Acceptable Use Policy
Last updated: August 5, 2026
1. Purpose and Scope
This Acceptable Use Policy ("AUP") governs use of the Living Patterns Readings Workflow Software platform and related services (the "Platform") by clinic owners, practitioners, and other authorized workforce members (each a "User," and together with the subscribing clinic, "you").
This AUP supplements the Terms of Service, Privacy Policy, and Business Associate Agreement. Capitalized terms not defined here have the meanings in the Terms of Service or the HIPAA Rules, as applicable. Violations of this AUP are violations of the Terms of Service and may result in suspension or termination of access.
This AUP was last updated on August 5, 2026 (version 2026-08-05.1).
2. Permitted Use
- Using the Platform solely for lawful clinical, administrative, and health care operations purposes related to patients and clinics you are authorized to treat, support, or administer.
- Accessing PHI only on a minimum-necessary basis for treatment, payment, or health care operations, or as otherwise permitted by law and applicable patient authorization.
- Maintaining unique credentials; enabling and maintaining multi-factor authentication as required for practitioner PHI access; locking unattended devices; and safeguarding endpoints used to access PHI.
- Using documented export, Secure Patient Link, secure patient–practitioner messaging, and (where enabled for the clinic account) invitation or collaboration features only within the scope of your clinic role and authorization.
- Sending Secure Patient Links only to the intended patient or that patient's legally authorized personal representative, and not republishing or broadly distributing patient access links.
- Using in-app secure messaging for care-related Q&A when the feature is available rather than pasting message PHI into personal email, SMS, or other unsecured channels.
- Promptly reporting suspected security incidents, lost devices containing PHI access, or unauthorized access to Living Patterns Readings and your clinic administrator.
3. Prohibited Conduct
You shall not, and shall not permit others to:
- Access, view, download, or disclose patient records without a legitimate treatment, payment, health care operations, or other legally authorized purpose.
- Share workforce login credentials, allow another person to use your account, or use another person's account.
- Circumvent, disable, or interfere with access controls, Secure Patient Link identity checks, audit logging, encryption, multi-factor authentication, or other security features.
- Create, share, or use Secure Patient Links for persons who are not the clinic's patients (or their legally authorized representatives), or use link access to obtain information outside the scoped task.
- Scrape, crawl, bulk-export, probe, penetration-test, or reverse engineer the Platform except (a) through documented export features you are authorized to use, or (b) with LPR's prior written authorization for security research.
- Upload, transmit, or store malware, ransomware, spyware, or any unlawful, harassing, defamatory, or infringing content.
- Upload data unrelated to permitted clinic use, or use the Platform as a general-purpose file host or email system for non-clinic purposes.
- Use the Platform in violation of HIPAA, HITECH, the California Confidentiality of Medical Information Act (CMIA) or other state privacy laws, professional licensing or advertising rules, consumer-protection laws, or U.S. export control or sanctions laws.
- Misrepresent your identity, licensure, credentials, specialty, or authority to bind your clinic or to treat patients.
- Interfere with Platform integrity, availability, performance, or other customers' use, including denial-of-service activity.
- Resell, sublicense, white-label, or provide the Platform to third parties as a service bureau except as expressly permitted in writing by LPR.
- Use the Platform to send unsolicited bulk communications unrelated to clinic operations, or to violate anti-spam laws.
- Attempt to access another clinic's data or any system, account, or network without authorization.
4. Credentials, Devices, and Workforce Duties
- Each User must use an individual account. Shared or generic logins are prohibited.
- Users must notify the clinic owner or administrator and LPR promptly of suspected credential compromise.
- Clinic owners are responsible for timely deprovisioning of departing workforce members where team features are used.
- Users must not store PHI on unencrypted removable media or personal cloud accounts except as directed by clinic policy and applicable law.
5. HIPAA and Professional Responsibilities
Users are responsible for complying with their clinic's policies, applicable professional standards, patient rights processes, documentation standards, and breach-notification duties as members of a Covered Entity's workforce (or as otherwise applicable). Living Patterns Readings' obligations as Business Associate are set forth in the BAA and do not relieve Users or clinics of Covered Entity or professional duties. Clinical judgment and patient care remain solely with licensed practitioners and their clinics. The Platform is not an electronic health record or charting system; Users remain responsible for maintaining clinical records as required by law and professional standards.
6. Content and Accuracy
Users are responsible for the accuracy and appropriateness of information they enter into the Platform, including assessments, notes, package and checklist selections, laboratory uploads, secure messages, and patient communications initiated through clinic workflows. LPR does not independently verify clinical content entered by Users.
7. Monitoring and Investigation
LPR may monitor Platform use for security, fraud prevention, abuse detection, service integrity, and legal compliance, including review of logs and automated signals. LPR may investigate suspected violations, preserve evidence, require remediation, suspend or terminate access, and cooperate with lawful process and, where required, licensing authorities.
8. Reporting Violations
Suspected violations of this AUP, security incidents, or unauthorized PHI access should be reported promptly to support@livingpatternsreadings.com and to your clinic administrator. Do not delay reporting while investigating internally if patient data may be at risk.
9. Enforcement
LPR may, without liability, warn, suspend, limit features, or terminate accounts or clinic access for violations of this AUP, the Terms of Service, or the BAA. Serious, willful, or repeated violations may result in permanent termination and referral to appropriate authorities or licensing boards where required by law. Enforcement actions do not waive LPR's other rights or remedies.
10. Changes
LPR may update this AUP from time to time. Material changes may require re-acceptance in-product. Continued use after the effective date constitutes acceptance of non-material updates. The version and last-updated date identify the operative text.