API TERMS OF USE
HM Health Solutions Inc. (“ HMHS”) acts as an intermediary and offers access to each application programming interface listed at https://cmsapiportal.hmhs.com/(“ API”) on behalf of its customers to allow access to the Data made available through such APIs. “ Data” means data, information, security tokens, or other content HMHS makes available through an API.
These Terms of Use (“ Terms”) govern use of each API listed at https://cmsapiportal.hmhs.com/and made available to you by HMHS. You accept these Terms by confirming Your agreement to these Terms, by registering to use an API, by using an API, or by continuing to use an API after a change to these Terms has been published.
WHEN YOU ACCEPT THESE TERMS, YOU AGREE TO THEM ON YOUR INDIVIDUAL BEHALF AND ON BEHALF OF THE ORGANIZATION BY WHICH YOU ARE EMPLOYED OR RETAINED AND FOR WHOSE BENEFIT YOU ARE CONNECTING TO OR USING AN API (“ EMPLOYER”). YOU REPRESENT AND WARRANT THAT YOU (A) HAVE READ AND UNDERSTAND THESE TERMS, (B) ARE OF A LEGAL AGE TO ENTER INTO A BINDING AGREEMENT, AND (C) ARE AUTHORIZED BY EMPLOYER TO AGREE TO THESE TERMS ON ITS BEHALF. References herein to “ You” shall mean “you and/or Employer.”
ONLY USERS AND APPLICATIONS AUTHORIZED BY HMHS (“ PERMITTED USERS”) MAY USE AN API OR PART THEREOF (INCLUDING ANY ASSOCIATED DATA). ANY USE OF AN API OTHER THAN BY A PERMITTED USER IN ACCORDANCE WITH THESE TERMS IS STRICTLY PROHIBITED.
Any failure to abide by these Terms is grounds for immediate suspension or termination of access to any or all APIs (including suspension or termination of access by other Permitted Users working for the same Employer) and may give rise to other legal rights and remedies.
1. Revisions to Terms; Changes to an API
HMHS may revise these Terms from time to time for any reason. You may be required to agree to revised Terms as a condition of continued use of an API, and in any event Your continued use of an API after the effective date of any revised Terms confirms You agree to be bound by such Terms.
As permitted by applicable law, HMHS reserves the right to reconfigure or discontinue features or functionality or any other aspect of any API, with no liability to You. HMHS will attempt to make available reasonable notice of material changes to features or functionality of an API by posting notice.
HMHS will make reasonable efforts to provide support services to assist You in accessing and using an API; however, HMHS may require payment for any ancillary services (i.e., services separate from the making an API available for use) that You request, subject to HMHS’ advance written approval and pursuant to the terms of a separate written agreement.
2. API Registration and Credentials
Registration may be required to access and use an API. HMHS has established and may from time to time change requirements and conditions for such access and use as permitted by applicable law. HMHS reserves the right to refuse access to any API to anyone as permitted by applicable law.
To complete Your registration, You must (a) provide accurate, current and complete information as prompted by our registration form; (b) provide a valid email address; and (c) maintain and update your email address and other registration information to ensure that such information remains accurate, current, and complete. You may also be required to attest to maintaining a privacy policy that governs the Data received from an API and describes how the Data may be accessed, used, disclosed, and sold, and privacy controls.
Each Permitted User will receive credentials from HMHS. Credentials issued by HMHS to a Permitted User may only be used by that Permitted User for the purpose for which the credentials were issued. Any use of credentials or access to an API by a different user or for a different purpose is not authorized by these Terms.
You are responsible for the confidentiality and security of the credentials You receive. You agree not to permit any other person or entity to use the credentials to gain access to an API, and You agree that You are responsible for any and all activities conducted using the credentials. If You believe that the confidentiality of the password has been compromised, You must immediately notify HMHS.
3. Intellectual Property Rights.
HMHS and/or its licensors are the owner of all right, title, and interest in and to all APIs, including all rights to the design, software code, scripts, database structures, documentation, trademarks, service marks, copyrights, and other intellectual property included in or utilized by any API, and any updates thereto, and its name and logo, and all intellectual property rights in all of the foregoing (the “ HMHS IP”). HMHS IP is protected by applicable intellectual property and other laws, including laws governing patents, copyrights, trade secrets, trademarks, and unfair competition.
You do not and will not acquire any ownership in any HMHS IP as a result of these Terms or Your use of an API. You may not and shall not permit any other person to copy, distribute, display, modify, or otherwise use any HMHS IP except as expressly permitted by these Terms.
During the term of these Terms, You grant us a non-exclusive, royalty-free right to use Your Employer’s name and logo solely to identify that Your Employer is registered to use an API. You may not under these Terms use HMHS’ name, logo, or other trademarks or service marks for any purpose unless HMHS provides prior written approval in each instance.
4. Right to Use.
Subject to Your compliance with these Terms and the documentation associated with the applicable API, HMHS grants to You a non-exclusive, non-sublicensable, non-transferable right to access and use each API, for which credentials were issued by HMHS, for internal, non-commercial use in a lawful manner and using reasonable security measures. Such right shall expire upon termination of these Terms as set forth in Section 11 (Termination) below. The documentation for the APIs is located at https://cmsapiportaldev.hmhs.com/. You must use the credentialing and tokenization processes set forth in such documentation, if applicable. You may access and permit access to Data only through an API as intended by HMHS and through no other method. HMHS reserves the right, but is not obligated, to monitor Your use of an API.
5. Restrictions and Limitations on Use.
You may not: (a) copy, modify, or create a derivative work, collective work, or compilation of any HMHS IP; (b) reverse-engineer, decompile, or disassemble, or otherwise attempt to extract code from any HMHS IP; (c) license, sell, assign, lease, loan, sublicense, distribute or otherwise transfer or encumber any HMHS IP; (d) attempt to circumvent any access control or digital rights management measures or technology thereof associated with the HMHS IP; (e) remove, alter, or obscure any intellectual property marking or license notice; (f) generate excessive load on an API or cause an API to behave inaccurately or inconsistently; (g) attempt to breach, defeat, avoid, bypass, remove, deactivate, or otherwise circumvent any firewall, encryption, security, authentication routines, or software protection mechanisms in an API, including any such mechanism used to restrict or control the functionality of an API; (h) use any automated program, tool, or process (including web crawlers, scrapers, robots, bots, spiders, and automated scripts) to access an API, or any server, network, or system associated with an API, or to extract, collect, harvest, or gather Data through an API without Express Consent from the individual about whom the Data relates when required by applicable law; (i) submit any malware or other software code or programming of any kind to or through an API; (j) interfere with or disrupt the integrity or performance of an API or related systems; or (k) allow any other individual or entity to do any of the foregoing. You agree to promptly notify HMHS if You have reason to believe that any other individual or entity has engaged in any of the activities set forth in the foregoing (a) through (k).
You, and not HMHS, are solely responsible and liable for Your and Your account’s use of an API.
“ Express Consent” means an individual’s electronic or other consent, permission, or authorization for the collection, use, disclosure, or other processing of such individual’s Data as required by applicable laws.
6. Compliance with Laws.
You agree to abide by all applicable laws in connection with Your access and use of an API, including without limitation privacy, data protection, non-disclosure, and information security laws and regulations, and laws governing the use and processing personal information, including health-related information.
7. Data.
HMHS is not responsible or liable under these Terms for (a) the accuracy, quality, legality, loss, corruption, or unavailability of Data; or (b) making Data available to You or Your access and use of such Data. By providing You with access to an API or providing You with access to Data, HMHS is not representing or guaranteeing that that You may lawfully access or use Data.
You represent and warrant at all times that when you use an API to access Data (u) Your requests for Data via software or otherwise through the API will not infringe any rights of any individual or third party; (v) You have obtained Express Consent from the individuals for and about whom You request Data through the API (which Express Consent is still in place and has not expired or been withdrawn or revoked) when required by applicable law; (w) You have made available a mechanism for individuals to revoke any Express Consent previously provided to You, and will comply with revocations made through such mechanism when required by applicable law; (x) You will not obtain or attempt to obtain individuals’ credentials during the process of obtaining identification or security tokens in connection with making Data requests through the API; (y) You will use reasonable security measures in connection with using the API; and (z) You recognize that Data may be considered Protected Health Information (as defined by the Health Insurance Portability and Accountability Act (“ HIPAA”)). You agree to notify HMHS immediately if You receive access to data from an API that was not requested, You discover any defect or error in an API that prevents the receipt of accurate Data or compromises the security of an API or Data, or You experience a Security Breach. A “ Security Breach” means any event experienced by You that compromises the security of access or use of an API or results in unauthorized access, use, disclosure, or other processing, or loss, corruption, or unplanned unavailability of Data or credentials or identification or security tokens used in connection with an API. You also agree that HMHS has no responsibility or liability under these Terms for any security breach or incident (including, without limitation, a Security Breach) You experience, including for any investigation, remediation, or breach notification activities. You agree to immediately and securely delete/destroy any Data You receive from an API that You are not authorized to receive.
8. Indemnification.
To the fullest extent permissible by applicable law, You agree to indemnify, defend, and hold harmless HMHS, its Affiliates, licensors and subcontractors, and all of their respective officers, directors, agents, representatives, shareholders, members, employees, partners, successors, and assigns (the “ HMHS Group”), from and against any claim, suit, action, or loss (including reasonable attorneys’ fees) arising from or related to (a) any information submitted to HMHS or its Affiliates or subcontractors as part of registration or through an API; (b) Your use of or inability to use an API; (c) Your application that accesses an API; or (d) Your breach of these Terms or violation of applicable law.
9. Disclaimer of Warranties; Liability Limitations.
EACH API IS PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE FULLEST EXTENT PERMITTED BY LAW THE HMHS GROUP: (A) DISCLAIMS ALL EXPRESS AND IMPLIED WARRANTIES AND, IN ADDITION, SHALL NOT BE LIABLE TO YOU FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES ARISING UNDER THESE TERMS OR ASSOCIATED WITH YOUR ACCESS TO OR USE OF AN API, DATA, CREDENTIALS OR TOKENS USED IN CONNECTION WITH AN API, OR WITH RESPECT TO AN API AND ANY RELATED TECHNOLOGY OR SERVICES PROVIDED OR MADE AVAILABLE BY HMHS, INCLUDING BUT NOT LIMITED TO DAMAGES FOR LOSS OF REVENUE, PROFITS, GOODWILL, OR USE OF DATA, LACK OR LOSS OF DATA, OR OTHER INTANGIBLE LOSSES, WHETHER THE CLAIM FOR SUCH DAMAGES IS BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE OR STRICT LIABILITY) OR OTHERWISE (EVEN IF HMHS OR ITS LICENSOR(S) OR SERVICE PROVIDER(S) HAS BEEN ADVISED OF OR SHOULD HAVE BEEN AWARE OF THE POSSIBILITY OF SUCH DAMAGES), AND (B) SHALL HAVE A MAXIMUM AGGREGATE LIABILITY ARISING UNDER OR RELATING TO THESE TERMS, AN API, OR ANY TECHNOLOGY OR RELATED SERVICES PROVIDED BY HMHS OF ONE HUNDRED DOLLARS ($100.00). THE FOREGOING LIMITATIONS SHALL APPLY TO ALL CAUSES OF ACTION, WHETHER ARISING FROM BREACH OF CONTRACT, BREACH OF WARRANTY, NEGLIGENCE OR OTHER TORT, OR ANY OTHER LEGAL THEORY; MOREOVER, THESE LIMITATIONS WILL APPLY NOTWITHSTANDING A FAILURE OF ESSENTIAL PURPOSE OF ANY LIMITED REMEDY.
NOTHING IN THESE TERMS IS INTENDED TO EXCLUDE OR LIMIT ANY CONDITION, WARRANTY, RIGHT, OR LIABILITY IN A MANNER THAT IS NOT PERMISSIBLE UNDER APPLICABLE LAW. SOME JURISDICTIONS LIMIT OR DO NOT PERMIT THE EXCLUSION OF CERTAIN WARRANTIES OR CONDITIONS, THE EXCLUSION OF INCIDENTAL OR CONSEQUENTIAL DAMAGES. ACCORDINGLY, THE LIABILITY OF THE HMHS GROUP WILL BE LIMITED IN KEEPING WIT THE ABOVE BUT ONLY TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW.
10. Assignment.
You may not assign, transfer, or sublicense any obligations or benefits under these Terms without the prior written consent of HMHS. Subject to the foregoing, these Terms will bind and inure to the benefit of the parties, their respective successors, and permitted assigns.
HMHS may extend its rights or delegate its responsibilities to its Affiliates and subcontractors acting on its behalf (which may also be Affiliates), in which case such party will remain responsible for their compliance with this Agreement. “ Affiliate” means a Person that, directly or indirectly, owns or controls, is owned or is controlled by or is under common ownership or control with a party, where “control” means the power to direct the management or affairs of a Person, and “ownership” means the beneficial ownership of 50% or more of the voting equity securities or other equivalent voting interests of a Person. “ Person” means any individual, corporation, limited liability company, partnership, bank, firm, joint venture, association, trust, unincorporated organization, governmental entity, or other entity, now or later formed.
11. Termination.
These Terms shall remain effective until terminated. HMHS may immediately terminate these Terms and/or Your access to and use of any or all APIs or any portion thereof, for any reason or no reason, to the extent permitted by applicable law. In addition, HMHS may terminate these Terms at any time for cause if You fail to comply with any provision of these Terms, in which case all rights granted to You by these Terms will terminate, and You will lose any status as a Permitted User.
Upon termination, You shall no longer have any license under these Terms, and You must immediately (i) cease use of all APIs, (ii) uninstall and delete any connection to all APIs on any system used by You, and (iii) securely delete and destroy all credentials and identification and security tokens issued to You by HMHS in Your possession or control.
All provisions or obligations contained in these Terms which by their nature or effect are required or intended to be observed, kept, or performed after termination (including without limitation Sections 3 (Intellectual Property Rights), 7 (Data), 8 (Indemnification), 9 (Liability Limitations), 11 (Termination), 12 (Applicable Law), and 13 (Miscellaneous) of these Terms) shall survive any termination of Your rights under these Terms.
12. Applicable Law.
These Terms shall be governed by and construed in accordance with the laws of the United States and of the Commonwealth of Pennsylvania, without regard to conflicts of law principles. Any claim or dispute between the parties will be resolved on an individual basis in the state or federal courts of the Commonwealth of Pennsylvania and the United States, respectively, sitting in Allegheny County, Pennsylvania. If You are a United States city, county, or state government entity, then the following applies instead of the language above: The parties agree to remain silent regarding governing law and venue.
13. Miscellaneous.
These Terms are the complete and exclusive statement of the agreement with respect to the subject matter hereof and supersede all other communications or representations or agreements (whether oral, written, or otherwise) relating thereto. Without limiting the generality of the foregoing, a separate agreement between You and HMHS is independent from and has no bearing on these Terms. The failure of HMHS to require performance of any provision of these Terms in no manner shall affect its right at a later time to enforce the same. No waiver by HMHS of any breach of the terms of these Terms, whether by conduct or otherwise, in any one or more instances, shall be deemed to be or construed as a further or continuing waiver of any other such breach, or a waiver of any other breach of such terms.
If any provision of these Terms shall to any extent be held invalid, illegal, or unenforceable, the validity, legality, and enforceability of the remaining provisions of these Terms shall in no way be affected or impaired thereby and each such provision of these Terms shall be valid and enforceable to the fullest extent permitted by law. In such case, these Terms shall be reformed to the minimum extent necessary to correct any invalidity, illegality, or unenforceability, while preserving to the maximum extent the rights and commercial expectations of the parties hereto, as expressed herein. The section headings in these Terms are for convenience only and shall have no legal or contractual effect.
HMHS will not be liable for failure or delay in performing its obligations if such failure or delay is due to a force majeure event or other circumstances beyond its reasonable control, including acts of any governmental body, war, cyber war or attack, terrorism, insurrection, sabotage, embargo, fire, flood, severe weather, earthquake, tornado, hurricane, pandemic, labor disturbance, criminal act, security incident, interruption of or delay in the internet or transportation, unavailability of third-party services, failure of third-party software or services, or inability to obtain raw materials, supplies, or power used in or equipment needed for provision of an API.
HMHS may provide You with notices, including those regarding changes to an API by email or by posting such on notices on a website.
Effective Date: 8/16/21