HANA Health, Inc.
Acceptable Use Policy
Effective Date: 10 May 2026 | Last Updated: 10 May 2026
This Acceptable Use Policy (the "AUP") describes prohibited and restricted uses of HANA Health, Inc.'s services, products, and platform (the "Services"). This AUP is incorporated by reference into the HANA Master Services Agreement (the "Agreement") between HANA and Customer. Capitalized terms not defined here have the meanings given in the Agreement.
By using the Services, Customer and its Users agree to comply with this AUP. Violation of this AUP is a material breach of the Agreement and may result in suspension or termination of the Services.
1. General principles
Customer and its Users must use the Services lawfully, ethically, and in accordance with the Agreement. Customer is responsible for all activity conducted through Customer's account, including activity by Customer's personnel, contractors, and patients.
2. Prohibited uses
Customer and its Users must not, and must not allow any third party to:
2.1 Unlawful conduct
- Use the Services to violate any applicable law, regulation, or order, including the Telephone Consumer Protection Act (TCPA), the Telemarketing Sales Rule (TSR), the Do-Not-Call Implementation Act, the CAN-SPAM Act, the Health Insurance Portability and Accountability Act (HIPAA), the Gramm-Leach-Bliley Act (GLBA), the Fair Credit Reporting Act (FCRA), or applicable state privacy, consumer protection, or biometric privacy laws.
- Use the Services to perpetrate fraud, deception, or any unfair or abusive practice.
- Use the Services to make calls or send messages to recipients who have not provided required consent under applicable law, or who have opted out of communications.
2.2 Harm and abuse
- Use the Services to harass, threaten, intimidate, defame, or otherwise harm any individual or organization.
- Use the Services to discriminate against any individual or group on the basis of any protected characteristic.
- Use the Services to communicate with minors in any context where such communication is restricted or prohibited by law.
2.3 Misrepresentation and impersonation
- Use the Services to impersonate any individual, organization, or governmental authority without lawful authorization or, where required, the express written consent of the person being impersonated.
- Use the Services to generate synthesized or cloned voices that mimic real individuals without proper authorization.
- Misrepresent the AI-assisted nature of communications where disclosure is required by law (including under FCC rules regarding AI-generated voice communications).
2.4 High-risk applications
- Use the Services in connection with any High-Risk Activity, including emergency response, life-support systems, medical diagnosis or treatment decisions, or any application where failure of the Services could reasonably be expected to result in death, personal injury, financial loss to a third party, or environmental damage.
- Use the Services as a substitute for professional medical, legal, or financial judgment.
- Direct the Services to provide medical advice, diagnosis, or treatment recommendations to patients.
2.5 Technical restrictions
- Reverse engineer, decompile, disassemble, or attempt to derive the source code of the Services.
- Copy, modify, or create derivative works of the Services or any HANA Technology, except as expressly permitted by the Agreement.
- Conduct security testing, penetration testing, vulnerability scanning, load testing, or benchmarking of the Services without HANA's prior written consent.
- Interfere with the operation of, cause performance degradation of, or impose an unreasonable load on the Services.
- Attempt to gain unauthorized access to the Services, accounts, or systems other than those for which Customer has been granted access.
- Use any other person's account credentials or share Customer's credentials with unauthorized third parties.
- Submit malicious code, viruses, worms, or content that infringes any third party's rights to or through the Services.
2.6 Competitive use
- Use the Services to develop, train, fine-tune, validate, or improve any artificial intelligence or machine-learning model that competes with the Services or any HANA Technology.
- Use Outputs of the Services to compile a database for the purpose of competing with or replacing the Services.
2.7 Resale and sublicensing
- Resell, sublicense, lease, distribute, or otherwise make the Services available to any third party without HANA's prior written consent, except for use by Customer's authorized Users in accordance with the Agreement.
3. Customer obligations specific to voice AI
Customer acknowledges that the Services include AI-generated voice communications and assumes the following responsibilities:
3.1 Patient consent
- Obtain and maintain all consents, authorizations, and approvals required by law for HANA to make and receive calls or send messages on Customer's behalf, including any consents required for AI-generated voice communications under the TCPA and FCC rules.
- Maintain auditable records of such consents and provide them to HANA upon reasonable request.
3.2 Disclosure
- Ensure that the AI-assisted nature of communications is disclosed to recipients where required by law.
- Ensure that all call scripts, prompts, and knowledge base content used with the Services accurately represent Customer and the nature of the communications.
3.3 Human oversight
- Maintain appropriate human oversight of Outputs generated by the Services before acting upon or communicating any Output to any patient or third party.
- Direct callers with emergency or urgent medical needs to appropriate emergency services.
3.4 Do-not-call compliance
- Maintain and honor internal and national do-not-call lists, opt-out preferences, and applicable calling-time restrictions.
4. Healthcare and PHI
When the Services process Protected Health Information (PHI), Customer must comply with HIPAA, the Business Associate Agreement (BAA) executed between the parties, and all applicable state medical privacy laws. Customer must not transmit PHI to the Services through any channel not authorized by the Agreement and the BAA.
5. Reporting violations
If Customer becomes aware of any actual or suspected violation of this AUP, Customer must promptly notify HANA in writing at abuse@hana.health. Reports should include sufficient detail for HANA to investigate.
6. Enforcement
HANA may, in its sole discretion and consistent with the Agreement:
- Investigate any actual or suspected violation of this AUP
- Suspend or restrict access to the Services
- Remove or refuse to process content or communications
- Cooperate with law enforcement and regulatory authorities
- Terminate the Agreement for material breach
HANA will use commercially reasonable efforts to provide notice of suspension or restriction where practicable, except where immediate action is required to protect HANA, the Services, or third parties.
7. Modifications
HANA may update this AUP from time to time to reflect changes in applicable law, the Services, or operational requirements. Material changes will be posted at hana.health/aup with reasonable advance notice (typically thirty (30) days), except where shorter notice is necessary to address a security, legal, or regulatory issue.
8. Contact
Questions regarding this AUP can be directed to:
This AUP is incorporated by reference into the HANA Master Services Agreement and the Order Form executed between HANA Health, Inc. and Customer. In the event of conflict, the Agreement governs.
