Terms of Service & Privacy Policy

Last updated: August 26, 2026

Effective Date: August 26, 2026. Supersedes the version dated April 20, 2026.


Part I — Terms of Service

These Terms of Service (“Terms”) constitute a legally binding agreement between Lime Health Labs, Inc., a Delaware corporation (“Lime Health Labs,” “Company,” “we,” “our,” or “us”), and the individual or entity that accesses or uses the Services (“you” or, where the context refers to the contracting organization, “Customer”). These Terms govern access to and use of the Lime Health Labs website at getlimeai.com (the “Site”), our mobile applications (the “App”), and our platform and related services (collectively, the “Services”).

BY ACCESSING OR USING THE SERVICES, OR BY EXECUTING AN ORDER FORM OR SERVICE AGREEMENT THAT REFERENCES THESE TERMS, YOU AGREE TO BE BOUND BY THESE TERMS. IF YOU DO NOT AGREE, DO NOT ACCESS OR USE THE SERVICES.

SECTION 20 CONTAINS A BINDING ARBITRATION PROVISION AND A CLASS ACTION WAIVER THAT AFFECT YOUR LEGAL RIGHTS. SECTIONS 7, 17, 18, AND 19 CONTAIN IMPORTANT ALLOCATIONS OF RISK RELATING TO THIRD-PARTY SYSTEM INTEGRATIONS, DISCLAIMERS, LIMITATIONS OF LIABILITY, AND INDEMNIFICATION OBLIGATIONS. PLEASE READ THEM CAREFULLY.

1. Agreement Structure and Order of Precedence

1.1 Components of the Agreement. The complete agreement between Lime Health Labs and Customer (the “Agreement”) consists of: (a) any Business Associate Agreement executed by the parties (a “BAA”); (b) any order form, statement of work, or subscription schedule executed or otherwise accepted by the parties (an “Order Form”); (c) any master services agreement, subscription agreement, or similar negotiated agreement executed by the parties (an “MSA”); (d) these Terms; and (e) any policies, documentation, or exhibits expressly incorporated by reference into any of the foregoing, including the Privacy Policy.

1.2 Order of Precedence. In the event of a conflict or inconsistency among the components of the Agreement listed in Section 1.1, they govern in the descending order in which they are listed there, as follows:

  1. the BAA, but solely with respect to the use, disclosure, safeguarding, and handling of Protected Health Information and solely to the extent required by HIPAA;
  2. the Order Form, with respect to the commercial terms it addresses (including fees, subscription scope, term, and any Service-specific terms);
  3. the MSA, if any;
  4. these Terms; and
  5. all other documents incorporated by reference.

1.3 BAA Controls for PHI. Nothing in these Terms is intended to, and nothing in these Terms shall be construed to, limit, waive, modify, or conflict with any obligation of Lime Health Labs or Customer under HIPAA or under an executed BAA. To the extent any provision of these Terms conflicts with the BAA with respect to PHI, the BAA governs that subject matter. To the extent a matter is not addressed by the BAA, or does not concern PHI, these Terms and the other components of the Agreement govern.

1.4 No Implied Amendment of the BAA. Customer’s acceptance of these Terms does not amend, supersede, or serve as a waiver of any term of an executed BAA, and Lime Health Labs’s performance under these Terms does not constitute a representation that any particular use or disclosure of PHI is permitted where the BAA or HIPAA provides otherwise.

2. Definitions

Capitalized terms used but not defined in these Terms have the meanings given in the MSA, Order Form, or BAA, as applicable. Terms defined in HIPAA — including “Covered Entity,” “Business Associate,” “Breach,” “Security Incident,” and “Unsecured PHI” — have the meanings given to them in HIPAA. In addition:

“Authorized User” means an individual authorized by Customer to access or use the Services on Customer’s behalf, including clinicians, administrators, coders, QA reviewers, and IT personnel.

“Customer Data” means all data, content, records, documentation, audio, and other information that Customer or its Authorized Users submit to the Services, that Lime Health Labs collects or generates on Customer’s behalf in performing the Services, or that Lime Health Labs receives from or transmits to a Third-Party Service at Customer’s direction.

“Effective Date” means August 26, 2026, the effective date of these Terms as stated above. The Effective Date of these Terms is distinct from the date on which these Terms become binding on a particular Customer, which is determined under Section 15.1.

“Customer Instruction” means any direction, configuration, request, authorization, election, enablement, credential provision, or approval given to Lime Health Labs by Customer or by an Authorized User acting or reasonably appearing to act on Customer’s behalf, whether given in writing, through the Services’ user interface or administrative controls, through an implementation or onboarding process, through a support channel, or through any other means Lime Health Labs reasonably accepts.

“HIPAA” means the Health Insurance Portability and Accountability Act of 1996, as amended, together with the Health Information Technology for Economic and Clinical Health Act and their implementing regulations.

“Integration” means any connection, interoperation, data exchange, or interaction between the Services and a Third-Party Service, established or enabled at Customer’s direction. Integrations include, without limitation, connections effected through: application programming interfaces (APIs); Customer-provided or Customer-provisioned credentials; OAuth, SAML, SMART on FHIR, token-based, certificate-based, or other authentication or authorization frameworks; HL7, FHIR, X12, or other health data interchange standards; browser-based, session-based, or user-interface-mediated access; robotic process automation, automated data entry, automated data retrieval, or other programmatic interaction with a user interface; secure file transfer, batch export or import, flat-file exchange, or messaging queues; direct database or data warehouse connections; Customer-controlled accounts, service accounts, or delegated-access accounts; webhooks, event streams, or push notifications; middleware, interface engines, or integration platforms; and any other current or future mechanism by which the Services and a Third-Party Service exchange data or interoperate, regardless of the technical method used and regardless of whether that method exists as of the Effective Date.

“PHI” means Protected Health Information as defined at 45 C.F.R. § 160.103.

“Third-Party Provider” means the vendor, licensor, owner, operator, or controller of a Third-Party Service, including any electronic medical record or electronic health record vendor.

“Third-Party Service” means any software, platform, system, database, network, or service that is not owned, operated, or controlled by Lime Health Labs, including electronic medical record and electronic health record systems (“EMR/EHR”), practice management systems, billing and revenue cycle systems, scheduling systems, clearinghouses, health information exchanges, identity providers, and any other system Customer uses or licenses.

3. Eligibility, Authority, and Authorized Users

3.1 Authority to Contract. You represent and warrant that: (a) you are at least 18 years of age; (b) you have the legal capacity and authority to enter into these Terms; and (c) if you are accessing or using the Services on behalf of an organization, you have been duly authorized to bind that organization, and that organization is the Customer under these Terms.

3.2 Responsibility for Authorized Users. Customer is responsible for: (a) determining who is granted Authorized User status and the scope of each Authorized User’s permissions; (b) ensuring that each Authorized User complies with these Terms; (c) ensuring that each Authorized User has the professional licensure, credentialing, supervision, training, and internal authority appropriate to their role; and (d) all acts and omissions of its Authorized Users. Any act or omission of an Authorized User that would constitute a breach of these Terms if performed by Customer is a breach by Customer.

3.3 Authority to Instruct. Customer is solely responsible for ensuring that any individual who gives a Customer Instruction — including any instruction relating to an Integration, a credential, a data flow, or a workflow — holds the internal authority to do so on Customer’s behalf. Customer will maintain reasonable internal controls governing who may give such instructions and will promptly notify Lime Health Labs when an individual’s authority is revoked or changed. See Section 7.8 (Reliance on Customer Instructions).

4. Accounts and Security

4.1 Account Registration. To access certain features, Customer and its Authorized Users must register an account and provide accurate, current, and complete information, and must keep that information updated.

4.2 Account Security. Customer and each Authorized User are responsible for maintaining the confidentiality of account credentials and for all activity occurring under their accounts. Customer will use unique, individually attributable credentials for each Authorized User wherever the Services and applicable Third-Party Services support them, and will not permit credential sharing among individuals except where no technically supported alternative exists and doing so is permitted by applicable law, applicable security requirements, and Customer’s agreements with any affected Third-Party Provider.

4.3 Notification. Customer will notify Lime Health Labs promptly at security@getlimeai.com or support@getlimeai.com upon learning of any actual or suspected unauthorized access to or use of the Services or any account.

4.4 Allocation. Lime Health Labs is not liable for loss or damage arising from Customer’s or an Authorized User’s failure to safeguard credentials, except to the extent such loss or damage results from Lime Health Labs’s own breach of its security obligations under the Agreement, the BAA, or applicable law.

5. The Services

5.1 Scope. Lime Health Labs provides an artificial-intelligence-assisted clinical documentation platform for post-acute and home-based healthcare organizations. The Services may include, without limitation: an ambient AI clinical scribe with audio capture; automated drafting of clinical documentation (including visit notes and OASIS and HOPE assessments); AI-suggested ICD-10 coding; documentation quality assurance and review; admissions intake automation; and Integrations with Third-Party Services.

5.2 License Grant. Subject to the Agreement and payment of applicable fees, Lime Health Labs grants Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable right to access and use the Services during the subscription term solely for Customer’s internal business and clinical operations.

5.3 Changes to the Services. Lime Health Labs may modify, enhance, or discontinue features of the Services from time to time. Lime Health Labs will not materially degrade the core functionality of the Services purchased under an active Order Form during the then-current subscription term without notice as provided in the MSA or Order Form.

5.4 Restrictions. Customer will not, and will not permit any Authorized User or third party to: copy, modify, distribute, sell, resell, lease, sublicense, or create derivative works of the Services; reverse engineer, decompile, or disassemble the Services except to the extent that restriction is prohibited by applicable law; access the Services to build a competing product or to benchmark without written consent; use the Services to transmit malicious code; interfere with or disrupt the integrity or performance of the Services; attempt to gain unauthorized access to the Services or related systems; or use the Services in violation of applicable law or third-party rights.

6. Audio Recording and Consent

6.1 User-Initiated Recording. Audio recording is initiated solely by an Authorized User through an affirmative action within the App. The Services do not passively record and do not activate recording without affirmative user action.

6.2 Customer Responsibility for Consent. Customer is solely responsible for obtaining and documenting all consents, notices, and authorizations required from patients, caregivers, workforce members, and any other individuals present during a recorded encounter, in compliance with all applicable federal, state, and local laws — including all-party and two-party consent wiretapping and eavesdropping statutes — and with Customer’s own policies, HIPAA, and applicable professional standards.

6.3 Allocation. Customer bears responsibility for its failure to obtain required consents and for its violation of any recording, wiretapping, eavesdropping, or surveillance law. Lime Health Labs does not determine which consents are required in Customer’s jurisdiction or for a given encounter and does not undertake to advise Customer on that question.

7. Third-Party Integrations, Customer Authorization, and Third-Party Systems

This Section 7 states a core allocation of risk. Customer chooses which Third-Party Services to connect, controls its relationships with Third-Party Providers, and is the only party in a position to know what its agreements with those providers permit. Accordingly, Customer bears the risk arising from its own authorization decisions, and Lime Health Labs is entitled to rely on Customer’s authorization.

7.1 Customer-Directed Access

When Customer or an Authorized User enables, requests, configures, provisions credentials or access for, initiates, approves, or otherwise authorizes an Integration between the Services and any Third-Party Service, Customer thereby expressly instructs and authorizes Lime Health Labs to access, connect to, authenticate to, read data from, write data to, and otherwise interact with that Third-Party Service on Customer’s behalf, at Customer’s direction, and solely as reasonably necessary to provide the Services that Customer has requested. Such access is performed on Customer’s behalf and within the scope of Customer’s instruction. Lime Health Labs does not access any Third-Party Service in the absence of such a Customer Instruction.

This Section applies to every Integration mechanism within the definition of “Integration” in Section 2, including API-based, credential-based, OAuth or token-based, browser-based, automated-data-entry, automated-retrieval, file-transfer, and Customer-controlled-account mechanisms, and to any integration mechanism developed or adopted in the future, whether or not that mechanism is described in these Terms or existed as of the Effective Date. The parties intend this Section to be read broadly and to apply to the substance of the connection rather than to its technical form.

7.2 Customer Representation of Authority

Customer represents and warrants, on a continuing basis and as of each occasion on which an Integration is enabled, configured, modified, or used, that Customer has and will maintain all rights, title, licenses, consents, permissions, contractual rights, regulatory approvals, workforce and organizational authorizations, and other authority necessary to:

  1. authorize Lime Health Labs to establish and operate the Integration by the method Customer has selected or approved;
  2. grant Lime Health Labs the access, credentials, tokens, accounts, or other means of connection that Customer provides or provisions;
  3. permit Lime Health Labs to retrieve, receive, process, generate, transmit, and write back the categories of data involved in the Integration, including PHI;
  4. permit the volume, frequency, and automated or programmatic nature of the access contemplated by the Integration; and
  5. give each Customer Instruction relating to the Integration.

Customer further represents and warrants that the Integration and each Customer Instruction relating to it comply with all applicable laws and do not violate the rights of any third party.

Lime Health Labs is entitled to rely, without independent investigation, on Customer’s representations under this Section 7.2 and on each Customer Instruction. Lime Health Labs’s willingness to establish or operate an Integration is not a representation, determination, or endorsement by Lime Health Labs that the Integration is permitted under Customer’s agreements with any Third-Party Provider or under any law applicable to Customer.

7.3 Customer Responsibility for Third-Party Agreements

Customer is solely responsible for, and Lime Health Labs has no responsibility for:

  1. Customer’s relationship with each Third-Party Provider, including each EMR/EHR vendor;
  2. Customer’s compliance with its contracts, license agreements, end-user license terms, terms of service, API terms, developer terms, acceptable use policies, security requirements, data-use restrictions, and any other terms imposed by a Third-Party Provider;
  3. obtaining any consent, approval, authorization, waiver, certification, registration, developer enrollment, or written permission that a Third-Party Provider requires before a third party such as Lime Health Labs may access, integrate with, or exchange data with that Third-Party Service;
  4. confirming that Customer’s licenses, seat counts, user entitlements, and subscription tier permit the requested use, including any additional use arising from the Integration;
  5. determining, in the first instance, whether a proposed Integration and the method by which it operates are permitted;
  6. creating, maintaining, and appropriately provisioning authorized user accounts, service accounts, tokens, and credentials, and de-provisioning them when they are no longer authorized;
  7. obtaining all patient, workforce, organizational, payor, and regulatory consents, notices, authorizations, and permissions required in connection with the Integration and the data it moves; and
  8. ensuring that every Customer Instruction it gives to Lime Health Labs is lawful and consistent with Customer’s obligations to third parties.

Lime Health Labs is not obligated to interpret, review, audit, monitor, enforce, or police Customer’s agreements with any Third-Party Provider, and does not undertake to determine whether a given Integration is permitted under those agreements, unless Lime Health Labs has expressly agreed to do so in a writing signed by an authorized representative of Lime Health Labs. Any assistance, guidance, technical configuration support, or informal comment provided by Lime Health Labs personnel regarding a Third-Party Service does not constitute legal advice, does not constitute such a written undertaking, and does not shift responsibility under this Section 7.3 to Lime Health Labs.

7.4 No Relationship with Third-Party Providers

Unless expressly stated otherwise in a writing signed by Lime Health Labs:

  1. Lime Health Labs is independent of, and has no commercial, contractual, licensing, agency, partnership, joint venture, or certification relationship with, any Third-Party Provider, including any EMR/EHR vendor whose system Customer directs Lime Health Labs to access;
  2. the existence or operation of an Integration does not imply and shall not be construed as endorsement, sponsorship, approval, partnership, certification, validation, accreditation, authorization, affiliation, or agency by, with, or on behalf of any Third-Party Provider, and Lime Health Labs makes no representation that any Integration is certified by or approved by any Third-Party Provider;
  3. Lime Health Labs does not own, operate, or control any Third-Party Service, and does not control that service’s availability, performance, security, data accuracy, retention, or continued support for any interface;
  4. Lime Health Labs does not and cannot guarantee the continued availability, functionality, performance, or permissibility of any Integration; and
  5. Third-Party Providers may at any time and without notice to Lime Health Labs modify, deprecate, throttle, restrict, condition, suspend, or discontinue their APIs, interfaces, data models, workflows, authentication requirements, security requirements, terms, pricing, or access, and may block, disable, or take action against accounts or credentials, including those Customer has provisioned for the Integration.

Customer’s use of any Third-Party Service is governed by Customer’s agreement with the applicable Third-Party Provider and not by these Terms.

7.5 Credentials and Access

Where an Integration involves credentials, tokens, certificates, accounts, or other means of access:

  1. Customer represents and warrants that it is permitted to provide or provision the access it provides, including under its agreements with the applicable Third-Party Provider and under applicable law, and that the account type, permission scope, and access method it selects are permitted for the intended use.
  2. Lime Health Labs will use such access solely to provide the Services that Customer has requested, within the scope of Customer’s authorization, and consistent with the Agreement, the BAA, and applicable law. Lime Health Labs will not use Customer’s access for any other purpose.
  3. Customer will apply the minimum necessary access principle. Customer will, wherever the applicable Third-Party Service supports it, provision access through mechanisms designed for programmatic or delegated third-party access — such as an API key, an OAuth grant, a named service account, or a role-scoped integration account with unique identification and independent audit attribution — rather than by sharing an individual clinician’s or administrator’s personal login. Customer will not provide Lime Health Labs with credentials whose provision or use would itself violate applicable law, applicable security or authentication requirements, or Customer’s agreements with the applicable Third-Party Provider. Nothing in these Terms requires, requests, invites, or authorizes Customer to share credentials in a manner inconsistent with those requirements, and Lime Health Labs’s acceptance of credentials Customer provides is not a determination that their provision was permitted.
  4. Customer remains responsible for maintaining appropriate permissions throughout the term, including reviewing access periodically, applying its own access-control and workforce-security policies, rotating credentials in accordance with its policies, and promptly disabling or revoking access when it is no longer authorized or appropriate.
  5. Customer will promptly notify Lime Health Labs — and, where feasible, in advance — if any access should be revoked or restricted; if credentials have changed, expired, or been compromised; if Customer’s authority to grant the access changes or terminates; or if a Third-Party Provider raises any question, objection, restriction, or claim concerning Lime Health Labs’s access. Until Lime Health Labs receives such notice and has had a commercially reasonable opportunity to act on it, Lime Health Labs may continue to rely on the access previously authorized.
  6. Lime Health Labs will maintain the administrative, physical, and technical safeguards described in the Agreement and the BAA with respect to credentials in its possession, including encryption in transit and at rest and access restriction on a need-to-know basis.

7.6 Data Flows

Customer acknowledges that, depending on the Integration Customer configures, the Services may retrieve data from a Third-Party Service, generate or transform data, and write data back into a Third-Party Service, including into the legal medical record. Customer is responsible for configuring, reviewing, and approving which data is retrieved and which data is written back, and for the consequences of that configuration within its own systems and records. See Section 9 (Clinical, Documentation, and Regulatory Responsibilities).

7.7 Third-Party Objections and Claims

If a Third-Party Provider objects to, questions, restricts, throttles, suspends, terminates, or asserts any claim, demand, investigation, or proceeding relating to an Integration or to Lime Health Labs’s access to that Third-Party Service at Customer’s direction:

  1. the underlying dispute regarding whether Customer was authorized to permit the Integration is between Customer and that Third-Party Provider;
  2. Customer will notify Lime Health Labs promptly, and in any event within five (5) business days of becoming aware;
  3. Customer will cooperate in good faith with Lime Health Labs to investigate and, where appropriate, to suspend, modify, or terminate the Integration;
  4. Customer’s defense and indemnification obligations under Section 19 apply to the extent set forth in that Section; and
  5. Lime Health Labs may exercise its suspension rights under Section 7.9.

Nothing in this Section 7.7 limits Lime Health Labs’s right to defend itself, to communicate directly with a Third-Party Provider regarding a claim asserted against Lime Health Labs, or to take steps it reasonably believes necessary to mitigate its own exposure.

7.8 Reliance on Customer Instructions

Lime Health Labs is entitled to rely, and Customer expressly authorizes Lime Health Labs to rely, on Customer Instructions given by any individual who is an Authorized User or who reasonably appears to Lime Health Labs to be acting with Customer’s authority, including instructions regarding:

  1. which Third-Party Services to connect to, and by which method;
  2. which accounts, environments, tenants, facilities, or organizational units to access;
  3. which credentials, tokens, or access mechanisms to use;
  4. which data, records, encounters, patients, or date ranges to retrieve;
  5. which information to generate, transform, or write back into a Third-Party Service, and into which fields, forms, or record locations;
  6. which workflows, automations, or features to enable, disable, or configure; and
  7. the scope, frequency, and duration of access.

Lime Health Labs has no obligation to independently verify that an individual giving a Customer Instruction holds the internal authority to give it, and no obligation to second-guess the substance of a Customer Instruction. Customer is responsible for ensuring that its personnel who give Customer Instructions have appropriate authority to do so, and Customer is bound by Customer Instructions given by such individuals. Lime Health Labs may, but is not required to, seek confirmation of any Customer Instruction, and may decline to act on any instruction it believes may be unauthorized, unlawful, or inconsistent with the Agreement.

7.9 Right to Suspend or Disable an Integration

Lime Health Labs may suspend, disable, restrict, or decline to establish any Integration, in whole or in part, immediately and with or without advance notice, if Lime Health Labs reasonably believes that:

  1. Customer lacks, or may lack, the authority or authorization required under Section 7.2;
  2. continued access could violate applicable law or regulation;
  3. there is a security, privacy, integrity, or data-protection concern relating to the Integration, the credentials, or the Third-Party Service;
  4. a Third-Party Provider or other owner or controller of the relevant system has credibly disputed, restricted, objected to, or revoked the access;
  5. continued operation could expose Lime Health Labs, Customer, patients, or any third party to material legal, regulatory, clinical, reputational, or security risk; or
  6. Customer has materially breached Section 7.

Suspension of a particular Integration does not, by itself, suspend or terminate Customer’s account or Customer’s right to use the remainder of the Services, and Lime Health Labs will limit any suspension in scope and duration to what it reasonably believes necessary to address the concern. Lime Health Labs will provide notice of the suspension as promptly as reasonably practicable (and in advance where practicable and appropriate), will describe the basis for the suspension in reasonable detail, and will work in good faith with Customer to restore the Integration if and when the basis for suspension is resolved. Suspension under this Section is not a breach of the Agreement by Lime Health Labs and does not relieve Customer of its payment obligations, except as expressly provided in an MSA or Order Form.

7.10 Operational Risks of Third-Party Services

Lime Health Labs is not responsible for, and Customer assumes the risk of, data loss, data corruption, delay, downtime, account lockout, throttling, rate limiting, degraded performance, incomplete data, or interruption of an Integration resulting from: (a) incorrect, expired, revoked, insufficiently permissioned, or compromised credentials provided by Customer; (b) changes a Third-Party Provider makes to its system, APIs, data model, workflows, authentication requirements, security requirements, or terms; (c) actions a Third-Party Provider takes against accounts or credentials Customer provisioned; (d) outages, errors, defects, or data-quality problems originating in a Third-Party Service; or (e) Customer’s own configuration, mapping, or authorization decisions. This Section does not limit Lime Health Labs’s responsibility for its own breach of its security obligations under the Agreement, the BAA, or applicable law.

8. Customer Responsibilities

In addition to its obligations elsewhere in these Terms, Customer will:

  1. use the Services in compliance with all applicable laws, regulations, and professional standards, including HIPAA, state health-privacy and consumer-privacy laws, Medicare and Medicaid conditions of participation and program-integrity requirements, applicable CMS guidance, professional licensing requirements, and applicable anti-fraud and anti-kickback laws;
  2. obtain and maintain all required patient consents, notices, and authorizations;
  3. safeguard all account credentials, Third-Party Service credentials, API keys, and tokens, and maintain access controls appropriate to a healthcare environment;
  4. maintain the accuracy and completeness of Customer Data it supplies to the Services, and hold all rights necessary to supply it;
  5. supervise its clinicians and workforce and maintain policies governing use of the Services; and
  6. not use the Services for any unlawful purpose or in any manner prohibited by Section 5.4.

9. Clinical, Documentation, and Regulatory Responsibilities

9.1 Lime Health Labs Does Not Practice Medicine. Lime Health Labs is not a healthcare provider, does not practice medicine, nursing, or any other licensed profession, and does not provide medical advice, diagnosis, or treatment. Use of the Services does not create a provider-patient relationship between Lime Health Labs and any individual. The Services support and assist Customer’s licensed workforce; they do not exercise clinical judgment and do not replace it.

9.2 Customer Retains Clinical and Regulatory Responsibility. As between the parties, Customer is solely responsible for:

  1. all clinical judgment, clinical decision-making, and patient care decisions;
  2. the review, editing, verification, and approval of all documentation before it is finalized, signed, submitted, or relied upon, including all documentation drafted or suggested by the Services;
  3. the accuracy, completeness, timeliness, and clinical appropriateness of any information entered into, written to, or submitted to a medical record, EMR/EHR, payor, clearinghouse, registry, or regulatory body;
  4. all coding, billing, claims, and reimbursement decisions, including the final selection and validation of diagnosis and procedure codes and the certification of any claim submitted for payment;
  5. compliance with CMS, state survey agency, accrediting body, payor, and other regulatory and contractual obligations, including OASIS and HOPE submission requirements and documentation-integrity requirements;
  6. determining whether any documentation, assessment, or output is appropriate for the individual patient and encounter; and
  7. appropriate supervision, training, credentialing, and oversight of its clinicians and workforce in their use of the Services.

9.3 Mandatory Human Review. Customer will ensure that a qualified Authorized User reviews and approves AI-generated content before it is submitted to any medical record, payor, or regulatory body. Customer will not configure or use the Services in a manner that bypasses human review where such review is required by law, payor rule, accreditation standard, or professional standard.

10. AI-Generated Content

THE SERVICES USE ARTIFICIAL INTELLIGENCE TO GENERATE DRAFT CLINICAL DOCUMENTATION, CODING SUGGESTIONS, AND QUALITY-ASSURANCE ANALYSIS. CUSTOMER ACKNOWLEDGES AND AGREES THAT:

  1. AI-generated outputs are drafts and suggestions only, are not final clinical documentation, and are not a substitute for professional clinical judgment;
  2. AI systems can produce output that is incomplete, inaccurate, internally inconsistent, or not clinically appropriate, including output that appears plausible but is incorrect;
  3. the reviewing Authorized User is solely responsible for reviewing, correcting, and approving all AI-generated content before it is used, signed, submitted, or relied upon for patient care, documentation, billing, or regulatory purposes;
  4. Lime Health Labs does not warrant the accuracy, completeness, or clinical appropriateness of AI-generated content; and
  5. Customer assumes the risk associated with reliance on AI-generated content that has not been independently reviewed and verified.

11. Data, PHI, and HIPAA

11.1 Business Associate Status. Where Lime Health Labs creates, receives, maintains, or transmits PHI on behalf of Customer, Lime Health Labs acts as a Business Associate under HIPAA. The parties will execute a BAA before Lime Health Labs processes PHI. Lime Health Labs’s use and disclosure of PHI is governed by the BAA and HIPAA.

11.2 Customer’s HIPAA Status. Customer is responsible for determining and representing whether it is a Covered Entity, a Business Associate, or neither with respect to the data it submits or directs Lime Health Labs to access, and for performing its own obligations in that capacity — including minimum necessary determinations, notice of privacy practices, individual rights requests, workforce training, and its own risk analysis and risk management under the HIPAA Security Rule. Customer is responsible for obtaining any downstream authorization required where Customer is itself a Business Associate of another entity.

11.3 Integrations and PHI. Where an Integration involves PHI, the BAA governs Lime Health Labs’s use, disclosure, and safeguarding of that PHI, and these Terms govern the commercial and authorization matters addressed here — including Customer’s representation of authority in Section 7.2, Customer’s responsibility for Third-Party Provider agreements in Section 7.3, and the allocation of risk in Sections 18 and 19. These are complementary, not conflicting: Customer’s compliance with HIPAA does not establish that Customer was contractually permitted by a Third-Party Provider to authorize an Integration, and Lime Health Labs’s compliance with the BAA does not constitute a determination that the Integration was so permitted.

11.4 Customer Data Ownership. As between the parties, Customer owns and retains all right, title, and interest in and to Customer Data, including clinical documentation generated through the Services from Customer’s data and any medical records processed through the Services. Lime Health Labs claims no ownership of Customer’s medical records or PHI by virtue of processing them. Lime Health Labs retains all right, title, and interest in and to the Services and the underlying software, models, algorithms, and technology, as set forth in Section 12.

11.5 No Sale of PHI; Limits on Use. Lime Health Labs does not sell PHI. Lime Health Labs does not use PHI for marketing or advertising, and does not use PHI for any purpose other than as permitted by the BAA, required by law, or otherwise permitted under HIPAA. Any use of data for improving the Services will be performed only to the extent permitted by the BAA and HIPAA, and any data de-identified for such purposes will be de-identified in accordance with 45 C.F.R. § 164.514.

11.6 Privacy Policy. Lime Health Labs’s collection and use of information is further described in the Privacy Policy, which is incorporated by reference. Where the Privacy Policy and the BAA address the same subject matter with respect to PHI, the BAA controls.

12. Intellectual Property

12.1 Lime Health Labs IP. All right, title, and interest in and to the Services — including software, source code, models, model weights, algorithms, interfaces, documentation, know-how, trademarks, and trade secrets — is and remains the exclusive property of Lime Health Labs and its licensors. No rights are granted except as expressly stated in Section 5.2.

12.2 Customer Data. Customer retains ownership of Customer Data as set forth in Section 11.4. Customer grants Lime Health Labs a limited, non-exclusive license to host, process, transmit, display, and otherwise use Customer Data solely as necessary to provide, secure, and support the Services, subject to the BAA with respect to PHI.

12.3 Feedback. If Customer provides suggestions or feedback regarding the Services, Lime Health Labs may use it without restriction or obligation, provided such use does not include or disclose Customer Data or Confidential Information.

13. Confidentiality

13.1 Obligations. Each party will protect the other’s Confidential Information using at least the degree of care it uses for its own confidential information of like importance, and in no event less than reasonable care, and will not disclose it except to its personnel and advisors who have a need to know and are bound by confidentiality obligations at least as protective, or as required by law.

13.2 Definition and Exclusions. “Confidential Information” means non-public information disclosed by one party to the other that is identified as confidential or that a reasonable person would understand to be confidential, including business strategies, pricing, technology, security information, and Customer Data. Confidential Information excludes information that is or becomes public through no fault of the recipient, was lawfully known to the recipient without obligation of confidence, is independently developed without use of the discloser’s Confidential Information, or is lawfully obtained from a third party without restriction.

13.3 Compelled Disclosure. A party may disclose Confidential Information as required by law or legal process, provided it gives, where legally permitted, prompt notice and reasonable cooperation to allow the other party to seek protective treatment.

13.4 PHI. PHI is governed by the BAA and HIPAA in addition to this Section; where they conflict as to PHI, the BAA and HIPAA control.

14. Fees and Payment

Fees are set forth in the applicable Order Form or MSA. Unless otherwise stated there, fees are non-refundable, invoices are due net thirty (30) days, and Lime Health Labs may change pricing effective upon renewal with at least thirty (30) days’ prior written notice. Customer is responsible for applicable taxes other than taxes on Lime Health Labs’s income. Lime Health Labs may suspend access for non-payment following written notice and a reasonable opportunity to cure as provided in the MSA or Order Form.

15. Term, Suspension, and Termination

15.1 Term. These Terms are effective upon the earlier of Customer’s first use of the Services or the effective date of an Order Form, and continue until terminated in accordance with this Section or the MSA or Order Form.

15.2 Termination for Breach. Either party may terminate for the other’s material breach if the breach remains uncured thirty (30) days after written notice.

15.3 Suspension. In addition to the Integration-specific suspension right in Section 7.9, Lime Health Labs may suspend Customer’s or an Authorized User’s access to the Services, in whole or in part, if Lime Health Labs reasonably believes that continued access presents a material security risk, violates applicable law, or materially breaches the Agreement. Lime Health Labs will limit any such suspension to what is reasonably necessary and will restore access promptly once the basis is resolved.

15.4 Effect of Termination. Upon termination, Customer’s right to access the Services ceases. Return and deletion of Customer Data, including PHI, will be handled in accordance with the BAA, the MSA or Order Form, and applicable law. Customer is responsible for exporting Customer Data prior to termination or within any transition period specified in the MSA or Order Form.

15.5 Survival. Sections 1, 2, 3.2, 5.4, 6.2, 6.3, 7.2, 7.3, 7.4, 7.5(a), 7.5(d), 7.5(e), 7.7, 7.10, 9, 10, 11, 12, 13, 14 (as to accrued amounts), 15.4, 15.5, 16, 17, 18, 19, 20, 21, 22, and 23 survive termination or expiration, together with any other provision that by its nature is intended to survive.

16. Representations and Warranties; Compliance

16.1 Mutual. Each party represents that it has the authority to enter into the Agreement and that its performance will comply with applicable law.

16.2 Customer. Customer represents and warrants, on a continuing basis, that: (a) it holds all licenses, certifications, and enrollments required to provide the healthcare services it delivers; (b) it has all rights necessary to provide Customer Data to the Services and to authorize the processing contemplated by the Agreement; (c) it has obtained all consents, authorizations, and permissions required in connection with its use of the Services, including under Section 6.2 and Section 7.2; and (d) neither Customer nor any Authorized User is excluded, debarred, or suspended from participation in any federal healthcare program.

16.3 Lime Health Labs. Lime Health Labs represents and warrants that it will provide the Services in a professional and workmanlike manner consistent with generally accepted industry standards, and will maintain the administrative, physical, and technical safeguards required by the BAA, the HIPAA Security Rule as applicable to Business Associates, and the Agreement.

17. Disclaimer of Warranties

EXCEPT AS EXPRESSLY STATED IN SECTION 16.3 AND IN THE BAA, AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE. LIME HEALTH LABS DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.

WITHOUT LIMITING THE FOREGOING, LIME HEALTH LABS DOES NOT WARRANT THAT: (A) THE SERVICES WILL MEET CUSTOMER’S REQUIREMENTS OR EXPECTATIONS; (B) THE SERVICES WILL BE UNINTERRUPTED, TIMELY, OR ERROR-FREE; (C) AI-GENERATED CONTENT WILL BE ACCURATE, COMPLETE, OR CLINICALLY APPROPRIATE; (D) THE SERVICES WILL BE COMPATIBLE OR REMAIN COMPATIBLE WITH ANY THIRD-PARTY SERVICE, OR THAT ANY INTEGRATION WILL REMAIN AVAILABLE OR FUNCTIONAL; (E) ANY INTEGRATION IS PERMITTED UNDER CUSTOMER’S AGREEMENTS WITH ANY THIRD-PARTY PROVIDER; OR (F) ALL DEFECTS WILL BE CORRECTED.

NOTHING IN THIS SECTION DISCLAIMS ANY WARRANTY OR LIABILITY THAT CANNOT BE DISCLAIMED UNDER APPLICABLE LAW, AND NOTHING IN THIS SECTION LIMITS LIME HEALTH LABS’S OBLIGATIONS UNDER THE BAA OR HIPAA.

18. Limitation of Liability

18.1 Exclusion of Indirect Damages. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PARTY, NOR ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, OR AFFILIATES, WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, GOODWILL, BUSINESS OPPORTUNITY, OR ANTICIPATED SAVINGS, OR FOR LOSS OR CORRUPTION OF DATA (EXCEPT AS PROVIDED IN SECTION 18.4), REGARDLESS OF THE THEORY OF LIABILITY AND EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

18.2 Aggregate Cap. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, AND EXCEPT AS PROVIDED IN SECTION 18.4, EACH PARTY’S TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THE AGREEMENT OR THE SERVICES WILL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER TO LIME HEALTH LABS UNDER THE APPLICABLE ORDER FORM IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

18.3 Third-Party Services and Customer Decisions. WITHOUT LIMITING SECTIONS 18.1 AND 18.2, AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, LIME HEALTH LABS WILL NOT BE LIABLE FOR:

  1. outages, downtime, latency, degradation, defects, or errors originating in a Third-Party Service;
  2. changes a Third-Party Provider makes to its system, APIs, interfaces, data models, workflows, authentication or security requirements, terms, or pricing;
  3. a Third-Party Provider’s restriction, throttling, suspension, revocation, blocking, or termination of access, accounts, credentials, or an Integration;
  4. the discontinuation or unavailability of any Integration, or the inability to establish an Integration;
  5. inaccurate, incomplete, stale, or corrupted data received from or written to a Third-Party Service where the cause originates in that Third-Party Service or in Customer’s configuration;
  6. Customer’s configuration, mapping, field-selection, workflow, or authorization decisions;
  7. Customer’s breach of, or alleged breach of, any agreement between Customer and a Third-Party Provider, including any claim arising from Customer’s authorization of an Integration that Customer was not entitled to authorize;
  8. clinical decisions made by Customer or its Authorized Users, or the accuracy, completeness, or appropriateness of documentation that an Authorized User has reviewed and approved;
  9. Customer’s failure to obtain required patient, workforce, or regulatory consents, or Customer’s violation of any recording, privacy, or data protection law; or
  10. unauthorized access resulting from Customer’s failure to safeguard credentials, or from credentials Customer provisioned that it was not entitled to provision.

18.4 Exclusions from the Limitations. The limitations in Sections 18.1 and 18.2 do not apply to, and nothing in these Terms limits or excludes liability for:

  1. Customer’s payment obligations under Section 14;
  2. either party’s indemnification obligations under Section 19;
  3. either party’s breach of Section 13 (Confidentiality);
  4. Customer’s breach of Section 5.4 (Restrictions) or infringement or misappropriation of Lime Health Labs’s intellectual property;
  5. a party’s fraud, willful misconduct, or gross negligence;
  6. liability that cannot be limited or excluded under applicable law, including liability for death or personal injury caused by a party’s negligence where such limitation is prohibited; or
  7. Lime Health Labs’s obligations and liability under the BAA and HIPAA, and its liability for a breach of its own security obligations under the Agreement, to the extent such liability may not lawfully be limited.

18.5 Essential Basis. The parties acknowledge that the limitations in this Section 18 are an essential basis of the bargain and reflect the allocation of risk between them, and that the fees for the Services reflect that allocation. These limitations apply notwithstanding the failure of essential purpose of any limited remedy.

19. Indemnification

19.1 Customer Indemnification. Customer will defend, indemnify, and hold harmless Lime Health Labs and its officers, directors, employees, agents, affiliates, successors, and permitted assigns from and against any third-party claim, demand, suit, investigation, enforcement action, or proceeding, and all resulting liabilities, damages, penalties, settlements, losses, costs, and expenses (including reasonable attorneys’ fees), arising out of or relating to:

  1. Authority to authorize an Integration — any allegation that Customer lacked the right, authority, license, consent, permission, or approval necessary to authorize, enable, configure, or permit an Integration, or to authorize Lime Health Labs’s access to or interaction with any Third-Party Service;
  2. Violation of a third-party agreement — any allegation that an Integration, or Lime Health Labs’s access to or use of a Third-Party Service at Customer’s direction, breached or violated any agreement, license, terms of service, API or developer terms, acceptable use policy, security requirement, or data-use restriction between Customer and a Third-Party Provider, or infringed or misappropriated a Third-Party Provider’s intellectual property, trade secret, or contractual rights as a result of Customer’s authorization;
  3. Credentials and access — Customer’s provision or provisioning of credentials, tokens, accounts, service accounts, sub-accounts, test users, or other access that Customer was not entitled to provide, or Customer’s failure to revoke or restrict access when required under Section 7.5;
  4. Unlawful or infringing instructions — any Customer Instruction that violates applicable law or the rights of a third party;
  5. Misuse of the Services — Customer’s or an Authorized User’s use of the Services in violation of the Agreement or applicable law, including Section 5.4;
  6. Customer Data and content — any allegation that Customer Data, or Lime Health Labs’s processing of it in accordance with the Agreement and Customer Instructions, infringes, misappropriates, or violates the rights of a third party, or was provided to Lime Health Labs without required rights, consents, or authorizations;
  7. Consents and recording — Customer’s failure to obtain required patient, caregiver, or workforce consents, or violation of any recording, wiretapping, eavesdropping, or surveillance law; and
  8. Clinical, coding, and billing — clinical decisions made by Customer or its Authorized Users, and documentation, codes, or claims submitted to any medical record, payor, clearinghouse, or regulatory body following review and approval by an Authorized User.

19.2 Limits on Customer’s Obligation. Customer’s obligations under Section 19.1 do not apply to the extent a claim arises from Lime Health Labs’s own fraud, willful misconduct, or gross negligence; from Lime Health Labs’s access to or use of a Third-Party Service materially outside the scope of Customer’s authorization; from Lime Health Labs’s breach of the BAA or of its security obligations under the Agreement for which Lime Health Labs is legally responsible; or from any other liability that Lime Health Labs may not lawfully shift to Customer. Nothing in this Section 19 is intended to indemnify Lime Health Labs against liability that cannot lawfully be indemnified.

19.3 Lime Health Labs Indemnification. Lime Health Labs will defend, indemnify, and hold harmless Customer from and against any third-party claim alleging that the Services, as provided by Lime Health Labs and used in accordance with the Agreement, infringe or misappropriate a United States patent, copyright, trademark, or trade secret. This obligation does not apply to any claim arising from: Customer Data; a Third-Party Service; an Integration to the extent the claim arises from Customer’s lack of authority or breach of a Third-Party Provider agreement; modification of the Services by anyone other than Lime Health Labs; use of the Services in combination with items not supplied by Lime Health Labs where the claim would not have arisen but for the combination; or Customer’s use of the Services in violation of the Agreement.

19.4 Procedure. The indemnified party will: (a) promptly notify the indemnifying party of the claim (provided that delay relieves the indemnifying party only to the extent it is materially prejudiced); (b) give the indemnifying party sole control of the defense and settlement, except that the indemnifying party may not settle any claim in a manner that imposes a non-indemnified obligation or liability on, or requires an admission of wrongdoing by, the indemnified party without its prior written consent, not to be unreasonably withheld; and (c) provide reasonable cooperation at the indemnifying party’s expense. The indemnified party may participate in the defense with counsel of its own choosing at its own expense.

19.5 Interaction with Section 18. For the avoidance of doubt, and as provided in Section 18.4(b), a party’s indemnification obligations under this Section 19 are not subject to the aggregate cap in Section 18.2.

20. Dispute Resolution and Arbitration

PLEASE READ THIS SECTION CAREFULLY. IT AFFECTS YOUR LEGAL RIGHTS, INCLUDING YOUR RIGHT TO FILE A LAWSUIT IN COURT.

20.1 Informal Resolution. Before initiating arbitration, the parties will attempt in good faith to resolve any dispute through discussion between senior representatives for a period of thirty (30) days following written notice describing the dispute.

20.2 Binding Arbitration. Any dispute, claim, or controversy arising out of or relating to the Agreement or the Services that is not resolved under Section 20.1 will be resolved by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, before a single arbitrator. The seat of arbitration is Wilmington, Delaware; hearings may be conducted remotely at the arbitrator’s discretion. Judgment on the award may be entered in any court of competent jurisdiction.

20.3 Class Action Waiver. Proceedings will be conducted only on an individual basis and not in a class, collective, consolidated, or representative action. Each party waives any right to participate in a class action or class-wide arbitration against the other.

20.4 Exceptions. Either party may seek injunctive or other equitable relief in a court of competent jurisdiction to protect its intellectual property rights or Confidential Information. Nothing in this Section limits either party’s ability to participate in or respond to a governmental or regulatory investigation or enforcement action, or to report a matter to a regulator.

21. Governing Law

The Agreement is governed by the laws of the State of Delaware, without regard to its conflict of laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

22. General Provisions

22.1 Entire Agreement. The Agreement constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior and contemporaneous agreements and understandings.

22.2 Amendment. Lime Health Labs may update these Terms from time to time. Material changes will be communicated by email to the Customer’s designated contact or by prominent notice on the Site, and will take effect no earlier than thirty (30) days after notice, except where a change is required by law or is necessary to address a security or legal risk, in which case it may take effect sooner. Continued use of the Services after the effective date constitutes acceptance. Terms in a signed MSA or Order Form may be amended only in a signed writing.

22.3 Severability. If any provision is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable and to give effect to the parties’ intent, and the remaining provisions will remain in full force.

22.4 Waiver. No failure or delay in exercising a right operates as a waiver, and no waiver of any provision is a continuing waiver.

22.5 Assignment. Customer may not assign the Agreement without Lime Health Labs’s prior written consent, except to a successor in connection with a merger or sale of substantially all assets, provided the successor is not a competitor of Lime Health Labs and assumes all obligations. Lime Health Labs may assign the Agreement to an affiliate or in connection with a merger, acquisition, or sale of substantially all assets. Any other assignment is void.

22.6 Independent Contractors. The parties are independent contractors. Nothing in the Agreement creates a partnership, joint venture, employment, or franchise relationship. Lime Health Labs’s performance of Customer-directed access under Section 7 is performed on Customer’s behalf for that limited purpose and does not create a general agency relationship between the parties, and creates no relationship whatsoever between Lime Health Labs and any Third-Party Provider.

22.7 No Third-Party Beneficiaries. The Agreement is for the benefit of the parties only and confers no rights on any third party, except that the Lime Health Labs indemnified parties identified in Section 19.1 are intended beneficiaries of that Section.

22.8 Force Majeure. Neither party is liable for any failure or delay in performance (other than payment obligations) due to causes beyond its reasonable control, including acts of God, natural disasters, epidemic or pandemic, war, terrorism, civil unrest, governmental action, labor disruption, utility or power failure, internet or telecommunications disruption, cyberattack not resulting from the affected party’s failure to maintain required safeguards, or third-party service outages.

22.9 Notices. Notices to Lime Health Labs must be sent to legal@getlimeai.com and, if requested, by certified mail to Lime Health Labs’s registered address. Notices to Customer may be given by email to the address on file or by posting on the Site or within the Services.

22.10 Export and Government Rights. Customer will comply with applicable export control and sanctions laws. The Services are “commercial computer software” as defined in applicable federal acquisition regulations.

22.11 Interpretation. Section headings are for convenience only. “Including” means “including without limitation.” No rule of construction requiring interpretation against the drafter applies.

23. Contact

Lime Health Labs, Inc.
Legal: legal@getlimeai.com
Privacy: privacy@getlimeai.com
Security: security@getlimeai.com
Support: support@getlimeai.com


Part II — Privacy Policy

Lime Health Labs, Inc. (“Lime Health Labs,” “Company,” “we,” “our,” or “us”) provides AI-assisted clinical documentation software to healthcare organizations. This Privacy Policy describes how we collect, use, disclose, store, and protect information when you visit our website at getlimeai.com (the “Site”), use our mobile applications (the “App”), or access our platform and related services (collectively, the “Services”).

Please read Section 3 first — it explains the two very different roles we play with respect to information. Most of the health information we handle is processed on behalf of, and under the instructions of, the healthcare organization that engaged us. That organization — not Lime Health Labs — decides what information enters the Services and controls how it is used.

1. Definitions

“Customer” means the home health agency, hospice, healthcare organization, or other entity that has entered into an agreement with Lime Health Labs to use the Services.

“Authorized User” means an individual authorized by a Customer to access and use the Services on the Customer’s behalf — for example, a clinician, administrator, coder, QA reviewer, or IT administrator.

“Protected Health Information” or “PHI” has the meaning given in the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations (“HIPAA”).

“Personal Information” means information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household.

“Business Associate Agreement” or “BAA” means an agreement meeting the requirements of 45 C.F.R. §§ 164.504(e) and 164.314(a) between Lime Health Labs and a Customer.

“Third-Party Service” means any software, platform, or system not owned or operated by Lime Health Labs that a Customer uses or licenses, including electronic medical record and electronic health record systems (“EMR/EHR”), practice management systems, billing and revenue cycle systems, scheduling systems, and clearinghouses. “Third-Party Provider” means the vendor or operator of a Third-Party Service.

“Integration” means a connection, interoperation, or data exchange between the Services and a Third-Party Service that a Customer has directed or enabled, by any technical mechanism. This term is defined more fully in Section 2 of our Terms of Service, and that definition governs the parties’ contractual rights and obligations.

“Customer Data” means the data, content, records, documentation, audio, and other information that a Customer or its Authorized Users submit to the Services, that we collect or generate on a Customer’s behalf in providing the Services, or that we receive from or transmit to a Third-Party Service at a Customer’s direction.

2. Scope of This Policy

This Privacy Policy applies to:

  • visitors to the Site;
  • Authorized Users of the Services; and
  • information we process on behalf of Customers, as further limited by Section 3.

This Privacy Policy does not describe how any Customer collects, uses, or discloses information in its own capacity as a healthcare provider. Each Customer maintains its own privacy practices and its own Notice of Privacy Practices. If you are a patient, please see Section 10.

Where a BAA is in effect, that BAA governs our use and disclosure of PHI. If anything in this Privacy Policy conflicts with an executed BAA with respect to PHI, the BAA controls.

3. Our Two Roles

3.1 As a service provider to healthcare organizations (Business Associate). When we process clinical, patient, workforce, and operational information within the Services, we do so on behalf of and at the direction of the Customer. Under HIPAA, the Customer is typically the Covered Entity (or a Business Associate of one), and Lime Health Labs acts as a Business Associate. In this role:

  • the Customer determines what information enters the Services, which Integrations are enabled, and what the Services are used for;
  • we use and disclose that information only as permitted by the BAA, as directed by the Customer, or as required by law;
  • we do not use it for our own independent purposes; and
  • requests from patients regarding their health information should be directed to the Customer, which is the entity legally responsible for responding.

3.2 As a business in our own right. When you visit the Site, request a demo, correspond with our team, create an account, or receive our communications, we process information about you for our own business purposes — operating the Site, providing support, billing, security, and marketing our Services to businesses. This Privacy Policy describes those practices directly.

4. Information We Collect

4.1 Information provided directly

When you create an account, request a demo, contact support, or otherwise interact with us, we may collect:

  • name, email address, telephone number, and job title;
  • organization name, address, and National Provider Identifier;
  • account credentials and authentication information;
  • billing and payment information (payment card details are processed by our third-party payment processor and are not stored by us in full); and
  • the content of your communications with us, including support requests.

4.2 Audio recordings and clinical information

When an Authorized User activates the recording feature in the App, we collect audio of the clinical encounter. Recording requires affirmative action by the Authorized User each time. The App does not record passively or in the background without active user initiation.

Audio recordings and the documentation generated from them — including visit notes, OASIS and HOPE assessments, ICD-10 code suggestions, and related clinical content — are treated as PHI and are handled in accordance with HIPAA, the applicable BAA, and this Privacy Policy.

The Customer is responsible for obtaining any patient, caregiver, or workforce consents required by applicable law before recording. See Section 10.

4.3 Information received from and sent to Customer systems (Integrations)

Where a Customer directs us to connect the Services to an EMR/EHR or other Third-Party Service, we may receive information from that system, and — where the Customer has enabled write-back functionality — we may transmit information back into it. These flows occur only at the Customer’s direction and only to provide the Services the Customer has requested.

How connections are established. Depending on what the Customer configures, an Integration may operate through an API; through credentials, tokens, or accounts the Customer provisions; through OAuth, SMART on FHIR, or another authentication framework; through health data interchange standards such as HL7 or FHIR; through browser-based or user-interface-mediated access; through automated data entry or retrieval; through secure file transfer or batch exchange; or through another interoperability mechanism the Customer selects.

Information we may receive. The categories depend entirely on the Customer’s configuration and may include:

  • patient information — name, date of birth, contact information, identifiers, insurance and coverage information;
  • clinical information — diagnoses, medications, allergies, assessments, orders, care plans, visit history, vitals, notes, and other medical record content;
  • demographic information — including, where present in the source record, information that may be sensitive under applicable law (for example, race or ethnicity, primary language, sexual orientation or gender identity, and disability status);
  • administrative and operational information — episodes of care, authorizations, referrals, scheduling and visit data, and utilization data;
  • workforce information — identifiers, roles, licensure, credentials, assignments, and productivity or documentation-completion data for the Customer’s clinicians and staff; and
  • account and technical information — user accounts, permissions, authentication events, connection metadata, and audit logs.

Information we may transmit back. Where write-back is enabled, we may transmit drafted or finalized documentation, assessment responses, coding suggestions, structured data elements, and status or workflow information into the Customer’s system. The Customer configures and controls which information is written back and to which fields, and the Customer’s Authorized Users are responsible for reviewing and approving content before it becomes part of the medical record.

Credentials. Where a Customer provides credentials, tokens, or accounts to enable an Integration, we encrypt them in transit and at rest, restrict access to personnel who need it to operate and support the Integration, and use them solely to provide the Services the Customer has requested. The Customer is responsible for ensuring that the access it provides is permitted under its agreements with the relevant Third-Party Provider and under applicable law, and for revoking access when it is no longer authorized. See Section 7 of our Terms of Service.

Our relationship to the Third-Party Provider. Unless we state otherwise in writing, we are independent of the Customer’s EMR/EHR and other Third-Party Providers. An Integration does not mean the Third-Party Provider has endorsed, certified, partnered with, or authorized Lime Health Labs, and we do not control those systems or their privacy and security practices. Information handled inside a Third-Party Service is governed by that provider’s practices and the Customer’s agreement with it, not by this Privacy Policy.

4.4 Site usage data

When you visit the Site, we automatically collect certain information through cookies, pixels, web beacons, and similar technologies, including IP address, browser and device type, operating system, pages viewed, links clicked, time on page, referring URL, search terms, and approximate geographic location derived from IP address.

We use third-party analytics providers (such as Google Analytics) to understand Site usage. We do not deploy advertising or analytics trackers within the authenticated portions of the Services where PHI is present.

4.5 Service operation and diagnostic data

We collect logs, telemetry, error reports, performance metrics, and audit records generated by the Services. These are used to operate, secure, troubleshoot, and support the Services and may incidentally contain identifiers associated with PHI, in which case they are protected as PHI.

4.6 Cookies and tracking technologies

We use cookies and similar technologies to operate the Site, remember preferences, and analyze traffic. You can manage cookies through your browser settings; disabling some cookies may limit Site functionality. Where required by applicable law, we obtain consent before setting non-essential cookies. We honor Global Privacy Control and Do Not Track signals where technically feasible and legally required.

5. How We Use Information

5.1 To provide the Services. We use information — including information received through Integrations — to operate and deliver the Services: transcribing and drafting clinical documentation, performing quality assurance review, generating coding suggestions, supporting admissions intake, and exchanging data with the Customer’s systems as the Customer has configured. This processing is performed to provide the requested Services and is directed by the Customer.

5.2 Account management and support. To create and administer accounts, authenticate users, respond to inquiries, and provide technical support.

5.3 Security and integrity. To detect, investigate, prevent, and respond to fraud, abuse, unauthorized access, security incidents, and technical problems, and to maintain audit trails.

5.4 Service operations and improvement. To monitor performance, diagnose defects, and improve the reliability, accuracy, and safety of the Services. Where this activity involves PHI, we perform it only to the extent permitted by the applicable BAA and HIPAA — for example, for our proper management and administration, to carry out our legal responsibilities, or for data aggregation services relating to the Customer’s health care operations, in each case only where the BAA so permits. We may create de-identified information in accordance with 45 C.F.R. § 164.514 and use it as permitted by the BAA and applicable law.

5.5 Business communications and marketing. To send service-related notices and, where permitted, to market our Services to business contacts. We do not use PHI for marketing or advertising. You can opt out of marketing email at any time using the unsubscribe link or by contacting privacy@getlimeai.com.

5.6 Legal and compliance. To comply with applicable law, respond to lawful requests, enforce our agreements, and establish or defend legal claims.

5.7 What we do not do. We do not sell PHI. We do not sell Personal Information, and we do not share Personal Information for cross-context behavioral advertising as those terms are defined under California law. We do not use PHI for any purpose unrelated to the Services except as permitted by the BAA or required by law.

6. How We Disclose Information

We disclose information only as described below. We use vendors and subprocessors to operate the Services, so we cannot and do not promise that information is never shared with anyone. What we commit to is that disclosures are limited to the categories below, are subject to contractual protections, and — where PHI is involved — are governed by HIPAA and the applicable BAA.

6.1 To the Customer. We make clinical documentation, QA results, audit logs, and other outputs available to the Customer and its Authorized Users as part of the Services. If you are an Authorized User, your employer or contracting organization may access your account and activity information within the Services.

6.2 To the Customer’s designated systems. Where the Customer has directed it, we transmit information into the Customer’s EMR/EHR or other Third-Party Services as described in Section 4.3.

6.3 To service providers and subprocessors. We engage vendors to perform functions on our behalf, including:

  • cloud hosting and infrastructure;
  • data storage, backup, and disaster recovery;
  • AI and machine learning model providers used to generate documentation drafts;
  • speech-to-text and audio processing;
  • security monitoring, logging, vulnerability management, and incident response;
  • error monitoring and application performance management;
  • customer support and ticketing tooling;
  • payment processing and billing; and
  • communications and email delivery.

Each is bound by written contract to confidentiality and security obligations and may use information only to perform services for us. Where a subprocessor may access PHI, we execute a Business Associate Agreement with that subprocessor as required by HIPAA, and we require it to apply restrictions at least as protective as those that apply to us. A current list of subprocessors that may access PHI is available to Customers on request at privacy@getlimeai.com.

6.4 Legal requirements. We may disclose information where required by law, regulation, subpoena, court order, warrant, or other lawful governmental or regulatory request, or where necessary to establish or defend legal claims. Disclosures of PHI are made in accordance with HIPAA, including 45 C.F.R. § 164.512, and, where a BAA requires it, we will notify the Customer as permitted by law.

6.5 Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred to the acquiring or surviving entity, subject to this Privacy Policy, HIPAA, and applicable BAAs. We will provide notice as required by law or contract.

6.6 With consent or at direction. We may disclose information with your consent or at the Customer’s direction.

6.7 Aggregated and de-identified information. We may create and use aggregated or de-identified information that cannot reasonably be used to identify an individual, in accordance with 45 C.F.R. § 164.514 and the applicable BAA, and may share it for purposes such as benchmarking, research, and describing Service performance. We will not attempt to re-identify such information and will contractually prohibit recipients from doing so.

7. HIPAA Compliance

Where we create, receive, maintain, or transmit PHI on behalf of a Customer, we act as a Business Associate. We execute a BAA with each Customer before processing PHI. Our obligations include:

  • using and disclosing PHI only as permitted by the BAA and HIPAA;
  • implementing administrative, physical, and technical safeguards required by the HIPAA Security Rule;
  • reporting Security Incidents and Breaches of Unsecured PHI as required by HIPAA and the BAA;
  • ensuring that subcontractors with access to PHI agree in writing to equivalent restrictions and conditions;
  • making PHI available to support the Customer’s obligations regarding individual access, amendment, and accounting of disclosures; and
  • returning or destroying PHI at termination as provided in the BAA, or extending protections where return or destruction is infeasible.

In the event of any conflict between this Privacy Policy and an executed BAA, the BAA controls with respect to PHI.

We do not claim ownership of any Customer’s medical records or PHI. Processing a record through the Services does not transfer ownership of it to Lime Health Labs. As between Lime Health Labs and the Customer, the Customer owns its clinical data and the documentation generated from it, as set forth in the Terms of Service. We retain ownership of the Services and the underlying software, models, and technology.

8. Data Security

We maintain an information security program with administrative, physical, and technical safeguards designed to protect information, including:

  • AES-256 encryption of data at rest and TLS 1.2 or higher in transit;
  • role-based access control, least-privilege provisioning, and multi-factor authentication;
  • encrypted storage and restricted access for Customer-provided Integration credentials;
  • network segmentation, monitoring, and intrusion detection;
  • regular vulnerability assessment and periodic penetration testing;
  • audit logging of system access and data transactions;
  • background screening, confidentiality obligations, and security awareness training for workforce members; and
  • a documented incident response plan, including breach notification procedures.

No method of transmission or storage is completely secure. While we work to protect information, we cannot guarantee absolute security. This statement does not limit our obligations under the BAA, HIPAA, or applicable law.

9. Data Retention

We retain information for as long as needed to provide the Services and as required by the Customer’s agreement, the BAA, and applicable law. Upon termination of a Customer agreement, we return or delete Customer Data — including PHI — in accordance with the BAA and the Customer’s instructions, subject to any legally required retention. We may retain information as necessary to comply with legal obligations, resolve disputes, and enforce agreements. De-identified and aggregated information that cannot be used to identify an individual may be retained indefinitely.

Retention periods for specific data types are set out in our Customer documentation and, where applicable, in the Order Form or BAA.

10. If You Are a Patient

If you are a patient whose health information is processed through the Services, your healthcare provider — our Customer — is the entity responsible for your health information under HIPAA. Please direct requests to access, amend, restrict, or obtain an accounting of disclosures of your health information, and any questions about consent to recording, to that provider. We will support our Customers in responding to those requests as required by HIPAA and the applicable BAA.

If you contact us directly with such a request, we will refer you to the relevant Customer where we are able to identify it, and we will not act on the request independently except as permitted or required by law.

11. If You Are an Authorized User or Workforce Member

If you use the Services on behalf of a Customer, information about your account and activity — including authentication events, documentation you create or edit, and audit logs — is accessible to your organization. Your organization’s policies govern how it uses that information. Direct questions about your organization’s use of the Services to your organization.

12. Your Rights and Choices

Depending on your jurisdiction and your relationship to us, you may have rights to access, correct, delete, obtain a copy of, or limit certain processing of your Personal Information, and to appeal a denial of a request. To exercise these rights, contact privacy@getlimeai.com. We will verify your identity before responding and will respond within the period required by applicable law (generally 45 days, extendable where permitted).

Important limitations. Where we hold information as a service provider or Business Associate on behalf of a Customer, we will refer your request to that Customer rather than acting on it ourselves, and will assist the Customer as required by our contract with it. Rights under state consumer privacy laws generally do not apply to PHI governed by HIPAA or to information covered by other exemptions; HIPAA rights apply instead and are exercised through the Covered Entity.

We will not discriminate against you for exercising a privacy right.

13. State Privacy Laws

13.1 California (CCPA/CPRA). California residents may have rights to know, access, correct, delete, and obtain a portable copy of their Personal Information, and to limit use of sensitive Personal Information. We do not sell Personal Information and do not share it for cross-context behavioral advertising. PHI governed by HIPAA, and medical information governed by the California Confidentiality of Medical Information Act, are exempt from the CCPA. To the extent we process Personal Information on behalf of a Customer, we do so as a “service provider” under a contract that prohibits retaining, using, or disclosing it except to perform the Services.

13.2 Other states. Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect — may have similar rights. Where we act as a “processor,” we assist the Customer (the “controller”) in responding to consumer rights requests.

13.3 Washington My Health My Data Act, Nevada SB 370, and similar consumer health data laws. These laws regulate consumer health data outside HIPAA. To the extent they apply to information we process that is not PHI, we do not sell consumer health data and do not use it for targeted advertising.

14. Children’s Privacy

The Site and Services are directed to healthcare organizations and their workforce, not to individuals under 18. We do not knowingly collect Personal Information directly from children through the Site. Clinical records processed on behalf of a Customer may relate to patients of any age; that information is handled as PHI under HIPAA and the applicable BAA. If you believe a child has provided us information directly, contact privacy@getlimeai.com.

15. International Users

The Services are operated from and hosted in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.

16. Changes to This Privacy Policy

We may update this Privacy Policy. We will post the updated version with a revised Effective Date and, for material changes, will notify Customers by email to the designated contact or by prominent notice on the Site. Changes do not modify an executed BAA, which can be amended only as that agreement provides.

17. Contact Us

Lime Health Labs, Inc.
Privacy: privacy@getlimeai.com
Security: security@getlimeai.com
Legal: legal@getlimeai.com
Support: support@getlimeai.com

If you have a concern we have not resolved, you may contact your state attorney general or, for HIPAA matters, the U.S. Department of Health and Human Services Office for Civil Rights.