These Terms of Service (“Terms”) govern access to and use of the Aro platform, websites, applications, integrations, APIs, and related services collectively referred to as the “Service”. The Service is provided by Aro Medical, a United States company (“Aro”, “we”, “us”, or “our”).
These Terms apply to organizations and individuals who access or use the Service, including healthcare organizations, hospitals, clinics, medical practices, administrators, clinicians, medical coders, billing personnel, contractors, and authorized users (“Customer”, “you”, or “your”).
By accessing or using the Service, creating an account, or entering into an agreement that references these Terms, you agree to be bound by them. If you use the Service on behalf of an organization, you represent that you have the authority to bind that organization to these Terms. If you do not agree to these Terms, you may not access or use the Service.
1. The Aro service
Aro provides a software-as-a-service platform designed to process clinical documentation and generate suggested medical coding information, including potential CPT and ICD-10 codes. The Service may integrate with electronic medical record systems, healthcare information systems, third-party APIs, and other systems designated by the Customer. The Service may include:
- Receiving and processing clinical documents.
- Extracting and analyzing clinical information.
- Generating suggested medical codes.
- Transmitting results to authorized systems.
- Storing clinical documents and related processing records.
- Providing administrative, operational, monitoring, and reporting functionality.
- Providing related implementation, integration, and support services.
Available functionality may depend on the Customer’s subscription, configuration, integration, or separate agreement with Aro.
2. Eligibility and authorized use
The Service is intended for use by healthcare organizations and their authorized workforce members and contractors. You may use the Service only:
- For lawful healthcare and business operations.
- Within the scope of your professional role and authorization.
- In accordance with these Terms and any applicable order form, subscription agreement, Business Associate Agreement, or other written agreement with Aro.
- In compliance with applicable federal, state, and local laws and regulations.
The Service is not intended for direct use by patients or consumers unless expressly authorized by Aro in writing.
3. Medical coding recommendations
The Service generates suggested medical coding information based on clinical documentation and other information submitted by the Customer. Aro does not guarantee that any suggested CPT, ICD-10, HCPCS, or other code is:
- Complete.
- Accurate.
- Appropriate for a specific patient or encounter.
- Reimbursable.
- Compliant with payer requirements.
- Suitable for a particular claim or clinical context.
All coding results generated by the Service must be reviewed and validated by appropriately qualified and authorized personnel before being:
- Submitted to a payer.
- Incorporated into a medical record.
- Used for billing or reimbursement.
- Used for compliance or audit purposes.
- Relied upon for any clinical, financial, or legal decision.
The Customer remains solely responsible for:
- Final code selection.
- Claim submission.
- Documentation sufficiency.
- Billing accuracy.
- Reimbursement decisions.
- Compliance with coding guidelines, payer policies, contracts, and applicable laws.
The Service is a decision-support and workflow-automation tool. It does not replace professional medical coding judgment, clinical judgment, compliance review, or legal advice.
4. No medical advice
Aro does not provide medical advice, diagnosis, treatment, or patient care. The Service is not a substitute for the professional judgment of a physician, clinician, medical coder, compliance professional, billing specialist, or other qualified healthcare professional. The Customer and its authorized users remain solely responsible for all clinical and operational decisions, including decisions concerning:
- Diagnosis.
- Treatment.
- Clinical documentation.
- Medical coding.
- Billing.
- Patient care.
The Service must not be used as the sole basis for decisions that could affect patient health or safety.
5. Accounts and access credentials
Certain features of the Service require an account. You agree to:
- Provide accurate and complete account information.
- Maintain the confidentiality of usernames, passwords, API credentials, encryption keys, and authentication information.
- Restrict access to authorized personnel.
- Revoke access when a user is no longer authorized.
- Notify Aro promptly of suspected unauthorized access or credential compromise.
- Remain responsible for activities performed through your accounts and credentials.
You may not share credentials between users unless expressly permitted by the Service. Aro may suspend access when it reasonably believes that an account has been compromised, is being used unlawfully, or presents a security risk.
6. Customer responsibilities
The Customer is responsible for:
- Determining which users may access the Service.
- Configuring and maintaining its systems and integrations.
- Ensuring that submitted information is accurate and lawfully obtained.
- Obtaining all necessary patient consents, authorizations, notices, and permissions.
- Establishing an appropriate legal basis for transmitting data to Aro.
- Reviewing outputs generated by the Service.
- Maintaining appropriate clinical, coding, billing, privacy, and security procedures.
- Complying with applicable healthcare, privacy, billing, reimbursement, and professional regulations.
- Ensuring that use of the Service does not violate third-party rights or contractual obligations.
The Customer must not submit information to the Service unless it is authorized to collect, use, process, store, and disclose that information for the purposes contemplated by the Service.
7. Protected health information and HIPAA
To the extent that Aro creates, receives, maintains, or transmits Protected Health Information (“PHI”) on behalf of a Customer that is a covered entity or business associate under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”), the parties will enter into a separate Business Associate Agreement (“BAA”) where required. The BAA, if applicable, governs:
- Aro’s permitted uses and disclosures of PHI.
- The Customer’s responsibilities regarding PHI.
- Security incident and breach notification obligations.
- Data return, retention, and deletion requirements.
- Other obligations required by HIPAA.
If these Terms conflict with an applicable BAA concerning PHI, the BAA will control. The Customer may not use the Service to transmit PHI unless:
- Aro has expressly authorized that use.
- Any required BAA has been executed.
- The Customer uses an Aro-approved method or integration to transmit the PHI.
Aro may redact, transform, tokenize, encrypt, or otherwise process information to reduce the exposure of identifying information. Such processing does not necessarily mean that information satisfies a legal standard for de-identification unless expressly stated by Aro in writing.
8. Data processing and security
Aro may process and store:
- Clinical documents.
- Protected Health Information.
- Redacted or de-identified clinical information.
- Coding requests and coding results.
- Account and organization information.
- Integration metadata.
- Audit and operational records.
- Technical logs and diagnostic information.
Aro will maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Data against unauthorized access, use, alteration, loss, or disclosure. These safeguards may include:
- Encryption.
- Access controls.
- Credential management.
- Monitoring.
- Data minimization.
- Separation of identifying information from clinical content.
No system is completely secure. Aro does not guarantee that unauthorized access, security incidents, data loss, or service interruptions will never occur. The Customer is responsible for securing its own:
- Systems.
- Networks.
- Endpoints.
- Electronic medical record systems.
- Credentials.
- Integration configurations.
9. Customer data
“Customer Data” means information, documents, content, records, and other data submitted to or processed through the Service on behalf of the Customer. As between the parties, the Customer retains its rights in Customer Data. The Customer grants Aro a limited, non-exclusive right to host, receive, reproduce, transmit, transform, analyze, store, and otherwise process Customer Data as necessary to:
- Provide and maintain the Service.
- Perform requested integrations.
- Generate coding results.
- Provide support.
- Maintain security and reliability.
- Comply with legal obligations.
- Exercise rights expressly granted under these Terms or another written agreement.
Aro will not sell PHI. Aro may use aggregated or de-identified information that does not identify the Customer or any individual to:
- Operate the Service.
- Secure the Service.
- Analyze Service performance.
- Improve the Service.
Any such use will remain subject to applicable law and any applicable BAA or written agreement.
10. Artificial intelligence and automated processing
The Service may use:
- Machine learning.
- Artificial intelligence.
- Rules-based systems.
- Statistical methods.
- Third-party models.
- Combinations of these technologies.
Outputs produced through automated processing may be incomplete, incorrect, inconsistent, or inappropriate for a particular context. The Customer acknowledges that:
- Automated results require human review.
- Similar inputs may produce different results.
- Changes to models, prompts, rules, code sets, or configurations may affect results.
- The Service may not identify every relevant diagnosis, procedure, modifier, exclusion, or coding requirement.
- Outputs must not be treated as authoritative coding determinations.
The Customer must implement appropriate human oversight based on the nature and risk of its use of the Service.
11. Third-party services and integrations
The Service may interoperate with third-party products and services, including:
- Electronic medical record systems.
- Cloud infrastructure providers.
- Identity providers.
- Coding resources.
- APIs.
- Other software selected by the Customer.
Aro does not control third-party services and is not responsible for:
- Their availability, security, performance, or accuracy.
- Changes made by their providers.
- Data loss or corruption caused by them.
- Their terms, policies, fees, or licensing requirements.
- Failures resulting from the Customer’s configuration or use of those services.
The Customer is responsible for obtaining and maintaining all third-party accounts, licenses, permissions, and agreements required for its use of those services. Links to third-party websites or services are provided for convenience and do not constitute an endorsement by Aro.
12. Coding systems and third-party intellectual property
CPT, ICD-10, HCPCS, and other coding systems may be owned, maintained, licensed, or administered by third parties. The Customer is responsible for determining whether its use of any coding system, code description, data set, or related content requires a separate license. Nothing in these Terms grants the Customer ownership of, or rights to, third-party coding systems or proprietary materials beyond the rights expressly provided by the applicable owner or licensor. CPT is a registered trademark of the American Medical Association.
13. Acceptable use
You may not use the Service to:
- Violate any applicable law or regulation.
- Submit data that you are not authorized to process.
- Access another customer’s data or systems.
- Interfere with or disrupt the Service.
- Introduce malware, malicious code, or harmful content.
- Probe, scan, or test vulnerabilities without written authorization.
- Bypass access controls, usage limits, or security mechanisms.
- Reverse engineer or attempt to derive the source code of the Service, except where prohibited by law.
- Copy, resell, sublicense, or commercially exploit the Service except as expressly permitted.
- Use the Service to develop or train a competing product using Aro’s proprietary outputs, interfaces, or documentation.
- Impersonate another person or organization.
- Use the Service in a manner that creates an unreasonable risk to patients, healthcare operations, Aro, or third parties.
Aro may investigate suspected violations and suspend or terminate access when reasonably necessary to protect the Service, customers, patients, or third parties.
14. Intellectual property
The Service, including its software, workflows, interfaces, designs, documentation, models, configurations, features, functionality, and original content, is owned by Aro or its licensors. The Service is protected by applicable intellectual property laws. Except for the limited right to access and use the Service under these Terms, no rights are granted to the Customer. The Customer may provide suggestions, ideas, or feedback regarding the Service. The Customer grants Aro a perpetual, irrevocable, worldwide, royalty-free right to use that feedback without restriction or compensation, provided that Aro does not publicly identify the Customer without authorization.
15. Fees and payment
Fees, subscription terms, usage limits, payment schedules, and renewal terms may be specified in:
- An order form.
- A subscription agreement.
- A statement of work.
- Another written agreement.
Unless otherwise stated:
- Fees are non-refundable.
- Fees do not include applicable taxes.
- The Customer is responsible for applicable taxes other than taxes based on Aro’s net income.
- Overdue amounts may result in suspension of the Service.
If these Terms conflict with an executed order form regarding fees or commercial terms, the order form will control.
16. Service availability and changes
Aro may modify, update, improve, restrict, or discontinue features of the Service. Aro may perform scheduled or emergency maintenance that temporarily affects availability. Aro does not guarantee that the Service will be uninterrupted, error-free, or available at all times unless a separate written service-level agreement expressly provides otherwise. Aro may change:
- Models.
- Infrastructure.
- Integrations.
- Code sets.
- Processing rules.
- Third-party service providers.
Such changes may be made as necessary to maintain, secure, or improve the Service.
17. Suspension and termination
Aro may suspend or terminate access to the Service if:
- The Customer violates these Terms.
- Payment is overdue.
- Continued use presents a security, legal, compliance, or patient-safety risk.
- The Customer’s use threatens the availability or integrity of the Service.
- Aro is required to do so by law.
- An applicable subscription or agreement expires or is terminated.
The Customer may stop using the Service at any time, subject to applicable contractual commitments. Upon termination, the Customer’s right to access the Service will cease. Data return, retention, deletion, and transition assistance will be handled according to the applicable:
- Order form.
- Business Associate Agreement.
- Data retention policy.
- Other written agreement.
Sections that by their nature should survive termination will survive, including provisions concerning:
- Intellectual property.
- Confidentiality.
- Warranty disclaimers.
- Limitations of liability.
- Indemnification.
- Governing law.
18. Confidentiality
Each party may receive non-public information from the other party that is designated as confidential or should reasonably be understood to be confidential.
The receiving party will:
- Use confidential information only for purposes related to the parties’ relationship.
- Protect confidential information using reasonable care.
- Disclose confidential information only to personnel and contractors who need access and are bound by confidentiality obligations.
- Not disclose confidential information to third parties except as authorized or required by law.
Confidential information does not include information that the receiving party can demonstrate:
- Is publicly available through no breach of obligation.
- Was already lawfully known without confidentiality restrictions.
- Was lawfully received from a third party without confidentiality restrictions.
- Was independently developed without use of the other party’s confidential information.
PHI will be handled according to the applicable BAA.
19. Disclaimer of warranties
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE”. ARO DISCLAIMS ALL EXPRESS, IMPLIED, STATUTORY, AND OTHER WARRANTIES, INCLUDING WARRANTIES OF:
- MERCHANTABILITY.
- FITNESS FOR A PARTICULAR PURPOSE.
- TITLE.
- NON-INFRINGEMENT.
- ACCURACY.
- RELIABILITY.
- AVAILABILITY.
- RESULTS.
ARO DOES NOT WARRANT THAT:
- THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE.
- ALL CODING SUGGESTIONS WILL BE COMPLETE OR ACCURATE.
- USE OF THE SERVICE WILL RESULT IN PAYMENT OR REIMBURSEMENT.
- THE SERVICE WILL SATISFY THE REQUIREMENTS OF ANY PAYER, REGULATOR, AUDITOR, OR ACCREDITATION BODY.
- THE SERVICE WILL IDENTIFY FRAUD, ABUSE, OVERCODING, UNDERCODING, OR COMPLIANCE ISSUES.
- CUSTOMER DATA WILL NEVER BE LOST, CORRUPTED, OR ACCESSED WITHOUT AUTHORIZATION.
THE CUSTOMER IS RESPONSIBLE FOR EVALUATING AND VALIDATING ALL RESULTS GENERATED BY THE SERVICE.
20. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER ARO NOR ITS AFFILIATES, OFFICERS, DIRECTORS, EMPLOYEES, CONTRACTORS, LICENSORS, OR SERVICE PROVIDERS WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, CONSEQUENTIAL, OR PUNITIVE DAMAGES. THIS EXCLUSION INCLUDES DAMAGES ARISING FROM:
- LOST PROFITS OR REVENUE.
- LOST OR CORRUPTED DATA.
- BUSINESS INTERRUPTION.
- DENIED OR DELAYED CLAIMS.
- REPAYMENTS, RECOUPMENTS, PENALTIES, OR AUDIT FINDINGS.
- CODING OR BILLING ERRORS.
- LOSS OF GOODWILL.
- THIRD-PARTY SERVICES.
- UNAUTHORIZED ACCESS TO OR USE OF DATA.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, ARO’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS WILL NOT EXCEED THE AMOUNTS PAID OR PAYABLE BY THE CUSTOMER TO ARO FOR THE SERVICE DURING THE TWELVE MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
These limitations apply regardless of the legal theory and even if a remedy fails of its essential purpose. Any limitations or exclusions prohibited by applicable law will apply only to the maximum extent permitted.
21. Indemnification
The Customer will defend, indemnify, and hold harmless Aro and its affiliates, officers, directors, employees, and contractors from claims, damages, losses, liabilities, costs, and expenses, including reasonable attorneys’ fees, arising out of or relating to:
- The Customer’s use of the Service.
- Customer Data.
- The Customer’s violation of these Terms or applicable law.
- Unauthorized access caused by the Customer’s systems or credentials.
- Coding, billing, reimbursement, clinical, or compliance decisions made by the Customer.
- The Customer’s failure to obtain required authorizations or permissions.
- Claims that Customer Data infringes or violates third-party rights.
This obligation does not apply to the extent that a claim is caused by Aro’s gross negligence, willful misconduct, or violation of applicable law.
22. Governing law
These Terms are governed by the laws of the State of California, without regard to its conflict-of-laws principles. Any legal action arising from or relating to these Terms or the Service must be brought in the state or federal courts located in San Diego, California. Each party consents to the personal jurisdiction and venue of those courts.
23. Dispute resolution
Before initiating formal legal proceedings, each party agrees to make a good-faith effort to resolve the dispute through discussions between authorized representatives. Nothing in this section prevents either party from seeking temporary or injunctive relief to protect:
- Confidential information.
- Intellectual property.
- Customer Data.
- Systems.
- Security.
Any additional arbitration, mediation, or dispute-resolution requirements must be established in an applicable order form or separate written agreement.
24. Changes to these terms
Aro may modify these Terms from time to time. When changes are material, Aro will provide reasonable notice through:
- The Service.
- Email.
- Another appropriate method.
The updated Terms will identify their effective date. Continued use of the Service after updated Terms become effective constitutes acceptance of the updated Terms. If you do not agree to the updated Terms, you must stop using the Service. Changes to an executed BAA, order form, or other signed agreement must be made according to that agreement.
25. Notices
Aro may provide notices through the Service, by email, or using the contact information associated with the Customer’s account. The Customer is responsible for keeping its contact information current. Legal notices to Aro must be sent to: support@aromedical.net
26. General provisions
These Terms, together with any applicable order form, BAA, subscription agreement, or other written agreement, constitute the entire agreement concerning the Customer’s use of the Service. If a provision of these Terms is held invalid or unenforceable, the remaining provisions will remain in effect. Aro’s failure to enforce a provision is not a waiver of its right to do so later. The Customer may not assign these Terms without Aro’s prior written consent. Aro may assign these Terms in connection with:
- A merger.
- An acquisition.
- A corporate reorganization.
- A sale of assets.
- An assignment by operation of law.
Neither party will be liable for delays or failures caused by circumstances beyond its reasonable control, except for payment obligations. Headings are provided for convenience and do not affect interpretation.
27. Contact us
Questions about these Terms may be sent to support@aromedical.net.