Published: September 15, 2026
Last Revised: See Revision History
Incorporated into: health.network Startup Terms of Service — Startup Embeddables and Startup SDK Packages only
health.network Acceptable Use Policy
This Acceptable Use Policy (“AUP” or “Policy”) governs how Customers may use b.well’s health.network Startup Products and Services. It is incorporated by reference into the health.network Startup Terms of Service (the “Agreement”) and has the same legal effect as the Agreement. Terms not defined here have the meanings assigned in the Agreement (including Exhibit A — Definitions, the Data Processing Addendum (DPA) or Business Associate Addendum (BAA), as specified in the Order Form).
In the event of any conflict between this Policy and the Agreement, the Agreement controls unless expressly stated otherwise herein.
b.well’s mission is to empower individuals to manage their health through connected, transparent, and trustworthy digital experiences. This Policy reflects b.well’s commitment to maintaining the integrity, safety, and reputation of its platform across all Customer integrations. Customers who fail to comply with this Policy are in material breach of the Agreement.
1. Compliance with Applicable Law
Customer must use and present b.well’s Products and Services solely in compliance with all Applicable Law. Customer must not use the Products and Services in any manner that: (a) violates Applicable Law; (b) would require b.well to violate Applicable Law as a result of Customer’s use or integration; or (c) take any action that would subject b.well to regulatory action or third-party claims.
1.1 Healthcare Regulatory Requirements
Without limiting the foregoing, Customer must:
- comply with HIPAA and its implementing regulations to the extent applicable to Customer’s use of the Products and Services, including requirements applicable to covered entities and business associates (if applicable);
- comply with applicable state consumer health data privacy laws in all jurisdictions where Customer operates or serves Consumer End Users (to the extent applicable);
- ensure that all required notices, authorizations, and consent disclosures are provided to Consumer End Users before they use the Products and Services; and
- not use the Products and Services in connection with any activity that Customer knows or reasonably should know violates applicable healthcare fraud and abuse laws, including anti-kickback statutes, or constitutes an unfair or deceptive business practice.
1.2 Data Obligations
Customer’s data-related obligations under this Policy are consistent with its obligations under the Agreement (Section 3 and Section 6) and the DPA or BAA, as specified in the Order Form. In particular:
- Customer must handle all Customer Data collected through b.well Products and Services in accordance with ToS Section 3.
- Customer acknowledges and agrees that Customer must store all Customer Data collected through the Products and Services for their effective use and deployment. Customer agrees not to route Customer Data to external systems without b.well’s prior written consent, which shall not be unreasonably withheld, conditioned or delayed.
- Customer must not circumvent, disable, or interfere with any b.well consent mechanism, privacy notice, or data rights workflow required under the Agreement, the DPA or BAA, as specified in the Order Form, or Applicable Law.
1.3 Regulatory Cooperation
Customer must promptly notify b.well of any governmental or regulatory inquiry, investigation, or proceeding relating to Customer’s use of the Products and Services and must reasonably cooperate with b.well in responding.
2. Brand Integrity and Presentation
In furtherance of the quality and trustworthiness that b.well’s Products and Services carries for Customer End Users, Customer agrees to acquire, operate, and maintain all software, systems, equipment, and services as necessary to access and use the Products and Services.
2.1 Branding Requirements
Customer must comply with b.well’s Documentation and integration specifications, as updated by b.well from time to time upon reasonable notice, and obtain written consent from b.well prior to making any representation about b.well’s products, services, data practices, or capabilities.
2.2 Prohibited Conduct
Customer must not:
- frame, present, or contextualize the Products and Services in any manner that removes, obscures, or disguises its b.well identity or source;
- present the Products and Services in a manner that is false, misleading, deceptive, or likely to confuse Consumer End Users as to the source, nature, scope, or capabilities of the experience;
- alter, modify, obscure, remove, or override any b.well branding, Marks, disclaimers, notices, or consent mechanisms embedded in or required to accompany the Products and Services; or
- present the Products and Services alongside or within content that is defamatory, obscene, hateful, discriminatory, or otherwise objectionable in b.well’s reasonable determination.
3. Security and Technical Integrity
b.well’s platform handles sensitive personal health information. Accordingly, Customer must use commercially reasonable security measures to secure such software, systems, equipment, and services owned, hosted, or operated by Customer or its suppliers to prevent unauthorized access to the Products and Services or introduce or amplify security vulnerabilities that could harm Consumer End Users, b.well, or the broader health data ecosystem. Customer must maintain industry-standard security controls for its own systems and integration environment, including appropriate access controls, encryption in transit and at rest, and vulnerability management practices.
Customer must not:
- attempt to probe, scan, penetration test, or test the vulnerability of b.well’s systems, networks, or infrastructure without b.well’s prior written authorization;
- introduce, transmit, or facilitate the transmission of any malicious code, virus, worm, ransomware, or other harmful component through or in connection with the Products and Services;
- interfere with, disrupt, or degrade the integrity, availability, performance, or security of b.well’s systems, services, APIs, or data;
- attempt to reverse engineer, decompile, disassemble, or derive the source code or algorithms of any b.well component, except to the limited extent expressly permitted by Applicable Law;
- circumvent, disable, or interfere with any access control, authentication mechanism, rate limit, or security feature of the Products and Services or related APIs;
- deploy the Products and Services in a technical configuration not authorized by b.well’s documentation; or
- collect, transmit, store, or process data through the Products and Services in a manner that violates b.well’s security requirements or the DPA or BAA, as specified in the Order Form.
At the earliest identification of an actual or suspected security incident involving b.well’s Products, Services, or data or Consumer End User data processed through the integration, Customer must notify b.well’s security team in writing within forty-eight (48) hours, or as specified in the Data Processing Addendum to support timely mitigation and response efforts.
4. SDK-Specific Terms and Specifications
b.well’s Smart Connect™ is an automatic record locator service that searches across connected networks to locate and retrieve available consumer health records on behalf of Customer. Consumer End Users enable health record retrieval by securely authenticating using OAuth 2.0 and/or an IAL2- and AAL2- compliant digital verification solution, which b.well will make available via Customer’s preferred SDK integration method.
4.1 Authorization, Consent, Authentication, and Integration Requirements
Customers of b.well’s Startup SDK package agree to:
- implement, deploy, and maintain Consumer End User authorizations, as necessary for b.well to deliver the Products and Services in compliance with all Applicable Laws the latest supported releases of Company Software as identified in applicable Documentation;
- obtain a Consumer End User’s consent to each transfer of ePHR Information (each, a “Consent”) to Company Software without obscuring language identifying b.well as the data intermediary in the user experience;
- submit proposed consent language to b.well for written approval prior to being granted production system access;
- provide to b.well all data reasonably necessary for effective deployment of the Services, including Consumer End User authorizations, Consents, and any changes thereto;
- design, develop, test, and deploy all consumer-facing user interface and user experience within Customer applications; and
- drive adoption by providing Consumer End Users with first-tier support, communication, education, training, and engagement strategies.
4.2 Smart Connect™ Requirements
Customer shall agree and align to the integration of Smart Connect™ in the user experience within its user-facing application (“Integration”), as approved by b.well and including relevant disclosures and access to privacy choices, prior to launch of the Integration into production. Any licenses granted by b.well with respect to Smart Connect™ functionality shall not be effective until b.well has approved the end-to-end user experience in writing.
Customers of b.well’s Startup SDK package must:
- have a Kantara-certified IAL2-compliant digital identity solution (which may be obtained from b.well);
- maintain documentation enabling Customer alignment to b.well’s contractual commitments with connected networks;
- submit screens or user experience that materially affect the Integration or references b.well Products and Services for approval by b.well and monitor and report any modifications to any Consumer End User-facing components that contains, relates to, or references b.well Products or Services;
- present for Consumer End Users’ acceptance the Smart Connect™ Terms of Service and Privacy and Security Notice (required by TEFCA) and designate b.well as its individual access service provider, any rights and obligations under b.well’s Privacy and Security Statement notwithstanding; and
- provide first-tier support, education, and training to Consumer End Users; and
- implement and maintain privacy disclosures and mechanisms to receive and respond to data rights requests of verified Consumer End Users and share them promptly with b.well, and promptly respond to inbound requests if and to the extent they are received by b.well, as described under b.well’s Patient Rights and Requests disclosure.
5. Other Prohibited Uses
Customer must not use the Products and Services:
- in connection with any activity that is illegal, fraudulent, harmful to third parties, or that encourages Consumer End Users to engage in any conduct that violates this Policy;
- to generate disproportionate, excessive, or abusive automated traffic or API queries on b.well’s infrastructure beyond a number that is reasonable and customary, based on b.well’s experience for similarly situated customers;
- in a manner intended or reasonably likely to harm b.well’s goodwill, trade reputation, or relationships with its regulators, partners, or other customers;
- in connection with any product, service, or campaign that directly competes with b.well’s core product offerings, unless expressly authorized; or
- in any manner that would subject b.well to regulatory action, negative press coverage, or third-party claims arising from Customer’s conduct.
Customer must promptly notify b.well of any circumstance Customer becomes aware of that is reasonably likely to result in harm to b.well’s business, reputation, or legal standing arising from Customer’s integration or use of the Products and Services.
6. Monitoring and Audit
b.well reserves the right to monitor Customer’s integration for compliance with this Policy using technical means, including API usage monitoring, logging, and anomaly detection, consistent with the Agreement and Applicable Law.
Upon reasonable prior written notice of no less than ten (10) business days (except in the case of a suspected material breach or Security Incident), b.well may audit Customer’s use of the Products and Services to verify compliance with this Policy, no more than once per calendar year absent a specific compliance concern. Audits will be conducted in a manner that is intended to reasonably minimize disruption to Customer’s operations. Customer will cooperate reasonably and provide b.well with reasonable access to relevant records, personnel, and systems.
Customer will conduct periodic internal reviews of its integration to confirm compliance with this Policy and will promptly notify b.well in writing of any known or suspected violation.
7. Enforcement and Remedies
A material violation or pattern of recurrent violations of this Policy is a material breach of the Agreement. b.well’s remedies set out below are in addition to all other remedies available at law or in equity.
7.1 Immediate Suspension
b.well may suspend Customer’s access to the Products and Services immediately and without prior notice in the event of:
- a material or ongoing violation of this Policy that poses an imminent risk of harm to Consumer End Users, b.well, or third parties;
- an active or suspected Security Incident involving the integration; or
- a regulatory or legal requirement to suspend access.
7.2 Cure Period for Non-Emergency Violations
For violations that do not pose an imminent risk of harm, b.well will provide Customer with written notice and a cure period of fifteen (15) calendar days to remediate. If Customer fails to cure within that period, b.well may suspend or terminate Customer’s access in accordance with the Agreement.
7.3 Termination
Repeated, willful, or uncured material violations of this Policy constitute grounds for termination of the Agreement in accordance with its terms. Upon termination, Customer’s wind-down period obligations under Order Form Section 4 (Term and Termination) apply immediately.
7.4 Indemnification
Customer’s indemnification obligations under Section 8 of the Agreement expressly cover claims arising from Customer’s breach of this Policy, Customer’s violation of Applicable Law in connection with its integration, and any misrepresentation by Customer to Consumer End Users regarding the Products and Services, in each case subject to the exclusions and provisions of Section 8 of the Agreement.
8. Updates to This Policy
b.well may update this Policy from time to time to reflect changes in its products, Applicable Law, or industry standards. Updates are effective upon posting at icanbwell.com/legal/health-network-startup-acceptable-use-policy. Customer’s continued use of the Products and Services following the effective date of any update constitutes acceptance. If Customer objects to any material change, Customer may terminate the Agreement in accordance with its terms upon thirty (30) days’ written notice.
9. Contact
Questions about this Policy, requests for authorization, or reports of known or suspected violations should be directed to:
b.well Connected Health, Inc.
Legal & Compliance Email: [email protected]
Address: 145 West Ostend Street, Suite 300, Baltimore MD 21230
For security incidents, contact b.well’s security team directly at [email protected] within forty-eight (48) hours of discovery, as required by DPA or BAA, as applicable and specified in the Order Form.
10. Revision History
| Effective Date | Summary of Changes | Link to prior version (as applicable) |
| June 5, 2026 | First Published | https://www.icanbwell.com/legal/health-network-startup-acceptable-use-policy-june-2026/ |
| August 13, 2026 | Updated to clarify terms that align with b.well’s current standard requirements. | https://www.icanbwell.com/legal/health-network-startup-acceptable-use-policy-august-2026/ |
By accepting the Agreement that incorporates this Policy, Customer acknowledges that it has read, understood, and agrees to comply with this Acceptable Use Policy in its entirety.