Skip to content

BetaVadia is still being built. You will find rough edges — we would rather you found them than your patients did. Report something broken

Acceptable Use Policy

Last updated: August 20, 2026

This Acceptable Use Policy governs everything done through Vadia Health. It is part of the Terms of Service, and it applies to every practice, every user in a practice, and everyone who uses the client portal or a public interface. If you are not sure whether something is permitted, ask us before doing it.

1. Lawful use

Do not use the Service to violate any law, regulation, professional rule, or the rights of anyone else. This includes health-care fraud and abuse law, the federal False Claims Act and Anti-Kickback Statute, payer and Texas Medicaid rules, privacy and confidentiality law, consumer-protection and telemarketing law, and export and sanctions law. Do not use the Service to deliver care you are not licensed to deliver, in a place where you are not licensed to deliver it.

2. Prohibited content

Do not upload, store, or transmit content that is unlawful, defamatory, harassing, threatening, or that infringes or misappropriates anyone's intellectual property or privacy rights; malware, ransomware, or any code intended to damage or gain unauthorized access to a system; or material that has no legitimate connection to the operation of your practice. Do not put protected health information into a field, feature, or integration that is not intended for it, including a beta feature not covered by the Business Associate Agreement or a payment-processor field.

3. Security and testing

Do not probe, scan, or test the vulnerability of the Service or any related system; do not breach or circumvent authentication, authorization, tenancy isolation, rate limits, or any other security or access control; do not attempt to access another practice's data, another user's account, or any data you are not authorized to see; and do not reverse engineer, decompile, or attempt to derive source code except where the law makes that restriction unenforceable. Penetration testing requires our prior written permission and a scope agreed in advance. If you discover a vulnerability, report it to us promptly and do not exploit it or disclose it publicly before we have had a reasonable chance to fix it.

4. Account and access hygiene

Do not share credentials, use another person's account, or create an account for someone who cannot lawfully hold one. Do not keep access active for a workforce member who has left. Do not grant a role broader than the person's job requires. Every action taken under your credentials is attributed to you in the audit trail.

5. Communications

Do not send unsolicited marketing, bulk, or automated messages of any kind through the Service. Do not text, call, or fax anyone who has not given the consent the law requires, and honor every opt-out — including a STOP reply — immediately. Do not use the Service for political, commercial, or fundraising outreach. Keep clinically specific detail out of message bodies, because a message may be read on a lock screen by someone other than your client. Do not spoof a sender identity or use a number you are not authorized to use.

6. Artificial intelligence features

Do not present AI-generated output as a clinician's own reviewed work without reviewing it. Do not use AI features to make a clinical decision without independent professional judgment. Do not attempt to extract, reproduce, or reverse engineer any underlying model, and do not use the Service's output to train a competing model. Do not submit protected health information to an AI feature that is not enabled for PHI in your account.

7. Open data and public interfaces

If you use a public Vadia interface, including any Open-Data API: do not attempt to re-identify any individual, client, or practice; do not combine published data with other data to single anyone out; do not scrape, overload, or circumvent rate limits; attribute the data to Vadia Health where you display or redistribute it; do not present the data as clinical, diagnostic, or individual decision-making information; and do not imply endorsement or affiliation without our written permission.

8. Resource use

Do not use the Service in a way that degrades it for anyone else: no automated bulk operations beyond documented limits, no crawling, no unreasonable storage or bandwidth consumption, no cryptocurrency mining, no proxying of unrelated traffic, and no resale or sublicensing of capacity.

9. Enforcement

We may investigate suspected violations and may remove content, restrict a feature, suspend a user or a whole account, or terminate the agreement. Where circumstances allow we give notice and a chance to cure; where a violation creates urgent risk to the Service, to data, or to a person, we act first and notify afterward. We cooperate with lawful requests from authorities. Enforcement of this policy does not limit any other remedy, and our decision not to act in one case does not waive our right to act in another.

10. Reporting a violation

Report abuse, a suspected security vulnerability, or a violation of this policy to [email protected]. Do not include protected health information in the report; describe the issue and we will arrange a secure channel if details are needed.