Legal
Acceptable Use Policy
acceptable use policyThis policy defines permitted and prohibited use of MedEazy services by visitors, evaluators, authorized clinicians, pharmacists, and administrators.
Draft legal content for MedEazy. Independent legal review and sign-off required before production reliance (APR-043).
Purpose
purposeMedEazy is provided for legitimate clinical decision support, medication safety, stewardship, monitoring, and hospital governance workflows. This policy protects patients, customers, staff, and platform integrity.
Permitted Use
permitted useAuthorized users may access features enabled for their tenant, facility, and role, including:
- Searching approved drug reference and interaction content for patient care and pharmacy review.
- Reviewing, acknowledging, overriding, escalating, and resolving alerts according to hospital policy.
- Documenting stewardship interventions and monitoring activities within configured workflows.
- Administrative configuration, content publication, imports, and audit review within assigned permissions.
- Participating in pilots, training, and sandbox environments using synthetic or de-identified data as directed.
Prohibited Use
prohibited useYou must not:
- Share credentials or allow unattended use of your account.
- Attempt to access another tenant’s data or bypass facility scope controls.
- Probe, scan, or test vulnerabilities except through an authorized security disclosure program.
- Introduce malware, excessive automated traffic, or denial-of-service activity.
- Scrape, mirror, or bulk download clinical content except as expressly permitted in writing.
- Circumvent licensing, print/export controls, watermarks, or kill switches.
- Use the platform for unlawful discrimination, harassment, or non-clinical personal purposes.
- Enter real patient information into unauthorized demo, test, or public environments.
- Misrepresent MedEazy outputs as autonomous clinical decisions or hide required safety disclosures.
- Use metrics or exports to rank individual clinicians without governance approval and fair methodology.
Data Entry and PHI
data entry and phiEnter patient information only in authorized production or approved pilot environments under your organization’s policies. Public forms, marketing email, and social channels must never contain PHI or credentials.
Administrative Responsibilities
administrative responsibilitiesCustomer administrators must maintain accurate user lists, revoke access promptly for departing staff, enforce MFA where required, and ensure separation of duties for content and rule publication.
Enforcement
enforcementViolations may result in warning, suspension, termination of access, contractual remedies, and reporting to authorities where required. We may investigate security events and preserve evidence in accordance with law and contract.