Terms of Service
Version 1.0 · Effective August 8, 2026
- 1. The Service
- 2. Account
- 3. Subscriptions, Pricing, Billing
- 4. Customer Data; Flat Multi-Tenancy
- 5. Acceptable Use
- 6. Service Outputs, SRA Accuracy, and Compliance Disclaimers
- 7. Sealed PDF and SHA-256 Seal
- 8. Intellectual Property
- 9. Privacy and Data Processing
- 10. Suspension and Termination
- 11. Confidentiality
- 12. Warranties and Disclaimers
- 13. Limitation of Liability
- 14. Indemnification
- 15. General Provisions
- 16. Updates
- Contact
Effective Date: Phase-0 (pre-launch); commercial activity has not commenced.
These Terms of Service ("Terms") form a binding agreement between Ellis Intelligence LLC, a Colorado limited liability company doing business as SRAReady ("SRAReady", "we", "us"), and the healthcare practice subscribing to or using the Service ("Customer", "you").
The Service is intended for use by covered entities under the Health Insurance Portability and Accountability Act ("HIPAA") — typically healthcare practices. The Service is not for use by consumers or patients.
1. The Service
1.1 SRAReady is a software-as-a-service application that guides a healthcare practice (covered entity under HIPAA) through a self-conducted HIPAA Security Risk Assessment ("SRA") using the U.S. Department of Health and Human Services ("HHS") 800-66 Rev 2 guidance framework, and generates a sealed SRA report documenting that assessment. (References in these Terms to "OCR" mean the HHS Office for Civil Rights, the HHS component that enforces the HIPAA Security Rule.) The Service provides a guided wizard, a live risk register, and a SHA-256-sealed PDF that the practice can use to document its self-conducted assessment.
1.2 Tier-specific features and limits (including any request-volume or usage bands) are described at sraready.com/pricing. Tier names, and the figures behind them, live on that page and are never restated in these Terms. Tier names: Solo, Practice, Multi-Location. Figures live at sraready.com/pricing and are never restated here.
1.3 Healthcare Practice Use Only. The Service is intended for use by covered entities and their authorized workforce members for internal HIPAA compliance documentation purposes.
1.4 SRAReady Is Software, Not a Law Firm, Compliance Consultant, or HIPAA Certifier. SRAReady is a software vendor providing a self-assessment documentation tool. There is no HIPAA certification body; SRAReady does not certify HIPAA compliance. SRAReady does not: - Certify, attest to, or guarantee the accuracy or sufficiency of any SRA or risk assessment - Act as your compliance consultant, privacy officer, or HIPAA attorney - Provide legal advice, compliance advice, or legal opinions — any content the Service provides is general information, not legal or professional advice - Form an attorney-client relationship with the Customer - Guarantee that the sealed SRA PDF will satisfy any specific OCR audit finding or enforcement action - Conduct the assessment on your behalf — the Customer self-conducts the assessment using the wizard
See the standalone Disclaimers at sraready.com/disclaimers for the full framing.
1.5 SRAReady Does Not Access, Store, or Process Protected Health Information (PHI). The Service collects information about the Customer's systems and security controls — not about patients. SRAReady is not a Business Associate ("BA") under HIPAA because it does not create, receive, maintain, or transmit PHI on behalf of a covered entity. Do not enter any PHI, patient records, patient identifiers, or any other protected health information into the Service. SRAReady does not execute Business Associate Agreements ("BAAs") in v1; no BAA mechanism exists because no PHI is processed. If future features are scoped that would involve PHI, a formal BA/legal review will be conducted before any such feature is built or deployed.
1.6 No Affiliation, Endorsement, or Government Action; Customer Self-Conducts the Assessment. SRAReady is not affiliated with, endorsed by, sponsored by, or officially recognized or supported by the U.S. Department of Health and Human Services ("HHS"), the HHS Office for Civil Rights ("OCR"), or any other government agency, or the U.S. Government in any way. SRAReady does not represent that the sealed SRA PDF's organization is required, approved, endorsed, or accepted by HHS or OCR, and makes no representation about how OCR or any other party will regard the document. SRAReady does not predict, forecast, or represent how HHS, OCR, or any other government agency will assess, review, or act on any Customer's sealed SRA PDF, and SRAReady does not act, and is not authorized to act, on behalf of HHS, OCR, or any other government agency in any capacity. Using SRAReady does not create any government-recognized status. The HIPAA Security Risk Assessment is self-conducted by the Customer using the Service as a guided documentation tool; the Customer is responsible for reviewing the generated risk register and sealed PDF before treating them as final documentation. SRAReady's outputs, marketing pages, and app UI render as plain text/typography only — no seal, badge, ribbon, watermark, or certificate-style graphic, or other supportive-looking insignia — so no surface visually or verbally suggests such affiliation, endorsement, sponsorship, or action on any government agency's behalf.
2. Account
2.1 Account creation requires an authorized representative of the Customer entity (owner, office manager, practice administrator, or designated HIPAA Security Officer).
2.2 Each seat is for a single named individual. Seat-sharing is prohibited.
3. Subscriptions, Pricing, Billing
3.1 Solo, Practice, and Multi-Location are monthly or annual subscriptions, billed via Stripe; annual pricing is shown at sraready.com/pricing.
3.2 Pricing at sraready.com/pricing. 30-day notice for material changes.
3.3 Billing via Stripe.
3.4 Free HIPAA Readiness Check. The 5-question free triage is available without a subscription. Sessions are ephemeral; no assessment record is created. The Readiness Check is a risk-tier indicator, not an SRA.
3.5 Refunds. Monthly fees are non-refundable for the current period except pro rata on our material breach or on discontinuation under §10.
3.6 No Service-Level Credits or Refunds. The Service carries no uptime or response-time commitment. No service credit, fee credit, refund, or other remedy arises from any delay, outage, missed response target, or unmet support expectation. The §12.1 limited-warranty remedy and the §10.2 pro-rata refund on our own discontinuation remain the only remedies.
3.7 Annual SRA Renewal. The HIPAA Security Rule requires covered entities to conduct a risk assessment periodically and whenever significant operational or environmental changes occur. Annual renewal reminders are provided as a convenience; the Customer remains responsible for meeting their regulatory renewal obligations on schedule.
3.8 An SRA must also be repeated when there is a material change to the practice's environment — a new electronic health record ("EHR") system, a new workforce member with access to electronic PHI ("ePHI"), a new physical location, or a change in how ePHI is stored or transmitted. The Service does not automatically detect material environmental changes; the Customer is responsible for initiating a new SRA when warranted.
4. Customer Data; Flat Multi-Tenancy
4.1 Ownership. As between us, you own all Customer Data you submit ("Customer Data"), including your practice name, provider information, wizard responses, and the assessment records the Service generates for you.
4.2 License to Us. You grant us a limited license to host, store, transmit, display, and process Customer Data solely to provide the Service (including generating the risk register, producing the sealed SRA PDF, and managing annual renewal reminders).
4.3 No Training / No Selling. We do not sell or share Customer Data, and we do not use it to train any model or to improve a Service used by other customers. See our Privacy Policy.
4.4 Flat Per-Tenant Isolation. Each business is one tenant. Single-level isolation is enforced: every tenant-scoped read and write routes through tenant-scoping helpers that raise if the scope is missing, so no tenant can access another tenant's data. There is no nested tenancy and no white-label resale in v1.
4.5 No PHI — The Customer Warrants This. By using the Service, you warrant that no PHI, patient records, patient identifiers, clinical data, or protected health information has been or will be entered into the Service. The wizard is designed to collect system and process information only; it is not designed to receive PHI and has no clinical data fields. The Customer is responsible for ensuring that wizard responses do not include PHI.
5. Acceptable Use
5.1 No reverse engineering, no scraping, no building a competing product from the Service, no resale.
5.2 No PHI. Customer will not enter PHI, patient records, or clinical data of any kind into the Service. See §1.5 and §4.5.
5.3 No Misrepresentation of Certification. You will not represent to any party (OCR, HHS, patients, staff, or any other party) that SRAReady has certified, assessed, or otherwise validated your HIPAA compliance posture. The sealed SRA PDF is a self-conducted documentation artifact; it does not constitute HHS approval, OCR certification, or a compliance guarantee.
5.4 Self-Conducted Assessment. The Customer is responsible for the accuracy of the information it enters into the wizard. SRAReady produces the documentation artifact from what the Customer provides; it does not verify the Customer's underlying security controls.
6. Service Outputs, SRA Accuracy, and Compliance Disclaimers
6.1 Self-Conducted Documentation, Not a Certification. The SRA wizard, risk register, and sealed PDF the Service generates are a documentation of the Customer's self-conducted HIPAA Security Risk Assessment using the HHS 800-66 framework. They are not an HHS audit, an OCR finding, a compliance certification, or a legal opinion. The Customer is solely responsible for the accuracy of the information they provide and for the completeness and appropriateness of the SRA as documentation of their actual security posture.
6.2 What the Sealed SRA PDF Contains. The sealed SRA PDF assembles the Customer's own wizard responses into a single document containing: a cover page with the practice's information and the generation date; a methodology statement identifying the HHS 800-66 framework and the scope of the assessment; a risk register organized by the HIPAA Security Rule's administrative, physical, and technical safeguard categories, with each finding shown at the severity the Customer's responses produced and mapped to its regulatory citation; remediation priorities ordered by severity; and a SHA-256 generation seal (§7). The document's organization follows published HHS guidance and patterns observed in OCR enforcement activity, so that the methodology, findings, and remediation actions appear in a consistent, organized structure for any reader reviewing the assessment. SRAReady does not represent that this organization is required, approved, endorsed, or accepted by HHS or OCR, and makes no representation about how OCR or any other party will regard the document. The assessment is self-conducted by the Customer (§1.6); the sealed PDF is not an HHS audit, an OCR finding, or a certification, and the Customer remains responsible for implementing the controls identified in it and for compliance with the HIPAA Security Rule. SRAReady does not guarantee the output will satisfy any specific OCR audit, investigation, or enforcement action.
6.3 Framework Currency. The Service implements HHS 800-66 Rev 2 (National Institute of Standards and Technology ("NIST") SP 800-66 Revision 2, "Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide," published 2022). Verify against current HHS guidance. The Customer is responsible for ensuring the framework version used is appropriate for their regulatory context.
6.4 Implementation Is the Customer's Responsibility. The Service documents the Customer's security controls as self-reported. Actual HIPAA compliance depends on the Customer implementing the controls they have documented. SRAReady does not implement security controls, verify their implementation, or monitor ongoing compliance.
6.5 No BA Relationship. SRAReady is not a Business Associate under HIPAA. The Service collects system and process information, not PHI. No BAA is executed. If the Customer enters PHI into the Service, the Customer is solely responsible for the consequences.
6.6 No Autonomous Distribution. SRAReady does not transmit, distribute, or share a sealed SRA PDF or any other Service output with HHS, OCR, or any other third party on the Customer's behalf; the Customer decides if, when, and with whom to share it. Because a human — the Customer — always makes that sharing decision, this sits in the standard disclaimer-plus-no-auto-action tier, not the stricter tier reserved for brands whose own output reaches a regulator or external party directly.
7. Sealed PDF and SHA-256 Seal
7.1 The sealed SRA PDF is generated at the moment the Customer clicks "Generate Report." A SHA-256 hash is computed at generation time and stored. The Customer may verify the integrity of the PDF on demand by comparing the file's current SHA-256 hash to the stored value.
7.2 A sealed SRA report, once generated, is immutable in the Service's records. If the Customer conducts a new assessment (mid-year review or annual renewal), a new sealed report is generated; the prior sealed report is retained as a record.
7.3 The SHA-256 seal is a data-integrity mechanism, not a legal certification. It proves the document has not been altered since generation; it does not constitute an attestation by SRAReady or an HHS endorsement. The seal and all disclaimer language render as plain text/typography only — no seal graphic, badge, ribbon, watermark, or certificate-style image appears anywhere on the PDF or any other customer-facing surface, regardless of whether it references HHS, OCR, or any other body, so the output never visually resembles a third-party validation or government mark.
8. Intellectual Property
8.1 Service IP. We own the Service and its contents. No license to the HHS 800-66 framework is granted by us — the framework is publicly available HHS guidance; we have implemented the framework's questions and control structure in the wizard.
8.2 Feedback. Standard perpetual-license grant on feedback.
8.3 Customer References. We may identify you as a customer (name, logo) on the customers page unless you opt out.
8.4 IP & Assignment Rider. An IP & Assignment Rider addressing ownership and assignment of intellectual property is incorporated by reference into these Terms and controls over this §8 and over §15.4 on the subjects within its scope.
8.5 Present assignment of Derivative IP. To the extent any Derivative IP would otherwise vest in Customer — by operation of law, under any work-made-for-hire or commissioned-work doctrine, because Customer's use, Inputs, or Feedback contributed to it, or on any other basis — Customer hereby irrevocably and presently assigns to Company all right, title, and interest in and to that Derivative IP, effective automatically upon its creation and without further action or consideration.
9. Privacy and Data Processing
9.1 Privacy Policy at sraready.com/privacy. We are the controller for marketing-site visitors and Customer account/billing contacts, and the processor for the compliance data you place under your tenant. Where the Data Processing Addendum and these Terms conflict as to the processing of Customer Data, the DPA controls; this Privacy Policy is a notice, not a contracting instrument.
10. Suspension and Termination
10.1 These Terms continue until the subscription is canceled or terminated. Cancellation takes effect at the end of the current billing period. 10.2 We may terminate for material breach of these Terms (including unauthorized PHI entry or misrepresentation of certification status), with 10 days' written notice (email to the account or billing contact, deemed given when sent; the period runs from the send date) unless the breach is incurable. 30 days' notice with pro rata refund for any discontinuation we initiate, paid within 30 days after the effective date of termination. 10.3 On termination, Customer Data (including sealed SRA reports) is available for export for 30 days, then deleted. 10.4 Survival. Sections 4 (data), 6 (outputs/disclaimers), 8 (IP), 11 (Confidentiality), 12 (Warranties), 13 (Liability), 14 (Indemnification), 15 (General) survive.
11. Confidentiality
Treat all Customer Data as confidential information; standard confidentiality commitments; 5-year survival; trade-secret indefinite.
12. Warranties and Disclaimers
12.1 Limited Warranty. The Service performs substantially per documentation. Exclusive remedy: repair or pro rata refund.
12.2 Disclaimer. THE SERVICE IS PROVIDED "AS IS." WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE IS FREE FROM ERRORS OR THAT REGULATORY FRAMEWORKS IMPLEMENTED IN THE SERVICE ARE CURRENT.
12.3 No Warranty Re OCR Audit or Enforcement Outcome. We do not warrant that the Service's outputs will satisfy any specific OCR audit, investigation, or enforcement action.
13. Limitation of Liability
13.1 TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS, LOST REVENUE, LOST DATA, OR ANY DAMAGES ARISING FROM A FAILED CONTRACT, DISQUALIFIED BID, REGULATORY ACTION, OR FCA PROCEEDING, EVEN IF ADVISED.
13.2 OUR TOTAL CUMULATIVE LIABILITY ARISING FROM OR RELATED TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE FEES YOU PAID US IN THE TWELVE MONTHS PRECEDING THE CLAIM.
13.3 No Liability for OCR Enforcement or Regulatory Outcomes. We are not liable for: any OCR enforcement penalty, breach notification cost, or legal fees arising from a HIPAA enforcement action; or any other finding, inquiry, investigation, or enforcement action by any regulatory, administrative, or enforcement body of any kind — including without limitation HHS OCR, any state attorney general, or any other regulator under any state health-data-privacy statute. This carve-out is stated as broadly as possible and applies uniformly regardless of the specific statute, regulation, or regulatory or enforcement body involved; a party asserting that this carve-out does not apply to a particular claim, statute, or regulatory or enforcement body bears the burden of establishing that, rather than us bearing the burden of having disclaimed each one individually.
14. Indemnification
14.1 Stated in the contract you execute. Both indemnities — ours for IP infringement and yours — are stated in full on the face of §7 of the SRAReady Engagement & Tiers SOW (sraready.com/sow, "7. Indemnification — the executed-instrument provision"), together with the claim procedure. That §7 is the indemnification block carried on the face of the click-signed Order Form you accept at any tier, rendered above the agree control. Those provisions govern; this §14 is a cross-reference and does not restate them.
14.2 No separate indemnity. These Terms state no indemnification obligation separate from, additional to, or narrower than SOW §7, and nothing in these Terms enlarges or limits it. Where these Terms refer to the §14 indemnity (§10.4 survival), the reference is to SOW §7.
15. General Provisions
15.1 Governing Law. Colorado. The United Nations Convention on Contracts for the International Sale of Goods ("CISG") does not apply. 15.2 Disputes. Binding arbitration via JAMS in Boulder County, CO. Each party waives any right to a jury trial and to participation in any class, collective, or representative proceeding. Either party may seek injunctive relief in court for §5, §6, §8, or §11 breaches. 15.3 Notices, Force Majeure, Entire Agreement, Modifications (30-day), Severability, No Waiver, Independent Contractors. Standard. Written notice under these Terms (email to the billing contact or in-product notice) is deemed given when sent or first displayed; any notice period runs from that date, and failure to read a notice does not extend it. 15.4 Assignment; Change of Control. You may not assign, delegate, or transfer these Terms, in whole or in part, whether by operation of law, merger, or change of control, without our prior written consent; any attempted assignment in violation of this sentence is void. We may, without your consent and without notice except as any applicable data-protection law requires, assign or transfer these Terms and all of our rights and obligations under them, in whole or in part, (a) to a successor or acquirer in connection with a merger, acquisition, or sale of substantially all of our business or assets, or (b) to an affiliate, subsidiary, or newly formed entity in connection with a corporate conversion, reorganization, or contribution or drop-down of assets undertaken to effect a sale, reorganization, or transfer of the specific business line or product to which these Terms relate. Upon such an assignment, all of our rights under these Terms pass to the assignee, the assignee assumes our obligations arising after the assignment, and your continued use of the Service constitutes acknowledgment of the assignee as "SRAReady" going forward. A change in our ownership, control, equity holders, or entity form is not a breach of, default under, or ground to terminate, suspend, renegotiate, or re-price these Terms, and does not trigger any right of termination, consent, first refusal, most-favored-nation, audit, or refund on your part. This §15.4 controls over any contrary term in a Customer purchase order or procurement addendum.
15.5 Regional and Supplemental Terms. No jurisdiction-specific supplemental term applies today. Where a supplemental jurisdiction-specific term applies, it controls over a conflicting general term of these Terms for that jurisdiction only.
16. Updates
30 days' email notice to the Customer billing contact for material changes. Notice is deemed given when sent; the 30-day period runs from the send date, and failure to read a notice does not extend it. Continued use after the effective date constitutes acceptance.
Contact
SRAReady — Ellis Intelligence LLC Email: [email protected] Address: 1500 N Grant St, Ste N, Denver, CO 80203, USA
SRAReady is a product of Ellis Intelligence LLC. SRAReady is software, not a HIPAA certifier, an auditor, or a law firm; this is general information, not legal, compliance, or professional advice. See also our Privacy Policy and Data Processing Addendum. Questions about this document? Email [email protected].