NewMissing Records Detection: flags every visit, provider, and date missing from the file. See how →
HomeLegal CenterMaster Service Agreement
Legal · Document 07

Master Service Agreement

The signed framework agreement between AI Health Studio LLC d/b/a Medrecords AI and its AI Enablement and Enterprise On-Prem customers. Every Order Form incorporates this MSA by reference, so the legal terms are negotiated once and each new deal or renewal only has to settle the commercial specifics.

Effective: August 28, 2026 Version 1.0
The short version: a summary, not a substitute
  • This MSA governs AI Enablement and Enterprise On-Prem customers who execute a signed Order Form. Self-Service and Test a File customers stay under the Terms of Service instead.
  • Fees, term length, renewal, and support tier are set in your Order Form, not here — this agreement is the reusable legal framework every Order Form plugs into.
  • The BAA and DPA still control for PHI and personal data, with the same never-train commitment as every other plan.
  • Verification duties, IP ownership, indemnification, and the liability cap are the same standard as the Terms of Service — one set of terms, not two.
  • Unlike the click-through Terms, this is a signed contract: it can only be amended in writing, by both parties.

01Agreement & applicability

This Master Service Agreement (this "MSA" or this "Agreement") is entered into by AI Health Studio LLC, a Wyoming limited liability company doing business as Medrecords AI ("Medrecords AI," "we," "us," or "our"), and the organization identified as customer in an Order Form that references this MSA ("Customer," "you," or "your"). It governs Customer's purchase and use of AI Enablement and Enterprise On-Prem — the Medrecords AI medical-evidence platform at workspace.medrecords.ai, its modules, the Connect API, and related support (the "Services").

This MSA applies only where Customer has executed an Order Form referencing it. Self-Service and Test a File use are governed instead by our Terms of Service; if Customer also uses Self-Service under the same account, the Terms of Service govern that separate usage. Customer accepts this MSA by countersigning an Order Form that references it, or by the execution method in Section 21. The individual signing does so on behalf of Customer and represents that they have authority to bind it.

This MSA incorporates by reference our Privacy Notice, Cookie Policy, Data Processing Addendum ("DPA"), and, where Customer processes protected health information, a Business Associate Agreement ("BAA"). Order of precedence is set out in Section 02.

02Order Forms & order of precedence

2.1 What an Order Form is. An "Order Form" is the deal-specific document that references this MSA and states Customer's name, the deployment plan (AI Enablement or Enterprise On-Prem), effective and term dates, fees and payment schedule, implementation services, and support tier, together with any additional terms specific to that deal. This MSA carries the standing legal terms so that Order Forms stay short; a renewal or expansion Order Form does not require re-signing this MSA, and multiple Order Forms may reference the same MSA.

2.2 Order of precedence. Where a conflict exists among the documents governing Customer's use of the Services, the order of precedence is: (1) the BAA as to PHI, (2) the DPA as to personal data, (3) the applicable Order Form, (4) this MSA, (5) the Terms of Service, to the extent Customer also uses Self-Service under the same account. This mirrors the precedence stated in the Terms of Service and does not change it.

03Services & deployment models

3.1 What the Platform does. The Platform ingests medical records in any format — multi-page PDFs, scans, handwritten notes, and DICOM imaging studies — and produces structured, source-cited work product through its modules: Medical Records OCR, Medical Imaging Review (see Section 09), Medical Chronology, Medical Record Q&A, Verifiable AI Citations, Medical Summary Reports, and Case Outcome Benchmarks (informational ranges — see Section 08.4).

3.2 Deployment models. Under AI Enablement, AI inference runs inside Customer's own AWS or Azure tenancy, under Customer's keys and cloud agreements. Under Enterprise On-Prem, the Platform is deployed in infrastructure Customer controls. Typical implementation timelines and scope are described in the Order Form. Plan-specific data-handling terms are set out in Annex 3 of the DPA; if a description here conflicts with the DPA, the DPA controls.

3.3 What Customer doesn't get. The Services are provided as online or on-premises software services; Customer will not receive a copy of, or access to, the underlying source code except as an Enterprise On-Prem Order Form expressly grants for delivered components. Templates, documentation, and sample content we provide ("Medrecords AI Content") are part of the Services. All rights not expressly granted are reserved.

04Accounts, users & security

4.1 Registration and users. Customer must register with accurate information and keep it current. Access is limited to individuals Customer authorizes ("Users"), for Customer's own internal business purposes. Customer is responsible for its Users' compliance with this Agreement and for all activity under its accounts, except activity caused by a third party exploiting a vulnerability in the Services themselves.

4.2 Permissions are Customer's to manage. The Platform enforces case-level, minimum-necessary access: each User sees only the cases assigned to them. Customer is solely responsible for setting and managing those assignments and role permissions. We have no liability for permissions Customer or its Users configure.

4.3 Credentials. Customer is responsible for safeguarding credentials, multi-factor authentication devices, recovery codes, and API tokens. Notify [email protected] immediately of any suspected unauthorized access or security breach.

4.4 Audit logging. The Platform maintains an audit log of access to case content, including PHI access events. These logs exist for Customer's compliance and ours; they are retained as described in the DPA and are exportable by Customer's administrators in-product.

05Fees, payment & taxes

5.1 Fees. Fees, implementation services, support tiers, and any volume pricing are stated in the applicable Order Form, not in this MSA. Order Form payment obligations are non-cancelable and non-refundable except as the Order Form or this Agreement expressly states.

5.2 Payment. We invoice fees as the Order Form specifies. Where authorized, recurring or metered charges bill automatically until Customer's account is closed at the end of the applicable term. We may correct billing errors even after payment is requested or received.

5.3 Taxes. Fees exclude taxes, levies, and duties ("Taxes"). Customer is responsible for all Taxes on its purchases; we are responsible for taxes on our income, property, and employees. If we must collect Taxes Customer owes, we will invoice for them.

5.4 Billing disputes; failure to pay. If Customer believes it was billed incorrectly, contact [email protected] within 60 (60) days of the invoice containing the error to receive an adjustment. If fees are past due, we may, after notice, suspend access pending payment; correctly billed amounts confirmed after review are due within 10 (10) days of notice.

06PHI, HIPAA & the BAA

6.1 Roles. The records Customer processes may contain protected health information ("PHI") under HIPAA, or medical information protected by state law even where HIPAA does not apply to Customer. Our HIPAA & BAA page explains how the roles map to each customer type.

6.2 BAA required before PHI. Where we create, receive, maintain, or transmit PHI on Customer's behalf, a BAA must be in place first. Enterprise customers typically execute a negotiated BAA alongside this MSA. Uploading PHI without an executed BAA is a material breach of this Agreement. Where Customer is not a HIPAA-regulated entity, the BAA's safeguards still apply contractually to the medical records it processes.

6.3 Plan differences. Under AI Enablement, inference runs in Customer's cloud tenancy under Customer's provider agreements; under Enterprise On-Prem, records stay in infrastructure Customer controls. In both plans our business-associate role is limited to the functions we actually perform (e.g., support access Customer grants), as detailed in the BAA and DPA Annex 3.

6.4 Customer's responsibilities. Customer is responsible for obtaining all authorizations, consents, court orders, or other legal bases required to collect and submit the records it processes; honoring restrictions attached to them; configuring Platform access controls appropriately; and training its workforce. We are responsible for the safeguards and obligations stated in the BAA and DPA.

07Customer Content & the never-train promise

7.1 Customer Content. "Customer Content" means everything Customer or its Users upload or submit — medical records, DICOM studies, claims files, annotations, templates, letterhead — and the outputs generated from it (chronologies, summaries, answers, reports). Customer retains all right, title, and interest in Customer Content. Customer grants us and our subprocessors a non-exclusive, worldwide, royalty-free license to host, process, transmit, and display Customer Content solely to provide the Services, to comply with law, and as Customer otherwise directs. Customer represents it has all rights necessary to grant this license.

7.2 The never-train commitment

We will not use Customer Content (including de-identified, anonymized, or aggregated derivatives of it) to train, fine-tune, or improve any artificial-intelligence or machine-learning model, whether ours or a third party's. Every AI vendor in our processing path is bound in writing to the same restriction and to zero-retention inference. This commitment survives termination and appears again, contractually, in the DPA and BAA.

7.3 Service Data. "Service Data" means operational telemetry about use of the Services — feature usage, page counts, token metering, performance, and error data — that does not include Customer Content and is not derived from the substance of any medical record. We own Service Data and may use it in aggregated or de-identified form to operate, secure, bill for, and improve the Services.

7.4 Retention, export, deletion. Customer can export Customer Content at any time during the term. Retention schedules, deletion on case closure or termination, deletion certificates, and backup-purge timing are specified in the DPA.

08AI output & your duty to verify

8.1 Drafts, by design. The Platform uses large language models, vision models, and other AI systems. All generated output — chronologies, summaries, extracted values, Q&A answers, benchmark ranges, report drafts — is a preliminary draft for review by a qualified professional. AI systems can produce inaccurate, incomplete, or fabricated statements; OCR of degraded scans and handwriting can misread; imaging-derived events can be mis-dated or mis-attributed.

8.2 Citations are for verification — use them. Verifiable AI Citations links each generated statement to the source page or DICOM image it came from, and uncertainty scoring flags low-confidence readings instead of hiding them. These features exist so verification is fast — they are not a substitute for it. Before any output is filed with a court, served on a party, submitted to a regulator, used in a claim determination or reserve decision, incorporated into an IME/QME opinion, or otherwise relied on, a licensed or qualified professional on Customer's side must verify it against the source record.

8.3 Not professional advice. We are a technology company. The Services do not constitute, and are not a substitute for, the practice of law or medicine or the provision of legal, medical, actuarial, or claims-adjusting advice. Using the Platform does not create an attorney-client, physician-patient, or fiduciary relationship with us. Customer remains solely responsible for professional decisions.

8.4 Case Outcome Benchmarks. Benchmark ranges are statistical information drawn from comparable resolved matters and the drivers cited in Customer's record. They are not a valuation, settlement recommendation, reserve figure, or prediction of any outcome, and must not be presented to a client, insured, claimant, court, or regulator as ours.

09Not a medical device; no clinical use

Medical Imaging Review (including DICOM ingestion, the integrated PACS-style viewer, 3D reconstruction, and imaging events placed on the chronology) is provided solely for record-review, claims, and medico-legal purposes: understanding, organizing, and cross-referencing imaging that already exists in a file.

The Services are not a medical device, are not cleared or approved by the U.S. Food and Drug Administration, and must not be used for primary diagnostic reading, diagnosis, treatment planning, patient monitoring, or any other clinical purpose. Rendered reconstructions are visualization aids and may not be diagnostic-quality. If a clinical question arises from anything seen in the Services, refer it to a qualified physician working from the original imaging.

10Acceptable use

Customer will not, and will not permit any User or third party to, directly or indirectly:

  • upload records it has no lawful basis to hold or process, or use the Services to stalk, harass, or profile any individual;
  • use the Services for clinical care (Section 09) or to provide legal or medical advice to the public without professional involvement;
  • copy, modify, translate, or create derivative works of the Services; reverse engineer, decompile, or attempt to discover source code, non-public APIs, models, prompts, or underlying algorithms (except to the extent this restriction is prohibited by law);
  • sell, resell, rent, lease, sublicense, time-share, or otherwise make the Services available to any third party, except as expressly permitted in an Order Form;
  • use the Services to build, train, benchmark, or support a competing product, or publish benchmarks of the Services without our prior written consent;
  • circumvent license validation, rate limits, or any security or access control; probe, scan, or test the vulnerability of any Medrecords AI system except under a written security-testing agreement;
  • introduce malware or interfere with the integrity or performance of the Services;
  • remove or obscure proprietary notices, or use our marks except as permitted in writing.

If use of the Services (including by Customer's Users) threatens the security, integrity, or availability of the Services or other customers' data, we may suspend access. We will use commercially reasonable efforts to give notice and an opportunity to cure first, to limit any suspension to the accounts involved, and to lift it promptly once resolved.

11Connect API & integrations

11.1 Connect API. The Connect API (case create/update, file upload, template context, webhooks) is part of the Services. We may set and enforce rate and usage limits, version and deprecate endpoints with reasonable notice, and suspend API access that threatens platform stability. API credentials and Case Access Tokens are Customer's Confidential Information to protect.

11.2 Third-party applications. If Customer connects a case-management, claims, or other third-party system, it is responsible for that system's security and for its agreements with its provider. We do not endorse and are not responsible for third-party applications; webhook payloads delivered to endpoints Customer configures are Customer's responsibility once delivered.

12Intellectual property

12.1 Ours. Medrecords AI and its licensors own the Services, the underlying software, models, prompts, interfaces, documentation, Medrecords AI Content, and all related intellectual-property rights, including improvements and derivatives. No implied licenses.

12.2 Customer's. As between the parties, Customer owns Customer Content — including the generated chronologies, summaries, and reports produced for it, which for law-firm customers typically constitute attorney work product. To the extent we hold any right in generated output, we assign it to Customer upon creation, subject to our ownership of the Services and of any Medrecords AI Content embedded in templates.

12.3 Feedback. If Customer sends suggestions or feedback, we may use them without restriction or obligation, provided we do not identify Customer as the source without consent and never use Customer Content as "feedback."

13Confidentiality

Each party may receive non-public information of the other ("Confidential Information"). Ours includes non-public features, security documentation, pricing, and the terms of any Order Form; Customer's includes all Customer Content. Each party will protect the other's Confidential Information with at least reasonable care, use it only to perform under this Agreement, and limit access to those with a need to know who are bound by obligations at least as protective. Exclusions: information that is or becomes public without breach, was already known without restriction, is received lawfully from a third party, or is independently developed.

If disclosure is compelled by law, subpoena, or court order, the receiving party will (where legally permitted) give prompt notice and reasonable assistance to contest or narrow the demand. Given the nature of medical-legal records, we treat litigation-hold and protective-order constraints Customer communicates to us as instructions under the DPA.

14Disclaimers of warranties

EXCEPT AS EXPRESSLY PROVIDED IN THIS AGREEMENT, AN ORDER FORM, THE BAA, OR THE DPA, THE SERVICES, MEDRECORDS AI CONTENT, AND ALL RELATED COMPONENTS AND INFORMATION ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS, AND MEDRECORDS AI EXPRESSLY DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, TITLE, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WITHOUT LIMITING THE FOREGOING, MEDRECORDS AI DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR-FREE; THAT ANY OUTPUT WILL BE ACCURATE, COMPLETE, OR RELIABLE WITHOUT THE PROFESSIONAL VERIFICATION REQUIRED BY SECTION 08; OR THAT THE SERVICES SATISFY CUSTOMER'S REGULATORY OBLIGATIONS. DETERMINING SUITABILITY FOR CUSTOMER'S MATTERS REMAINS CUSTOMER'S RESPONSIBILITY.

SOME JURISDICTIONS DO NOT ALLOW CERTAIN WARRANTY DISCLAIMERS, SO PORTIONS OF THE FOREGOING MAY NOT APPLY TO CUSTOMER. OUR SECURITY, PRIVACY, AND NEVER-TRAIN COMMITMENTS IN SECTION 07, THE DPA, AND THE BAA ARE UNAFFECTED BY THIS SECTION.

15Indemnification

15.1 By Customer. Customer will defend, indemnify, and hold harmless Medrecords AI and its officers, members, employees, and agents from third-party claims and resulting damages, costs, and reasonable attorneys' fees arising out of: (a) Customer Content, including any claim that Customer lacked the rights, authorizations, or consents to submit it; (b) Customer's or its Users' violation of law or of Sections 06, 08, 09, or 10; or (c) professional decisions made, filings served, determinations issued, or opinions rendered in reliance on output that was not verified as Section 08 requires.

15.2 By us. We will defend, indemnify, and hold Customer harmless from third-party claims that the Services, as provided by us and used per this Agreement, infringe a U.S. patent, copyright, or trademark, or misappropriate a trade secret — excluding claims arising from Customer's modifications, from combination with items not provided by us, or from use in violation of this Agreement. If the Services are enjoined, we may procure the right to continue, replace or modify them to be non-infringing, or terminate the affected Services and refund prepaid, unused fees. This Section 15.2 states our entire liability for IP infringement.

15.3 Procedure. The indemnified party must give prompt notice, reasonable cooperation, and sole control of defense and settlement to the indemnifying party; no settlement imposing obligations on the indemnified party without its consent.

16Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUES, DATA, OR GOODWILL, EVEN IF ADVISED OF THE POSSIBILITY AND REGARDLESS OF THE THEORY OF LIABILITY.

EACH PARTY'S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT (INCLUDING THE APPLICABLE ORDER FORM, THE DPA, AND THE BAA, AND ACROSS ALL CLAIMS, INCIDENTS, AND CAUSES OF ACTION COMBINED) WILL NOT EXCEED, IN THE AGGREGATE, THE FEES ACTUALLY PAID BY CUSTOMER FOR THE SERVICES IN THE 12 (12) MONTHS PRECEDING THE FIRST EVENT GIVING RISE TO LIABILITY. THIS IS A SINGLE, NON-REPLENISHING AGGREGATE CAP — NOT A CAP PER INCIDENT OR PER CLAIM.

SECURITY INCIDENTS. A SECURITY INCIDENT (AS DEFINED IN THE DPA) IS NOT, BY ITSELF, A BREACH OF THIS AGREEMENT. MEDRECORDS AI IS LIABLE IN CONNECTION WITH A SECURITY INCIDENT ONLY TO THE EXTENT THE INCIDENT RESULTED FROM ITS MATERIAL FAILURE TO MAINTAIN THE SAFEGUARDS IN DPA ANNEX 2, AND IN NO EVENT FOR INCIDENTS ARISING FROM (A) CUSTOMER OR USER CREDENTIALS, PERMISSIONS, OR CONFIGURATIONS; (B) CUSTOMER SYSTEMS, CRM CONNECTIONS, OR WEBHOOK ENDPOINTS CUSTOMER CONFIGURES; (C) DATA AFTER CUSTOMER EXPORTS IT OUT OF THE SERVICES; OR (D) INFRASTRUCTURE CUSTOMER CONTROLS UNDER AI ENABLEMENT OR ENTERPRISE ON-PREM. THE NOTIFICATION, MITIGATION, AND COOPERATION DUTIES IN THE DPA AND BAA ARE CUSTOMER'S EXCLUSIVE NON-MONETARY REMEDIES FOR A SECURITY INCIDENT, AND EACH PARTY BEARS THE COSTS OF ITS OWN LEGAL OBLIGATIONS ARISING FROM ONE; ANY MONETARY LIABILITY REMAINS SUBJECT TO THE AGGREGATE CAP AND EXCLUSIONS ABOVE.

NOTHING IN THIS SECTION LIMITS LIABILITY FOR A PARTY'S FRAUD OR WILLFUL MISCONDUCT, CUSTOMER'S PAYMENT OBLIGATIONS, OR LIABILITY THAT CANNOT BE LIMITED BY LAW. THESE LIMITS ARE AN ESSENTIAL PART OF THE BARGAIN AND APPLY EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.

17Term, suspension & termination

17.1 Term. Each Order Form states its own term and renewal. This MSA takes effect on execution and remains in effect for as long as at least one Order Form referencing it is active, and continues to govern any surviving obligations after all Order Forms under it have ended.

17.2 Termination for cause. Either party may terminate the applicable Order Form on written notice if the other materially breaches this Agreement and fails to cure within 30 (30) days of notice. We may suspend or terminate immediately for breaches of Section 06.2 (PHI without a BAA), Section 10 (acceptable use), or non-payment after notice, or where required by law.

17.3 Effect of termination. If Customer terminates for our uncured breach, we will refund prepaid fees for the unused portion of the then-current term. If we terminate for Customer's uncured breach, unpaid fees for the remainder of the then-current term become due. Upon termination of an Order Form, Customer's license under it ends; for 30 (30) days Customer retains export-only access to retrieve Customer Content, after which we delete Customer Content per the DPA's disposal terms (including from backups) and provide a deletion certificate on request. PHI handling on termination follows the BAA.

17.4 Survival. Sections 5 (as to accrued fees), 7.2, 8, 9, 12, 13, 14, 15, 16, 17.3, 19, and 20 survive termination.

18Changes to this MSA

Unlike the click-through Terms of Service, this MSA is a signed contract and is not amended by posting a new version to this page. It may be amended only by a written amendment signed by both parties, or by a superseding Order Form that expressly states it modifies this MSA.

The Services are online or on-premises software and evolve over time; we will not materially decrease core functionality of a deployed plan during a paid term. Operational changes to the Services described in Section 03 do not, by themselves, amend this MSA. Changes to the Subprocessor List follow the separate notice-and-objection mechanism in the DPA.

19Governing law & venue

This Agreement and any dispute arising out of or related to it are governed by the internal laws of the State of Wyoming, without regard to conflicts-of-law rules. The state and federal courts located in Sheridan, Wyoming have exclusive jurisdiction, and each party consents to personal jurisdiction and venue there. Each party waives any right to a jury trial in any action arising out of or related to this Agreement.

Before filing suit (other than for injunctive relief or to protect intellectual property or Confidential Information), the parties will attempt in good faith to resolve any dispute through executive-level discussion for 30 (30) days after written notice. In any action to enforce this Agreement, the prevailing party is entitled to recover its reasonable attorneys' fees and costs.

Individual claims; time limit. To the fullest extent permitted by law, claims may be brought only in a party's individual capacity — not as a plaintiff or member of any class, consolidated, or representative proceeding — and any claim arising out of or related to this Agreement (other than a claim for unpaid fees) must be commenced within one (1) year after the cause of action accrues, or it is permanently barred.

20General provisions

20.1 Mutual authority. Each party represents that it has the full right, power, and authority to enter into this Agreement and, for the individual signing on its behalf, that the individual is authorized to bind that party.

20.2 Publicity. We will identify Customer by name or logo as a customer only with its prior written consent. Given the sensitivity of medical-legal work, we default to archetype descriptions (e.g., "a national IME firm") unless Customer approves attribution.

20.3 Notices. We may give service notices by email to Customer's account address or in-product; notices are deemed effective the next business day. Legal notices to us go to [email protected] and by mail to AI Health Studio LLC, 30 North Gould Street, Sheridan, Wyoming 82801, USA.

20.4 Assignment. Neither party may assign this Agreement without the other's prior written consent (not to be unreasonably withheld), except either party may assign it in connection with a merger, acquisition, reorganization, or sale of substantially all assets; any assignee of ours must assume the BAA, DPA, and Section 7.2 in full. Purported assignments in violation of this section are void.

20.5 Force majeure. Neither party is liable for delay or failure (other than payment obligations) caused by events beyond its reasonable control (natural disasters, acts of government, epidemics, war, terrorism, labor disputes, internet or power failures), provided it resumes performance promptly.

20.6 Relationship; no third-party beneficiaries. The parties are independent contractors; nothing creates a partnership, agency, fiduciary, or employment relationship. There are no third-party beneficiaries, except that individuals' rights under HIPAA are addressed exclusively through the BAA and applicable law.

20.7 Severability; waiver; entire agreement. If any provision is held unenforceable, the remainder stays in effect and the provision is enforced to the maximum extent permitted. Waivers must be in writing and signed. This Agreement, together with all Order Forms referencing it, the BAA, the DPA, and the policies it references, is the entire agreement between the parties regarding the Services and supersedes all prior agreements and representations concerning its subject matter.

21Contact, legal entity & execution

This Master Service Agreement is entered into between AI Health Studio LLC d/b/a Medrecords AI and the Customer identified in the applicable Order Form, effective as of that Order Form's effective date. It is executed by countersignature of an Order Form that references this MSA, or by another written execution method the parties agree to (including electronic signature). To request a countersigned copy for your records, contact [email protected].

Legal entity
AI Health Studio LLC
d/b/a Medrecords AI
30 North Gould Street
Sheridan, Wyoming 82801
United States of America
Contact
Legal notices: [email protected]
Privacy: [email protected]
Security: [email protected]
Billing: [email protected]