This document is not a Business Associate Agreement (BAA).
SoloPractice handles Protected Health Information (PHI) on behalf of the medical practices that use it. Where HIPAA requires a signed Business Associate Agreement between a covered-entity practice and SoloPractice/Agyeman Enterprises before PHI may be processed, that agreement must be executed separately and is not satisfied by acceptance of these Terms. Do not process live patient PHI in SoloPractice until your practice has a signed BAA in place, if one is legally required for your arrangement. See § 8 below.
These Terms of Service (“Terms”) govern access to and use of SoloPractice, an electronic health record and practice-management system operated by Agyeman Enterprises (“SoloPractice,” “we,” “us”). By creating an account or using SoloPractice, you agree to these Terms. If you are creating an account on behalf of a medical practice, you represent that you have authority to bind that practice, and “you” in these Terms refers to both you and the practice.
1. What SoloPractice is
SoloPractice is a system of record for a solo or small independent medical practice: patient registration and scheduling, visit documentation (including AI-assisted SOAP note drafting that a licensed clinician must review and sign before it is final), e-prescribing, lab and imaging ordering, insurance eligibility checks, telehealth visits, and claims billing. It includes a separate patient portal through which a practice’s patients can view their own records and communicate with the practice.
2. Who may use SoloPractice
The staff-facing application is intended for licensed medical practices and their authorized staff — physicians, advanced practice providers, nurses, medical assistants, and administrative/billing personnel acting within the scope of their role at that practice. You must be at least 18 years old to hold a staff account. Staff accounts are provisioned or approved by the practice administrator/owning physician and may be suspended or removed by the practice at any time.
The patient portal is intended for a practice’s own patients (or their authorized representatives, e.g. a parent/guardian for a minor patient, consistent with the practice’s own consent policies), invited by that practice. Portal access is separate from and does not grant any staff-level access.
3. Accounts and responsibilities
- You are responsible for keeping your login credentials confidential and for all activity under your account.
- Clinical staff roles require multi-factor authentication; do not attempt to disable or bypass it.
- Notify your practice administrator immediately if you suspect unauthorized access to your account.
- Practice administrators are responsible for promptly deactivating staff accounts when someone leaves the practice.
- You will provide accurate registration information and keep it current.
4. Acceptable use
You agree not to:
- Access, view, or export patient records you do not have a legitimate clinical or administrative reason to access — every access is logged and auditable.
- Share your account credentials with another person, or use another person’s account.
- Attempt to circumvent role-based access controls, rate limits, or the practice-isolation boundary between tenants.
- Use the system to store or transmit PHI for a patient outside a lawful treatment, payment, or healthcare-operations purpose.
- Upload malicious files, attempt to probe or scan the application for vulnerabilities without authorization, or interfere with other practices’ use of the system.
- Rely on AI-generated note drafts, coding suggestions, or clinical-decision-support output as final without independent clinician review — these are drafting aids, not a substitute for clinical judgment.
5. The patient portal
The patient portal is a supplementary communication and records-access tool. It is not a substitute for emergency care: patients must not use the portal to report a medical emergency, and should call 911 or go to the nearest emergency department for urgent symptoms. A practice sets its own expected response time for portal messages and is responsible for communicating that to its patients. Portal access does not create or modify the underlying physician-patient relationship, which is governed by the practice’s own patient agreements.
6. Payments
Where SoloPractice is used to collect patient payments (co-pays, self-pay balances, invoices), those payments are processed by Stripe. By making or accepting a payment through SoloPractice you also agree to Stripe’s terms governing payment processing. SoloPractice does not store full payment card numbers. Where a practice or its patients are charged a subscription fee for SoloPractice access itself, billing terms, pricing, and cancellation policy will be presented at checkout and are incorporated into these Terms by reference.
7. Third-party services
SoloPractice relies on a defined set of third-party services to operate — including Supabase (database/auth/storage), Stripe (payments), Twilio (SMS/voice reminders and optional video), AssemblyAI (visit transcription), Resend (transactional email), Amazon Web Services (bulk data export storage), Sentry (error monitoring, configured to exclude PHI), and Anthropic (AI drafting assistance). Full detail on what each service processes is in the Privacy Policy. Availability of SoloPractice depends in part on the availability of these providers; we are not responsible for outages caused by a third-party provider outside our control.
8. Healthcare compliance and Business Associate Agreements
SoloPractice is designed with HIPAA-oriented technical safeguards — practice-scoped Row-Level Security, encryption in transit and at rest for the most sensitive identifiers, role-based access control, and a persistent audit log of privileged clinical actions. Technical safeguards alone do not satisfy HIPAA’s legal requirements. If your practice is a HIPAA covered entity (or you are a business associate of one) and you will process PHI using SoloPractice, HIPAA requires a signed Business Associate Agreement between your practice and Agyeman Enterprises before PHI is processed, and Agyeman Enterprises to in turn have appropriate BAAs in place with the underlying service providers listed in § 7 to the extent they touch PHI. Contact us at the address in § 12 to request or execute a BAA. Using SoloPractice with real patient PHI before that agreement is in place, where one is legally required, is done at your own risk and against our guidance.
9. Intellectual property
SoloPractice, its software, and its content (excluding data you or your practice input) are owned by Agyeman Enterprises. You are granted a limited, non-exclusive, non-transferable right to use SoloPractice for your practice’s internal healthcare operations, subject to these Terms. You retain ownership of the clinical and patient data your practice creates; we process it on your behalf as described in the Privacy Policy.
10. Disclaimers
SoloPractice is a documentation, scheduling, and billing tool for licensed medical professionals. It does not practice medicine, diagnose, or treat patients. AI-drafted notes, coding suggestions, and clinical-decision-support content are aids only and must be reviewed and approved by a licensed clinician before being relied upon; SoloPractice and Agyeman Enterprises are not responsible for clinical decisions made using the platform. The service is provided “as is” and “as available” without warranties of any kind except as expressly stated here or required by law.
11. Limitation of liability
To the maximum extent permitted by law, Agyeman Enterprises’ total liability arising out of or relating to these Terms or use of SoloPractice will not exceed the amount you or your practice paid for the service in the twelve months preceding the claim. Neither party will be liable for indirect, incidental, special, consequential, or punitive damages. Nothing in these Terms limits liability where the law does not permit such a limitation, including liability arising from gross negligence, willful misconduct, or violations of applicable healthcare privacy law that cannot be limited by contract.
12. Termination
A practice may stop using SoloPractice at any time; contact us to close an account and arrange export or deletion of practice data consistent with applicable medical-records retention law and the Privacy Policy’s retention terms. We may suspend or terminate an account that violates § 4 (Acceptable Use), poses a security risk to other tenants, or where required by law. On termination, HIPAA retention obligations described in the Privacy Policy continue to apply to any data already collected.
13. Changes to these Terms
We may update these Terms as the product changes. Material changes will be communicated to practice administrators before taking effect. Continued use of SoloPractice after a change takes effect constitutes acceptance of the updated Terms.
14. Governing law
These Terms are governed by the laws of the jurisdiction in which Agyeman Enterprises is organized, without regard to conflict-of-laws principles, except where a practice’s applicable healthcare or data-protection law requires otherwise.
15. Contact
Questions about these Terms, or to request a Business Associate Agreement, contact: [email protected].
This document is a good-faith, product-grounded draft and does not by itself constitute a Business Associate Agreement or a substitute for review by qualified legal counsel. See docs/launch/LEGAL_COMPLIANCE.md for review status.