Effective October 20, 2024

Plato Healthcare Terms of Service

Thank you for choosing Plato Healthcare.

These Terms of Use apply to your use of any associated software applications and websites (all together, “Services”) owned by Plato Healthcare Corporation. These Terms form an agreement between you and Plato Healthcare Corporation, and they include our Service Terms and important provisions for resolving disputes through arbitration. By using our Services, you agree to these Terms.

Registration and Access

  • Minimum Age. You must be at least 13 years old or the minimum age required in your country to consent to use the Services. If you are under 18 you must have your parent or legal guardian’s permission to use the Services.
  • Registration. You must provide accurate and complete information to register for an account to use our Services. You may not share your account credentials or make your account available to anyone else and are responsible for all activities that occur under your account. If you create an account or use the Services on behalf of another person or entity, you must have the authority to accept these Terms on their behalf.

Using Our Services

  • What You Can Do. Subject to your compliance with these Terms, you may access and use our Services. In using our Services, you must comply with all applicable laws as well any other documentation, guidelines, or policies we make available to you.
  • What You Cannot Do. You may not use our Services for any illegal, harmful, or abusive activity. This includes (1) using our Services in a way that infringes, misappropriates or violates anyone’s rights; (2) Modify, copy, lease, sell or distribute any of our Services ; (3) Attempt to or assist anyone to reverse engineer, decompile or discover the source code or underlying components of our Services, including our models, algorithms, or systems (except to the extent this restriction is prohibited by applicable law); (4) Interfere with or disrupt our Services, including circumvent any rate limits or restrictions or bypass any protective measures or safety mitigations we put on our Services; (5) Use our Outputs or data to develop products or services to compete with Plato Healthcare Corporation.
  • Text Messaging. Our Services may allow you to use SMS text messages. By signing up for our Services, you acknowledge that you agree to receive SMS text messages from us.
  • Third Party Services. Our services may include third party software, products, or services, (“Third Party Services”) and some parts of our Services, like our browse feature, may include output from those services (“Third Party Output”). Third Party Services and Third Party Output are subject to their own terms, and we are not responsible for them.
  • Feedback. We appreciate your feedback, and you agree that we may use it without restriction or compensation to you.

Paid Accounts

  • Billing. If you purchase any Services, you will provide complete and accurate billing information, including a valid payment method. For paid subscriptions, we will automatically charge your payment method on each agreed-upon periodic renewal until you cancel. You’re responsible for all applicable taxes, and we’ll charge tax when required. If your payment cannot be completed, we may downgrade your account or suspend your access to our Services until payment is received.
  • Cancellation. You can cancel your paid subscription at any time. Payments are non-refundable, except where required by law.
  • Changes.We may change our prices from time to time. If we increase our subscription prices, we will give you at least 30 days’ notice and any price increase will take effect on your next renewal so that you can cancel if you do not agree to the price increase.

Data Security and Encryption

  • Data Encryption. All data stored in Plato Healthcare’s systems is encrypted both in transit and at rest to ensure maximum protection of user information, unless specifically requested by you to do otherwise for the purposes of timely speed of data transmission and user experience.
  • Secure Infrastructure. Plato Healthcare uses industry-standard encryption protocols and secure servers to protect user data.

HIPAA Compliance

  • HIPAA - Consent to Portability of Data. You consent for us to have the ability to share your information with individuals, organizations, and entities that you designate.
  • HIPAA - Informed Consent. At Plato Healthcare, we store your information in highly secure, encrypted environments. However, in certain situations, you may choose to share your information with third parties who require non-encrypted or less secure transmission methods (ex: to your doctor via email). By using our Services, you acknowledge and consent to the potential risks of transmitting your information in unencrypted ways. If such a scenario arises, we will inform you of the associated security risks, allowing you to make an informed decision before proceeding.
  • Data Protections. You understand that your health information which may be temporarily stored (ex: "in memory") on your device(s) is not the security responsibility of Plato Healthcare.

User Responsibility for Device and Password Security

  • Device Security. You are responsible for the security of your own device and password. Plato Healthcare is not liable for unauthorized access due to your failure to safeguard your credentials.
  • Password Protection. Safeguard your password to prevent unauthorized access. Plato Healthcare will not be liable for any breach arising from poor password protection.

User Responsibilities for Health Information

  • Accuracy of Information. You are responsible for ensuring that any health information you input into our system is accurate and up to date.
  • Health-Related Decisions. The information available on our platform should not replace professional medical advice. You agree to always consult with your healthcare provider for health-related decisions and not use our products or services as professional medical advice.

Termination and Suspension.

  • Termination. You are free to stop using our Services at any time. We reserve the right to suspend or terminate your access to our Services or delete your account if we determine: (1) You breached these Terms; (2) We must do so to comply with the law; (3) Your use of our Services could cause risk or harm to Plato Healthcare Corporation, our users, or anyone else.

Right to Change These Terms.

  • Changing Terms. Plato Healthcare Corporation holds the right to change these Terms at any time without warning to users.

Special Notice for Terms and Conditions for:

Centers of Medicare and Medicaid Services (CMS): Blue Button 2.0 Data Access Terms

As a CMS Blue Button 2.0 organization, Plato Healthcare adheres to the data access and usage requirements set forth by CMS. The following section provides a detailed explanation of how we comply with specific CMS data handling requirements to ensure transparency, security, and accountability when managing your personal health data.

Policies and Responses to CMS Data Requirements

Transparency

CMS Requirement: The existence of record-keeping systems and databanks containing data about beneficiaries should be publicly known, along with a description of the main purposes and uses of the data.

Plato Healthcare Response: We are transparent about the data we collect and store. The main purpose of our services is to centralize health information and enable users to share this information with whomever they want. We do not share or sell any customer data with 3rd parties, unless the user specifically asks us to do so. We may develop features that analyze a user's healthcare information to provide the user (or people who have the shared information) more information about their health.

Consent

CMS Requirement: Data should be collected lawfully, with the knowledge or consent of the beneficiary. Data must not be communicated externally without the beneficiary's consent, unless permitted by law.

Plato Healthcare Response: We require informed consent from our users before we start collecting their health information. This informed consent process is part of a customer's onboarding activies. We collect personal data with the explicit consent of users, which includes data from CMS's Blue Button 2.0. No data is shared externally without the user's permission, unless required by law.

Use and Disclosure

CMS Requirement: Personal data should only be used for the specified purposes at the time of collection and should not be shared externally without the beneficiary's consent.

Plato Healthcare Response: We only use personal data for its intended purpose of improving user health outcomes. Data is not shared with third parties without user consent, except where legally required.

Individual Access

CMS Requirement: Each beneficiary should have the right to see their own data and correct any inaccurate, incomplete, or outdated information.

Plato Healthcare Response: Users have full access to their health information and can update or correct inaccuracies directly through our platform, ensuring that the data remains relevant and accurate. Users also have the right to delete any or all of the data we posess.

Security

CMS Requirement: Personal data should be protected by reasonable security safeguards against risks like loss, unauthorized access, or disclosure.

Plato Healthcare Response: We utilize industry-standard encryption protocols and other safeguards to protect all user data from unauthorized access, loss, or disclosure.

Data Quality

CMS Requirement: Personal data should be accurate, complete, and relevant for the purposes for which they are used.

Plato Healthcare Response: During user onboarding, we confirm personal data remain accurate. We also periodically check-in with users to ensure personal information is accurate. We ensure that the data we collect is accurate and relevant to providing our products and services. Users can also update their data to ensure it remains accurate over time.

Accountability

CMS Requirement: Record keepers should be accountable for complying with fair information practices.

Plato Healthcare Response: We are fully accountable for protecting and managing the personal data of our users in compliance with all applicable laws and regulations, including CMS's Blue Button 2.0.