate limits to APIs and bulk operations to protect Platform stability. Rate limits will be published in the Documentation and will not be set at a level that defeats the export rights in Section B.5.2.1 or the retrieval window in Section B.9.18.4.

B.9.13 SUPPORT

B.9.13.1 Support. OmniPACS will use commercially reasonable efforts to respond to support requests during 9:00 a.m. to 6:00 p.m. Eastern Time, Monday through Friday, excluding US federal holidays. Support requests are submitted at support@omnipacs.com, through the in-product ticket function, or by telephone to 813-590-0846. There is no separate support policy document.

B.9.13.2 No response-time or resolution-time commitments. OMNIPACS MAKES NO COMMITMENT AS TO INITIAL RESPONSE TIME, RESTORATION TIME OR RESOLUTION TIME FOR ANY SUPPORT REQUEST, AT ANY SEVERITY OR PRIORITY, AND OFFERS NO SEVERITY-BASED SERVICE LEVEL, NO ESCALATION TIMETABLE AND NO AFTER-HOURS OR 24×7 SUPPORT. OmniPACS will use commercially reasonable efforts to prioritize requests that the Subscriber identifies as affecting active patient care.

B.9.13.3 Events affecting active patient care. An event in which the Platform is unavailable, or in which Studies cannot be ingested or retrieved, in a way that affects active patient care is a patient-safety-relevant event and will be treated as such by both parties. The Subscriber will designate at least two support contacts and one escalation contact, and will report suspected malfunctions under Section B.4.10.

B.9.13.4 No support commitment for free access. Free, evaluation, trial and legacy accounts receive no support commitment of any kind (Section B.2.1(b)). OmniPACS may provide best-efforts assistance without creating an entitlement.

B.9.14 TRANSPARENCY AND DILIGENCE SUPPORT

B.9.14.1 On written request, not more than once in any twelve (12) month period absent a security incident or a regulatory requirement, and in each case under a non-disclosure agreement and only to the extent such materials exist, OmniPACS will make available: its security documentation; its subprocessor list; its DICOM Conformance Statement; its Intended Use statement; a software bill of materials for the Platform components OmniPACS supplies (Section B.4.11); a summary of its incident response process; certificates of insurance (Section B.11.5); and a completed security questionnaire in OmniPACS’ standard format or, at OmniPACS’ option, in the Subscriber’s format.

B.9.14.2 What OmniPACS does not provide. OmniPACS holds no third-party attestation covering its own controls (Section B.9.20.2) and does not provide penetration-test reports or results, compliance-audit reports, disaster-recovery test results, or any assertion that a particular document or artifact exists. Nothing in this Section obligates OmniPACS to permit an on-site audit or an audit of its production environment, except where required by law or by Part C.

B.9.15 TERM, AUTO-RENEWAL, NON-RENEWAL AND CANCELLATION ON 30 DAYS’ NOTICE

B.9.15.1 Term of this Section. Section B.9 takes effect as to a Subscriber on the earlier of the effective date of its first Order Form and the date Section B.1.2 first applies to it, and continues until all Order Forms for the account have expired or been terminated.

B.9.15.2 Initial Term and automatic renewal.
    (a) Each Order Form has the Initial Term stated in it. Absent a stated Initial Term, the Initial Term is one (1) month for an account created through self-serve signup, and twelve (12) months for an account under a countersigned Order Form.
    (b) Unless either party gives notice of non-renewal under Section B.9.15.4, each Order Form automatically renews at the end of its then-current term for successive renewal terms of the same length as the Initial Term (each a “Renewal Term”), at the then-current Fees notified under Section B.9.10.
    (c) Renewal reminder. OmniPACS will email the Subscriber’s designated administrator a renewal reminder at least thirty (30) days before each renewal date, stating the renewal date, the renewal term length, the Fees that will apply, how to cancel, and a direct link to the cancellation function.
    (d) Separate consent to auto-renewal. At signup, the Subscriber’s acceptance of these automatic-renewal terms is captured by a separate, unchecked affirmative consent control, distinct from acceptance of these Terms as a whole, and OmniPACS provides a retainable acknowledgment containing the automatic-renewal terms, the cancellation policy, and instructions for cancelling (Part E, Section E.4).
    (e) Record of consent. OmniPACS retains verification of that affirmative consent for at least three (3) years, or one (1) year after the end of the subscription, whichever is longer (Part E, Section E.4).

B.9.15.3 State automatic-renewal laws. The mechanics in Section B.9.15.2 and the cancellation mechanics in Section B.9.15.5 are designed to satisfy state automatic-renewal statutes. Where such a statute gives the Subscriber a right that these Terms do not — for example, a pro-rata refund following a price increase — that statute prevails (Section B.12.4).

B.9.15.4 Non-renewal. Either party may elect not to renew an Order Form by giving written notice at least thirty (30) days before the end of the then-current term. The Subscriber may give that notice through the in-product cancellation function or in writing under Part A, Section A.15.

B.9.15.5 CANCELLATION FOR CONVENIENCE ON 30 DAYS’ WRITTEN NOTICE — EITHER PARTY

    (a) The right. At any time, and for any reason or no reason, either the Subscriber or OmniPACS may terminate the subscription or any Order Form for convenience by giving the other party thirty (30) days’ prior written notice. This right is in addition to non-renewal under Section B.9.15.4 and to termination for cause under Section B.9.18.2, and it applies during an Initial Term as well as during a Renewal Term. No early-termination charge, cancellation fee, or penalty applies.

    (b) How the Subscriber exercises it. The Subscriber may cancel by any of the following, at its option:
        (i) in the Platform, using the one-step cancellation function available to any account administrator, without needing to call, email, chat with, or speak to any person or agent, and without navigating a retention flow it has not chosen to enter;
        (ii) by email to sales@omnipacs.com; or
        (iii) by written notice under Part A, Section A.15.
    OmniPACS will make the cancellation mechanism at least as easy to use as the mechanism by which the Subscriber signed up, and available through each medium by which the Subscriber could have signed up. OmniPACS may present a retention or downgrade offer, but will not obstruct, delay or condition cancellation on the Subscriber’s engagement with it.

    (c) Confirmation. OmniPACS will send a written confirmation of cancellation within two (2) Business Days, stating the effective date of termination, the final Billing Period, the estimated final charges, and the start and end dates of the post-termination retrieval window under Section B.9.18.4.

    (d) How OmniPACS exercises it. OmniPACS may exercise this right by written notice to the Subscriber’s designated administrator and billing contact under Part A, Section A.15. The post-termination retrieval window in Section B.9.18.4 applies in full to a termination for convenience by either party. No refund or proration of prepaid Fees arises from a termination for convenience by either party (Section B.9.15.6).

    (e) Effective date; when the 30 days start. The thirty-day notice period begins on the date the notice is given in accordance with Part A, Section A.15 (or on the date the Subscriber submits the in-product cancellation). Termination takes effect at 11:59 p.m. America/New_York on the thirtieth (30th) day after the notice is given, unless the parties agree in writing to an earlier or later date.

B.9.15.6 NO PRORATION OF THE FINAL PERIOD

    (a) Where the Subscriber cancels for convenience under Section B.9.15.5, or does not renew under Section B.9.15.4, the base subscription fee for the Billing Period in which termination takes effect is payable in full and is NOT prorated, apportioned, credited or refunded, in whole or in part, unless these Terms or the applicable Order Form expressly state otherwise.
    (b) The Included Volume for that final Billing Period is likewise not prorated. The Subscriber may use the full Included Volume during the final Billing Period.
    (c) Overage fees and other usage-based charges accrued through the effective date of termination remain payable, and will be invoiced in arrears under Section B.9.8.1 after the effective date of termination. The obligation to pay them survives termination.
    (d) NO REFUNDS. NO PREPAID FEES ARE REFUNDED ON CANCELLATION, NON-RENEWAL, TERMINATION OR SUSPENSION, IN WHOLE OR IN PART, EXCEPT (i) the Subscriber’s termination for OmniPACS’ uncured material breach under Section B.9.18.2; (ii) the Subscriber’s termination for chronic failure to meet the availability target under Section B.10.6; (iii) the limited warranty remedy in Section B.6.3; and (iv) any refund required by applicable law. No other provision of these Terms creates a right to a refund or to proration.
    (e) Statutory refund rights. Where a state automatic-renewal statute or other applicable law requires a pro-rata refund — for example, following a price increase — that requirement prevails over this Section B.9.15.6 to the extent of the conflict (Sections B.9.15.3 and B.12.4).

B.9.15.7 Effect of cancellation on stored data. Cancellation does not, of itself, delete Customer Data. Section B.9.18.4 governs the post-termination retrieval window, and Part C governs the eventual return or destruction of PHI.

B.9.16 SUSPENSION

Section B.9.16.4 is a hard limit on every suspension right in this Section B.9 and everywhere else in this Agreement.

B.9.16.1 Grounds. OmniPACS may suspend Platform functions as described below where: (a) Fees are overdue and uncured; (b) the Subscriber has no valid payment method on file and has not cured; (c) the Subscriber or a user of its account has breached the AUP; (d) OmniPACS reasonably believes there is an active security threat, credential compromise, malware event, or unlawful use; (e) suspension is required by law or by a governmental order; or (f) the account’s usage is causing material degradation to the Platform or to other customers.

B.9.16.2 Non-payment: notice and cure required. For suspension on the grounds in Section B.9.16.1(a) or (b), OmniPACS will first give at least fifteen (15) days’ written notice of the undisputed past-due amount to the Subscriber’s billing contact and account administrator, and will allow that period to cure before suspending. OmniPACS will not suspend for non-payment of an amount disputed in good faith under Section B.9.9.6.

B.9.16.3 Security and AUP: immediate but scoped. For the grounds in Section B.9.16.1(c), (d), (e) or (f), OmniPACS may suspend immediately and without prior notice where necessary, but will (i) scope the suspension as narrowly as reasonably possible — to the offending user, credential, connection, Local Component, integration or function — (ii) notify the Subscriber as soon as practicable, (iii) work with the Subscriber to remediate, and (iv) restore full function promptly once the cause is remediated.

B.9.16.4 WHAT SUSPENSION MAY AND MAY NOT AFFECT — PHI ACCESS IS NEVER SUSPENDED FOR NON-PAYMENT

    (a) Suspension for non-payment or for absence of a valid payment method is limited to the following, and to nothing else:
        (i) acceptance of new Study ingestion and new uploads (including via DICOM network services, Local Components and write APIs);
        (ii) provisioning of new Authorized Clinical Users, sites, data sources or integrations;
        (iii) creation of new outbound external shares to third-party recipients;
        (iv) non-essential features, including analytics and reporting dashboards, AI Features, bulk CD/DVD ISO production, and non-clinical convenience functions; and
        (v) access to beta and pre-release features.

    (b) Suspension for non-payment or for absence of a valid payment method will NOT, under any circumstances, restrict, degrade, delay, throttle to unusability, encrypt against, or terminate:
        (i) the Subscriber’s and its Authorized Clinical Users’ ability to search, retrieve, view, and open previously stored Studies and other Customer Data, including through the worklist, the Platform, and Signed Ticket URLs to the CHILI Viewer;
        (ii) the Subscriber’s ability to export previously stored Customer Data, including bulk export in unmodified DICOM Part 10 format with manifest, under Section B.5.2.1;
        (iii) the Subscriber’s ability to retrieve PHI as necessary to satisfy an individual’s right of access under 45 CFR § 164.524, or to respond to any other legal or regulatory obligation regarding PHI;
        (iv) the Subscriber’s ability to retrieve records needed for continuity of patient care, including access by users needed to support active clinical care;
        (v) a Patient’s or Individual’s access to their own images under Part D; or
        (vi) the availability, confidentiality or integrity of stored ePHI.

    (c) The parties acknowledge the reason for this limit. OmniPACS is a Business Associate. Blocking a Covered Entity’s access to the PHI a Business Associate maintains on its behalf — including by activating a “kill switch” to resolve a payment dispute — is an impermissible use of PHI under the Privacy Rule and a violation of the Security Rule’s availability requirement, and it would prevent the Subscriber from meeting its own obligations under 45 CFR § 164.524. OmniPACS will not do it. The Subscriber likewise acknowledges that a covered entity may not agree to terms that prevent it from ensuring the availability of its own PHI, and that this Section is drafted so that the Subscriber is not asked to.

    (d) Security containment carve-out. Section B.9.16.4(b) does not prevent OmniPACS from taking a temporary, narrowly scoped technical measure genuinely necessary to contain an active security incident or to comply with a governmental order — for example, disabling a compromised credential or isolating a compromised Local Component. Any such measure will be (i) limited to what containment requires, (ii) notified to the Subscriber as soon as practicable, (iii) accompanied by OmniPACS’ reasonable efforts to provide an alternative retrieval path for clinically necessary Studies, and (iv) lifted as soon as containment permits. A commercial dispute is never a security incident.

    (e) No availability exclusion for the retrieval path. A suspension permitted under this Section B.9.16 is Excluded Time for purposes of Section B.10 only to the extent it lawfully affects suspended functions. Any interruption of the retrieval and export path described in Section B.9.16.4(b) is not Excluded Time.

    (f) This Section controls. THIS SECTION B.9.16.4 CONTROLS OVER EVERY OTHER PROVISION OF THIS AGREEMENT, INCLUDING SECTION B.6, SECTION B.7, SECTION B.9.15, SECTION B.9.18 AND SECTION B.10. NO SUSPENSION, TERMINATION, EXPIRY, DISCLAIMER, LIMITATION, EXCLUSION OR COMMERCIAL DISPUTE OPERATES TO BLOCK, DELAY OR CONDITION THE RETRIEVAL OF, ACCESS TO, OR EXPORT OF PHI.

B.9.16.5 Fees during suspension. Fees continue to accrue during a suspension arising from the Subscriber’s breach. Fees do not accrue during a suspension arising from OmniPACS’ own security incident or from a cause attributable to OmniPACS.

B.9.16.6 Restoration. OmniPACS will restore suspended functions promptly, and in any event within two (2) Business Days, after the cause of suspension is cured or remediated. OmniPACS may charge a documented reactivation fee only where the Order Form states one.

B.9.18 TERMINATION AND EFFECTS OF TERMINATION

(Section B.9 contains no Section B.9.17. The service level provisions are Section B.10 of this Part.)

B.9.18.1 Termination for convenience. Either party may terminate on thirty (30) days’ written notice under Section B.9.15.5.

B.9.18.2 Termination for cause. Either party may terminate the subscription or an affected Order Form immediately on written notice if the other party:

    (a) commits a material breach and fails to cure it within thirty (30) days after written notice describing the breach — reduced to fifteen (15) days for non-payment and for failure to maintain a valid payment method;
    (b) commits a material breach that is not capable of cure;
    (c) becomes insolvent, makes a general assignment for the benefit of creditors, or has a receiver, trustee or liquidator appointed, or files or has filed against it a petition in bankruptcy not dismissed within sixty (60) days; or
    (d) commits a material breach of Part C that is not cured as provided in Part C.

B.9.18.3 Effect of termination generally. On termination: (a) the right to use the Platform granted under Part A, Section A.4 terminates, except as needed to exercise the retrieval rights in Section B.9.18.4; (b) the Subscriber will cease using the Platform other than for retrieval and export; (c) the Subscriber will uninstall Local Components after the retrieval window closes; (d) all accrued Fees, including overage fees for the final Billing Period, become due; and (e) the provisions identified in Part E, Section E.3 survive — including Part A, Sections A.4 through A.7 in their entirety, which continue to bind the Subscriber and its users after termination.

B.9.18.4 POST-TERMINATION DATA RETRIEVAL WINDOW

    (a) For a period of thirty (30) days after the effective date of termination or expiration (the “Retrieval Window”), OmniPACS will continue to provide the Subscriber, at no charge, with read and export access to all Customer Data that was accessible to it immediately before termination, including full bulk export in unmodified DICOM Part 10 format with the manifest described in Section B.5.2.1.
    (b) During the Retrieval Window, the Subscriber may designate a reasonable number of users for retrieval and export purposes. Those users may not otherwise use the Platform, and no new Studies may be ingested.
    (c) THE RETRIEVAL WINDOW IS ABSOLUTE. IT IS PROVIDED AT NO CHARGE AND IS NOT CONDITIONED ON PAYMENT OF ANY AMOUNT, WHETHER DISPUTED OR UNDISPUTED, AND OMNIPACS WILL NOT WITHHOLD, SHORTEN, DEGRADE OR CONDITION IT AS LEVERAGE IN A COMMERCIAL DISPUTE. This Section is subject to Section B.9.16.4, which controls.
    (d) Extension. The Subscriber may extend the Retrieval Window, or retain Customer Data in an archive-only state, month to month at OmniPACS’ then-current published rate, by written notice given before the Retrieval Window closes. Extended retention beyond the Retrieval Window is available only as ordered (Section B.9.23.1).
    (e) Migration assistance. OmniPACS will provide reasonable assistance with a Subscriber-directed migration on the terms in Section B.5.2.8.
    (f) Reminders. OmniPACS will remind the Subscriber’s administrators of the closing of the Retrieval Window at least seven (7) days before it closes.

B.9.18.5 Deletion; return or destruction of PHI. After the Retrieval Window closes, OmniPACS will return or destroy PHI in accordance with Part C and will not retain copies except as Part C permits. Where return or destruction is not feasible, Part C’s protections continue to apply to the retained PHI for as long as OmniPACS retains it. OmniPACS may delete Customer Data at any time more than sixty (60) days after the effective date of termination or expiration, and will delete it on the Subscriber’s written instruction, in each case subject to the expiry of backups within the thirty-five (35) day backup retention period. OmniPACS will not delete or destroy Customer Data before the Retrieval Window closes. OmniPACS will provide a certificate of destruction on written request.

B.9.18.6 No deletion during a dispute. OmniPACS will not delete or destroy Customer Data while a good-faith dispute regarding the Fees, the termination, or the completeness of an export is pending, and will preserve Customer Data as required by any applicable litigation hold of which it has notice.

B.9.19 INDEMNIFICATION BY OMNIPACS

B.9.19.1 IP indemnity. OmniPACS will defend the Subscriber against any third-party claim alleging that the Platform, as provided by OmniPACS and used in accordance with these Terms, infringes or misappropriates a United States patent, copyright, trademark or trade secret, and will indemnify the Subscriber against damages, costs and reasonable attorneys’ fees finally awarded against it or agreed in settlement by OmniPACS.

B.9.19.2 Exclusions. OmniPACS has no obligation under Section B.9.19.1 to the extent the claim arises from: (a) Customer Data; (b) combination or use of the Platform with products, data, services or systems not supplied by OmniPACS, where the claim would not have arisen but for the combination; (c) modification of the Platform by anyone other than OmniPACS; (d) continued use after OmniPACS has notified the Subscriber to discontinue or has provided a non-infringing alternative; (e) beta, trial, preview or free features and accounts; (f) a third-party product, including the CHILI Viewer; or (g) the Subscriber’s breach of these Terms.

B.9.19.3 Remedy ladder. If the Platform is or may become the subject of a claim under Section B.9.19.1, OmniPACS may, at its option and expense: (a) procure the right for the Subscriber to continue using the Platform; (b) modify or replace the Platform so it is non-infringing while materially preserving its functionality; or (c) if neither (a) nor (b) is commercially reasonable, terminate the affected Order Form on notice and refund prepaid, unused Fees. Where OmniPACS terminates under (c), the Retrieval Window in Section B.9.18.4 applies in full.

B.9.19.4 No other OmniPACS indemnity. Sections B.9.19.1 through B.9.19.3 state OmniPACS’ only indemnification obligations, and OmniPACS gives no other indemnity. OmniPACS’ liability arising from a Breach of Unsecured PHI or from a security incident is governed by Sections B.7.1 through B.7.5 and by Part C.

B.9.19.5 Procedure. The mutual procedure in Section B.8.2 applies.

B.9.20 SECURITY, HOSTING, DATA RESIDENCY AND SUBPROCESSORS

B.9.20.1 Security measures OmniPACS maintains. OmniPACS maintains a written information security program with administrative, physical and technical safeguards designed to protect Customer Data against unauthorized access, use, disclosure, alteration and destruction, consistent with the HIPAA Security Rule and with Part C, and including:

    (a) encryption of Customer Data in transit using TLS 1.2 or higher;
    (b) encryption of stored Studies, Customer Data and backups at rest, using platform-managed encryption on the underlying cloud infrastructure;
    (c) unique credentials for each individual user, with no shared or generic human accounts, and credential provisioning and de-provisioning controlled by the Subscriber’s administrators;
    (d) role-based access control and configurable sharing controls, configured by the Subscriber;
    (e) audit logging of access to and disclosure of PHI, retained for six (6) years;
    (f) least-privilege administrative access for OmniPACS personnel, limited to what is necessary to operate and support the Platform;
    (g) workforce training on HIPAA and information security, and a workforce sanctions policy;
    (h) written agreements, including business associate agreements where required, with subprocessors that process PHI;
    (i) a documented incident response process;
    (j) backups of Customer Data, retained for thirty-five (35) days; and
    (k) time-limited, cryptographically signed URLs for diagnostic viewer hand-off.

These measures apply to all Customer Data OmniPACS holds, including Customer Data in a free or legacy account.

B.9.20.1A Authentication; one-time passcode verification at two events; multi-factor authentication is not enforced on every sign-in. Authentication is performed through Firebase Authentication using signed JSON Web Tokens. OmniPACS requires verification by a one-time passcode, sent to the email address or mobile number on file, when an account is created and when a password is reset. OMNIPACS DOES NOT CURRENTLY ENFORCE MULTI-FACTOR AUTHENTICATION ON EVERY ROUTINE SIGN-IN. The Subscriber remains responsible for evaluating whether that is sufficient for its environment and for applying compensating controls, including device management, network controls and session policy, where its own risk assessment requires them, together with the credential discipline required by Section B.3.4 and Part A, Section A.8.

B.9.20.1B Security testing. OmniPACS performs security testing at intervals it determines appropriate. OmniPACS does not commit to any testing cadence, does not commit to third-party penetration testing, and does not commit to sharing testing results. OmniPACS conducts no annual independent compliance audit and makes no representation that one has been performed.

B.9.20.2 Certifications — none of OmniPACS’ own; AWS’s attestations cover AWS’s infrastructure only. OMNIPACS DOES NOT CURRENTLY HOLD A SOC 2 TYPE I OR TYPE II REPORT, A HITRUST CSF CERTIFICATION, AN ISO/IEC 27001 CERTIFICATE, AN AT-C 315 HIPAA COMPLIANCE EXAMINATION REPORT, A PCI DSS ATTESTATION OF COMPLIANCE, OR ANY OTHER INDEPENDENT THIRD-PARTY ATTESTATION COVERING OMNIPACS’ OWN CONTROLS, AND MAKES NO REPRESENTATION THAT IT DOES. OmniPACS gives no commitment to obtain any such report or certification. OmniPACS will make available its then-current security documentation, to the extent it exists, under a non-disclosure agreement on written request (Section B.9.14).

The Platform is hosted on Amazon Web Services, which maintains its own independent third-party audit reports and certifications, including SOC 1, SOC 2 and SOC 3 reports and ISO/IEC 27001 certification, and which offers a HIPAA Business Associate Addendum covering HIPAA-eligible services. Those reports are obtained from AWS and are made available by AWS through AWS Artifact. THEY ATTEST TO THE CONTROLS AWS OPERATES FOR ITS OWN INFRASTRUCTURE AND SERVICES. THEY ARE NOT AN ATTESTATION OF OMNIPACS’ CONTROLS, THEY DO NOT COVER THE OMNIPACS APPLICATION LAYER, AND A SUBSCRIBER MAY NOT TREAT THEM AS A SUBSTITUTE FOR A SOC 2 REPORT COVERING OMNIPACS. OmniPACS does not furnish AWS’s reports.

B.9.20.3 Data location. The Platform is hosted on third-party cloud infrastructure. OMNIPACS DOES NOT WARRANT THAT CUSTOMER DATA WILL BE STORED OR PROCESSED IN ANY PARTICULAR COUNTRY, REGION, DATA CENTER OR AVAILABILITY ZONE. OmniPACS will identify the regions then in use on written request under a non-disclosure agreement. A Subscriber with a data-residency requirement must obtain a written commitment to that effect in an Order Form.

B.9.20.4 Hosting. The Platform is hosted on third-party cloud infrastructure supplied by Amazon Web Services and by the other subprocessors identified in Section B.9.20.5. OmniPACS makes no representation as to hosting region, availability zone, service configuration or the eligibility of any underlying cloud service for use with PHI.

B.9.20.5 Subprocessors. OmniPACS engages the subprocessors listed at https://omnipacs.com/legal/subprocessors. As at the Effective Date these include: Amazon Web Services (hosting, object storage, queueing and compute); Google/Firebase (authentication and push notification); Sentry (error tracking); New Relic (application performance monitoring); Intercom (in-app support and engagement); Stripe (payment processing); Maxio/Chargify (subscription billing); GoHighLevel/LeadConnector (customer relationship management and lead capture); CHILI (diagnostic viewer); and Google Workspace (transactional email). OmniPACS enters into written agreements, including business associate agreements where required, with each subprocessor that processes PHI.

B.9.20.6 Subprocessor obligations and change notice. OmniPACS will impose on each subprocessor that processes PHI written obligations no less protective than those in Part C, and will require termination of the subprocessor’s access to Customer Data within a reasonable time after termination of the applicable agreement. OmniPACS will give the Subscriber at least thirty (30) days’ notice before adding or replacing a subprocessor that will process PHI, by posting to the subprocessor page and by notice to the Subscriber’s administrators where the Subscriber subscribes to notifications. If the Subscriber reasonably objects on documented security or privacy grounds, the parties will confer in good faith; if the objection cannot be resolved, the Subscriber may terminate the affected Order Form without penalty. No refund or proration of prepaid Fees arises from such a termination (Section B.9.15.6).

B.9.20.7 Vulnerability disclosure. Section B.11.3.3 governs.

B.9.21 ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING

OmniPACS’ commitments in Sections B.9.21.1 and B.9.21.2 apply to all Customer Data OmniPACS holds, including Customer Data in a free or legacy account and data held under Part D. The Subscriber-facing obligations in Sections B.9.21.4 and B.9.21.8 apply to Subscribers.

B.9.21.1 No training on Customer Data. OmniPACS will not use Customer Data — including images, DICOM headers, pixel data, reports, or any PHI — to train, fine-tune, evaluate, benchmark or otherwise develop or improve any machine learning or artificial intelligence model, whether OmniPACS’ own or a third party’s, and will not disclose Customer Data to any third-party model provider for those purposes. The only exceptions are:

    (a) where the Subscriber opts in under a separate, specific written agreement identifying the data, the purpose and the model; and
    (b) then only using data de-identified in accordance with 45 CFR § 164.514(b) (Expert Determination or Safe Harbor), including removal of DICOM header identifiers and burned-in annotation.

B.9.21.2 No model memorization. Where an AI Feature applies a model to Customer Data at inference time, OmniPACS will configure that processing so that Customer Data is not retained in, or used to update, model weights, and is not persisted by any third-party model provider beyond the transient processing necessary to return the output. Where OmniPACS uses a third-party model provider, OmniPACS will require that provider by contract to observe that limitation.

B.9.21.3 Worklist prioritization is triage ordering, not a diagnostic reader. Any AI Feature that orders, ranks, scores, flags or highlights entries in a worklist affects only the order in which Studies are presented for human review. It:

    (a) is not a diagnostic device, computer-aided detection or diagnosis function, or triage-and-notification device, and is not intended to detect, characterize, measure, rule in or rule out any finding, condition or disease;
    (b) does not generate a clinical conclusion and must not be relied on as one;
    (c) does not remove, hide, defer or deprioritize any Study from the worklist, and does not relieve the Subscriber of any obligation to review every Study within its own turnaround-time and escalation policies; and
    (d) is not a substitute for the Subscriber’s own protocols for identifying and escalating urgent or critical findings.

The Platform is not FDA-cleared, approved or authorized, and is not marketed for primary diagnostic interpretation. Any worklist prioritization feature orders Studies on the basis of workflow metadata and does not analyze image pixel data to infer the presence, absence or characteristics of any finding, condition or disease.

B.9.21.4 Human in the loop. The Subscriber will ensure that every AI Output used in connection with diagnosis, interpretation, prioritization affecting patient care, or treatment planning is reviewed by an appropriately licensed and qualified practitioner, who makes the ultimate clinical decision. The Subscriber will not configure or operate any workflow in which an AI Output is acted on, or a Study is dispositioned, without such review. This duplicates and does not narrow Part A, Section A.9, which binds every user.

B.9.21.5 AI output disclaimer. AI Features and AI Outputs are provided as informational aids only. They may be inaccurate, incomplete, out of date, or biased; may perform differently across patient populations, modalities, protocols, scanners and sites than in development; and are not a diagnosis, a medical opinion, or clinical advice. Every AI Output must be independently verified against the source images and the clinical record. AI Outputs may be non-unique, and similar outputs may be generated for other customers.

B.9.21.6 Output ownership. As between the parties, the Subscriber owns AI Outputs generated from its Customer Data, and those Outputs are Customer Data for purposes of these Terms. OmniPACS retains all rights in the models, algorithms, weights, prompts and software that generate them (Part A, Section A.7).

B.9.21.7 Model change notice and transparency. OmniPACS will give the Subscriber at least thirty (30) days’ notice before materially changing, replacing or retiring a clinically relevant AI model, and will make available, to the extent such materials exist, a model card or performance-characteristics document stating the model’s intended use, inputs, development population, performance characteristics, known limitations and monitoring approach. OmniPACS does not represent that any such document exists.

B.9.21.8 State AI law compliance and flow-down. The state AI law landscape is active and changing. The parties will each comply with applicable law, and:

    (a) Patient-facing generative communications. Where an OmniPACS feature generates a communication that the Subscriber transmits to a patient, the Subscriber is responsible for including the required disclaimer that the communication was generated by artificial intelligence and clear instructions for the patient to reach a human health care provider, as required by California Health & Safety Code § 1316.9 (AB 3030) and comparable laws. OmniPACS will provide the information and configuration options the Subscriber needs to do so.
    (b) AI in diagnosis or treatment. Where the Subscriber uses an AI Feature in the diagnosis or treatment of patients, the Subscriber is responsible for the patient disclosure required by Texas HB 149 (TRAIGA) and comparable laws, and for the practitioner-review requirements of Texas SB 1188 and any standards set by its licensing board.
    (c) Automated decision-making. Neither party will use the Platform to make or materially influence a consequential decision about an individual by automated means without the disclosures and rights required by applicable law, including Colorado SB 26-189 when it takes effect.
    (d) Licensed-profession disclosure. Where an OmniPACS generative feature interacts directly with an individual in a context involving a state-licensed profession or sensitive personal information, the interacting party will disclose that the individual is interacting with generative AI, as required by the Utah Artificial Intelligence Policy Act as amended. Where that individual is a Patient using the Platform under Part D, OmniPACS makes that disclosure.
    (e) Data location. Section B.9.20.3 applies to any model provider or AI subprocessor that processes Customer Data. OmniPACS gives no data-residency commitment in respect of AI processing.

B.9.21.9 No AI regulatory representation. OmniPACS makes no representation that any AI Feature is, or is not, subject to regulation as a medical device or as clinical decision support software, and makes no representation that any AI Feature is exempt from device regulation. The Subscriber is responsible for determining the requirements applicable to its own use.

B.9.22 INSURANCE

B.9.22.1 Pointer. OmniPACS’ insurance is stated in Section B.11.5, which states the coverages and limits OmniPACS actually carries and the limits of OmniPACS’ insurance obligations. This Section B.9.22 is a pointer only and adds no substance.

B.9.22.2 Insurance does not expand liability. The existence, limits or exhaustion of insurance does not expand OmniPACS’ liability beyond the caps in Section B.7, which control, and does not relieve either party of any obligation.

B.9.23 RETENTION AND STORAGE ENTITLEMENTS

B.9.23.1 Retention. OmniPACS will retain the Subscriber’s Customer Data for the duration of the subscription, subject to the no-silent-deletion covenant in Section B.5.2.6. ABSENT AN ORDER FORM SPECIFYING A LONGER RETENTION PERIOD, OMNIPACS HAS NO OBLIGATION TO RETAIN CUSTOMER DATA BEYOND THE SUBSCRIPTION TERM, other than during the post-termination Retrieval Window in Section B.9.18.4. Extended retention is available only if ordered, and is chargeable at OmniPACS’ then-current published rate, which is set on a cost basis. There are no plan-based or tier-based retention entitlements; retention beyond the Subscription Term exists only where an Order Form states it.

B.9.23.2 The Subscriber determines the required period. The Subscriber warrants that it has determined the retention period required by its jurisdiction, licensure, accreditation and payer obligations, and is responsible for ordering and configuring retention sufficient to meet it. Retention obligations vary by state and modality and are longer for mammography. OmniPACS does not advise on retention periods (Section B.4.5).

B.9.23.3 Archive tiering. Where an Order Form provides for archive tiering, that Order Form states the retrieval latency and any retrieval charge. Archive tiering must not be applied in a way that defeats the retrieval, export or individual-access rights in Sections B.5.2.1, B.5.2.5 and B.5.2.7 or in Section B.9.16.4. OmniPACS makes no representation that archive tiering is available.

B.9.24 PART C AND CROSS-REFERENCES WITHIN THIS SECTION

B.9.24.1 Part C governs PHI. Part C is an integral Part of this Agreement. It, and not this Section B.9, governs: permitted and required uses and disclosures of PHI; safeguards for PHI; reporting of security incidents, impermissible uses and disclosures, and Breaches; subcontractor flow-down; access, amendment and accounting support; availability of books and records to the Secretary; and return or destruction of PHI on termination.

B.9.24.2 Nothing in this Section B.9 reduces Part C. Nothing in this Section B.9 — including the limitation of liability in Section B.7, the suspension rights in Section B.9.16, or the disclaimers in Section B.6.5 — is interpreted to reduce, waive or condition any obligation OmniPACS owes under Part C or the HIPAA Rules, or to permit OmniPACS to condition the availability of PHI on payment.

B.9.24.3 Patient access is not a Subscriber entitlement to price. A Subscriber may not charge, and OmniPACS will not charge the Subscriber for, a Patient’s or Individual’s access to their own images through the Platform under Part D (Section B.5.2.7).


B.10 SERVICE LEVELS

Section B.10 applies only to paying Subscribers. Free, evaluation, trial, pilot, legacy, share-link and view-only access carries no availability target and no remedy under this Section (Section B.2.1(b)).

Nothing in this Section B.10 — and no exclusion, measurement rule or limitation in it — limits Section B.9.16.4, which controls.

B.10.1 Availability target. The Platform is “Available” when a Subscriber can log in and can ingest, retrieve, view and export Studies through the Platform’s standard interfaces. OmniPACS’ target is that the Platform will be Available for at least 99.5% of the minutes in each calendar month, excluding the Excluded Time described in Section B.10.4. THIS FIGURE IS A TARGET AND NOT A WARRANTY, A GUARANTEE OR A CONDITION. OMNIPACS DOES NOT WARRANT ANY LEVEL OF AVAILABILITY, AND FAILURE TO MEET THE TARGET IS NOT A BREACH OF THE LIMITED WARRANTIES IN SECTION B.6.2.

B.10.2 NO SERVICE CREDITS. OMNIPACS DOES NOT OFFER SERVICE CREDITS. NO CREDIT, REBATE, DISCOUNT, SET-OFF OR OTHER PAYMENT OF ANY KIND IS PAYABLE, AND NO CLAIM FOR ONE MAY BE MADE, IF THE AVAILABILITY TARGET IS NOT MET IN ANY MONTH OR IN ANY NUMBER OF MONTHS. The Subscriber’s only remedy for failure to meet the availability target is the termination right in Section B.10.6.

B.10.3 Reporting and measurement. A Subscriber that believes the availability target was not met in a calendar month may notify OmniPACS at support@omnipacs.com within thirty (30) days after the end of that month, stating the dates, times and affected function. Availability is measured by OmniPACS’ own monitoring records, which are determinative absent manifest error.

B.10.4 Excluded Time. The following are excluded from the availability calculation:

    (a) scheduled maintenance, of which OmniPACS will give at least forty-eight (48) hours’ notice where practicable;
    (b) emergency maintenance, which OmniPACS may perform at any time, with notice as soon as practicable;
    (c) failures caused by the Subscriber’s own environment, including its internet connectivity, network, VPN, firewall, modalities, routers, gateways, workstations, Local Components or displays;
    (d) the Subscriber’s failure to meet minimum hardware, software, browser, connectivity or configuration specifications in the Documentation, including any access from a browser that is not a Supported Browser under Part A, Section A.4.6;
    (e) inability to authenticate resulting from the Subscriber’s own identity, authentication or directory configuration;
    (f) use of the Platform other than in accordance with the Documentation, these Terms, or the Acceptable Use Policy in Section B.3;
    (g) beta, trial, preview, pilot and pre-release features, including UDE (Section B.2.1(f));
    (h) third-party services, products, hardware and networks not under OmniPACS’ control, including the CHILI viewer;
    (i) Force Majeure Events under Part E, Section E.3;
    (j) suspension permitted under Section B.9.16, including suspension for non-payment or breach of the Acceptable Use Policy — provided that a suspension for non-payment may never affect the retrieval and export path (Section B.9.16.4), and any interruption of that path is not Excluded Time;
    (k) throttling of activity OmniPACS reasonably suspects to be abusive or that exceeds documented rate limits (Section B.9.12.3); and
    (l) any period during which the Subscriber has not paid undisputed Fees when due.

B.10.5 Force majeure. A Force Majeure Event is Excluded Time (Part E, Section E.3).

B.10.6 CHRONIC FAILURE — SOLE AND EXCLUSIVE REMEDY. If measured monthly availability falls below the availability target in three (3) consecutive calendar months, the Subscriber may terminate the affected subscription or Order Form by written notice given within thirty (30) days after the end of the third such month, and will receive a pro-rata refund of prepaid, unused Fees for the terminated period. THIS TERMINATION RIGHT AND PRO-RATA REFUND ARE THE SUBSCRIBER’S SOLE AND EXCLUSIVE REMEDY FOR ANY FAILURE TO MEET THE AVAILABILITY TARGET, IN ANY MONTH OR IN ANY COMBINATION OF MONTHS. The post-termination Retrieval Window in Section B.9.18.4 applies in full.

B.10.7 Scope of this Section. This Section B.10 addresses availability only. It does not apply to, and provides no remedy for: (a) any security incident, or unauthorized access to or disclosure of Customer Data or PHI; (b) any breach of Part C or of the HIPAA Rules; (c) loss, corruption, deletion or unrecoverable alteration of Customer Data; (d) breach of Section B.5.2 (data access, portability and non-interference); or (e) any matter within Section B.7.4. Those matters are governed by Sections B.7 and B.8 and by Section B.9.19. This Section B.10 does not limit Section B.9.16.4.

B.10.8 Service status information. OmniPACS may publish service-status and incident information from time to time. OmniPACS does not commit to maintaining a public status page or an incident history. Incident information is available on request at support@omnipacs.com.

B.10.9 Backups and restoration; no recovery objectives. OmniPACS maintains backups of Customer Data, retained for thirty-five (35) days, and will use commercially reasonable efforts to restore service and data as promptly as practicable following an outage or data-loss event. OMNIPACS DOES NOT WARRANT ANY RECOVERY POINT OBJECTIVE, ANY RECOVERY TIME OBJECTIVE, ANY DURABILITY FIGURE OR ANY GEOGRAPHIC REDUNDANCY CONFIGURATION, AND DOES NOT COMMIT TO ANY DISASTER-RECOVERY TESTING CADENCE OR TO PROVIDING DISASTER-RECOVERY TEST RESULTS. A failure of backup or restoration is addressed under Sections B.7 and B.8 and Section B.9.19.


B.11 CONFIDENTIALITY; COMPLIANCE; EXPORT CONTROL; SUPPORT AND VULNERABILITY REPORTING; GOVERNMENT USERS

B.11.1 CONFIDENTIALITY

B.11.1.1 Definition. “Confidential Information” means non-public information disclosed by one party to the other that is designated as confidential or that a reasonable person would understand to be confidential, including product roadmaps, pricing, security documentation, audit reports, and business plans. Customer Data, including PHI, is the disclosing party’s Confidential Information, and PHI is additionally governed by Part C.

B.11.1.2 Obligations. The receiving party will (a) use the disclosing party’s Confidential Information only to perform these Terms, (b) protect it with at least reasonable care and no less care than it uses for its own confidential information of like importance, and (c) limit disclosure to personnel and contractors who need it and who are bound by confidentiality obligations at least as protective.

B.11.1.3 Exclusions. Confidential Information does not include information that is or becomes public without breach, was known to the receiving party without obligation, is independently developed without use of the Confidential Information, or is rightfully received from a third party without restriction. These exclusions do not apply to PHI.

B.11.1.4 Compelled disclosure. A party may disclose Confidential Information where required by law, provided it gives prompt notice (where legally permitted) and reasonable cooperation to allow the disclosing party to seek protection. Compelled disclosure of PHI is governed by Part C.

B.11.1.5 Duration. These obligations continue for five (5) years after disclosure, and indefinitely for trade secrets and for PHI.

B.11.2 COMPLIANCE WITH LAW; EXPORT CONTROL; ANTI-CORRUPTION; ACCESSIBILITY

B.11.2.1 Each party will comply with all laws applicable to its performance under these Terms.

B.11.2.2 Export and sanctions. You will not access or use the Platform, or permit any user to do so, from an embargoed or sanctioned country or region, or in violation of US export control or economic sanctions laws, and you represent that you and your users are not on any US government restricted-party list. You will not export or re-export Customer Data or the Local Components in violation of those laws. The Platform is offered for use in the United States. OmniPACS does not represent that it restricts access by geography, and the Subscriber is responsible for controlling the locations from which its users access the Platform.

B.11.2.3 Anti-corruption. Neither party will offer or accept any bribe, kickback or improper payment in connection with these Terms, and each will comply with the Foreign Corrupt Practices Act and the federal Anti-Kickback Statute and Stark Law to the extent applicable to it.

B.11.2.4 Accessibility. OmniPACS does not represent that the Platform conforms to WCAG 2.1 Level A or AA or to any other accessibility standard, and does not publish an accessibility conformance report. OmniPACS will provide the accessibility information it holds, to the extent such materials exist, on written request at support@omnipacs.com. The Subscriber is responsible for its own obligations under Section 504 of the Rehabilitation Act, Section 1557 of the Affordable Care Act and the Americans with Disabilities Act.

B.11.3 CONTACT, SUPPORT AND VULNERABILITY REPORTING

B.11.3.1 Support and general contact. support@omnipacs.com · 813-590-0846. Support hours, and the absence of any response-time or resolution-time commitment, are stated in Section B.9.13. There is no 24×7 clinical-urgency line. Free and legacy accounts receive no support commitment (Section B.2.1(b)).

B.11.3.2 Security incidents and suspected unauthorized use. Report immediately to support@omnipacs.com with the subject line “SECURITY.” Your notification obligation is in Part A, Section A.8; OmniPACS’ obligations are in Section B.9.20 and in Part C.

B.11.3.3 Vulnerability reporting. Security researchers and users may report suspected vulnerabilities to support@omnipacs.com with the subject line “SECURITY.” OmniPACS will not pursue legal action against a reporter who acts in good faith, and will coordinate disclosure timing with the reporter where practicable. Research is conducted in good faith, and is authorized for purposes of Part A, Section A.6, only where it is limited to OmniPACS’ own systems, does not access, alter, exfiltrate or destroy Customer Data or PHI, does not degrade the Platform, and is reported promptly to OmniPACS and not disclosed publicly before OmniPACS has had a reasonable opportunity to respond. OmniPACS does not publish a vulnerability disclosure policy and commits to no acknowledgment, response or remediation timeframe.

B.11.3.4 Product-safety and malfunction reports. Report suspected Platform malfunctions with a potential patient-safety impact under Section B.4.10 and Part A, Section A.9 to support@omnipacs.com with the subject line “URGENT — PATIENT SAFETY,” and, where the matter is urgent, by telephone to 813-590-0846.

B.11.3.5 Billing questions and disputes. sales@omnipacs.com. Disputed charges must be raised under Section B.9.9.6.

B.11.3.6 Privacy and HIPAA. support@omnipacs.com, with the subject line “PRIVACY REQUEST.” Individual-access, amendment and accounting requests from a Covered Entity are handled under Part C; requests from a Patient or Individual are handled under Part D. Breach notifications to OmniPACS are sent to support@omnipacs.com with the subject line “HIPAA BREACH NOTICE.”

B.11.3.7 Legal notices. Part A, Section A.15.

B.11.4 GOVERNMENT USERS

B.11.4.1 If you are a US federal, state, local or tribal government entity, or a public hospital or state university, the Platform is provided as “commercial computer software” and “commercial computer software documentation” under FAR 12.212 and DFARS 227.7202, and additional or conflicting terms required by applicable public-procurement law will be addressed in the Order Form. OmniPACS holds no FedRAMP authorization or state equivalent and makes no representation that the Platform meets any government security authorization requirement.

B.11.5 INSURANCE

B.11.5.1 Coverage OmniPACS carries. OmniPACS maintains, at its own expense, insurance with an insurer licensed to do business in the United States and rated A- or better by AM Best, at not less than the following limits:

CoverageLimit
Commercial general / business liability — each occurrence$2,000,000
General aggregate$4,000,000
Products and completed operations aggregate$4,000,000
Personal and advertising injury$2,000,000
Damage to premises rented$1,000,000
Medical expenses$10,000
Data breach — response expenses$50,000
Data breach — defense and liability$500,000
Data breach — business income and extra expense$10,000 (24-hour waiting period)
Data breach — extortion threats$10,000
Employment practices liability — each claim / aggregate$25,000 / $25,000

B.11.5.2 Coverage OmniPACS does not carry. OMNIPACS DOES NOT CARRY STANDALONE TECHNOLOGY ERRORS-AND-OMISSIONS INSURANCE, PROFESSIONAL LIABILITY INSURANCE OR MEDICAL MALPRACTICE INSURANCE, AND DOES NOT CARRY CYBER LIABILITY COVERAGE BEYOND THE DATA BREACH LIMITS STATED IN SECTION B.11.5.1. OMNIPACS IS UNDER NO OBLIGATION TO OBTAIN, INCREASE, EXTEND OR MAINTAIN ANY COVERAGE ABOVE THE LIMITS STATED IN SECTION B.11.5.1, AND NO PROVISION OF THIS AGREEMENT, AND NO ORDER FORM, REQUEST OR PROCUREMENT REQUIREMENT, OBLIGATES OMNIPACS TO DO SO.

B.11.5.3 Additional insured; waiver of subrogation. OmniPACS’ general liability coverage includes blanket additional insured status by written contract and a blanket waiver of subrogation. A Subscriber may be named as an additional insured on the general liability coverage on written request where a written agreement between the parties requires it.

B.11.5.4 Certificates. Certificates of insurance are furnished on written request to sales@omnipacs.com.

B.11.5.5 Insurance does not expand liability. THE EXISTENCE, LIMITS OR EXHAUSTION OF INSURANCE DOES NOT EXPAND OMNIPACS’ LIABILITY BEYOND THE CAPS IN SECTION B.7, WHICH CONTROL, and does not relieve either party of any obligation. Part C carries no insurance covenant; insurance is addressed only in this Section B.11.5.


B.12 DISPUTE RESOLUTION, GOVERNING LAW AND VENUE

This Section B.12 applies only to professional and organizational users. Dispute resolution for patients and individuals is in Part D, Section D.8.

B.12.1 Notice of dispute and executive escalation. Before commencing any proceeding (other than an action described in Section B.12.5), the party raising a dispute will give the other written notice describing the dispute and the relief sought. The parties’ senior business representatives (or, where one party is an individual, that individual) will confer in good faith to resolve the dispute within thirty (30) days of that notice. This is a condition precedent to filing, and the applicable limitations period is tolled during it.

B.12.2 Governing law. These Terms are governed by the laws of the State of New Jersey, without regard to its conflict-of-laws rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

B.12.3 Venue; jurisdiction; service. The state courts located in Monmouth County, New Jersey, and the United States District Court for the District of New Jersey, have exclusive jurisdiction and are the exclusive venue for any dispute not resolved under Section B.12.1. Each party irrevocably consents to the personal jurisdiction of those courts, waives any objection based on venue or forum non conveniens, and consents to service of process by nationally recognized overnight courier to the notice address in Part A, Section A.15.

B.12.4 Non-waivable rights preserved. Nothing in these Terms limits or waives any right or protection that cannot be waived under the law applicable to you, including state automatic-renewal statutes, state medical-records access statutes and state privacy and consumer-health-data statutes. Where such a law conflicts with these Terms, that law prevails to the extent of the conflict and only as to the affected provision.

B.12.5 Carve-outs. Either party may, without first completing Section B.12.1, seek injunctive or other equitable relief in any court of competent jurisdiction to protect its intellectual property or Confidential Information, to prevent or stop a security incident, or to enforce Section B.5.2.5 or Section B.9.16.4. OmniPACS may bring an action for collection of undisputed unpaid Fees in any court of competent jurisdiction, without first completing Section B.12.1.

B.12.6 Order Form override. An Order Form may specify a different governing law, venue or dispute-resolution procedure for a particular Subscriber, and that specification prevails over this Section B.12 for that Order Form.

B.12.7 JURY TRIAL WAIVER. EACH PARTY KNOWINGLY, VOLUNTARILY AND INTENTIONALLY WAIVES ANY RIGHT TO TRIAL BY JURY IN ANY PROCEEDING ARISING OUT OF OR RELATING TO THESE TERMS, THE PLATFORM OR THE RELATIONSHIP BETWEEN THE PARTIES. This waiver is mutual. It does not apply to a Patient or Individual, who is governed by Part D, Section D.8.

B.12.8 CLASS ACTION AND COLLECTIVE ACTION WAIVER. EACH PARTY AGREES THAT ANY DISPUTE WILL BE BROUGHT ONLY IN THAT PARTY’S INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF, CLASS MEMBER OR REPRESENTATIVE IN ANY PURPORTED CLASS, COLLECTIVE, CONSOLIDATED, PRIVATE ATTORNEY GENERAL OR REPRESENTATIVE PROCEEDING. THE PARTIES DO NOT CONSENT TO CLASS OR CONSOLIDATED TREATMENT OF ANY DISPUTE, AND NO COURT MAY CONSOLIDATE THE CLAIMS OF MORE THAN ONE ACCOUNT HOLDER WITHOUT ALL AFFECTED PARTIES’ WRITTEN CONSENT. If this Section B.12.8 is held unenforceable as to a particular claim, that claim is severed and litigated in court, and the remainder of this Section B.12 continues to apply. This waiver does not apply to a Patient or Individual, who is governed by Part D, Section D.8.

B.12.9 No arbitration. THIS AGREEMENT DOES NOT REQUIRE ARBITRATION. NEITHER PARTY IS OBLIGED TO ARBITRATE ANY DISPUTE, AND NO DISPUTE WILL BE SUBMITTED TO ARBITRATION UNLESS THE PARTIES AGREE TO DO SO IN A SEPARATE WRITTEN AGREEMENT SIGNED AFTER THE DISPUTE HAS ARISEN. Disputes are resolved by the courts identified in Section B.12.3, subject to Sections B.12.1, B.12.5, B.12.7 and B.12.8.

B.12.10 Prevailing party’s attorneys’ fees. In any proceeding between OmniPACS and a professional or organizational user arising out of or relating to these Terms, the prevailing party is entitled to recover its reasonable attorneys’ fees and costs, including the costs of collection. This Section does not apply to a Patient or Individual, and no fee award may be made against a Patient or Individual under these Terms.

B.12.11 Limitations period. The one (1) year limitations period in Section B.7.7 applies to every dispute governed by this Section B.12, to the maximum extent permitted by applicable law.


PART C — BUSINESS ASSOCIATE AGREEMENT

This Part applies only if you use the Platform in a professional or organizational capacity and Protected Health Information is created, received, maintained or transmitted through the Platform on behalf of your organization. If you are a patient or an individual using OmniPACS to look at your own images, or the images of someone you are legally allowed to act for, this Part does not apply to you at all — go to Part D. You will never be asked to sign a HIPAA contract. See Part C, Section C.5 and Part D, Section D.4.

How to read this Part. Part C is a complete HIPAA business associate agreement. It attaches automatically, through the same single acceptance that forms the rest of this Agreement, with no separate signature and no second step. Sections C.1 through C.6 explain how and when it attaches, who is bound, what happens if the person who accepted lacked authority, and how patient access and patient-uploaded content sit inside this Part C. Sections C.7 through C.31 are the business associate agreement itself, and satisfy each element required by 45 CFR 164.504(e).


C.1 WHEN THIS PART BECOMES A BUSINESS ASSOCIATE AGREEMENT

C.1.1 Automatic attachment; no separate signature. This Part C becomes a binding business associate agreement between OmniPACS and the Organization automatically, on the earlier of:

    (a) acceptance of this Agreement, in the manner described in Part A, Section A.2 and recorded under Part E, Section E.3, by any person acting for the Organization; or

    (b) the first upload, transmission, routing or other ingestion of Protected Health Information into an account held by, or administered for, the Organization, whether that ingestion occurs through the Platform interface, an API, a DICOM network service, OmniRouter, EPS-Pi, another Local Component, or an inbound share or forwarding rule.

No separate signature, countersignature, order form, purchase order, or execution of any other instrument is required for this Part C to take effect. The click that forms this Agreement forms this Part C at the same moment and by the same act.

C.1.2 “Organization.” For purposes of this Part C, “Organization” means the entity on whose behalf the accepting person acts — the hospital, health system, imaging center, radiology group, physician practice, mobile imaging provider, health plan, health care clearinghouse, or other entity whose Protected Health Information is or will be created, received, maintained or transmitted through the account. Where the accepting person acts for no entity — an individual practitioner in solo practice, an independent reading radiologist, or any other natural person who is themselves a Covered Entity or a Business Associate — the Organization is that individual in their professional capacity, and every reference in this Part C to the Organization is a reference to that individual acting professionally.

C.1.3 The Organization is the Covered Entity, or an Upstream Business Associate. The Organization is, and represents that it is, either (a) a Covered Entity under 45 CFR 160.103, or (b) a Business Associate of one or more Covered Entities. Section C.7.6 governs the second case.

C.1.4 OmniPACS is bound from first receipt of PHI. OmniPACS publishes this Part C, offers it to every user of the Platform, and accepts it as to every Organization. OmniPACS’ own obligations under this Part C bind OmniPACS from the moment it first creates, receives, maintains or transmits Protected Health Information for or on behalf of the Organization, and are not conditional on the Organization’s acceptance, on the authority of any accepting person, or on any signature. Section C.3.4 states the consequence.

C.1.5 Effect on the rest of the Agreement. This Part C does not create, modify or limit any commercial right or obligation. Fees, metering, billing, payment method, term, renewal, cancellation, suspension for non-payment, service levels, product warranties, licence grants, acceptable use, indemnity by the Organization, insurance, dispute resolution and the general limitation of liability are governed exclusively by Part A and Part B and are intentionally not addressed in this Part C. Nothing in this Part C is a licence to use the Platform, and nothing in this Part C obligates the Organization to pay any amount. No provision of this Agreement states that the Covered Services are provided free of charge, and any prior statement to that effect is superseded and of no effect; Fees are governed by Part B, Section B.9. Order of precedence is set in Part E, Section E.1.


C.2 AUTHORITY OF THE ACCEPTING PERSON

C.2.1 Representation. The person who accepts this Agreement on behalf of the Organization represents and warrants that they are authorized to bind the Organization to this Part C, and that they hold that authority at the time of acceptance.

C.2.2 What the acceptance flow records. Acceptance of this Agreement is recorded against the accepting person’s authenticated Platform account, together with the version of this Agreement accepted, the date and time of acceptance, and the network and device information available to OmniPACS at the time of acceptance. The acceptance record is retained and produced as described in Section C.30.2 and Part E, Section E.3.

By accepting this Agreement, the accepting person represents that they are authorized to bind the Organization to this Part C. OmniPACS may require written confirmation of that authority, signed by an officer or other authorized representative of the Organization, at any time.

C.2.3 Reliance. OmniPACS is entitled to rely on the representation in Section C.2.1 and on the acceptance record described in Section C.2.2. OmniPACS has no duty to investigate the accepting person’s actual authority, and no failure to investigate affects OmniPACS’ own obligations under this Part C, which bind OmniPACS regardless under Section C.1.4.

C.2.4 Notification of the Organization. On acceptance, OmniPACS sends the retainable acknowledgment email described in Part E, Section E.3, addressed to the accepting person and, where the account designates one, to the Organization’s privacy and security contact of record. That email, together with the permanent versioned link it contains, is the Organization’s copy of this Part C for its own HIPAA compliance file. The Organization may also obtain the acceptance record at any time under Section C.30.2.


C.3 IF THE ACCEPTING PERSON HAD NO AUTHORITY

This Section is the fallback. It preserves as much of the protection this Part C provides as the law permits, in the case where the person who clicked was not in fact authorized to bind their employer.

C.3.1 Personal binding of the accepting individual. Where the accepting person did not hold authority to bind the Organization, that individual is personally bound by this Part C in their own capacity, to the extent that they are themselves a Covered Entity or a Business Associate — for example, a licensed practitioner in solo or independent practice, an independent contractor reading radiologist, or any other natural person who is a Covered Entity or Business Associate under 45 CFR 160.103. In that case the accepting individual is the Organization for purposes of this Part C under Section C.1.2, and this Part C is a valid business associate agreement between OmniPACS and that individual with respect to Protected Health Information that individual causes to be submitted to the Platform. Where the accepting individual is not themselves a Covered Entity or a Business Associate, this Section C.3.1 imposes no personal HIPAA obligation on them.

C.3.2 Ratification by the Organization. The Organization is bound by this Part C by ratification where, after the initial acceptance:

    (a) the Organization continues to use the Platform, or continues to permit Protected Health Information to be submitted to or maintained in the account, with knowledge of the arrangement — including where the Organization has received the acknowledgment email under Section C.2.4, has received an invoice, notice or report referencing this Agreement, has had an administrator, compliance officer, privacy officer or officer access the account, or has otherwise had actual or constructive notice that the Platform is being used with its Protected Health Information; or

    (b) any person who does hold authority to bind the Organization later accepts this Agreement, accepts a subsequent version of it, executes an Order Form referencing it, or confirms the arrangement in writing.

Ratification under this Section C.3.2 binds the Organization to this Part C from the date of the original acceptance or of first PHI ingestion, whichever is earlier, so that there is no gap in coverage.

C.3.3 Suspension of new PHI ingestion — and what is never suspended. Where OmniPACS learns that the representation in Section C.2.1 was untrue, or receives written notice from the Organization disclaiming the acceptance, OmniPACS may suspend the ingestion of new Protected Health Information into the affected account until a person with authority to bind the Organization accepts this Agreement.

    (a) OmniPACS will not, under any circumstances, suspend, restrict, degrade, delay, throttle to unusability, encrypt against or terminate the Organization’s ability to search, retrieve, view, open or export Protected Health Information already held in the account, or the ability of any person to retrieve PHI as necessary to satisfy an individual’s right of access under 45 CFR 164.524, or access needed for continuity of patient care. This is the access floor in Part B, Section B.9.16.4, and it controls over this Section C.3.3 and over every other provision of this Agreement.

    (b) OmniPACS will give written notice of any suspension under this Section C.3.3 to the account administrators and to the Organization’s privacy and security contact of record as soon as practicable, will scope the suspension as narrowly as reasonably possible, and will lift it immediately on acceptance by an authorized person.

    (c) A dispute about authority is never a security incident and is never a ground for withholding data.

C.3.4 OmniPACS’ obligations bind regardless. Nothing in this Section C.3 limits, suspends, conditions or defers any obligation of OmniPACS under this Part C. Every obligation OmniPACS owes with respect to Protected Health Information — the use and disclosure limits in Section C.9, the safeguards in Section C.11, the reporting obligations in Section C.17, the subcontractor flow-down in Section C.15, individual-rights support in Section C.19, Secretary access in Section C.23, and return or destruction in Section C.27 — binds OmniPACS from first receipt of Protected Health Information, whether or not the accepting person held authority, whether or not the Organization ratifies, and whether or not this Part C is ever accepted by an authorized person. The Organization, and the Covered Entity on whose behalf the Organization acts, may rely on those obligations accordingly.

C.3.5 No adverse inference. OmniPACS’ exercise, or non-exercise, of any right under this Section C.3 is not an admission that a business associate agreement is absent, and is not a defence to any obligation of OmniPACS under this Part C or under the HIPAA Rules.


C.4 A SEPARATELY EXECUTED BAA SUPERSEDES THIS PART

C.4.1 The invitation. OmniPACS welcomes a separately executed business associate agreement and will execute one on request, on the Organization’s paper or on OmniPACS’ own. An Organization that requires its own form, or a countersigned copy for its compliance file, should contact OmniPACS at support@omnipacs.com. Nothing in this Agreement discourages, conditions or delays that request, no request for an executed business associate agreement delays or conditions access to the Platform, and OmniPACS charges no fee for it.

C.4.2 Supersession. Where OmniPACS and the Organization execute a business associate agreement signed by both parties — whether on OmniPACS’ paper or on the Organization’s paper, and whether executed before or after acceptance of this Agreement — that executed agreement replaces this Part C in full with respect to that Organization, from its stated effective date, and this Part C ceases to apply to that Organization except as to Protected Health Information and periods the executed agreement does not cover.

C.4.3 Precedence. An executed business associate agreement under this Section C.4 occupies the position of Part C in the order of precedence in Part E, Section E.1, at the highest level, as to the use, disclosure and safeguarding of Protected Health Information.

C.4.4 No gap. Where an executed business associate agreement is signed after Protected Health Information has already been submitted to the Platform, this Part C governs the period before the executed agreement’s effective date, so that there is no period in which Protected Health Information was held without a business associate agreement in place.

C.4.5 Interim effect. The pendency of a negotiation under this Section C.4 does not suspend this Part C. This Part C remains in force until an executed agreement takes effect.


C.5 PATIENTS AND INDIVIDUALS ARE NEVER PARTIES

C.5.1 Parties. The only parties to this Part C are OmniPACS and the Organization. A patient, research subject, personal representative or other Individual whose Protected Health Information is processed in the Platform is not a party to this Part C and cannot enter into one.

C.5.2 Why. HIPAA does not contemplate a business associate agreement with an Individual. A business associate agreement is the written contract required between a Covered Entity and its vendor under 45 CFR 164.504(e); the Individual is the person the contract protects, not a contracting party. This is definitional under 45 CFR 160.103, not a drafting choice.

C.5.3 A patient’s acceptance of this Agreement does not bind them to this Part C. A Patient or Individual who accepts this Agreement accepts Part A and Part D only. Accepting this Agreement does not make a Patient or Individual a party to this Part C, does not make them a Covered Entity or a Business Associate, and does not subject them to any obligation in this Part C. OmniPACS will not ask a patient to sign a business associate agreement. See Part D, Section D.4.

C.5.4 Where a patient’s rights live instead. Individuals who access the Platform are bound by Part A and Part D. Their rights with respect to Protected Health Information held for the Organization are exercised through the Organization in accordance with Section C.19. Nothing in this Section C.5 limits any right an Individual holds under HIPAA or other applicable law, or any obligation OmniPACS owes to the Organization under Section C.19.

C.5.5 No third-party beneficiaries. Nothing in this Part C creates any right of action in any Individual or other third party. See Part E, Section E.4.


C.6 PATIENT ACCESS AND PATIENT-UPLOADED CONTENT

C.6.1 Patient access arises through a provider relationship. An Individual reaches the Platform only through the relationship between that Individual and the Organization — including provider-initiated study sharing, patient-access links generated from an Organization account, and Disclosures made to satisfy the Organization’s obligations under 45 CFR 164.524. In every such case OmniPACS acts as a Business Associate of the Individual’s health care provider, and that Protected Health Information remains subject to this Part C in full.

C.6.2 Patient-Uploaded Content is Protected Health Information under this Part C. An Individual with provider-linked access may also upload their own prior imaging and related records, including imaging supplied to them on a compact disc or other portable media. Patient-Uploaded Content is received and handled as Protected Health Information under this Part C, on behalf of the Organization whose relationship gave the Individual access, and is subject to the same safeguards under Section C.11 and Exhibit C-1, the same access controls, the same audit logging, and the same Security Incident, impermissible-use and Breach reporting obligations under Section C.17, as Studies supplied by the Organization. Nothing in this Section C.6.2 makes an Individual a party to this Part C; Section C.5 continues to govern.

C.6.3 No standalone patient-controlled account. OmniPACS does not offer a standalone, patient-controlled account that exists independently of a health care provider relationship, and an Individual cannot obtain Platform access without one. If OmniPACS in future offers a direct-to-individual service in which an Individual holds their own account, that service will be governed by separate terms and a separate notice published before it launches, and this Part C will not be the instrument that governs it. Nothing in this Section C.6.3 is a commitment to offer such a service, and nothing in it diminishes any protection owed to the Organization’s Protected Health Information under this Part C. Patient-facing terms are in Part D.


C.7 SCOPE, COVERED SERVICES AND EXCLUDED SERVICES

C.7.1 Subject matter. This Part C governs OmniPACS’ creation, receipt, maintenance, transmission, use and disclosure of Protected Health Information in connection with the Covered Services. OmniPACS provides cloud-based medical image management services — ingestion, storage, indexing, worklist management, search, sharing, distribution, reporting and export of DICOM studies. In performing them OmniPACS creates, receives, maintains and transmits Protected Health Information on the Organization’s behalf and is therefore a Business Associate under 45 CFR 160.103.

C.7.2 Cloud provider status acknowledged. The parties acknowledge that a cloud service provider that maintains electronic Protected Health Information on behalf of a Covered Entity is a business associate even where it maintains only encrypted electronic Protected Health Information and does not hold the decryption key, and that such a provider is both contractually liable under this Part C and directly liable under the HIPAA Rules.

C.7.3 Purpose. This Part C is entered into to satisfy 45 CFR 164.502(e), 164.504(e), 164.308(b) and 164.314(a), and to allocate responsibilities relating to Protected Health Information between the parties.

C.7.4 Covered Services. Protected Health Information may be submitted to, processed in and stored in only the following OmniPACS products, modules and features (the “Covered Services“):

    (a) the OmniPACS cloud platform, including DICOM study ingestion, archive and storage, worklist and search, study sharing and distribution, patient records, reports, notifications, and study export and media creation;
    (b) OmniRouter, the local DICOM relay agent, and EPS-Pi, the Enterprise PACS Server, in each case as configured for transmission to and from the OmniPACS cloud platform;
    (c) the CHILI third-party diagnostic viewer, accessed through OmniPACS signed ticket URLs, as a named Subprocessor under Section C.15; and
    (d) such additional products, modules or features as OmniPACS designates in writing as Covered Services, provided that OmniPACS will not withdraw that designation with respect to the Organization on less than thirty (30) days’ prior written notice.

C.7.5 Excluded Services and prohibited channels. The Organization will not submit, and will instruct its Users not to submit, Protected Health Information to:

    (a) support tickets, chat sessions, the in-application support widget, email to OmniPACS support addresses, or any other support channel. No OmniPACS support channel is a Covered Service and none is eligible to receive Protected Health Information;
    (b) free-text fields not designated for clinical content, including account names, User profile fields, institution display labels, ticket subject lines and support attachments;
    (c) any feature designated alpha, beta, preview, early access or evaluation, including UDE (Universal Diagnostic Environment), which is distributed as a pre-release evaluation build and is not a Covered Service, unless OmniPACS has expressly confirmed in writing that the feature is a Covered Service; or
    (d) any OmniPACS product, module or feature not listed in Section C.7.4.

This Section C.7.5 is a channel restriction, not a general commercial covenant; the Organization’s broader configuration and secure-transmission obligations sit in Part B, Section B.3 and Part B, Section B.4. See Section C.22.5.

C.7.6 Upstream Business Associate. Where the Organization is a Business Associate rather than a Covered Entity, OmniPACS is the Organization’s Subcontractor within the meaning of 45 CFR 160.103, this Part C is the written contract required by 45 CFR 164.504(e)(5) and 164.314(a)(2)(iii), and each reference in this Part C to “Covered Entity” is read as a reference to the Organization in its capacity as a Business Associate, with the obligations and restrictions flowing through accordingly.

C.7.7 No diagnostic or medical device representation. This Part C makes no representation regarding the regulatory status or intended use of the Platform. Intended use, diagnostic-use limitations and any statement regarding clearance or classification are addressed exclusively in Part A, Section A.9 and Part B, Section B.4 and in product documentation. Nothing in this Part C authorizes use of the Platform as a medical device, for primary diagnostic interpretation, or to generate a diagnosis.


C.8 DEFINITIONS USED IN THIS PART

The consolidated definitions table for the whole Agreement is in Part E, Section E.2. The following are the HIPAA-specific and imaging-specific terms this Part C relies on, and control within this Part C.

C.8.1 HIPAA-defined terms. Capitalized terms used but not otherwise defined have the meaning given in the HIPAA Rules. Without limiting the foregoing: Breach (45 CFR 164.402); Business Associate (45 CFR 160.103); Covered Entity (45 CFR 160.103); Data Aggregation (45 CFR 164.501); Designated Record Set (45 CFR 164.501); Disclosure (45 CFR 160.103); Electronic Protected Health Information or ePHI (45 CFR 160.103); Health Care Operations (45 CFR 164.501); Individual (45 CFR 160.103), including a personal representative under 45 CFR 164.502(g); Limited Data Set (45 CFR 164.514(e)(2)); Minimum Necessary (45 CFR 164.502(b) and 164.514(d)); Notice of Privacy Practices (45 CFR 164.520); Protected Health Information or PHI (45 CFR 160.103), limited to PHI created, received, maintained or transmitted by OmniPACS on behalf of the Organization; Required By Law (45 CFR 164.103); Secretary (45 CFR 160.103); Security Incident (45 CFR 164.304); Subcontractor (45 CFR 160.103); Unsecured Protected Health Information or Unsecured PHI (45 CFR 164.402); Use (45 CFR 160.103).

C.8.2 Additional defined terms.

    (a) “Aggregate Data” means statistical, operational and performance data derived from use of the Platform that does not identify, and cannot reasonably be used to identify, any customer, facility, Individual or Study, and that contains no PHI.
    (b) “Contingency Plan Activation” means OmniPACS’ formal invocation of its documented contingency, disaster recovery or business continuity plan with respect to a production environment in which the Organization’s PHI is maintained.
    (c) “De-Identify” and “De-Identified” mean the removal of identifiers from PHI so that the information is not individually identifiable health information, in accordance with 45 CFR 164.514(a) and either the safe-harbor method at 45 CFR 164.514(b)(2) or the expert-determination method at 45 CFR 164.514(b)(1), and, for imaging data, in accordance with Section C.13.2.
    (d) “DICOM” means the Digital Imaging and Communications in Medicine standard published by the National Electrical Manufacturers Association, as amended.
    (e) “DICOM Part 10” means the DICOM File Format and media storage encoding specified in DICOM PS3.10.
    (f) “Discovery” of a Breach or Security Incident has the meaning given in 45 CFR 164.410(a)(2): the first day on which the Breach is known, or by exercising reasonable diligence would have been known, to any person, other than the person committing the Breach, who is an employee, officer or other agent of OmniPACS.
    (g) “HIPAA Rules” means the Administrative Simplification provisions of the Health Insurance Portability and Accountability Act of 1996, as amended by HITECH and Subtitle D of the American Recovery and Reinvestment Act of 2009, and the implementing regulations at 45 CFR Parts 160, 162 and 164, including Subpart C of Part 164 (the “Security Rule“), Subpart D of Part 164 (the “Breach Notification Rule“) and Subpart E of Part 164 (the “Privacy Rule“), each as amended.
    (h) “PHI Incident” means any Security Incident that is not an Unsuccessful Security Incident, any Breach, and any Use or Disclosure of PHI not permitted by this Part C.
    (i) “Study” means a set of one or more DICOM Objects sharing a single DICOM Study Instance UID (0020,000D), together with the associated study-, series- and instance-level metadata maintained by the Covered Services.
    (j) “Study Instance UID” means the DICOM attribute (0020,000D) that uniquely identifies a Study.
    (k) “Subprocessor” means a Subcontractor that creates, receives, maintains or transmits PHI on OmniPACS’ behalf in connection with the Covered Services.
    (l) “Unsuccessful Security Incident” means a Security Incident that does not result in unauthorized access to, acquisition of, use of, disclosure of, modification of or destruction of PHI, or interference with system operations in an information system containing PHI, including: pings and other broadcast attacks on a firewall; port scans; unsuccessful attempts to log on to a system or to access PHI; denial-of-service attacks that do not result in a system being taken offline; malware and phishing attempts blocked or quarantined by security controls; and packet sniffing that does not result in access to PHI beyond the header information used for routing.
    (m) “User” means an individual authorized by the Organization to access the Covered Services under the Organization’s account.
    (n) “Patient-Uploaded Content” means imaging and related records that an Individual uploads into the provider-linked access described in Section C.6.1. Patient-Uploaded Content is PHI received and maintained by OmniPACS on behalf of the Organization and is within the definition of PHI in Section C.8.1 for every purpose of this Part C.

C.8.3 Regulatory references. A reference to a section of the HIPAA Rules or other law means the section as in effect or as amended from time to time, including any successor provision.

C.8.4 Interpretation. Any ambiguity in this Part C is resolved in favor of a meaning that permits the parties to comply with the HIPAA Rules. Headings are for convenience only. “Including” means “including without limitation.” “Days” means calendar days unless “business days” is specified; “business day” means a day other than a Saturday, Sunday or federal public holiday in the United States.


C.9 PERMITTED AND REQUIRED USES AND DISCLOSURES OF PHI

Element required by 45 CFR 164.504(e)(2)(i) and 164.504(e)(2)(ii)(A).

C.9.1 General limitation — no further use or disclosure. OmniPACS will not Use or Disclose PHI other than as permitted or required by this Part C or as Required By Law. OmniPACS will not Use or Disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by the Organization, except as permitted by Sections C.9.3, C.9.4 and C.13 in reliance on 45 CFR 164.504(e)(2)(i)(A)–(B) and 164.504(e)(4).

C.9.2 Performance of the Covered Services. OmniPACS may Use and Disclose PHI as necessary to perform, deliver, support, maintain, monitor, secure, troubleshoot and improve the Covered Services for the Organization, including: ingestion, validation, indexing, storage, replication and backup of Studies; worklist, search and retrieval functions; transmission and sharing of Studies to recipients designated by the Organization or its Users; report and record management; generation of export media; audit logging; and provision of technical support, including through impersonation of a User where such access is initiated on documented instruction of the Organization and logged in accordance with Exhibit C-1.

C.9.3 Management, administration and legal responsibilities. OmniPACS may Use PHI as necessary for its own proper management and administration and to carry out its legal responsibilities. OmniPACS may Disclose PHI for those purposes only if the Disclosure is Required By Law or if OmniPACS obtains, prior to the Disclosure, reasonable assurances from the recipient, evidenced in writing, that the PHI will be held confidentially and Used or further Disclosed only as Required By Law or for the purpose for which it was disclosed, and that the recipient will notify OmniPACS of any instance of which it becomes aware in which the confidentiality of the PHI has been breached. OmniPACS will notify the Organization of any such Disclosure to the extent it involves the Organization’s PHI and is not prohibited by law.

C.9.4 Data Aggregation. OmniPACS may Use and Disclose PHI to provide Data Aggregation services relating to the Health Care Operations of the Organization, as permitted by 45 CFR 164.504(e)(2)(i)(B).

C.9.5 De-Identification. OmniPACS may De-Identify PHI only as expressly permitted by Section C.13.

C.9.6 Required By Law. OmniPACS may Use and Disclose PHI as Required By Law, subject to Section C.21.

C.9.7 Minimum Necessary. OmniPACS will, in its Use and Disclosure of, and in its requests for, PHI, limit the PHI to the Minimum Necessary to accomplish the intended purpose, consistent with 45 CFR 164.502(b) and 164.514(d) and with HITECH § 13405(b), and will use a Limited Data Set where practicable and sufficient. OmniPACS reasonably relies on the Organization’s configuration of the Covered Services, its role and permission assignments, and its instructions in determining what constitutes the Minimum Necessary for a Use or Disclosure initiated by the Organization or its Users.

C.9.8 Prohibited activities. OmniPACS will not:

    (a) sell PHI or receive direct or indirect remuneration in exchange for PHI, within the meaning of 45 CFR 164.502(a)(5)(ii) and HITECH § 13405(d);
    (b) Use or Disclose PHI for marketing or fundraising, within the meaning of 45 CFR 164.501, 164.508(a)(3) and 164.514(f), without a valid authorization obtained by the Organization;
    (c) Use or Disclose genetic information for underwriting purposes, within the meaning of 45 CFR 164.502(a)(5)(i);
    (d) attempt to re-identify, or permit any third party to attempt to re-identify, information OmniPACS has De-Identified, or contact any Individual whose information is contained in De-Identified information, except as necessary to perform the Covered Services or at the Organization’s written direction; or
    (e) Use or Disclose PHI to train, fine-tune, evaluate, validate or otherwise develop or improve any artificial intelligence or machine learning model, except as expressly permitted by Section C.14.

C.9.9 Compliance with the Organization’s obligations. To the extent OmniPACS is to carry out an obligation of the Organization under Subpart E of 45 CFR Part 164, OmniPACS will comply with the requirements of Subpart E that apply to the Organization in the performance of that obligation, as required by 45 CFR 164.504(e)(2)(ii)(H). The parties do not intend for OmniPACS to carry out any such obligation except as expressly stated in this Part C or as separately agreed in writing.

C.9.10 Direct liability. OmniPACS acknowledges that, as a Business Associate, it is directly liable under the HIPAA Rules and subject to civil and, in some cases, criminal penalties for Uses and Disclosures of PHI not authorized by this Part C or Required By Law, and for failing to safeguard ePHI in accordance with the Security Rule.


C.10 DATA OWNERSHIP AND NO RIGHTS CONFERRED

C.10.1 Ownership. As between the parties, the Organization or the applicable Individual, referring provider or upstream covered entity retains all right, title and interest in and to PHI and Studies submitted to the Covered Services. OmniPACS’ role is that of a steward of PHI on the Organization’s behalf. Possession, hosting, indexing, replication or processing of PHI confers no ownership right, licence or other proprietary interest, and OmniPACS acquires no rights in PHI except the limited rights expressly granted in Sections C.9, C.13 and C.14. See also Part A, Section A.7.

C.10.2 No lien. OmniPACS will not assert or exercise any lien, retention right or right of set-off over PHI or Studies, including for non-payment. Consequences of non-payment, including suspension and termination, are governed by Part B, Section B.9, subject to the access floor in Part B, Section B.9.16.4, and OmniPACS’ obligations under Sections C.20, C.25 and C.27 apply notwithstanding any payment dispute.


C.11 SAFEGUARDS AND SECURITY PROGRAM

Element required by 45 CFR 164.504(e)(2)(ii)(B) and 164.314(a)(2)(i)(A).

C.11.1 Security Rule compliance. OmniPACS will Use appropriate administrative, physical and technical safeguards, and will comply with Subpart C of 45 CFR Part 164 with respect to ePHI, to prevent Use or Disclosure of PHI other than as provided for by this Part C.

C.11.2 Risk analysis and risk management. OmniPACS will conduct and document an assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of ePHI it holds, in accordance with 45 CFR 164.308(a)(1)(ii)(A), and will implement security measures sufficient to reduce identified risks to a reasonable and appropriate level under 45 CFR 164.308(a)(1)(ii)(B). OmniPACS will maintain the documentation for at least six years.

C.11.3 Security Program commitments. Without limiting Section C.11.1, OmniPACS will maintain, throughout the term, an information security program that includes the controls described in Exhibit C-1 (Security Program), which is part of this Part C.

C.11.4 Amendment of Exhibit C-1. OmniPACS may update Exhibit C-1 from time to time provided that no update materially reduces the protections afforded to PHI. OmniPACS will give at least thirty (30) days’ notice of any material change to Exhibit C-1, and will update it as necessary to reflect the Security Rule as amended.

C.11.5 Workforce. OmniPACS will train its workforce members with access to PHI on their obligations under the HIPAA Rules and this Part C, will require each workforce member with access to PHI to be bound by confidentiality obligations at least as protective as those in this Part C, and will apply appropriate sanctions for non-compliance, in accordance with 45 CFR 164.308(a)(1)(ii)(C), 164.308(a)(3) and 164.308(a)(5).

C.11.6 Where the Organization’s own responsibilities sit. The Organization’s obligations to configure the Covered Services, provision and de-provision Users, assign roles and permissions, safeguard credentials, and secure its own networks and Local Components are set out in Part B, Section B.3 and Part B, Section B.4, and are not restated here. OmniPACS is not responsible for PHI that does not reach the Covered Services because of a failure of the Organization’s network, equipment or on-premises software.

C.11.7 Patient-Uploaded Content is inside the safeguards. The safeguards required by this Section C.11 and Exhibit C-1 apply to Patient-Uploaded Content as defined in Section C.8.2(n) in the same way, and to the same extent, as they apply to Studies the Organization submits. OmniPACS does not review, validate, verify, interpret, correct or confirm the accuracy, completeness, provenance or clinical relevance of Patient-Uploaded Content, and no OmniPACS clinician examines it; that limitation is a limitation on clinical review only and does not reduce any safeguard, access control, audit-logging or reporting obligation OmniPACS owes in respect of that content. See Part A, Section A.9.


C.12 RETENTION AND AVAILABILITY OF STUDIES

C.12.1 No hard-copy retention. OmniPACS does not, and will not, create or maintain printed, film or other hard-copy reproductions of PHI or Studies as a retention or continuity measure. Any prior or superseded commitment by OmniPACS to maintain hard copies of customer information, including any commitment to hold hard copies for seven years at two separate locations, is superseded and of no effect. Hard-copy or non-DICOM reproduction of imaging data is inconsistent with the requirement under the Mammography Quality Standards Act that original mammograms be retained in retrievable form in the modality in which they were produced and not be produced by copying or digitizing hardcopy originals (21 CFR 900.12(c)(4)), and with the ACR–AAPM–SIIM technical standard’s warning that proprietary or non-DICOM formats impede the viewing, processing and migration of imaging data.

C.12.2 Electronic retention. OmniPACS will retain each Study submitted to the Covered Services in electronic, DICOM-conformant form for the duration of the Organization’s subscription (the “Contract Retention Period“). Absent an Order Form specifying a longer period, OmniPACS has no obligation to retain Studies or other Customer Data beyond the subscription term. Extended retention is available only where ordered, and is chargeable at OmniPACS’ then-current published rate, which is cost-based. Retention and deletion mechanics are otherwise governed by Part B, Section B.9.

C.12.3 No silent deletion. During the Contract Retention Period, OmniPACS will not delete, purge, overwrite or otherwise render unavailable any Study, except: (a) on documented instruction of the Organization; (b) as expressly permitted by Section C.27 following termination; or (c) as Required By Law. OmniPACS will give at least sixty (60) days’ prior written notice and a reasonable export window before any change in storage tiering, media or architecture that would materially affect the availability or retrieval time of Studies.

C.12.4 Backups, restoration and processing locations. OmniPACS maintains encrypted backups of Studies and associated metadata, retained for thirty-five (35) days, and maintains retrievable copies of ePHI in accordance with 45 CFR 164.308(a)(7)(ii)(A). OmniPACS will use commercially reasonable efforts to restore service and data as promptly as practicable following a loss. OMNIPACS DOES NOT WARRANT ANY RECOVERY POINT OBJECTIVE OR ANY RECOVERY TIME OBJECTIVE.

    (a) The Platform is hosted on third-party cloud infrastructure. OmniPACS does not warrant that PHI or other Customer Data will be stored or processed in any particular country or region, and will identify the regions then in use on written request, subject to a confidentiality undertaking. An Organization with a data-residency requirement must obtain a written commitment to that effect in an Order Form.

    (b) Where PHI is processed outside the United States, OmniPACS will, and will cause the relevant Subprocessor to, submit to the jurisdiction of the Secretary and of the courts of the United States with respect to that processing, and will not assert any defence based on lack of jurisdiction.

C.12.5 Contingency Plan Activation notice. OmniPACS will notify the Organization without unreasonable delay of any Contingency Plan Activation affecting a production environment in which the Organization’s PHI is maintained. This obligation is independent of, and in addition to, the reporting obligations in Section C.17, and such a notice is not itself an admission that a Security Incident or Breach has occurred.

C.12.6 The Organization determines its own legally required retention period. The parties acknowledge that:

    (a) the retention period legally applicable to a medical imaging record is the longest of any applicable federal, state and local requirement and varies by jurisdiction, program and modality — CMS hospital conditions of participation require medical records to be retained in original or legally reproduced form for at least five years (42 CFR 482.24(b)(1)); MQSA requires retention of original mammograms and reports for the longest of not less than five years, not less than ten years where no additional mammograms of the patient are performed at the facility, or any period mandated by state or local law (21 CFR 900.12(c)(4)); and New Jersey requires treatment records to be maintained for seven years from the date of the most recent entry and mammography images for seven years from issuance of the last interpretation report (N.J.A.C. 13:35-6.5(b); 13:35-2.6(h)(3));
    (b) the Organization, and not OmniPACS, is responsible for determining the retention period required by its own licensure, accreditation, payer and jurisdictional obligations, for maintaining a written record retention policy, and for ordering or configuring retention that satisfies that period; and
    (c) OmniPACS’ Contract Retention Period is a contractual commitment and is not a representation that it satisfies any particular legal retention requirement applicable to the Organization.

C.12.7 Legal holds. On receipt of written notice that specified Studies or PHI are subject to a litigation hold, government investigation or other preservation obligation, OmniPACS will suspend deletion of the identified PHI and preserve it until the hold is released in writing. Where the hold requires retention beyond the Contract Retention Period, the extended retention is chargeable at OmniPACS’ then-current published rate, which is cost-based.


C.13 DE-IDENTIFICATION AND AGGREGATE ANALYTICS

C.13.1 No de-identification for OmniPACS’ own purposes. OmniPACS reserves no right to De-Identify the Organization’s PHI for its own purposes. OmniPACS will De-Identify PHI only (a) on the Organization’s documented instruction, or (b) as otherwise permitted by 45 CFR 164.502(d) and 164.514(a)–(c) in the course of performing the Covered Services for the Organization. Any De-Identification performed under this Section C.13.1 uses either the safe-harbor method at 45 CFR 164.514(b)(2) or an expert determination under 45 CFR 164.514(b)(1).

C.13.2 Imaging-specific De-Identification requirements. Because DICOM data carries identifiers inside the file itself, any De-Identification performed under Section C.13.1 will address, at a minimum:

    (a) all DICOM header attributes containing or capable of containing identifiers listed in 45 CFR 164.514(b)(2)(i), including patient name, patient ID, other patient IDs, patient birth date, accession number and its issuing authority, referring, consulting and reading physician names, institution name and address, device serial numbers, study, series and instance UIDs where replacement is required, and all dates other than year;
    (b) private and vendor-specific DICOM attributes, curve and overlay data, and structured report content;
    (c) pixel data containing burned-in annotation, including patient identifiers rendered into the image by the acquiring modality, ultrasound and nuclear medicine screen captures, and secondary capture objects; and
    (d) associated non-DICOM artifacts, including report text, worklist metadata and audit records.

C.13.3 Permitted uses of De-Identified information. Information De-Identified under Section C.13.1 is no longer PHI, and OmniPACS will Use and Disclose it only for the purpose for which the Organization directed the De-Identification, or as necessary to perform the Covered Services, subject to the following limitations:

    (a) OmniPACS will not attempt, and will not permit any third party to attempt, to re-identify the information or contact any Individual;
    (b) OmniPACS will not Disclose De-Identified information derived from the Organization’s PHI to any third party in a form that identifies the Organization or any of its facilities, or from which either could reasonably be identified, without the Organization’s prior written consent;
    (c) OmniPACS will contractually prohibit re-identification by any recipient; and
    (d) OmniPACS will not Use De-Identified information derived from the Organization’s PHI to train or develop any artificial intelligence or machine learning model, except as permitted by Section C.14.

C.13.4 Aggregate Data. OmniPACS may generate and Use Aggregate Data for platform capacity planning, performance and reliability engineering, security analytics, billing verification and product development. Aggregate Data is derived from operational and usage metadata, contains no PHI, and does not include any data set from which a single customer, facility, Individual or Study could reasonably be identified.

C.13.5 Boundary. De-Identified information and Aggregate Data are not PHI, and Section C.27 (return and destruction) does not apply to them, provided OmniPACS complies with Sections C.13.2 and C.13.3. Nothing in this Section C.13 permits OmniPACS to Use a Limited Data Set as though it were De-Identified information; a Limited Data Set remains PHI.


C.14 ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING

C.14.1 No training on PHI. OmniPACS does not Use, and will not permit any Subprocessor or other third party to Use, the Organization’s PHI, Studies, pixel data, DICOM metadata, reports or audit records to train, fine-tune, retrain, evaluate, validate, benchmark or otherwise develop or improve any artificial intelligence or machine learning model, algorithm or foundation model, whether OmniPACS’ own or any third party’s, except with the Organization’s separate, specific, written consent identifying the model, the purpose, the data categories involved, and the retention and deletion terms.

C.14.2 No cross-customer models. No model, weights, embeddings, gradients, indices or derived parameters trained or tuned on the Organization’s PHI with consent under Section C.14.1 will be Used to serve, or made available to, any other customer or third party.

C.14.3 Enumerated AI features. No feature of the Covered Services processes PHI through an artificial intelligence or machine learning component as of the Effective Date. OmniPACS will not enable an AI or machine learning feature that processes the Organization’s PHI without at least thirty (30) days’ prior notice and, where the feature involves a Use described in Section C.14.1, the Organization’s written consent.

C.14.4 No PHI in third-party AI services. OmniPACS will not transmit PHI to any third-party artificial intelligence or machine learning service unless that service is a named Subprocessor under Section C.15, is bound by a business associate agreement, and is configured so that PHI is not retained for abuse monitoring, human review or model improvement beyond what is necessary to provide the service.

C.14.5 No diagnostic inference. OmniPACS will not Use PHI to generate a diagnosis, a differential diagnosis or a clinical interpretation, or to represent any output of the Covered Services as a diagnostic finding, except as expressly permitted by Part A, Section A.9, Part B, Section B.4 and applicable product labeling. Any AI-assisted worklist ordering or triage output is a workflow aid and is not a clinical determination.

C.14.6 Logging and retention of AI processing. Where an AI feature processes PHI, OmniPACS will maintain audit records sufficient to support Section C.19.5 (accounting of disclosures) and Section C.24 (compliance evidence), and will retain prompts, intermediate representations and outputs containing PHI only for the period necessary to deliver the feature.


C.15 SUBCONTRACTORS AND SUBPROCESSORS

Element required by 45 CFR 164.502(e)(1)(ii), 164.504(e)(2)(ii)(D), 164.308(b)(2) and 164.314(a)(2)(i)(B) and (a)(2)(iii).

C.15.1 Flow-down. OmniPACS will ensure that each Subprocessor agrees in writing, before receiving access to PHI, to restrictions, conditions and obligations with respect to PHI that are at least as protective as those that apply to OmniPACS under this Part C, including compliance with Subpart C of 45 CFR Part 164 with respect to ePHI, reporting of Security Incidents and Breaches to OmniPACS, and return or destruction of PHI on termination with no retained copies. Where a Subprocessor creates, receives, maintains or transmits PHI, that written agreement includes a business associate agreement.

C.15.2 Responsibility. OmniPACS remains responsible to the Organization for the acts and omissions of its Subprocessors with respect to PHI to the same extent as for its own.

C.15.3 Named Subprocessors. OmniPACS maintains a current list of Subprocessors, including each Subprocessor’s name and function, at https://omnipacs.com/legal/subprocessors. As of the Effective Date, the Subprocessors that create, receive, maintain or transmit PHI are:

SubprocessorFunctionPHI processed
Amazon Web Services, Inc.Cloud hosting, storage, compute, queueing and serverless computeStudies, DICOM metadata, reports, audit logs
Google LLC (Firebase)Authentication and push notification deliveryAccount identifiers and notification payloads
CHILI GmbHThird-party diagnostic viewer accessed by signed ticket URLStudies and DICOM metadata rendered for viewing

The following Subprocessors support the Platform and are configured so that PHI is not transmitted to them: Sentry (application error tracking), New Relic (application performance monitoring), Intercom (in-application engagement and support), and Google Workspace (transactional and business email). OmniPACS does not permit PHI to be transmitted to Stripe, Maxio/Chargify or GoHighLevel, which process billing, subscription and customer-relationship data only. Where any of these providers does process PHI, OmniPACS will bring it within the list above and will maintain a business associate agreement with it under Section C.15.1.

C.15.4 Change notice. OmniPACS will notify the Organization of any addition of, or material change in the role of, a Subprocessor that processes PHI at least thirty (30) days before that Subprocessor begins processing the Organization’s PHI, by email to the account’s designated privacy and security contact of record, by in-application notice, and by updating the Subprocessor list.

C.15.5 Objection. If the Organization reasonably objects to a new Subprocessor on documented HIPAA privacy or security grounds within thirty (30) days of notice, the parties will discuss in good faith whether the concern can be addressed through configuration, contractual or technical measures. If it cannot, the Organization may terminate the affected Covered Services without penalty, with Sections C.25 and C.27 applying and any fee consequences governed by Part B, Section B.9.

C.15.6 Processing locations. OmniPACS does not warrant that PHI will be created, received, maintained, transmitted or processed in any particular country or region. Section C.12.4(a) and Section C.12.4(b) govern processing locations and the submission to United States jurisdiction, and apply to every Subprocessor.

C.15.7 Subprocessor incidents and pattern of activity. OmniPACS will require each Subprocessor to report Security Incidents and Breaches to OmniPACS without unreasonable delay and no later than seventy-two (72) hours after Discovery, and will include such incidents in its reporting under Section C.17. If OmniPACS knows of a pattern of activity or practice of a Subprocessor that constitutes a material breach or violation of the Subprocessor’s obligations, OmniPACS will take reasonable steps to cure the breach or end the violation and, if unsuccessful, will terminate the arrangement if feasible, consistent with 45 CFR 164.504(e)(1)(iii).


C.16 MITIGATION

OmniPACS will take reasonable measures to mitigate, to the extent practicable, any harmful effect known to OmniPACS of a Use or Disclosure of PHI by OmniPACS or any Subprocessor in violation of this Part C or the HIPAA Rules, as required by 45 CFR 164.530(f) as applied through this Part C. Mitigation measures will be coordinated with the Organization where they affect its systems, workflows or communications with Individuals.


C.17 REPORTING: SECURITY INCIDENTS, IMPERMISSIBLE USES AND BREACHES

Element required by 45 CFR 164.504(e)(2)(ii)(C), 164.410 and 164.314(a)(2)(i)(C).

C.17.1 Breach of Unsecured PHI — five business days. Following Discovery of a Breach of Unsecured PHI, OmniPACS will notify the Organization without unreasonable delay and in no case later than five (5) business days after Discovery. This period is materially shorter than the sixty (60) calendar-day ceiling in 45 CFR 164.410(b), and is intended to preserve the Organization’s own investigation and notification window under 45 CFR 164.404(b).

C.17.2 Content of Breach notice. The notice under Section C.17.1 will include, to the extent then known and to the extent possible:

    (a) the identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, Used or Disclosed during the Breach, as required by 45 CFR 164.410(c)(1);
    (b) a brief description of what happened, including the date of the Breach and the date of Discovery;
    (c) a description of the types of Unsecured PHI involved, including whether names, dates of birth, patient identifiers, accession numbers, Study Instance UIDs, images or pixel data, diagnoses, referring provider identity, insurance information, Social Security numbers or financial information were involved;
    (d) the number of Studies and Individuals affected and the facilities and data sources implicated;
    (e) OmniPACS’ assessment under 45 CFR 164.402 of whether the acquisition, access, Use or Disclosure compromised the security or privacy of the PHI, including its low-probability-of-compromise risk assessment and any applicable exception;
    (f) the steps OmniPACS is taking to investigate, mitigate harm and protect against further Breaches;
    (g) the name and contact details of OmniPACS’ incident lead; and
    (h) any other information the Organization needs in order to notify Individuals under 45 CFR 164.404(c), the media under 45 CFR 164.406, and the Secretary under 45 CFR 164.408.

C.17.3 Rolling supplementation. Information required by Section C.17.2 that is not available at the time of initial notice will be provided promptly as it becomes available, and OmniPACS will provide written status updates at least every five (5) business days until the investigation is closed, together with a final written incident report within thirty (30) days of closure.

C.17.4 Security Incidents — five business days. OmniPACS will report any Security Incident of which it becomes aware, as required by 45 CFR 164.314(a)(2)(i)(C), without unreasonable delay and in no case later than five (5) business days after becoming aware of it.

C.17.5 Unsuccessful Security Incidents. Notwithstanding Section C.17.4, Unsuccessful Security Incidents as defined in Section C.8.2(l) do not require individual notice. This Section C.17.5 constitutes the Organization’s standing request for, and OmniPACS’ ongoing report of, Unsuccessful Security Incidents, satisfied by: (a) periodic aggregate reporting of Unsuccessful Security Incident volumes and categories, provided at least annually or on reasonable written request, not more than once in any twelve (12) month period; and (b) OmniPACS’ obligation to escalate under Section C.17.4 any incident that ceases to qualify as an Unsuccessful Security Incident. An incident is escalated as soon as OmniPACS becomes aware of facts indicating unauthorized access to, acquisition of, use of, disclosure of, modification of or destruction of PHI, or interference with system operations affecting PHI.

C.17.6 Impermissible Uses and Disclosures — five business days. OmniPACS will report any Use or Disclosure of PHI not provided for by this Part C of which it becomes aware, including by a Subprocessor or workforce member, without unreasonable delay and in no case later than five (5) business days after becoming aware of it.

C.17.7 Preliminary notice permitted. Where OmniPACS cannot complete its assessment within the applicable period, it will provide a preliminary notice within that period describing what is then known, and will supplement it under Section C.17.3. A preliminary notice does not extend the periods in Sections C.17.1, C.17.4 or C.17.6.

C.17.8 Notice mechanics. Notices under this Section C.17 will be delivered by email to the Organization’s designated privacy and security contact of record, with a duplicate in-application notice, and by telephone where the incident affects the availability or integrity of Studies. The Organization will maintain a current privacy and security contact in its account settings. A Breach or Security Incident is reported to OmniPACS by email to support@omnipacs.com with the subject line “HIPAA BREACH NOTICE,” or by telephone to 813-590-0846.

C.17.9 No admission. A notice under this Section C.17 is not an admission of fault or liability, and providing a notice earlier than required does not prejudice OmniPACS’ position.

C.17.10 Discovery imputed. OmniPACS is deemed to have Discovered a Breach on the first day on which the Breach is known, or by exercising reasonable diligence would have been known, to any person other than the person committing the Breach who is an employee, officer or other agent of OmniPACS, including a Subprocessor acting as OmniPACS’ agent.

C.17.11 Patient-Uploaded Content is inside the reporting scope. Every reporting obligation in this Section C.17 — Breach of Unsecured PHI, Security Incidents, and impermissible Uses and Disclosures — applies to Patient-Uploaded Content as defined in Section C.8.2(n) in the same way, and on the same periods, as it applies to Studies the Organization submits.


C.18 BREACH RESPONSE COOPERATION AND COST ALLOCATION

C.18.1 Cooperation. OmniPACS will cooperate with the Organization, and with its legal and forensic advisors, in the investigation and remediation of any PHI Incident affecting the Organization’s PHI, including by providing relevant logs, audit trails, configuration records, forensic findings, affected-Individual lists keyed to Study Instance UID and patient identifier, and reasonable access to knowledgeable personnel.

C.18.2 Who notifies. Unless the parties agree otherwise in writing for a specific incident, the Organization is responsible for determining whether notification is required and for drafting and issuing notices to Individuals, the media and the Secretary. OmniPACS will not notify Individuals, the media, regulators or any other third party regarding a Breach of the Organization’s PHI without prior written consent, except where Required By Law, in which case OmniPACS will notify the Organization in advance to the extent legally permitted.

C.18.3 Reporting on the Organization’s behalf. At the Organization’s written request, OmniPACS will assist with, or submit on its behalf, reports to the Secretary through the HHS breach reporting portal, recognizing that a separate report is required for each Breach incident, that a business associate may submit a report on behalf of a covered entity, that submissions must be made electronically with all required fields completed, and that addenda are filed using the transaction number from the initial report. Where the PHI includes records subject to 42 CFR Part 2, the parties will address the additional reporting obligation under 42 CFR 2.16(b).

C.18.4 Cost allocation. Where a Breach of Unsecured PHI results from OmniPACS’ or a Subprocessor’s breach of this Part C or violation of the HIPAA Rules, OmniPACS will reimburse the Organization for the reasonable, documented incremental costs above its standard operating costs incurred in complying with Subpart D of 45 CFR Part 164 and applicable state breach notification law as a result of that Breach, including: identification of affected Individuals; preparation, printing and mailing of notices; substitute notice, including website posting for the required 90-day period and media notice; establishment and operation of a toll-free number; forensic investigation attributable to OmniPACS’ systems; and reasonable regulatory response costs. OmniPACS does not fund credit monitoring, identity restoration or identity theft insurance, and those costs are not reimbursable under this Section C.18.4. Costs reimbursable under this Section C.18.4 are direct damages for purposes of Section C.28 and are subject to the PHI super-cap in Part B, Section B.7.

C.18.5 Duplicate recovery. The Organization will not recover the same loss twice under Section C.18.4 and Section C.28.


C.19 INDIVIDUAL RIGHTS SUPPORT

Elements required by 45 CFR 164.504(e)(2)(ii)(E)–(G), implementing 164.524, 164.526 and 164.528.

C.19.1 Routing of Individual requests. The Organization is the covered entity or upstream business associate responsible for responding to requests from Individuals. Where OmniPACS receives a request directly from an Individual or an Individual’s personal representative relating to PHI it maintains for the Organization, OmniPACS will not respond substantively and will forward the request to the Organization’s designated privacy contact within five (5) business days of receipt, together with any information reasonably necessary to identify the relevant records.

C.19.2 Access — 45 CFR 164.524. OmniPACS will make PHI in a Designated Record Set that it maintains for the Organization available to the Organization, or, at the Organization’s written direction, to an Individual or an Individual’s designee, in the time and manner necessary to permit the Organization to meet its obligations under 45 CFR 164.524, and in any event within ten (10) business days of request, or such shorter period as the Organization reasonably requires to meet a statutory deadline of which it notifies OmniPACS. Where the request concerns imaging data, OmniPACS will make Studies available in DICOM Part 10 format with original transfer syntax preserved, and, where requested, in an additional human-viewable format available in the Covered Services. OmniPACS has no obligation to duplicate or provide records the Organization maintains outside the Covered Services.

C.19.3 No fee for an individual access request. OmniPACS will not charge the Organization any fee for responding to a request under Section C.19.1, C.19.2, C.19.4 or C.19.5, or for any standard retrieval, export or production of PHI necessary for the Organization to meet its obligations under 45 CFR 164.524, 164.526 or 164.528. OmniPACS may charge a fee, at rates published in advance and limited to its reasonable, cost-based charges, only for extraordinary services the Organization expressly requests in writing after receiving a written estimate, meaning: forensic reconstruction of deleted or corrupted data; retrieval from archival tiers of PHI already returned or exported; restoration from backup media of PHI outside the Contract Retention Period; bulk production exceeding five hundred (500) Studies or one (1) terabyte in a single request other than a termination export under Section C.27; or production of custom-formatted or bespoke data extracts. No fee will be charged for a bulk export in DICOM Part 10 format under Section C.27. Cost barriers to lawful access, exchange or use of electronic health information may implicate the information blocking provisions of 45 CFR Part 171, and this Part C is to be construed so as not to create such a barrier.

C.19.4 Amendment — 45 CFR 164.526. OmniPACS will make PHI in a Designated Record Set available to the Organization for amendment, and will incorporate any amendment directed by the Organization, in the time and manner necessary to permit the Organization to meet its obligations under 45 CFR 164.526, and in any event will complete a directed amendment within fifteen (15) business days of written direction. For imaging data, the DICOM Study Instance UID and the integrity of the original acquired image must be preserved; amendments to imaging records will be implemented by addendum, corrected metadata or annotation retained alongside, and not overwriting or deleting, the original object, with an audit record of each amendment.

C.19.5 Accounting of disclosures — 45 CFR 164.528. OmniPACS will document Disclosures of PHI and the related information that would be required for the Organization to respond to a request for an accounting of disclosures under 45 CFR 164.528, and will make that information available within ten (10) business days of request. OmniPACS will retain the documentation for at least six years from the date of the Disclosure.

C.19.6 Restrictions and confidential communications — 45 CFR 164.522. OmniPACS will comply with any restriction on the Use or Disclosure of PHI agreed to by the Organization under 45 CFR 164.522(a), and any request for confidential communications accommodated under 45 CFR 164.522(b), of which the Organization notifies OmniPACS in writing, to the extent the restriction or accommodation affects OmniPACS’ Use or Disclosure of PHI and is technically implementable within the Covered Services. OmniPACS will notify the Organization promptly if a notified restriction cannot be implemented, in which case the Organization is responsible for managing it through its own workflows.

C.19.7 Mutual cooperation. Each party will cooperate in good faith with the other, and provide information and access reasonably necessary, to enable the other to respond to Individual rights requests, complaints from Individuals, and inquiries from the Secretary or a state regulator, within the timeframes those requests and inquiries impose. Neither party will impose an unreasonable procedural, technical or financial barrier on the other’s ability to meet an Individual rights obligation.

C.19.8 No fee to a patient. Nothing in this Section C.19 permits OmniPACS to charge a Patient or Individual for access to their own images. See Part D, Section D.9.


C.20 INTEROPERABILITY, IMAGE EXCHANGE AND INFORMATION BLOCKING

C.20.1 Standards conformance. OmniPACS will store and transmit Studies in DICOM-conformant form and will use only DICOM-defined compression schemes (including JPEG, JPEG-LS, JPEG-2000 and MPEG family transfer syntaxes) for PHI it maintains. OmniPACS will not apply proprietary compression algorithms or file formats to Studies in a manner that would impede viewing, processing or migration, and will not decompress and recompress a Study using a different irreversible compression scheme in the course of migrating data. OmniPACS will not apply irreversible compression to digital mammography images retained, transmitted or made available for final interpretation, consistent with FDA requirements, and will retain digital breast tomosynthesis data as DICOM breast tomosynthesis objects rather than secondary capture objects where received in that form.

C.20.2 Study record integrity. OmniPACS will maintain, for each Study, an accurate corresponding database record including patient name, patient identification number, accession number, examination date, modality, study description and originating facility or institution name, and will preserve the Study Instance UID as the primary identifier through storage, replication, migration and export.

C.20.3 Documented export path. OmniPACS will make available at all times during the term and during the Retrieval Window under Section C.27 a documented export path — including DICOM query/retrieve or C-MOVE, bulk export and media creation — by which the Organization may obtain its Studies and associated metadata in DICOM Part 10 format without OmniPACS’ further consent.

C.20.4 No unreasonable barrier. OmniPACS will not implement any practice, and will not impose any technical, contractual, procedural or financial condition, that constitutes an unreasonable interference with the access, exchange or use of electronic health information within the meaning of 45 CFR Part 171. This Part C is to be construed, and any exit, retrieval or fee provision applied, so as not to constitute information blocking.

C.20.5 Network participation. Where the Organization directs OmniPACS to exchange Studies through a health information exchange, health information network, Qualified Health Information Network, Participant or Subparticipant arrangement, including under TEFCA, OmniPACS will act only on the Organization’s documented instruction and within the exchange purposes permitted by the Organization’s own participation terms. OmniPACS makes no representation that it is a Qualified Health Information Network or a TEFCA Participant, and does not participate in TEFCA.


C.21 REQUIRED BY LAW, COMPELLED DISCLOSURES AND SENSITIVE REQUESTS

C.21.1 Routing of third-party and governmental requests. OmniPACS will route to the Organization, and will not respond substantively to, any request, demand, subpoena, warrant, court order, administrative request, civil investigative demand, law enforcement request or other legal process seeking PHI that OmniPACS maintains for the Organization, unless OmniPACS is the named and legally obligated recipient and is prohibited from redirecting the request. OmniPACS does not exercise independent judgment as to whether a Disclosure of the Organization’s PHI is permitted; the Organization, as the covered entity or upstream business associate, makes that determination.

C.21.2 Notice and opportunity to object. Where OmniPACS is legally obligated to respond, it will, unless legally prohibited: (a) notify the Organization in writing promptly and in any event before the response is due, and where practicable at least five (5) business days before making any Disclosure; (b) provide a copy of the process and a reasonable opportunity to object, seek a protective order or quash; (c) reasonably cooperate with the Organization’s efforts to limit or resist the Disclosure, at the Organization’s expense where it directs the challenge; and (d) Disclose only the Minimum Necessary PHI legally required.

C.21.3 Permitted-basis limitation. OmniPACS will make a compelled Disclosure of PHI only where the Disclosure is permitted by 45 CFR 164.512, including the conditions and assurances that provision requires for judicial and administrative proceedings (164.512(e)), law enforcement (164.512(f)), health oversight (164.512(d)) and decedents (164.512(g)(1)).

C.21.4 Sensitive categories and more protective state law. OmniPACS will comply with the Organization’s written instructions restricting the Use or Disclosure of PHI relating to sensitive categories of care — including reproductive health care, gender-affirming care, substance use disorder treatment, mental and behavioral health, HIV status and minors’ care — where the Organization instructs OmniPACS that a state shield law, state privacy law or other law more protective than HIPAA applies, to the extent the instruction is technically implementable within the Covered Services. Where a request for PHI concerns a sensitive category, OmniPACS will route the request under Section C.21.1 and will make no Disclosure absent written direction.

C.21.5 No reliance on the vacated attestation regime. The parties acknowledge that the HIPAA Privacy Rule to Support Reproductive Health Care Privacy, 89 FR 32976 (April 26, 2024), was declared unlawful and largely vacated on June 18, 2025 in Purl v. U.S. Department of Health and Human Services, No. 2:24-cv-00228-Z (N.D. Tex.), that HHS declined to appeal and the intervenors’ appeal was dismissed by the Fifth Circuit on September 10, 2025, and that the attestation requirement is therefore not enforceable federal law. This Part C does not incorporate the vacated attestation regime as a contractual obligation. Section C.21.4 is the parties’ substitute mechanism and operates independently of the status of that rule. If HHS or a court restores an attestation or similar requirement, the parties will amend under Section C.29.

C.21.6 Notice of Privacy Practices cooperation. The Organization will notify OmniPACS of any limitation in its Notice of Privacy Practices under 45 CFR 164.520, and of any change to or revocation of an Individual’s permission to Use or Disclose PHI, to the extent it affects OmniPACS’ Use or Disclosure of PHI. The modifications to 45 CFR 164.520 that survived Purl, relating to records subject to 42 CFR Part 2, carry a compliance date of February 16, 2026, and the parties will cooperate as necessary to meet that date. Where the Organization transmits records subject to 42 CFR Part 2 to the Covered Services, it will notify OmniPACS in writing, and the parties will enter into any additional written agreement Part 2 requires.

C.21.7 Record of compelled Disclosures. OmniPACS will maintain a record of compelled Disclosures of PHI and will make it available under Section C.19.5.


C.22 OBLIGATIONS OF THE ORGANIZATION — THE MINIMUM HIPAA REQUIRES, AND NOTHING MORE

This Section is deliberately short. Commercial covenants are kept out of this Part C and sit in Part B.

C.22.1 Permissible requests. The Organization will not request that OmniPACS Use or Disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by the Organization, except to the extent this Part C permits OmniPACS to Use or Disclose PHI for its own management and administration, legal responsibilities or Data Aggregation. This implements 45 CFR 164.504(e)(2)(i) and 164.504(e)(4).

C.22.2 Notice of restrictions and Notice of Privacy Practices limitations. The Organization will notify OmniPACS of the matters described in Section C.19.6 (restrictions and confidential communications agreed under 45 CFR 164.522) and Section C.21.6 (limitations in, or changes to, its Notice of Privacy Practices under 45 CFR 164.520, and any change to or revocation of an Individual’s permission), in each case to the extent the matter affects OmniPACS’ Use or Disclosure of PHI, and will maintain a current privacy and security contact of record so those notices, and OmniPACS’ incident notices under Section C.17, can be delivered.

C.22.3 Authorizations and legal bases. The Organization represents that it has obtained, and will maintain, any authorization, consent or other legal basis its own Uses and Disclosures require in order for it lawfully to submit PHI to the Covered Services and to direct OmniPACS’ Uses and Disclosures of that PHI, including for study sharing and distribution to external recipients it or its Users designate.

C.22.4 Pattern of activity. If OmniPACS knows of a pattern of activity or practice of the Organization that constitutes a material breach or violation of the Organization’s obligations under this Part C, OmniPACS will take reasonable steps to cure the breach or end the violation and, if unsuccessful, will terminate this Part C if feasible, consistent with 45 CFR 164.504(e)(1)(ii).

C.22.5 What is deliberately not here. The Organization’s obligations regarding configuration of the Covered Services, User provisioning and de-provisioning, role and permission assignment, credential security, the accuracy and lawfulness of the data it submits, secure transmission channels, acceptable use, indemnity, insurance and fees are set out in Part A, Section A.8 and Part B, Sections B.3, B.4, B.8, B.9 and B.11, and are not obligations of this Part C. Nothing in this Section C.22.5 narrows those obligations; it locates them.


C.23 AVAILABILITY OF PRACTICES AND RECORDS TO THE SECRETARY

Element required by 45 CFR 164.504(e)(2)(ii)(I).

OmniPACS will make its internal practices, books and records, including policies and procedures and PHI, relating to the Use and Disclosure of PHI received from, or created or received by OmniPACS on behalf of, the Organization available to the Secretary for purposes of determining the Organization’s compliance with Subpart E of 45 CFR Part 164. OmniPACS will notify the Organization of any such request to the extent legally permitted, and will provide a copy of the materials produced unless prohibited from doing so. Disclosure to the Secretary under this Section C.23 does not waive any privilege or protection as to any third party.


C.24 COMPLIANCE EVIDENCE, ASSESSMENTS AND AUDIT RIGHTS

C.24.1 No third-party certification or attestation covering OmniPACS’ own controls; AWS’s attestations cover AWS’s infrastructure only.

    (a) OMNIPACS DOES NOT CURRENTLY HOLD A SOC 2 TYPE I OR TYPE II REPORT, A HITRUST CSF CERTIFICATION, AN ISO/IEC 27001 CERTIFICATE, AN AT-C 315 HIPAA COMPLIANCE EXAMINATION REPORT, A PCI DSS ATTESTATION OF COMPLIANCE, OR ANY OTHER INDEPENDENT THIRD-PARTY ATTESTATION COVERING OMNIPACS’ OWN CONTROLS, AND MAKES NO REPRESENTATION THAT IT DOES. Nothing in this Part C obligates OmniPACS to obtain any such report, certification or attestation, and no provision of this Agreement is to be read as a commitment to do so.

    (b) The Platform is hosted on Amazon Web Services, which maintains its own independent third-party audit reports and certifications, including SOC 1, SOC 2 and SOC 3 reports and ISO/IEC 27001 certification, and which offers a HIPAA Business Associate Addendum covering HIPAA-eligible services. Those reports are obtained from AWS and are made available by AWS through AWS Artifact. THEY ATTEST TO THE CONTROLS AWS OPERATES FOR ITS OWN INFRASTRUCTURE AND SERVICES. THEY ARE NOT AN ATTESTATION OF OMNIPACS’ CONTROLS, THEY DO NOT COVER THE OMNIPACS APPLICATION LAYER, AND THE ORGANIZATION MAY NOT TREAT THEM AS A SUBSTITUTE FOR A SOC 2 REPORT COVERING OMNIPACS.

C.24.2 Security testing. OmniPACS performs security testing of the environments in which PHI is maintained at intervals it determines to be appropriate. OmniPACS does not commit to any testing cadence and does not commit to sharing testing results.

C.24.3 Security questionnaires and available materials. On written request, not more than once in any twelve (12) month period and subject to a confidentiality undertaking, OmniPACS will complete the Organization’s reasonable security and privacy due-diligence questionnaire, or provide a completed standardized questionnaire, and will make available its security documentation to the extent such materials exist. OmniPACS will also respond to a reasonable request following a PHI Incident affecting the Organization’s PHI.

C.24.4 Risk analysis support. OmniPACS will provide, on reasonable request, the artifacts the Organization reasonably requires to complete its own risk analysis under 45 CFR 164.308(a)(1)(ii)(A) with respect to ePHI held in the Covered Services, including a description of the security architecture, data flows, encryption implementation, authentication controls, logging capabilities, backup design, and the Subprocessor list.

C.24.5 Incident-triggered inspection. Following a PHI Incident affecting the Organization’s PHI, the Organization may, on ten (10) business days’ prior written notice, inspect the books, records, policies and procedures of OmniPACS that relate specifically to that PHI Incident. Such inspection: (a) is limited in scope to the reported PHI Incident; (b) will be conducted during normal business hours, remotely where practicable, without unreasonably disrupting OmniPACS’ operations; (c) is subject to advance written agreement on timing, scope and personnel; (d) requires execution of OmniPACS’ reasonable non-disclosure agreement; (e) permits OmniPACS to redact information relating to other customers, to third parties, or whose disclosure would create a security risk; and (f) does not extend to OmniPACS’ source code, multi-tenant infrastructure configuration, or the data of other customers. The Organization bears its own costs.

C.24.6 No general on-site audit right. Except as provided in Sections C.23 and C.24.5, this Part C does not grant a right to conduct an on-site audit of OmniPACS’ facilities or systems, and Sections C.24.1 through C.24.4 are the Organization’s exclusive compliance-evidence remedies.

C.24.7 Future verification requirements. If an amendment to the HIPAA Rules requires a business associate to verify to a covered entity that it has deployed specified technical safeguards, OmniPACS will provide that verification on the schedule the amended rule requires, without the need for amendment of this Part C. This Section C.24.7 creates no verification, attestation or certification obligation that applicable law does not itself impose.


C.25 TERM, TERMINATION AND CURE

Element required by 45 CFR 164.504(e)(2)(iii) and 164.504(e)(1)(ii).

C.25.1 Term. This Part C takes effect as provided in Section C.1.1 and continues until the later of: (a) termination or expiration of this Agreement as it applies to the Organization; or (b) the date on which all PHI is returned to the Organization or destroyed in accordance with Section C.27, subject to Section C.27.6.

C.25.2 Termination for material breach — by the Organization. The Organization may terminate this Part C and this Agreement, in whole or with respect to the affected Covered Services, if OmniPACS materially breaches this Part C and fails to cure the breach within thirty (30) days of written notice, or immediately if cure is not possible. This is the termination right required by 45 CFR 164.504(e)(2)(iii).

C.25.3 Termination for material breach — by OmniPACS. OmniPACS may terminate this Part C if the Organization materially breaches this Part C and fails to cure within thirty (30) days of written notice, or immediately if cure is not possible. OmniPACS will not exercise this right in a manner that deprives the Organization of access to its Studies without the Retrieval Window in Section C.27.2.

C.25.4 Pattern of activity. Consistent with 45 CFR 164.504(e)(1)(ii)–(iii): (a) if the Organization knows of a pattern of activity or practice of OmniPACS that constitutes a material breach or violation of OmniPACS’ obligations, the Organization will take reasonable steps to cause OmniPACS to cure the breach or end the violation and, if unsuccessful, will terminate this Part C if feasible; (b) OmniPACS’ reciprocal obligations with respect to the Organization are in Section C.22.4 and with respect to Subprocessors in Section C.15.7.

C.25.5 Suspension in lieu of termination. Where a PHI Incident or a suspected impermissible Use or Disclosure is ongoing, either party may, in lieu of termination, require suspension of the specific processing activity or User access giving rise to the concern, pending investigation, provided that suspension does not extend to the Organization’s ability to retrieve its own Studies. The access floor in Part B, Section B.9.16.4 controls.

C.25.6 Effect of termination. Termination does not relieve either party of obligations accrued before termination, and does not affect Sections C.18, C.23, C.27, C.28, or any other provision that by its nature survives.


C.26 INSURANCE

OmniPACS’ insurance obligations are set out exclusively in Part B, Section B.11. This Part C imposes no insurance obligation on OmniPACS, and no provision of this Part C requires OmniPACS to obtain, maintain or increase any coverage. The existence, limits or exhaustion of any insurance does not expand OmniPACS’ obligations or liability under this Part C or under Part B, Section B.7.


C.27 EXIT, RETURN AND DESTRUCTION OF PHI

Element required by 45 CFR 164.504(e)(2)(ii)(J).

C.27.1 Election. On termination or expiration of this Part C, the Organization will elect, by written notice, whether OmniPACS is to return PHI, destroy it, or both. Absent an election within thirty (30) days of termination, OmniPACS will make PHI available for retrieval under Section C.27.2 and will then destroy it under Section C.27.3.

C.27.2 Retrieval window and format. For a period of thirty (30) days following termination or expiration (the “Retrieval Window“), OmniPACS will maintain the Organization’s Studies and PHI and will provide read and export access sufficient to retrieve all of it. This Retrieval Window is absolute and is not conditioned on payment. Export will be provided in:

    (a) unmodified DICOM Part 10 files, with original transfer syntax preserved and no lossy transcoding, complete DICOM headers, and the Study Instance UID, series and instance identifiers intact;
    (b) a machine-readable manifest and index correlating each exported Study to its Study Instance UID, accession number, patient identifier, patient name, study date, modality, study description, originating institution and file location; and
    (c) associated non-DICOM records maintained in the Covered Services, including reports, notes, sharing records and audit logs relating to the Organization’s PHI, in a documented, non-proprietary machine-readable format.

OmniPACS will not charge any fee for a standard bulk export under this Section C.27.2. Extension of the Retrieval Window, and any physical-media production, are chargeable at OmniPACS’ then-current published rate, which is cost-based.

C.27.3 Destruction. After the Retrieval Window closes, or earlier at the Organization’s written direction, OmniPACS will destroy all PHI it maintains for the Organization, in a manner rendering it unusable, unreadable and indecipherable to unauthorized persons consistent with HHS guidance under 45 CFR 164.402(2), and will retain no copies, including copies held by its Subprocessors, agents, and in its backups, snapshots, replicas, logs, caches and export artifacts, subject to Section C.27.4. OmniPACS may delete PHI sixty (60) days after termination or expiration and will do so on the Organization’s written instruction. OmniPACS will cause each Subprocessor to terminate its access to and destroy the Organization’s PHI within a reasonable time.

C.27.4 Where return or destruction is infeasible. Where return or destruction is infeasible, OmniPACS will notify the Organization in writing, identifying the PHI, the reason infeasibility applies, and the expected duration of retention. For that PHI, OmniPACS will: (a) extend the protections of this Part C to it for as long as it is retained; (b) limit further Uses and Disclosures to those purposes that make return or destruction infeasible; and (c) destroy it when return or destruction becomes feasible. Infeasibility is limited to: retention Required By Law; retention necessary to comply with a legal hold or regulatory investigation; and PHI residing in immutable backup or archive media from which selective deletion is not technically possible, which OmniPACS will destroy on the media’s ordinary expiration cycle, not to exceed the thirty-five (35) day backup retention period in Section C.12.4. Cost, commercial inconvenience or the volume of data does not make return or destruction infeasible.

C.27.5 Certificate of destruction. On written request, OmniPACS will provide a written certificate of destruction, signed by an officer, identifying the categories of PHI destroyed, the date and method of destruction, the number of Studies destroyed, and confirmation that no copies have been retained other than as disclosed under Section C.27.4.

C.27.6 Survival. The obligations of OmniPACS under this Section C.27, and under Sections C.8, C.9.1, C.9.8, C.10, C.11.1, C.13.3, C.14.1, C.14.2, C.16, C.17, C.18, C.21, C.23, C.24.5, C.28 and C.30.2, survive termination of this Part C for so long as OmniPACS retains any PHI and, with respect to Sections C.18, C.23 and C.28, for the applicable limitations period.

C.27.7 No conflict with commercial terms. The Organization’s right to the Retrieval Window and to export under this Section C.27 is not conditioned on payment of disputed amounts, and OmniPACS will not withhold export as a collection measure. Amounts undisputedly owed for the period preceding termination remain payable under Part B, Section B.9.


C.28 HIPAA LIABILITY AND THE PHI SUPER-CAP

This Section C.28 is the only liability provision in this Part C. The general limitation of liability applicable to the Platform, and all exclusions and caps, are in Part B, Section B.7. This Section C.28 does not restate them and does not create a different limit.

C.28.1 Financial responsibility for a Breach. Where a Breach of Unsecured PHI results from OmniPACS’ or a Subprocessor’s breach of this Part C or violation of the HIPAA Rules, OmniPACS’ financial responsibility to the Organization is the cost reimbursement in Section C.18.4 and any damages recoverable under Part B, Section B.7, in each case subject to the PHI super-cap in Section C.28.3. This Part C creates no separate defence or indemnity obligation of OmniPACS; indemnities under this Agreement are located in Part B, Section B.8.

C.28.2 Indemnity by the Organization — deliberately not in this Part. The Organization’s indemnity obligations, including for its breach of this Part C, its violation of the HIPAA Rules, its submission of PHI without the necessary authority or authorization, its configuration of the Covered Services, and its Users’ impermissible Use or Disclosure of PHI, are set out in Part B, Section B.8 and are not obligations of this Part C.

C.28.3 PHI super-cap. Claims arising out of a breach of this Part C, a violation of the HIPAA Rules with respect to the Organization’s PHI, or a Breach of Unsecured PHI caused by OmniPACS or a Subprocessor, are subject to the PHI super-cap in Part B, Section B.7, which limits OmniPACS’ aggregate liability for such claims to THE LESSER OF (A) THREE (3) TIMES THE FEES PAID BY THE ORGANIZATION TO OMNIPACS IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO THE CLAIM AND (B) FIVE HUNDRED THOUSAND US DOLLARS ($500,000). That cap is aggregate across all claims and all theories. This Part C does not state a different cap, and any prior formulation of a different HIPAA cap is superseded and of no effect.

C.28.4 Direct damages. The following are direct damages, and are not excluded as indirect, incidental, special, consequential or punitive damages, in a claim within the scope of Section C.28.3: costs of Breach notification to Individuals, the media and regulators, including substitute notice and toll-free-number costs; forensic investigation costs; regulatory response, defence and cooperation costs; civil monetary penalties and fines assessed against the Organization to the extent caused by OmniPACS’ breach; the reasonable cost of data restoration and reconstruction of Studies; and the Organization’s reasonable costs of migrating PHI to an alternative platform where migration is necessitated by OmniPACS’ breach. All such damages remain subject to the PHI super-cap in Section C.28.3.

C.28.5 Indirect damages remain excluded. THE EXCLUSION OF INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE AND EXEMPLARY DAMAGES IN PART B, SECTION B.7 APPLIES TO EVERY CLAIM UNDER THIS PART C, INCLUDING A CLAIM WITHIN THE SCOPE OF SECTION C.28.3. The items listed in Section C.28.4 are direct damages and are not excluded by that provision.

C.28.6 Excluded from all caps. Nothing in this Part C or in Part B limits OmniPACS’ liability for its willful misconduct, fraud, gross negligence, or intentional impermissible Use or Disclosure of PHI, or for death or bodily injury caused by its negligence, or the Organization’s obligation to pay Fees.

C.28.7 Regulatory penalties context. The parties acknowledge, for context only and without creating any obligation, that civil monetary penalties under 45 CFR 160.404 and 45 CFR 102.3, as adjusted for inflation effective January 28, 2026, range from a minimum of $145 per violation in the lowest culpability tier to $73,011 per violation, with an annual cap of $2,190,294 per identical provision violated, and that business associates are directly liable for such penalties.

C.28.8 No third-party beneficiaries. Nothing in this Section C.28 or elsewhere in this Part C creates any right in any Individual or other third party.


C.29 REGULATORY CHANGE AND AMENDMENT

C.29.1 Duty to amend. The parties will negotiate in good faith to amend this Part C as necessary to comply with any amendment to the HIPAA Rules, any guidance from HHS or the Office for Civil Rights, or any other change in applicable law affecting the parties’ obligations with respect to PHI.

C.29.2 Automatic conformance. Where an amendment to the HIPAA Rules imposes a requirement on business associates more stringent than a corresponding provision of this Part C, that requirement applies to OmniPACS as of its compliance date whether or not this Part C has been formally amended, and this Part C is construed accordingly.

C.29.3 Failure to agree. If the parties cannot agree on an amendment necessary for compliance within thirty (30) days of either party’s written request, either party may terminate this Part C and the affected Covered Services on thirty (30) days’ written notice, with Section C.27 applying.

C.29.4 Changes to this Part C by OmniPACS. OmniPACS may modify this Part C from time to time, subject to Part A, Section A.14 (Changes to this Agreement). OmniPACS will give at least thirty (30) days’ prior notice of any material change, by email to the Organization’s designated contacts and by in-application notice, together with a summary of the changes and the new version identifier, and will re-present this Agreement for click-acceptance in accordance with Part A, Section A.14. If the Organization objects to a material change that reduces the protections afforded to PHI, it may terminate the affected Covered Services on notice given before the change takes effect, without penalty, with Section C.27 applying. OmniPACS will not expand the categories of PHI processed, add a Subprocessor that processes PHI, enable an AI or machine learning feature that processes PHI, or reduce the protections afforded to PHI, without the notice required by this Section C.29.4 and by Sections C.14.3 and C.15.4.

C.29.5 Version history. OmniPACS maintains a publicly accessible archive of prior versions of this Agreement, including this Part C, with effective dates, at https://omnipacs.com/legal/agreement/archive.


C.30 ACCEPTANCE, VERSIONING AND RECORDKEEPING FOR THIS PART

C.30.1 Acceptance. Acceptance of this Part C is manifested by the affirmative act described in Section C.1.1 and Part A, Section A.2. OmniPACS will present this Agreement in a manner that provides reasonable notice of its terms and requires an unambiguous affirmative act of assent, and will make the full text available for review and download before acceptance. OmniPACS does not and will not rely on passive posting of terms to bind any person to this Part C. See Part A, Section A.2.

C.30.2 Record of acceptance. OmniPACS will retain, for at least six (6) years, a record of each acceptance of this Agreement in so far as it forms this Part C, including the accepting person’s authenticated account, the version identifier and effective date of the Part C accepted, the date and time of acceptance, and the network and device information available at the time of acceptance, and will provide the Organization a copy of that record on written request. The acceptance-record specification for the Agreement as a whole is in Part E, Section E.3.

C.30.3 The acknowledgment email is the Organization’s copy. Because this Part C is not separately signed, the retainable acknowledgment email under Section C.2.4 and Part E, Section E.3, together with the permanent versioned link it contains and the acceptance record under Section C.30.2, constitute the Organization’s countersigned-equivalent copy of this business associate agreement for its own HIPAA documentation file. OmniPACS will reissue that copy on request at any time.

C.30.4 Availability. The current version of this Agreement, including this Part C, is available at https://omnipacs.com/legal/agreement, and within the OmniPACS application under the account’s legal documents section.


C.31 MISCELLANEOUS AS TO PHI

C.31.1 Precedence. This Part C controls over every other Part of this Agreement solely with respect to the use, disclosure, safeguarding, retention, return and destruction of Protected Health Information, and the other Parts control in all other respects. The full order of precedence is in Part E, Section E.1. There is no rule under this Agreement that the terms more favorable to OmniPACS govern, and any prior formulation to that effect is superseded and of no effect. No provision is construed in favor of or against either party on the basis of which party drafted it.

C.31.2 Notices. Notices under this Part C must be in writing and are given as provided in Part A, Section A.15 and Part E, Section E.5. Notice of a PHI Incident is given to OmniPACS by email to support@omnipacs.com with the subject line “HIPAA BREACH NOTICE.” Formal legal notice to OmniPACS is given in writing to OmniPACS Healthcare Technologies LLC, 17 Griffin Street, Monmouth Beach, New Jersey 07750, Attention: Legal, with a copy by email to support@omnipacs.com. Notice to the Organization is given to its privacy and security contact of record, with in-application notice.

C.31.3 Governing law, venue and dispute resolution. Governing law, venue and dispute resolution for this Part C are those set for professional and organizational users in Part B, Section B.12, and are not stated separately here. This Agreement is governed by the laws of the State of New Jersey, and does not require arbitration of any dispute. Nothing limits either party’s right to seek injunctive or other equitable relief to prevent or stop an unauthorized Use or Disclosure of PHI.

C.31.4 Jurisdiction over out-of-United-States processing. To the extent any PHI is processed outside the United States, OmniPACS submits, and will cause the relevant Subprocessor to submit, to the jurisdiction of the Secretary and of the courts of the United States with respect to that processing.

C.31.5 Assignment. Neither party may assign this Part C except in connection with an assignment of this Agreement permitted by Part E, Section E.4. OmniPACS will not transfer PHI in connection with a merger, acquisition or sale of assets except to a successor that assumes this Part C in writing.

C.31.6 No agency. Nothing in this Part C creates a partnership, joint venture, employment or agency relationship, and the parties do not intend for OmniPACS to be an agent of the Organization for purposes of 45 CFR 160.402(c).

C.31.7 Severability. If any provision of this Part C is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable while preserving its intent, and the remaining provisions remain in full force. In particular, if the attachment mechanism in Section C.1 or the authority representation in Section C.2 is held ineffective as to any Organization, Sections C.3.1 through C.3.4 apply, and OmniPACS’ own obligations under this Part C remain binding on OmniPACS in full.

C.31.8 No waiver. A failure or delay in exercising a right under this Part C is not a waiver of it.

C.31.9 Entire agreement as to PHI. This Part C, together with Exhibit C-1, constitutes the entire agreement of the parties with respect to the Use, Disclosure and safeguarding of PHI, and supersedes all prior business associate agreements between the parties, including any prior clickthrough business associate provisions, except a separately executed business associate agreement under Section C.4.

C.31.10 Electronic acceptance. This Part C may be accepted electronically, and an electronic record of acceptance has the same effect as a signed original. No signature block appears in this Part C because none is required; Section C.4 governs where the parties choose to sign.

C.31.11 Construction. This Part C is construed so as to permit the parties to comply with the HIPAA Rules.

C.31.12 The contracting party. The OmniPACS party to this Part C is OmniPACS Healthcare Technologies LLC, a New Jersey limited liability company, with its principal place of business at 17 Griffin Street, Monmouth Beach, New Jersey 07750, United States, telephone 813-590-0846, email support@omnipacs.com.


EXHIBIT C-1 — SECURITY PROGRAM

This Exhibit C-1 is part of Part C under Section C.11.3. It states the security measures OmniPACS maintains for the Covered Services. It states no control that OmniPACS does not maintain, and it contains no performance guarantee.

C-1.1 Encryption in transit. Encryption of ePHI in transit using TLS 1.2 or higher for Platform interfaces, including DICOM transmission from OmniRouter and EPS-Pi, API traffic, viewer ticket URLs and export downloads. Where PHI is transmitted over unencrypted legacy DICOM channels on the Organization’s own network, the Organization is responsible for network-level protection.

C-1.2 Encryption at rest. Encryption at rest for stored Studies, Customer Data and backups, using platform-managed encryption provided by the underlying cloud infrastructure.

C-1.3 Unique credentials. Unique credentials for each individual User. No shared or generic accounts. Credential provisioning and de-provisioning are controlled by the Organization’s administrators.

C-1.4 Authentication. Authentication is performed through Firebase Authentication using signed JSON Web Tokens. OmniPACS requires verification by a one-time passcode, sent to the email address or mobile number on file, when an account is created and when a password is reset. OMNIPACS DOES NOT CURRENTLY ENFORCE MULTI-FACTOR AUTHENTICATION ON EVERY ROUTINE SIGN-IN. The Organization remains responsible for evaluating whether that is sufficient for its environment and for applying compensating controls, including device management, network controls and session policy, where its own risk assessment requires them.

C-1.5 Role-based access control. Role-based access control and configurable sharing controls, configured by the Organization and aligned to the Minimum Necessary standard.

C-1.6 Audit logging. Audit logging of access to and Disclosure of PHI, recording User identity, timestamp, action and affected Study Instance UID, retained for six (6) years.

C-1.7 Least-privilege administrative access. OmniPACS personnel hold administrative access on a least-privilege basis, limited to what is necessary to operate and support the Platform. Use of the support impersonation feature is logged.

C-1.8 Workforce training and sanctions. Workforce training on HIPAA and information security, and a documented workforce sanctions policy for non-compliance.

C-1.9 Subprocessor agreements. Written agreements, including business associate agreements where required, with Subprocessors that process PHI, as described in Section C.15.

C-1.10 Incident response. A documented incident response process covering detection, triage, containment, eradication, recovery and notification, including notification to the Organization within the periods in Section C.17.

C-1.11 Backups. Backups of Studies and associated metadata, retained for thirty-five (35) days. Restoration is governed by Section C.12.4, including its express disclaimer of any recovery point objective and any recovery time objective.

C-1.12 Viewer hand-off. Time-limited, cryptographically signed URLs for diagnostic viewer hand-off to the CHILI viewer.

C-1.13 Certifications. OmniPACS does not currently hold a SOC 2 Type I or Type II report, a HITRUST CSF certification, an ISO/IEC 27001 certificate, an AT-C 315 HIPAA compliance examination report, a PCI DSS attestation of compliance, or any other independent third-party attestation covering OmniPACS’ own controls, and makes no representation that it does. The Platform is hosted on Amazon Web Services, which maintains its own independent third-party audit reports and certifications, including SOC 1, SOC 2 and SOC 3 reports and ISO/IEC 27001 certification, and which offers a HIPAA Business Associate Addendum covering HIPAA-eligible services; those reports are obtained from AWS and are made available by AWS through AWS Artifact. They attest to the controls AWS operates for its own infrastructure and services. They are not an attestation of OmniPACS’ controls, they do not cover the OmniPACS application layer, and the Organization may not treat them as a substitute for a SOC 2 report covering OmniPACS. See Section C.24.1.

C-1.14 Security testing. OmniPACS performs security testing at intervals it determines appropriate and commits to no cadence and to no sharing of results. See Section C.24.2.

C-1.15 Processing locations. OmniPACS does not warrant that PHI or other Customer Data will be stored or processed in any particular country or region. See Section C.12.4(a).


PART D — ADDITIONAL TERMS FOR PATIENTS AND INDIVIDUALS

This Part applies only if you are a patient or an individual using OmniPACS to look at your own images, or the images of someone you are legally allowed to act for. If that is you, Parts B and C do not apply to you at all.

Part D is written in plain language on purpose. You read the front matter, Part A, and this Part. That is all.

Before anything else, please read Part A, Section A.9 (Clinical safety — this is not a diagnosis). It is the most important section in this whole agreement: this platform shows you images, it does not tell you what they mean, and it is not a diagnosis. The paragraph written for patients in Part A, Section A.9 is written for you.

If anything here is unclear, email support@omnipacs.com or call 813-590-0846 and ask. You will get a human answer.


D.1 Who this Part is for; your age, and acting for someone else

D.1.1 Who this Part is for

This Part is for you, the patient — or for a parent, guardian, or other person who is allowed to look at someone else’s images.

OmniPACS is software that stores medical images and lets people view and share them. Hospitals, imaging centers, and radiology groups pay for it and use it to run their imaging. If you are reading this, you probably got a link to your scan, or you were signed in to look at your own images. You are not one of those organizations, and this Part is the part of the agreement written for you.

Where this Part says “we” or “us,” it means OmniPACS. Where it says “you,” it means you, the individual reading this. “The platform” means the OmniPACS software and website you are using. Part A, Section A.1 names the company; Part E, Section E.2 defines the rest of the words.

D.1.2 Your age

The platform is not directed to children. You cannot sign yourself up for an account here. Access comes from a health care provider, so no child can open an account on their own, and we do not knowingly give anyone under 13 their own login. If you are a parent or guardian of a child who had an imaging exam, your provider may give you access to that child’s images — see Section D.5.6.

D.1.3 Acting for someone else

You may access another person’s images only if the law lets you. That normally means one of these:

  • You are the parent or legal guardian of a minor child — see Section D.5.6.

  • You are a personal representative — for example, you hold a health care power of attorney, you are a court-appointed guardian or conservator, or you are the executor or administrator of the estate of someone who has died.

  • The patient gave written permission naming you.

When you use someone else’s images, you agree that:

    (a) you have the legal right to do so right now, not at some point in the past;
    (b) you will use the access only for that person’s benefit — for their care, their records, or their claims;
    (c) you will tell us if your authority ends (a child turns 18, a court order changes, a power of attorney is revoked); and
    (d) you will not use their images for your own purposes.

Your provider decides who counts as a representative, not us. Under Section D.3.1, that decision belongs to the health care provider that holds the records. If you need representative access, ask the provider. We will follow what the provider tells us. If we learn that someone no longer has authority, we may remove access.

State law sometimes limits a parent’s access to a teenager’s records — for example for reproductive health, mental health, or substance use care. Your provider applies those rules.

The rules about your login, your password, and sharing images with other people are in Part A, Section A.8, and they apply to you.


D.2 What does not apply to you

Part B and Part C do not apply to you at all.

  • Part B — the professional and subscription terms — does not apply to you. Part B is for hospitals, imaging centers, radiology groups, and the clinicians and administrators who work for them. It is written for their lawyers. None of it applies to you.

  • Part C — the HIPAA business associate agreement — does not apply to you. Part C is a contract between OmniPACS and a health care organization. You are not a party to it, and you will never be asked to sign it. See Section D.4.

To be completely clear, none of the following applies to you as a patient or individual:

  • Subscription and money terms. Plans, fees, per-study billing, study counting, payment methods, invoices, taxes, late charges, renewals, cancellation, suspension for non-payment, and service-level or uptime commitments. All of that is sold to health care organizations, and it all sits in Part B. You are not on a plan and you will never be billed. See Section D.9.

  • The Business Associate Agreement in Part C. That is a contract between us and your provider. You are not a party to it and you will never be asked to sign it. Accepting this Agreement does not make you a party to Part C. See Section D.4.

  • The professional indemnity in Part B. Our professional customers promise to cover us for certain legal claims. You make no such promise. See Section D.7.5.

  • The professional acceptable-use rules and the medical-imaging obligations for clinicians in Part B — monitor calibration duties, compression decisions, diagnostic reading requirements, account deprovisioning duties, complaint-reporting duties, and similar. Those are jobs for a radiology practice, not for a patient. The parts that genuinely concern you are in Part A, Section A.6 (what you may not do) and Part A, Section A.9 (clinical safety).

  • The right to install our software across an organization’s network, and the licence for locally installed components such as routers and gateways, both in Part B. You get access to a hosted service through your browser or app, and nothing more.

  • The rules in Part B, Section B.1 that turn an uploader into a paying customer and require a HIPAA vendor contract. Those rules are about professional use. Looking at your own images as a patient, or adding your own older images under Section D.3.3, does not turn you into a paying customer, and it does not put a HIPAA vendor contract on you.

  • The professional warranty, liability, indemnity and dispute-resolution terms in Part B. Yours are different, and they are better. They are in Sections D.6, D.7 and D.8 of this Part. Part A carries no liability cap, no warranty disclaimer and no dispute-resolution clause of its own, so nothing is missing — for you, those terms live here. Part A, Section A.3.4 says the same thing.

Where this Part and another Part disagree, this Part wins for you. Part E, Section E.1 sets that out in full.

D.2.1 What sits outside this Agreement altogether

Two things are outside this Agreement because they are not ours to write:

  • Your provider’s Notice of Privacy Practices. Your doctor, clinic, or imaging center put your images here, and that notice governs your images. If it ever conflicts with this Agreement, your provider’s notice wins.

  • The business associate agreement between us and your provider — Part C, or a separately signed agreement that replaces it under Part C, Section C.4. For protected health information, that contract controls what we may do. It only ever adds protection for you; it never takes any away.

You are a party to this Agreement in your own right as a patient, and you can enforce Part A and this Part D against us directly. Part E, Section E.4.5 says so.


D.3 Which rules apply to your images

Everything you can see here sits in one place: the access a health care provider gave you. Your provider makes your images available to you there. You can also add your own older images to that same access. The rules below apply to all of it.

D.3.1 Your doctor, clinic, or imaging center shared the images with you

Someone at your provider’s office sent you a link, or set you up with access, or added your images to a share.

Here is what that means:

  • Your provider is in charge of those images. We hold them and move them for your provider, the way a records company or a shredding company works for a doctor’s office.

  • Under the federal health privacy law — HIPAA — we are your provider’s “Business Associate.” We have a written contract with your provider called a business associate agreement — that is Part C of this Agreement, or a separately signed agreement that replaces it. That contract requires us to protect your images and limits what we are allowed to do with them.

  • Your images are still protected health information under HIPAA. They do not lose that protection by being viewed here.

  • Your provider’s Notice of Privacy Practices is the document that governs your images. You got that notice from your provider, or you can ask them for a copy. If anything in this Agreement ever conflicts with your provider’s Notice of Privacy Practices, your provider’s notice wins.

So, for these images:

If you want to…Contact
Fix a name, date of birth, or other wrong detailYour provider
Get a full copy of your recordsYour provider
Ask who has seen or received your imagesYour provider
Ask why your images were used or shared a certain wayYour provider
Ask us to delete images your provider put hereYour provider — we cannot delete a provider’s records on our own
Report a problem with the website, a broken link, or a login issuesupport@omnipacs.com

We are not being unhelpful. We are legally not allowed to change or release a provider’s medical records on our own. What we can do — and will do — is help your provider answer you quickly. If you write to us by mistake, we will point you to the right place and let your provider know you asked. We will not send you medical information directly.

D.3.2 We do not offer an account you can sign up for on your own

OmniPACS does not offer a patient-controlled account that you can sign up for yourself. There is no patient account here that exists on its own, without a health care provider. All patient access comes through a provider, as Section D.3.1 describes. Once a provider has given you access, you can add your own older images to it — see Section D.3.3. What you add stays inside that access and is handled the same way as everything else there. If we ever offer a standalone patient account, we will publish separate terms and a separate privacy notice for that service before it launches, so you can read them first.

D.3.3 Adding your own older images

You can add your own prior images to the access your provider gave you. Most people do this from a CD or a disc an imaging center handed them.

Here is what you need to know.

  • What you can add. Your own medical images and the records that come with them. That is it.

  • We protect it the same way. Anything you add is protected health information, exactly like the images your provider put here. Same security, same access rules, same audit trail, same breach duties. We handle it for your provider under Part C, the same as everything else.

  • Nobody here looks at it. No one at OmniPACS reviews it, checks it, corrects it, or interprets it. No doctor at OmniPACS reads it. We do not confirm that it is accurate, complete, about you, or useful for your care. Please read Part A, Section A.9 again: we show images, we do not tell you what they mean.

  • Adding a file does not send it to your doctor. This one matters. Putting a file here does not mean anyone at your doctor’s office will see it, open it, or even know it is there. If you need a clinician to look at it, tell them directly. Call the office. Do not assume the upload did the job for you.

  • It does not become part of your medical record unless your provider takes it. Your provider decides whether to accept it, review it, or act on it. That decision is theirs, not ours.

  • You must have the right to add it. You have to be the patient, or the person legally allowed to act for the patient — see Section D.1.3. Adding someone else’s images when you have no right to is not allowed, and Part A, Section A.6 covers that.

  • You can ask us to delete what you added. Email support@omnipacs.com with the subject line “PRIVACY REQUEST” and we will remove it. For images your provider put here, the request goes to your provider instead — see Section D.3.1 and Section D.5.3.1.

  • There may be limits. We may set and change limits on file size, how many files you add, which formats we accept, and how much you can store. We may refuse or remove a file that is not imaging or records, that is harmful, or that breaks the rules in Part A, Section A.6.

  • It is free. We never charge you to add, store, or download your own images. See Section D.9.


D.4 About the business associate agreement — you do not sign one

You may see the phrase “business associate agreement,” or “BAA,” on this site, in an email, or as the title of Part C of this Agreement. You might wonder whether you need to sign it. You do not.

A business associate agreement is a contract between a health care provider and one of its vendors. It is the provider promising, and the vendor promising back, to protect patient information. You are the person the agreement protects — not one of the parties to it. There is no patient version of it, and nobody will ever ask you to sign one.

Part C is that contract. It is between OmniPACS and a health care organization — the hospital, imaging center, or practice that holds your records. Accepting this Agreement does not make you a party to Part C. It does not make you a covered entity or a business associate under HIPAA, it does not put any HIPAA obligation on you, and it does not ask you to sign anything. Part C, Section C.5 says the same thing from the other side of the document.

What applies to you is Part A, this Part D, and your provider’s Notice of Privacy Practices.


D.5 Privacy notice for patients and individuals

This Section explains what we do with information about you. It sits alongside the main OmniPACS Privacy Policy, published at https://omnipacs.com/legal/privacy, which is a separate document, applies to everyone, and covers our marketing site, business accounts, and billing. Where the two differ for patients, this notice is the one for you. Part A, Section A.11 points here.

D.5.1 What we collect, how we use it, and who sees it

D.5.1.1 What we collect

Kind of informationExamples
Your medical images and recordsDICOM images from X-ray, CT, MRI, ultrasound, mammography and similar exams; the information attached to them, such as your name, date of birth, exam date, body part, and the facility; reports, where they are made available to you
Images you add yourselfPrior imaging you add to your access, usually from a CD, and the details attached to it — see Section D.3.3
Account informationYour name, email address, and any phone number given to us; your password, stored in a scrambled (hashed) form we cannot read; sign-in and security settings
How you use the platformWhen you signed in, what you viewed, what you downloaded, what you shared and with whom, and from what device and network — this is a security and audit record, not a marketing profile
Device and connection informationIP address, browser and device type, operating system, time zone
What you send usSupport emails, ticket contents, screenshots you attach, and anything you write in a message to us

Where it comes from: from your provider (the images and the identifying details attached to them), from you (your account details, any images you add yourself, what you write to us), and automatically from your device when you use the platform.

We do not buy information about you, and we do not add outside data to your record.

D.5.1.2 How we use it

We use your information to:

  • show you your images and let you download and share them;

  • run your access, sign you in, and keep you signed in;

  • keep the platform secure — detect suspicious sign-ins, stop misuse, and keep an audit trail of who accessed what;

  • provide the service to your provider, under Section D.3.1;

  • answer you when you ask for help;

  • send you service messages, such as “a new study is available,” a password reset, or a security alert;

  • keep the software working — find and fix bugs, monitor performance;

  • meet our legal obligations.

That is the list. It does not include advertising and it does not include product research on your medical images.

D.5.1.3 What we never do

We never sell your information. Not your images, not your account details, not your email address. Not for money and not for anything else of value.

We never use your images or your health information to train artificial-intelligence models. Not our models, and we do not give your information to anyone else to train theirs.

We never use your information for advertising — not ours, not anyone’s. We do not build advertising profiles, we do not do targeted advertising, and we do not send your health information to advertising companies.

D.5.1.4 No trackers where your images are

No advertising or analytics trackers run on any page where your images are visible.

 
 

To be specific: we do not put a Meta Pixel, Google Analytics, an advertising SDK, an ad-network tag, or a marketing tag manager on pages behind a login, on the login page, on any page that displays a study, or on any share link page. We do not send image content, report content, on-screen medical information, or anything you type into a form to any analytics, advertising, or marketing company.

D.5.1.5 Who we share it with

We share your information only in these situations.

With your provider. Under Section D.3.1 the images belong to your provider’s records, and the people at your provider who are allowed to see them can see them.

With people you choose. When you use the share feature, the recipient you name gets what you sent. See Part A, Section A.8.

With companies that help us run the platform. These companies work for us under written contracts. They may only use your information to do the job we hired them for, never for their own purposes. Where they can touch health information, we put a business associate agreement in place where one is required, as Part C, Section C.1 requires of us.

CompanyWhat it does for us
Amazon Web ServicesHosting, storage, and the background jobs that build exports and image discs
Firebase (Google)Sign-in, and push notifications to mobile devices
CHILIThe third-party diagnostic viewer that clinicians open from OmniPACS
SentryCatches software errors so we can fix them
New RelicMonitors whether the system is running properly
IntercomOur support widget and support conversations
Google WorkspaceSending service email
Stripe, and Maxio/ChargifyPayments and subscription billing — for our health care organization customers. Patients are not billed.
GoHighLevelMarketing and sales contacts on our public website, not patient access

A current list is kept at https://omnipacs.com/legal/subprocessors.

We stay responsible for the companies we hire. If one of them mishandles your information while doing work for us, that is on us, not on you to chase them.

When the law requires it. For example a valid court order or subpoena, or a lawful government request. We tell your provider and follow your provider’s instructions, because they are the ones who own the records. We do not hand over medical images just because someone asks.

To protect people. If we must, to stop serious harm or to investigate a security incident or fraud.

If our business changes hands. If OmniPACS is bought or merged, information may transfer to the buyer, which must keep these commitments — and, for provider-held records, the business associate obligations continue. See also Part E, Section E.4.1.

Where your data is held. The platform runs on cloud services we rent from other companies. We do not promise that your images will be stored or handled in any one country or region.

D.5.2 If something goes wrong: our breach commitment

Breaches of health information are handled under HIPAA. We must tell your provider without unreasonable delay, and your provider tells you as HIPAA requires. Your provider is your point of contact for a breach of its records. Our reporting duties to your provider are in Part C, and they include telling your provider what happened, when it happened, and what information was involved.

If one of our own service providers has a breach, it must tell us, and then we tell your provider.

Where a law requires us to notify you directly, we will do that too, within the time that law allows.

Nothing in Sections D.6 through D.8 — the parts about what we promise and what we owe you — cuts down this commitment or your rights after a breach.

D.5.3 Your rights

D.5.3.1 Your HIPAA rights go through your provider

You have HIPAA rights over your images — including the right to get a copy, the right to ask for a correction (an “amendment”), the right to an accounting of disclosures, the right to ask for restrictions on how your information is used or shared, and the right to complain.

YOU EXERCISE THOSE RIGHTS THROUGH YOUR HEALTH CARE PROVIDER, NOT THROUGH OMNIPACS.

 
 

Please do not send HIPAA requests to us — we cannot act on them, and sending them here only slows you down. Send them to the imaging center, hospital, or physician practice named on your images. Their Notice of Privacy Practices tells you how to ask and gives you a deadline they must meet.

What we will do: when your provider asks us for help answering you — pulling a copy of a study, checking an access log, applying a correction the provider has approved — we will support them promptly, as Part C requires. There is no charge for that help, and no charge to you for getting access to your own images. If you send a request to us by mistake, we will pass it to the right provider and tell them you asked.

You can also complain to your provider’s privacy officer, or to the HHS Office for Civil Rights, at any time. Nobody may retaliate against you for complaining.

D.5.3.2 Rights over an account of your own

There is no account you can open on your own here, so there is no separate set of rights to describe. See Section D.3.2. Images you add yourself are protected health information too, handled under Part C, so the routing in Section D.5.3.1 applies to them as well. You can still ask us to delete something you added yourself — Section D.3.3 explains how. If we ever offer a standalone patient account, we will publish separate terms and a separate notice first.

D.5.3.3 Rights no contract can take away

Some rights are given to you by law and cannot be signed away, no matter what a document like this says. Nothing in this Agreement takes away any of those rights. That includes your rights under HIPAA, under your state’s medical-records access law, under your state’s health privacy and consumer health data law, and under your state’s consumer protection law. If anything in this Agreement conflicts with one of those laws, the law wins for that point, and the rest of the Agreement keeps working. See also Section D.8.2.

D.5.4 How long we keep your images, and how to delete them

Images your provider put here. Your provider decides how long they are kept. Providers have their own legal record-retention periods, which vary by state and by the type of exam. We keep the images for as long as our agreement with your provider requires, and we delete or return them when the provider tells us to or when that agreement ends, as Part C requires. We cannot delete a provider’s records because you ask us to — that request goes to your provider.

Images you added yourself. You can ask us to delete those, and we will. Email support@omnipacs.com with the subject line “PRIVACY REQUEST.” See Section D.3.3.

When something is deleted. It goes out of the live system, and copies in our backups expire on the normal backup cycle. We keep backups for 35 days.

Account and log information. We keep your access record while your access is active. We keep security and access logs longer, because we need them to investigate problems and because audit logs are a legal requirement. Audit logs of access to health information are kept for six years.

Two honest warnings:

  • A share link is not storage. Links can expire and access can be turned off. If you need your images long term, download them and keep your own copy.

  • We may keep information when the law requires it — for example if there is a legal hold or an open investigation.

D.5.5 How we protect your information

We protect your information using reasonable administrative, technical, and physical safeguards. Here is what that means in practice:

  • Encryption in transit. Your information is encrypted while it travels over the internet, using TLS 1.2 or higher.

  • Encryption at rest. Stored images, stored records, and backups are encrypted where they sit, using the encryption built into the cloud services we use.

  • Individual logins. Every user gets their own login. We do not use shared or generic accounts.

  • Access controls. Only people who need access get it, and what they can see is limited by their role.

  • Audit trails. We record who accessed which study and when, and we keep those records for six years.

  • Least privilege for our staff. Our own people get only the access they need to run and support the platform.

  • Training. Our workforce is trained on HIPAA and information security, and there are consequences for staff who break the rules.

  • Vendor contracts. We review the companies we use and require them to protect your information by contract, including a business associate agreement where one is required.

  • Incident response. We have a written process for handling a security incident.

  • Monitoring and backups. We watch for errors and suspicious activity, and we keep backups.

A one-time code when you set up your account or reset your password. When you set up your account, and when you reset your password, we send you a one-time code and you have to type it in. It goes to the email address or mobile number we have on file for you. This does not happen every time you sign in. Sign-in itself is handled through Firebase Authentication with signed tokens. Your password is stored scrambled and never in readable form.

We are not certified by an outside auditor, and the company that runs our servers is — their audit reports cover their own systems, not ours, and we do not claim any certification of our own.

What you can do: use a strong, unique password, keep it private, sign out on shared devices, be careful where you download images, and tell us right away if something looks wrong. Part A, Section A.8 has the full list.

No system is perfectly secure. We do not promise that nothing will ever go wrong. We do promise to keep working at it, and to report a breach as Section D.5.2 says. Nothing in Section D.6 changes the security and privacy promises in this Section D.5.

D.5.6 Children and minors

Parents and guardians. If you are the parent or legal guardian of a child who had an imaging exam, your provider may give you access to that child’s images. Your access is for the child’s care. Section D.1.3 applies to you.

A child’s images inside the platform are protected health information. Any information about a minor patient that we handle through the platform is PHI, and we handle it under HIPAA and under Part C with the provider — exactly the same as for an adult patient. It is not treated as ordinary consumer data.

When a child gets older. In some states, and for some kinds of care — reproductive health, mental health, substance use — a teenager controls their own records and a parent’s access may be limited. Your provider decides and applies those rules. Ask the provider. When a child reaches adulthood, a parent’s access normally ends.

Our platform is not for children to sign up on. There is no self-signup here at all, the platform is not directed to children, and we do not knowingly give anyone under 13 their own login. If you believe a child has been given access by mistake, email support@omnipacs.com and we will look into it.


D.6 What we do and do not promise

D.6.1 What we do promise

We promise you these things, and we mean them:

  • We will handle your information the way Section D.5 says — we will not sell it, we will not use it for advertising, we will not train AI on it, and we will keep it secure using reasonable measures.

  • We will meet our HIPAA duties and the duties in Part C with your provider.

  • We will not knowingly put malicious code into the platform.

  • We will not hold your images hostage. We will not block your access to your own health information to gain leverage in a dispute with your provider or with you.

  • We will report a breach as Section D.5.2 describes.

D.6.1A Which web browsers we support

We build and test the platform on Google Chrome and Microsoft Edge on Windows and Mac computers. On a phone or tablet, we support Chrome on Android and Safari on iPhone and iPad.

Other browsers may still work, and we do not block them. But we cannot promise the platform will work correctly on them, and we may not be able to fix a problem that only happens on a browser we do not support. If something looks wrong, trying Chrome or Edge is the fastest thing to check.

You also need JavaScript, cookies and local storage turned on. Ad blockers, privacy tools and browser add-ons can break the platform, so if something is not working, turning them off for our site is worth a try.

This never stops you from getting your own images. If you cannot use one of these browsers and you need your images, email support@omnipacs.com and we will find another way to get them to you, at no charge.

And remember: no browser, on any device, is meant for a doctor to make a diagnosis from. That is in Part A, Section A.9.

D.6.2 What we do not promise

Apart from what Sections D.5 and D.6.1 say, and apart from anything else we have specifically promised you in writing:

THE PLATFORM IS PROVIDED “AS IS.” WE MAKE NO OTHER WARRANTIES OF ANY KIND.

 
 

In plain terms, that means we are not promising:

  • that the platform will always be available, or will never have an error or an outage;

  • that every bug will be fixed;

  • that it will suit your particular purpose or need;

  • that every image will display perfectly on every phone, tablet, or computer; or

  • that any other company’s product we connect to — including the separate diagnostic viewer described in Part A, Section A.10 — will keep working.

To the extent the law allows, we also disclaim the “implied” warranties that the law would otherwise read into an agreement like this — merchantability, fitness for a particular purpose, title, non-infringement, accuracy, and quiet enjoyment.

This “as is” does not cover our privacy and security promises. The commitments in Section D.5 and Section D.6.1 stay live for you, and no disclaimer here reduces what we owe your provider under Part C.

D.6.3 And most importantly, nothing clinical

WE MAKE NO PROMISE ABOUT THE CLINICAL ACCURACY OR DIAGNOSTIC QUALITY OF ANY IMAGE, MEASUREMENT, OR REPORT, OR ABOUT ANY HEALTH OUTCOME. THIS PLATFORM DOES NOT GIVE MEDICAL ADVICE, DIAGNOSIS, OR TREATMENT, AND IT IS NOT A SUBSTITUTE FOR YOUR DOCTOR’S JUDGMENT.

 
 

The platform is not cleared, approved, or authorized by the US Food and Drug Administration, and it is not sold for making a diagnosis. The images you see here are for your own reference and your own records. They are not a diagnostic reading. We display images. We do not interpret them.

Please read Part A, Section A.9 again. It is the most important thing in this Agreement.


D.7 Limits on what we owe you

This Section limits money. It does not limit your privacy rights, your HIPAA rights, or your right to complain to a regulator.

D.7.1 We are not liable for knock-on losses

NEITHER OF US IS LIABLE TO THE OTHER FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS OR LOST BUSINESS.

 
 

In plain terms: if something goes wrong, each of us is responsible for the direct harm caused, not for a long chain of knock-on effects. This limit is subject to Section D.7.4, which is where the important exceptions live.

D.7.2 A dollar limit on our total liability

EXCEPT AS SECTION D.7.4 SAYS, OUR TOTAL LIABILITY TO YOU FOR EVERYTHING ARISING OUT OF THIS AGREEMENT OR YOUR USE OF THE PLATFORM WILL NOT EXCEED TWENTY-FIVE THOUSAND US DOLLARS ($25,000).

 
 

A few plain points about that number:

  • It is a total limit, not a limit per complaint. Bringing several claims, or claims about several studies, does not raise it.

  • It is a fixed dollar figure. It does not shrink to nothing because you pay us nothing.

  • It covers everything, including anything to do with images you added yourself. Adding your own images creates no new promise from us and no new claim for you.

  • It is a ceiling, not a promise of payment. You still have to show that we did something wrong and that it caused you harm.

  • Costs of dealing with a breach that we caused — investigating it, telling you, and reasonable credit monitoring or identity protection where that is appropriate — count as direct harm, not as the knock-on losses excluded by Section D.7.1.

D.7.3 Why there is a limit at all

You pay us nothing, and this Section is part of how the whole arrangement is balanced. We say that plainly rather than hiding it.

D.7.4 What is never limited — read this

Sections D.7.1 and D.7.2 do not apply at all to any of the following:

  • death or bodily injury caused by our negligence;

  • our gross negligence, our willful misconduct, or our fraud;

  • anything that the law where you live says cannot be limited or excluded.

For those things, there is no cap and no exclusion. Nothing in this Agreement limits them, and nothing in this Agreement should be read as trying to.

Separately, the limits in this Section do not cut down your rights under HIPAA, under your provider’s Notice of Privacy Practices, under Part C with your provider, or under your state’s health privacy, consumer health data, or consumer protection laws. See Sections D.5.3.3 and D.8.2.

The professional caps and the shortened claim deadline in Part B, Section B.7 are deliberately not applied to you.

D.7.5 You do not indemnify us — and we mean that

Our professional contracts contain an indemnity: the customer promises to defend and pay us if a third party sues us over the customer’s conduct. It is a heavy promise, and it is normal between businesses. It is in Part B, Section B.8.

YOU OWE OMNIPACS NO INDEMNITY.

 
 

Not a limited one, not a narrow one, not one hidden in a cross-reference. As a patient or individual using this platform, you are not agreeing to defend us, to pay our legal bills, or to cover our losses. This is a deliberate choice, and we state it as a feature of this Agreement rather than leaving it out quietly. Part B, Section B.8 does not apply to you at all.

One thing does remain yours, and it is narrow. If you use the platform outside what Part A, Section A.5 allows, or you break the rules in Part A, Section A.6, then you are responsible for the consequences of that specific conduct — for example, if you look at images you have no right to see, or you take our software apart. That is ordinary responsibility for your own actions. It is not an indemnity, and it does not extend to anything else you do on the platform.


D.8 If we have a disagreement

We would rather fix a problem than fight about it. This Section explains what happens if we cannot. Part B, Section B.12 — the professional dispute-resolution section, with its jury waiver and class-action waiver — does not apply to you.

D.8.1 Talk to us first

Before either of us starts a court case, write to the other and describe the problem and what you want. Send yours to the address in Section D.10 or to support@omnipacs.com. We will do the same. Then let us try to sort it out for 30 days. Most problems end here.

This step does not stop the clock on your legal rights running out — the deadline for bringing a claim pauses while we are talking. And either of us can skip this step to ask a court for an emergency order, for example to stop a security incident or to protect information.

D.8.2 Which state’s law applies — and what it cannot change

This Agreement is interpreted, as between you and us, under the law of the State of New Jersey, without regard to its conflict-of-laws rules.

But your own state’s protections stay with you. Whatever this Agreement says:

  • every right you have under the consumer protection law of the state where you live that cannot be waived by contract, still applies;

  • every right you have under the health privacy and consumer health data law of the state where you live that cannot be waived by contract, still applies;

  • every right you have under medical-records access law, and under HIPAA, still applies.

If one of those laws conflicts with this Agreement, that law wins on the point it covers, and the rest of the Agreement continues to apply.

D.8.3 Where a case would be heard — and you do not have to travel

If we end up in court, a case may be brought in the state or federal courts in Monmouth County, New Jersey. That choice is not exclusive. It does not stop you from suing somewhere else that the law allows, and we do not ask you to agree that Monmouth County is the only place.

You are not required to travel, and we will not use distance as a weapon. So:

  • You may always bring an individual claim against us in the small-claims court of the county where you live, and we will not object that it is the wrong place.

  • If you have to appear in a case somewhere else, we will not object to your appearing by phone or video where the court allows it.

  • We will not ask a court to make you pay our legal fees. There is no fee-shifting against you in this Part.

D.8.4 No forced arbitration

This Agreement does not require arbitration of your claims. You are not giving up your right to go to court. If we cannot resolve a dispute, either of us may take it to a court, under the Sections above.

D.8.5 You keep your right to a jury, and your right to join with others

  • You do not give up your right to a jury trial. There is no jury-trial waiver that applies to you.

  • You do not give up your right to take part in a class action or any other group or representative case. There is no class-action waiver that applies to you.

We are saying this out loud because those two waivers appear in Part B — our professional terms — and people reasonably assume they appear everywhere. They do not apply to you.

D.8.6 How long you have to bring a claim

We do not shorten it. Whatever deadline the law gives you for bringing a claim, you get the full period. This Agreement does not cut it down. The shortened deadline in Part B, Section B.7 is not applied to patients.


D.9 What this costs you — no fee for access to your own images

Nothing. Patients are not charged to look at their own images here.

  • There is no fee for accessing your own images through OmniPACS.

  • Adding your own older images is free too. We do not charge you to add them, store them, or download them. See Section D.3.3.

  • Patients do not pay subscription fees. Our subscription plans are sold to health care organizations under Part B, Section B.9. You are not on one and you will not be billed for one.

  • We will not ask you for a credit card to view your images. If anyone claiming to be OmniPACS asks you to pay to see your scan, that is not us — tell us at support@omnipacs.com and do not pay.

  • Your provider may charge you its own fees for records — that is between you and your provider, and it is allowed by law in some situations. It is not our charge and we do not collect it.

  • You pay for your own internet, phone, and data.

Because you pay nothing, none of our billing rules apply to you: no plan, no invoice, no auto-renewal, no cancellation process, no late fees, and no suspension for non-payment. See Section D.2.

The same no-fee-for-access rule is a promise we make to providers too, in Part C — we do not charge for giving a person access to their own health information.


D.10 Contact us

OmniPACS Healthcare Technologies LLC
17 Griffin Street
Monmouth Beach, New Jersey 07750
United States
Phone: 813-590-0846

What you needWhere to go
Help with the site, a broken link, a login problemsupport@omnipacs.com · 813-590-0846
A copy of your records, a correction, an accounting of who saw your images, or a restrictionYour doctor, clinic, or imaging center — see Section D.5.3.1
A privacy question or a privacy requestsupport@omnipacs.com, subject line “PRIVACY REQUEST”
Reporting a security problemsupport@omnipacs.com, subject line “SECURITY”
A patient-safety or malfunction reportsupport@omnipacs.com, subject line “URGENT — PATIENT SAFETY” · 813-590-0846
A formal legal notice or a dispute under Section D.8Write to the address above, Attention: Legal, with a copy by email to support@omnipacs.com
A medical emergencyCall 911. Do not message us.

How we send you notices, and how you send them to us, is in Part A, Section A.15. How we tell you about changes to this Agreement is in Part A, Section A.14 — for patients, that is at least 30 days’ notice of a material change, with continued use counting as acceptance, and fresh consent collected where the law requires it. The full contact table for the whole Agreement is in Part E, Section E.5.


PART E — DEFINITIONS, PRECEDENCE AND GENERAL PROVISIONS

This Part applies to everyone. It sets out how the Parts of this Agreement fit together, defines the terms used throughout, explains how we record your acceptance, and contains the general legal provisions.

OmniPACS Healthcare Technologies LLC, a New Jersey limited liability company, 17 Griffin Street, Monmouth Beach, New Jersey 07750, United States (“OmniPACS“). Version 1.0. Effective Date: October 1, 2026. Last Updated: September 9, 2026.


E.1 Order of precedence

E.1.1 Applicability comes before precedence. Before asking which Part wins a conflict, ask which Parts apply to you at all. Part A applies to everyone. Part B and Part C apply only to professional and organizational users. Part D applies only to patients and individuals. A conflict between Part B and Part D is almost always not a conflict — the two Parts are addressed to different people, and only one of them is addressed to you. Part A, Section A.3 governs which Parts apply to you, and Part A, Section A.3.4 governs a person acting in more than one capacity.

E.1.2 Order of precedence. Where a genuine conflict exists between provisions that both apply to you, the following order controls, highest first:

    (a) a separately executed written agreement between OmniPACS and the Subscriber, signed by both parties, including a negotiated Business Associate Agreement executed under Part C, Section C.4. Such an agreement controls over this online Agreement as to the persons and subject matter it covers, and a negotiated Business Associate Agreement supersedes Part C for that Organization;

    (b) an Order Form, as to the persons and subject matter it covers;

    (c) Part C (the Business Associate Agreement), for matters concerning the use, disclosure and safeguarding of Protected Health Information, and solely as between OmniPACS and an Organization. As to PHI, Part C controls over Parts A, B, D and E.

    (d) Part B, for a professional or organizational user, or Part D, for a patient or individual. Because Parts B and C do not apply to a patient or individual at all, Part D does not compete with them;

    (e) Part A; and

    (f) Part E.

Nothing in this order of precedence permits a result below the requirements of 45 CFR 164.504(e), and nothing in it waives a right that the law of a patient’s home state makes non-waivable. Part B, Section B.9.16.4 (access to and retrieval of PHI) controls over every provision of this Agreement.

E.1.3 A conflict must be genuine. A provision that is more specific, or that addresses a subject the other does not, is not in conflict with a general provision. This Section applies only where two provisions that both apply to you cannot both be given effect.

E.1.4 No “most favorable to OmniPACS” rule. No rule that terms more favorable to OmniPACS govern a conflict applies to this Agreement. Conflicts are resolved by this Section E.1 alone. This Agreement will not be construed against either party by reason of authorship.

E.1.5 Your forms do not amend this Agreement. Any purchase order, vendor form, portal terms, click-accepted supplier terms or other document issued by you is for your administrative convenience only. Any additional, conflicting or preprinted terms in such a document are void and of no effect, even if OmniPACS accepts, signs or performs against it, unless OmniPACS signs a document that expressly identifies the provision of this Agreement it amends.


E.2 Definitions

Capitalized terms have the meanings given below or where first defined. These definitions apply throughout this Agreement — Parts A, B, C, D and E alike — except where Part C gives a term the meaning it carries under HIPAA, in which case the HIPAA meaning controls within Part C (Part C, Section C.7 and Section E.1).

E.2.1 “Affiliate” means an entity that controls, is controlled by, or is under common control with a party, where “control” means ownership of more than fifty percent (50%) of the voting interests.

E.2.2 “AI Feature” means any feature of the Platform that applies machine learning, statistical modeling or other automated inference to Customer Data or to Platform metadata, including worklist prioritization and any successor or additional feature so designated in the Documentation.

E.2.3 “AI Output” means any ranking, score, label, flag, ordering, summary or other output generated by an AI Feature.

E.2.4 “Authorized Clinical User” means an individual employee, contractor, member of the medical staff, or credentialed practitioner of a Subscriber or of a Subscriber’s Affiliate, whom the Subscriber provisions with unique credentials to access the Platform on the Subscriber’s behalf.

E.2.5 “AUP” means the Acceptable Use Policy set out in Part B, Section B.3. There is no separately published acceptable use policy.

E.2.6 “BAA” means Part C of this Agreement, the HIPAA Business Associate Agreement between OmniPACS and a Covered Entity or Business Associate. Part C is part of this Agreement, not a separate document, and attaches automatically under Part C, Section C.1. Where an Organization and OmniPACS have separately executed a business associate agreement, “BAA” means that executed agreement as to that Organization, under Part C, Section C.4.

E.2.7 “Billable Study” has the meaning given in Part B, Section B.9.5.

E.2.8 “Billing Period” means, unless an Order Form states otherwise, a calendar month, with the start and end of the month determined in the America/New_York time zone (Eastern Time, observing daylight saving time).

E.2.9 “Business Day” means Monday through Friday, excluding US federal holidays.

E.2.10 “CHILI Viewer” means the third-party diagnostic image viewing application supplied by CHILI GmbH, which users may access from the Platform by means of Signed Ticket URLs. The CHILI Viewer is not part of the Platform.

E.2.11 “Covered Entity” and “Business Associate” have the meanings given at 45 CFR 160.103.

E.2.12 “Customer Data” means all data, images, DICOM objects, metadata, reports, documents, text, worklist entries, patient records and other content uploaded to, transmitted through, generated in, or stored in the Platform by any user, including all PHI contained in it.

E.2.13 “DICOM” means the Digital Imaging and Communications in Medicine standard published by NEMA, including DICOM Part 10 file format and the DICOMweb service family.

E.2.14 “Documentation” means the then-current user and technical documentation for the Platform, including the DICOM Conformance Statement and the Intended Use statement, available from OmniPACS on written request to support@omnipacs.com.

E.2.15 “EHI” means electronic health information as defined at 45 CFR 171.102.

E.2.16 “Fees” means all amounts payable under Part B, Section B.9 or an Order Form, including base subscription fees, overage fees, storage fees, professional services fees, and any other charges stated in an Order Form.

E.2.17 “Included Volume” means the number of Billable Studies included in the base subscription fee for a Billing Period under the subscription plan applicable to the account.

E.2.18 “Local Component” means software OmniPACS makes available for installation or operation in a user’s own environment, including OmniRouter (local DICOM relay agent), EPS-Pi (Enterprise PACS Server for Mac/PC), UDE (Universal Diagnostic Environment iPad application), and OmniMonitor (synthetic monitoring agent).

E.2.19 “Order Form” means an ordering document, online checkout confirmation, or subscription configuration record that identifies the subscription plan, the base subscription fee, the Included Volume, the overage rate, the term and any special terms, and that is accepted by both parties (including by online selection and confirmation).

E.2.20 “Patient or Individual” means a natural person who accesses the Platform to view, download, upload or manage their own medical images and associated records, or those of a person for whom they hold legal authority, and not in a professional or organizational capacity.

E.2.21 “Permitted Medical Purposes” has the meaning given in Part A, Section A.5.

E.2.22 “PHI” means Protected Health Information as defined at 45 CFR 160.103.

E.2.23 “Platform” means the hosted OmniPACS application at app.omnipacs.com, its supporting APIs and infrastructure, the Local Components, and all related features, updates and support that OmniPACS makes available. The Platform does not include the CHILI Viewer, which is a third-party product accessed through the Platform.

E.2.24 “Primary Diagnostic Interpretation” means the professional act of rendering a diagnostic interpretation of a medical imaging examination for clinical purposes, including the generation of an interpretive report on which patient-management decisions are based.

E.2.25 “Referring or Shared-Study Recipient” means a professional recipient who receives access to a Study through a share initiated from a Subscriber’s account.

E.2.26 “Signed Ticket URL” means a time-limited, cryptographically signed URL issued by the Platform that authorizes a specific user session in the CHILI Viewer for specific Studies.

E.2.27 “SLA” means the service level terms in Part B, Section B.10, which state an availability target and not a warranty, apply only to paying Subscribers, and provide no service credits. There is no separately published service level agreement.

E.2.28 “Study” means a DICOM study, being the collection of DICOM objects sharing a single unique value of the DICOM attribute Study Instance UID (0020,000D).

E.2.29 “Study Instance UID” means the DICOM attribute (0020,000D) that uniquely identifies a Study.

E.2.30 “Subscriber” means any person who is a Subscriber under Part B, Section B.1.2, together with the entity in whose name the account is held.

E.2.31 “Subscription Term” means the initial term together with all renewal terms for an account, as described in Part B, Section B.9.15.

E.2.32 “you” and “your” mean the person accepting this Agreement and, where that person accepts on behalf of an entity, that entity.

E.2.33 “Contract Retention Period” means the period during which OmniPACS retains Customer Data, being the duration of the subscription. Absent an Order Form specifying a longer period, OmniPACS has no obligation to retain Customer Data beyond the Subscription Term. Extended retention is available only if ordered in an Order Form and is chargeable at OmniPACS’ then-current published rate. There are no retention tiers.

E.2.34 “Supported Browser” means a browser, browser version and operating system combination that OmniPACS officially supports, as stated in Part A, Section A.4.6. Access from any other browser, browser version, browser engine or operating system is unsupported, and the consequences of unsupported access are in Part A, Section A.4.6 and Part B, Section B.6.6.


E.3 How we record your acceptance

E.3.1 Assent is captured, not assumed. OmniPACS does not and will not rely on passive posting of terms — “browsewrap” — to bind any user. Assent is captured only by an affirmative click or checkbox. See Part A, Section A.2.

E.3.2 What the record contains. For each acceptance of this Agreement, OmniPACS records the acceptance against the accepting person’s authenticated account, together with:

    (a) the version identifier of the accepted document and its effective date;
    (b) the date and time of acceptance;
    (c) the network and device information available to OmniPACS at the time of acceptance; and
    (d) the state of each checkbox presented, including the separate auto-renewal consent described in Section E.3.3(d).

By accepting this Agreement on behalf of an Organization, the accepting person represents that they are authorized to bind the Organization, and OmniPACS may require written confirmation of that authority at any time (Part C, Section C.2). OmniPACS retains acceptance records for at least six (6) years, or one (1) year after the end of the user’s access, whichever is longer, and will produce the record applicable to a user, or to an Organization, on written request.

E.3.3 Acceptance interface. OmniPACS designs its signup, invitation, share-link and re-acceptance flows so that:

    (a) the notice of terms appears immediately adjacent to the action button, on an uncluttered background;
    (b) the notice uses explicit legal-significance wording — the user is told that the click is assent, not merely that terms exist. For a professional user the wording names the Business Associate Agreement expressly, for example: “By clicking CREATE ACCOUNT, I agree to the OmniPACS Platform Agreement, including the Business Associate Agreement in Part C, and I confirm I am authorized to accept it on behalf of my organization”;
    (c) this Agreement is presented as a conspicuous hyperlink in the same visual style as other hyperlinks on the page, in a text size no smaller than surrounding body text; and
    (d) a separate, unchecked checkbox — distinct from the general agreement checkbox — captures a Subscriber’s express affirmative consent to the automatic-renewal terms, the cancellation policy and the billing terms in Part B, Section B.9.

E.3.4 Routing does not narrow the Agreement. The interface may present a user with only the Parts applicable to them, and the acceptance record notes which Parts were presented. The full Agreement is available at the published URL at all times, and a user’s acceptance binds them to every Part applicable to their capacity, whether or not the interface displayed it. Nothing in this Section permits OmniPACS to withhold any Part from a user who wishes to read it.


E.4 General provisions

E.4.1 Assignment.
    (a) You may not assign or transfer this Agreement or any Order Form, in whole or in part, by operation of law or otherwise, including on a merger, reorganization, change of control, or sale of all or substantially all of your assets or equity, without OmniPACS’ prior written consent. The no-transfer restrictions in Part A, Section A.4 and Part A, Section A.7 continue to apply.
    (b) A patient or individual may not transfer this Agreement or their account to anyone else.
    (c) OmniPACS may assign this Agreement freely, in whole or in part, without your consent and without notice, including to an Affiliate and including on a change of control, merger, reorganization, or sale of all or substantially all of its assets or equity, provided the assignee assumes OmniPACS’ obligations under this Agreement and under Part C.
    (d) Any purported assignment in violation of this Section is void. This Agreement binds and benefits the parties’ permitted successors and assigns.

E.4.2 Subcontracting. OmniPACS may engage subprocessors and subcontractors to operate the Platform, subject to Part B, Section B.11 and Part C. OmniPACS enters into written agreements, including business associate agreements where required, with subprocessors that process PHI, and remains responsible for their compliance with Part C.

E.4.3 Force majeure.
    (a) Neither party is liable for any delay or failure in performance (other than a payment obligation) caused by an event beyond its reasonable control, including act of God, fire, flood, hurricane, earthquake, epidemic or pandemic, war, terrorism, civil unrest, governmental action, embargo, labor dispute, failure of the public internet or of a public utility, or a widespread failure of a third-party infrastructure provider (a “Force Majeure Event”).
    (b) The affected party will give prompt notice, use commercially reasonable efforts to mitigate, and resume performance as soon as practicable.
    (c) Limits on this Section. A Force Majeure Event does not excuse: (i) OmniPACS’ obligations not to interfere with access to Customer Data, or the access floor in Part B, Section B.9.16.4, except for the duration and to the extent of an actual technical inability to provide access; (ii) OmniPACS’ obligations under Part C or under Part B, Section B.11 to safeguard ePHI; (iii) OmniPACS’ obligation to provide a patient or individual access to their own health information under Part D; or (iv) a payment obligation. A Force Majeure Event is excluded from the availability calculation under Part B, Section B.10.
    (d) Chronic force majeure. If a Force Majeure Event materially impairs the Platform for more than thirty (30) consecutive days, either party may terminate the affected Order Form on written notice, and OmniPACS will refund prepaid unused base subscription fees and provide the retrieval window in Part B, Section B.9.

E.4.4 Independent contractors; no agency. The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, franchise, employment or agency relationship, and neither party may bind the other. OmniPACS does not practice medicine, does not render clinical services, and does not employ or supervise any clinician.

E.4.5 Third-party beneficiaries. This Agreement is for the benefit of the parties and their permitted successors and assigns only, and creates no rights in any payer, external recipient or other third party except as expressly stated. Three clarifications:
    (a) an individual whose PHI OmniPACS holds as a Business Associate has the rights the HIPAA Rules and Part C give that individual, and nothing in this Section is construed to diminish them;
    (b) a patient or individual who accepts this Agreement is a party to it in that capacity, not a third-party beneficiary, and may enforce Part A and Part D directly against OmniPACS; and
    (c) an Organization bound under Part C is a party to Part C, and may enforce it directly, whether or not it separately executes a BAA under Part C, Section C.4.

E.4.6 Severability. If any provision of this Agreement is held invalid, illegal or unenforceable, that provision will be construed and limited to the minimum extent necessary to make it enforceable, or if that is not possible, severed, and the remaining provisions remain in full force and effect. The parties intend that the limitations of liability and the exclusions of damages in Part B, Section B.7 and Part D, Section D.7 be given the maximum effect permitted by law, and that if a limitation is held unenforceable as to one category of claim, or as to one category of user, or in one Part, it remains enforceable as to all others. In particular, a holding that a provision of Part B is unenforceable against a professional user does not affect Part D, and a holding that a provision of Part D is unenforceable against a patient does not affect Part B.

E.4.7 No waiver. No failure or delay in exercising a right operates as a waiver of that right, and no course of dealing, course of performance, custom, practice or acquiescence waives any right or remedy. A waiver is effective only if in writing and signed by the waiving party, and applies only to the specific instance and the specific right waived.

E.4.8 Interpretation; headings. Section headings are for convenience only and do not affect interpretation. “Including” and “such as” mean “including without limitation.” “Days” means calendar days unless stated as Business Days. The singular includes the plural. References to a statute or regulation include its successors and implementing rules. This Agreement will not be construed against the drafting party (Section E.1.4). Where a provision of Part D expresses in plain language a concept also addressed in Part A or Part B, the plain-language expression is not narrower for being plainer; it is intended to have the same effect as to the person it binds.

E.4.9 Counterparts; electronic signature. Where an Order Form or a separately executed Business Associate Agreement is signed, it may be executed in counterparts and by electronic signature, each of which is an original and all of which together constitute one instrument. The parties consent to the use of electronic records and signatures under the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act) and the Uniform Electronic Transactions Act as enacted in the applicable state, and agree that acceptance of this Agreement by click or checkbox, recorded under Section E.3, constitutes a written and signed agreement for all purposes — including for purposes of the written-contract requirement in 45 CFR 164.504(e) as it applies to Part C.

E.4.10 Survival. The following survive the termination or expiry of your access, of any account through which you access the Platform, and of any Part: Section E.2 (Definitions), this Part E, Part A, Sections A.4 through A.10 in their entirety (the licence grant and its limits, permitted purpose, prohibited uses, ownership, account security, clinical safety and third-party components), Part A, Section A.9 as to Studies interpreted or images viewed while your access was active, and Part A, Section A.15 (notices); and, per their own terms — Part B, Sections B.5 through B.9 (Customer Data, warranties, liability, indemnity, and accrued Fees, taxes, late charges, true-up, termination effects and the preservation of data access), Part B, Section B.12 (dispute resolution); Part C in its entirety, to the extent PHI is retained; and Part D, Sections D.5 through D.8 (the privacy notice as to information still held, warranties, liability and dispute resolution); plus any other provision that by its nature should survive.

E.4.11 Entire agreement. This Agreement — comprising the front matter, Parts A through E, each Order Form, and any other document expressly incorporated by reference — is the complete and exclusive statement of the parties’ agreement regarding the Platform, and supersedes all prior and contemporaneous proposals, quotes, marketing materials, statements of work, oral and written communications, all prior versions of OmniPACS’ terms of service, and all prior clickthrough terms between the parties regarding the Platform.

    (a) Two documents sit outside this Agreement, because they are not OmniPACS’ to write: a Covered Entity’s own Notice of Privacy Practices, which governs PHI that entity placed on the Platform and which prevails over this Agreement as to that PHI; and any separately executed Business Associate Agreement under Part C, Section C.4, which replaces Part C for that Organization. Both only ever add protection for an individual; neither takes any away.
    (b) The Privacy Policy is a separate published notice, not part of this Agreement and not a contract. It applies to everyone. See Part A, Section A.11.
    (c) Purchase orders and your forms. Section E.1.5 applies.
    (d) No reliance. Each party acknowledges that it has not relied on any representation, warranty or statement not expressly set out in this Agreement. This Section does not limit liability for fraud or fraudulent misrepresentation.
    (e) Order of precedence. Conflicts are resolved under Section E.1, not by reference to which document is more favorable to either party.

E.4.12 Government users. If you are a US federal, state, local or tribal government entity, or a public hospital or state university, the Platform is provided as “commercial computer software” and “commercial computer software documentation” under FAR 12.212 and DFARS 227.7202, with only those rights granted to all other users under this Agreement. OmniPACS makes no representation that the Platform holds a FedRAMP authorization or any state equivalent authorization, and OmniPACS is under no obligation to obtain one. Any additional or conflicting term required by applicable public-procurement law is effective only if stated in an Order Form signed by OmniPACS.

E.4.13 Publicity. Neither party will use the other’s name, logo or trademarks in publicity, customer lists, case studies or press releases without prior written consent, except that OmniPACS may identify a Subscriber by name and logo in a customer list and on its website. OmniPACS will never use the name of a patient or individual for any publicity purpose.

E.4.14 Export control and sanctions compliance. You represent and warrant that you will comply with all applicable US export control, economic sanctions and anti-boycott laws, including the Export Administration Regulations and the sanctions programs administered by the US Department of the Treasury Office of Foreign Assets Control. You will not access or use the Platform, and will not permit any user to do so, from, or export, re-export or transfer any part of the Platform or any Local Component to, any country, region, entity or person subject to US sanctions or export restrictions, and you represent that you are not such an entity or person and are not owned or controlled by one. OmniPACS may suspend or terminate access immediately on becoming aware of a violation or suspected violation of this Section.

E.4.15 Notices. Formal legal notice to OmniPACS must be given in writing to OmniPACS Healthcare Technologies LLC, 17 Griffin Street, Monmouth Beach, New Jersey 07750, United States, Attention: Legal, with a copy by email to support@omnipacs.com. Notice to you may be given by email to the address associated with your account, by notice within the Platform, or in writing to the address on the account. Notice is effective on the date of delivery, or, for email and in-product notice, on the date sent. You are responsible for keeping your account contact information current.

E.4.16 Governing law. This Agreement and any dispute arising out of or relating to it or to the Platform are governed by the laws of the State of New Jersey, without regard to its conflict-of-laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply. The audience-specific venue, jurisdiction and dispute-resolution terms are set out in Part B, Section B.12 for professional and organizational users, and in Part D, Section D.8 for patients and individuals, and those Sections control over this Section as to venue, jurisdiction and procedure. Nothing in this Section waives a right that the law of a patient’s home state makes non-waivable.


E.5 Contact

PurposeAddress
General support and questionssupport@omnipacs.com · 813-590-0846
Sales, orders and plan changessales@omnipacs.com
Privacy requests and questionssupport@omnipacs.com, subject line “PRIVACY REQUEST”
Security reports and vulnerability disclosuresupport@omnipacs.com, subject line “SECURITY”
Patient-safety and malfunction reportssupport@omnipacs.com, subject line “URGENT — PATIENT SAFETY” · 813-590-0846
Breach notification to OmniPACSsupport@omnipacs.com, subject line “HIPAA BREACH NOTICE”
Business Associate Agreement matters, including a request for your organization’s executed copy or to submit your own business associate agreement form under Part C, Section C.4support@omnipacs.com, subject line “HIPAA”
Billing and cancellationsales@omnipacs.com, and the in-product cancellation control described in Part B, Section B.9
Formal legal notices and disputesOmniPACS Healthcare Technologies LLC, 17 Griffin Street, Monmouth Beach, New Jersey 07750, United States, Attention: Legal, with a copy by email to support@omnipacs.com

Postal address: OmniPACS Healthcare Technologies LLC, 17 Griffin Street, Monmouth Beach, New Jersey 07750, United States.

In a medical emergency, do not use any of these addresses. Call 911 or your local emergency number.