1. Introduction
PatientArc is built for dental front-office operations, where reliability, patient trust, and data integrity matter. This Acceptable Use Policy (the "AUP") describes uses of PatientArc that are not allowed. It applies to every practice, user, and integration that accesses the service.
PatientArc, Inc. may update this AUP from time to time. Continued use of PatientArc after an update constitutes acceptance of the revised policy.
2. No illegal activity
Do not use PatientArc to:
- violate any applicable law, regulation, or court order;
- infringe intellectual property, privacy, publicity, or contractual rights;
- facilitate fraud, deceptive billing, or misrepresentation of treatment, coverage, or claim status;
- engage in money laundering, sanctions evasion, or other unlawful financial activity.
3. No spam or abusive messaging
Patient and operational messaging through PatientArc must be lawful and respectful. Do not:
- send unsolicited bulk messages, marketing without consent, or any message that violates anti-spam, anti-robocall, or telecommunications laws;
- send messages to recipients who have opted out or who have not provided a valid contact relationship with the practice;
- use PatientArc to harass, threaten, intimidate, or repeatedly contact a recipient who has asked the practice to stop;
- send misleading subject lines, deceptive sender names, or content designed to trick recipients about clinical or financial outcomes.
4. No unauthorized patient data access
Patient data inside PatientArc is sensitive. You must not:
- access patient records that you are not authorized by the practice to view;
- export, copy, or share patient data outside the workflows the practice has authorized;
- use patient information for purposes unrelated to delivering care or operating the practice (for example, marketing to a patient on behalf of an unrelated business);
- combine patient data from one practice with another practice's data without proper authorization.
5. No scraping or credential abuse
Do not:
- scrape, crawl, harvest, or use automated tools to extract data from PatientArc beyond the documented APIs and product features;
- share, sell, or rent account credentials, or use credentials that were not issued to you;
- maintain more accounts than the practice's plan permits, or create accounts under false identities;
- use shared service accounts to obscure individual user activity that should be auditable.
6. No unauthorized security testing
Do not perform security testing, vulnerability scanning, penetration testing, fuzzing, or load testing against PatientArc without prior written permission from PatientArc, Inc.. Coordinated, good-faith vulnerability reports are welcome at security@patientarc.site.
7. No malware or harmful code
Do not upload, transmit, or distribute malware, ransomware, viruses, worms, trojans, keyloggers, or any code intended to damage, disable, overburden, or impair PatientArc, its infrastructure, or any user's systems.
8. No harassment or discrimination
Do not use PatientArc to:
- harass, threaten, intimidate, or stalk patients, staff, or other individuals;
- discriminate against patients or staff based on race, color, religion, national origin, sex, gender identity, sexual orientation, age, disability, or any other protected characteristic;
- generate or send content that is defamatory, hateful, or designed to incite violence.
9. No harmful AI use
AI features in PatientArc are intended to assist staff with administrative drafting, summarization, and prioritization. Do not use AI features to:
- generate or imply clinical diagnoses, treatment decisions, or prescriptions;
- generate guarantees of insurance coverage, eligibility outcomes, or claim payment that have not been verified by qualified staff;
- generate deceptive, manipulative, or coercive patient communications;
- generate content that impersonates a clinician, patient, payer, or regulator;
- bypass review steps that the workflow requires before a patient-facing message is sent.
10. No impersonation
Do not impersonate another person, practice, payer, vendor, or PatientArc itself. Do not misrepresent your role, your authority, or the source of communications sent through PatientArc.
11. No content without rights
Only upload content you have the right to upload. The practice is responsible for ensuring it has the necessary rights, permissions, and patient consents to enter, import, store, or transmit content through PatientArc, including any patient or third-party data.
12. No evasion of controls
Do not:
- circumvent, disable, or interfere with rate limits, authentication, authorization, audit logging, or other security or operational controls;
- probe or test the resilience of PatientArc or its providers without authorization;
- misrepresent traffic origin, headers, or identity to evade abuse controls.
13. Enforcement and suspension
PatientArc, Inc. may investigate suspected violations of this AUP. Depending on severity and context, PatientArc may:
- contact the practice or user to request remediation;
- throttle, restrict, or temporarily suspend the affected feature, user, or workspace;
- suspend or terminate the account in line with the Terms of Service;
- preserve and disclose information as required by law or to protect the safety, rights, or property of PatientArc, its customers, or the public.
Where reasonable and consistent with security obligations, PatientArc will notify the account owner of enforcement actions affecting their workspace.
14. Reporting abuse
Report suspected abuse, security issues, or AUP violations on the appropriate channel below. Please include enough detail to investigate (URLs, timestamps, account or workspace identifiers where known) without sharing more sensitive information than necessary.
Security and abuse reports
security@patientarc.siteLegal escalations
legal@patientarc.siteAccount or product issues
support@patientarc.site
Operated by PatientArc, Inc..
Contact