Terms of Service

Effective Date: July 4, 2026

Welcome to Ember AI.

These Terms of Service govern access to and use of the Ember AI website, platform, and related services (collectively, the "Services") provided by Wisdom, Inc. d/b/a Ember AI ("Ember AI," "we," "us," or "our") to healthcare organizations and other business customers. Ember AI is an AI revenue integrity platform that helps customers improve coding accuracy, prevent denials, recover underpayments, and automate revenue cycle workflows. By accessing or using the Services, you agree to these Terms and our Privacy Policy.

Services Overview

Depending on your agreement with Ember AI, the Services may include some or all of the following:

  • Autonomous medical coding, coding audits, and charge capture review
  • Claim scrubbing, pre-submission validation, and payer-rule checks
  • Denial prevention, underpayment detection, and revenue integrity analytics
  • Denial appeals, recovery workflows, and payer correspondence support
  • Eligibility verification and prior authorization workflows where enabled under your agreement
  • Integrations with electronic health records, practice management systems, and payer portals
  • Operational reporting, audit trails, and human-in-the-loop review for exceptions

Ember AI provides software and workflow automation tools. We do not provide medical, legal, billing, or coding advice, and customer personnel remain responsible for final coding, billing, and clinical decisions unless otherwise agreed in writing.

1. Information We Collect

  • Account and Contact Information: Names, business email addresses, credentials, and related account details provided during onboarding or support.
  • Customer Data and PHI: Clinical documentation, encounter and billing data, claims, remittance and payment information, payer policies, contracts, and other data you or your systems provide to deliver the Services.
  • Integration Data: Information received from connected EHR, practice management, clearinghouse, payer, or other systems authorized by you.
  • Usage and Audit Data: Product usage logs, configuration settings, workflow actions, and audit records needed to operate, secure, and support the platform.
  • Support Communications: Information you submit through support channels, implementation requests, or feedback.

2. How We Use Your Information

We use information to operate and improve the Services, including:

  • Provide, maintain, and improve the Services you purchase, including AI-assisted coding, denial prevention, appeals, and related revenue cycle workflows.
  • Validate outputs, monitor performance, investigate errors, and route exceptions for human review.
  • Secure the platform, prevent fraud or misuse, and comply with legal, contractual, and regulatory obligations.
  • Provide customer support, onboarding, training, and product communications related to the Services.
  • Generate aggregated or de-identified analytics to improve model accuracy and platform reliability, subject to applicable law and your agreement.

3. Data Protection

  • Encryption: Customer data is encrypted in transit and at rest using industry-standard safeguards.
  • Compliance: Ember AI maintains HIPAA compliance, enters into Business Associate Agreements with covered entities, and maintains SOC 2 Type II controls with regular third-party audits.
  • Access Controls: Role-based access, audit logging, and least-privilege principles govern internal and customer access to production systems.
  • Retention: Data is retained only as long as necessary to provide the Services, meet legal obligations, or as specified in your agreement.
  • PHI Processing: Protected Health Information is processed only as permitted by your agreement and the BAA attached as Schedule A.

4. User Rights

  • Access and Correction: Authorized customer contacts may request access to or correction of account information, subject to verification and applicable law.
  • Data Requests: Individuals seeking access, portability, or deletion of personal information may contact us; requests involving PHI may require coordination with your organization as the covered entity or business controller.
  • Marketing Preferences: Where applicable, you may opt out of non-essential marketing communications.

5. Cookies and Tracking

Our website uses cookies and similar technologies to operate the site, remember consent preferences, and measure engagement. Non-essential tracking technologies load only after you provide consent through our consent banner. For details, see our Privacy Policy.

6. Data Sharing and Disclosure

We do not sell Protected Health Information. We may share information with service providers that help us host, secure, support, or deliver the Services; with integration partners you authorize; when required by law or valid legal process; or to protect the rights, safety, and security of Ember AI, our customers, and the public. Subprocessors are bound by contractual obligations appropriate to the data they process.

7. Changes to These Terms

We may update these Terms from time to time. Material changes will be posted on our website and, where appropriate, communicated through the Services. Continued use after the effective date of updated Terms constitutes acceptance of the revised Terms.

8. Contact Us

Questions about these Terms may be sent to support@embercopilot.ai.

Schedule A: Business Associate Agreement

This Business Associate Agreement (this "BAA") is entered into by and between Wisdom, Inc., a Delaware corporation doing business as Ember AI, with offices at 330 Primrose Rd Ste 301, Burlingame, California 94010 ("Provider"), and the healthcare organization or other entity on whose behalf these Terms of Service are accepted, an account is created, or the Services are otherwise accessed or used ("Company"). The individual accepting these Terms on Company's behalf represents that they have the authority to bind Company, as set forth under "Your Consent" above. Provider and Company are each a "party" and together the "parties." This BAA is effective, with respect to each Company, as of the date that Company (or its representative) first accepts these Terms of Service, creates an account, or otherwise accesses or uses the Services (the "Effective Date"), regardless of the date the Terms of Service were last updated as stated above.

WHEREAS, the parties have entered into a Master Services Agreement, together with all order forms, statements of work, and amendments thereto (the "Agreement"), pursuant to which Provider provides certain products and services to Company (the "Services");

WHEREAS, Company is a Covered Entity, and in providing the Services, Provider creates, receives, maintains, or transmits Protected Health Information on Company's behalf and is therefore a Business Associate of Company, in each case as those terms are defined under HIPAA;

WHEREAS, HIPAA requires the parties to enter into a written agreement governing Provider's use and disclosure of PHI; and

WHEREAS, the parties intend this BAA to satisfy those requirements and to be incorporated into and made a part of the Agreement.

NOW, THEREFORE, in consideration of the mutual covenants and obligations set forth herein and the parties' continued performance under the Agreement, and intending to be legally bound, the parties agree as follows:

Key Terms

Relationship of the Parties. Provider creates, receives, maintains, or transmits PHI on behalf of Company in connection with the Services, and is Company's business associate as that term is defined under HIPAA.

Designated Record Set. Provider maintains PHI in a Designated Record Set on Company's behalf.

Breach Notification Period. For purposes of this BAA, "Breach Notification Period" means sixty (60) calendar days from the date of discovery.

1. Business Associate Obligations

1.1. Obligations and Restrictions. Provider may not use or disclose PHI other than as described in this BAA, as permitted under the Privacy Rule, or as otherwise required by applicable law.

1.2. Permitted Uses and Disclosures. Except as otherwise permitted or required in this BAA, Provider may only use or disclose PHI as reasonably necessary to provide the Services or as otherwise required by applicable law.

1.3. Privacy and Information Security Program. Provider will maintain a privacy and information security program that takes commercially reasonable steps to ensure that employees or agents of Provider comply with this BAA. This includes giving training to Provider's workforce to ensure compliance with this BAA, implementing policies and practices that meet the current standards for the protection of PHI, and appointing Privacy and Security Officials as required under HIPAA.

1.4. Safeguards. Provider will implement appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI that it receives, creates, maintains, or transmits on behalf of Company. Provider will maintain appropriate technical and organizational safeguards to reduce the risk of misuse or disclosure of PHI except as permitted under this BAA. In addition, Provider will comply with its obligations under the Security Rule.

1.5. Assessments. Provider agrees to conduct regular assessments of its compliance with its obligations under the Privacy Rule and Security Rule. Provider will make available a summary of such assessments to Company upon Company's reasonable request.

1.6. Mitigation of Risks. Provider agrees to mitigate, to the extent practicable, any harmful effect that is known to Provider of a use or disclosure of PHI by Provider and to promptly communicate to Company any actions taken pursuant to this paragraph.

1.7. Subcontractors. (a) Provider may disclose PHI to a Subcontractor; and (b) may allow the Subcontractor to create, receive, maintain, or transmit PHI on its behalf. However, Provider must first ensure that each Subcontractor executes a binding, written agreement requiring the Subcontractor to protect PHI under terms substantially similar to and no less stringent than this BAA. Provider will not be in compliance with this BAA if Provider knew of a pattern of activity or practice of a Subcontractor that constituted a material breach or violation of the Subcontractor's obligations under any agreement between Provider and the Subcontractor. Provider will conduct appropriate due diligence on all Subcontractors.

1.8. Books and Records to HHS. Upon request, Provider will make its books, records, and internal policies and procedures relating to the use and disclosure of PHI available to the Secretary of HHS for the purpose of determining Company's and Provider's compliance with HIPAA.

1.9. Audit of Books and Records. Upon reasonable written request, and no more than once in any twelve (12)-month period unless in connection with a known or suspected Security Incident or Breach, Provider will make its books, records, and internal policies and procedures relating to its compliance with this BAA available to Company no later than forty-five (45) days from the date the such request is received. Company will bear its own costs associated with any such audit or review. Any information obtained by Company under this Section 1.9 will be treated as Provider's Confidential Information and used solely to assess compliance with this BAA. However, Provider is not required to provide any information or records that interfere with Provider's confidentiality or proprietary rights or that would otherwise impact Provider's compliance with its legal obligations.

1.10. Individual Requests. Provider will take commercially reasonable efforts to support Company in completing requests related to individuals' rights under HIPAA as related to the Services in a timely manner, but in no event will Provider's response take more than ten (10) business days. Examples of individual rights under HIPAA include the right to access PHI pursuant to 45 CFR §164.524, amend PHI pursuant to 45 CFR §164.526, and receive accounting of disclosures pursuant to 45 CFR §164.528. If relevant to the Services, Provider will maintain an accounting of disclosures it makes on Company's behalf as required under 45 CFR §164.528(a). Except as directed by Company or required by law, Provider will not respond directly to any individual requests regarding their rights under HIPAA.

1.11. Compliance with Covered Entity's Obligations. To the extent that Provider carries out Company's obligations under the Privacy Rule, Provider will comply with the requirements of the relevant Privacy Rule regulations that apply to Company in the performance of such obligations.

2. Company Obligations

2.1. Notice of Privacy Practices. Upon request, Company will provide Provider with its current notice of privacy practices adopted as required by the Privacy Rule. Company will notify Provider if any limitations in its notice of privacy practices impact Provider's use or disclosure of PHI under the BAA.

2.2. Notice of Changes. Company will notify Provider in a timely manner of any changes to how Company uses or discloses PHI to the extent that the changes impact how Provider uses or discloses PHI under the BAA.

2.3. Notice of Restrictions. Company will notify Provider in a timely manner of any restrictions agreed upon with an individual or their legal representative to the extent that the restrictions may impact Provider's use or disclosure of PHI under the BAA.

2.4. Compliance with Laws. Company will only use and disclose PHI to Provider in accordance with its obligations under HIPAA and with applicable law.

3. Data Rights & Restrictions

3.1. Offshoring PHI. Provider is permitted to use and disclose PHI outside of the United States to provide the Services.

3.2. De-Identification. Provider may de-identify PHI in accordance with the standards set forth in 45 C.F.R. § 164.514(a)–(b) and use or disclose the resulting properly de-identified PHI as allowable by law.

3.3. Aggregation. Provider may aggregate PHI for its own purposes.

4. Breach Notification

4.1. Breach Reporting. Provider will report to Company within the Breach Notification Period each use or disclosure of PHI not permitted under this BAA of which Provider becomes aware, including breaches of unsecured PHI as required by §164.410 of HIPAA and any Security Incident involving PHI. In addition, each party will comply with its notification obligations under HIPAA regarding a Security Incident involving PHI.

4.2. Unsuccessful Attempts. Company agrees that this section will be deemed as sufficient notice under Section 4.1 if Provider periodically receives unsuccessful attempts for unauthorized access to, use of, or disclosure of PHI, or for general interference with the general operation of Provider's products and services.

4.3. Security Incident Reimbursement. Subject to the limitations of liability set forth in the Agreement, Provider will reimburse Company for reasonable, documented, direct costs associated with a Security Incident to the extent such Security Incident is caused by Provider's or a Subcontractor's negligence or breach of this BAA. Provider's aggregate liability under this Section 4.3 will not exceed the total fees paid by Company to Provider under the Agreement in the twelve (12) months preceding the Security Incident, and will be inclusive of, and not in addition to, any liability cap set forth in the Agreement. In no event will Provider be liable under this Section 4.3 for indirect, incidental, consequential, special, exemplary, or punitive damages, including lost profits or lost revenue, even if advised of the possibility of such damages.

4.4. Confidentiality. Provider will not disclose information related to a Security Incident except as required by applicable law.

5. Term & Termination

5.1. Term. This BAA will start on the Effective Date and will continue in effect until the later of when all obligations of the parties have been met under this BAA or when the Agreement ends or expires.

5.2. Termination. Either party may terminate this BAA if the other party fails to cure a material breach of the BAA within 30 days after receiving notice of the breach. A material breach of the BAA will be deemed a material breach of the Agreement.

5.3. Effect of Termination.

a. Upon any expiration or termination of this BAA, or earlier if directed by Company, Provider will either return or destroy, at Company's discretion and according to Company's instructions, all PHI maintained in any form by Provider, its agents, or its Subcontractors.

b. Provider may not retain any copies of PHI unless directed to do so by Company. However, if neither return nor destruction are feasible, Provider may retain PHI as long as Provider continues to comply with all provisions of this BAA for the time it retains PHI and limits the use or disclosure of retained PHI to those purposes that made the return or destruction of PHI infeasible.

6. Definitions

6.1. "BAA" means this Business Associate Agreement, including the Key Terms above and any policies or documents referenced in or attached to this BAA.

6.2. "Breach" has the meaning given to it under HIPAA.

6.3. "Business Associate" has the meaning given to it under HIPAA.

6.4. "Covered Entity" has the meaning given to it under HIPAA.

6.5. "Designated Record Set" has the meaning given to it under HIPAA.

6.6. "HHS" means the U.S. Department of Health and Human Services.

6.7. "HIPAA" means the Health Insurance Portability and Accountability Act of 1996 and the rules and regulations thereunder, as amended from time to time.

6.8. "Privacy and Security Officials" has the meaning given to it under HIPAA.

6.9. "Privacy Rule" means the federal privacy regulations issued pursuant to HIPAA, codified at 45 CFR Parts 160 and 164 (Subparts A & E).

6.10. "Protected Health Information" or "PHI" has the meaning given to it under HIPAA.

6.11. "Security Incident" has the meaning given to it under HIPAA.

6.12. "Security Rule" means the federal security regulations issued pursuant to HIPAA, codified at 45 CFR Parts 160 and 164 (Subparts A & C).

6.13. "Services" means the products and services provided by Provider under the Agreement.

6.14. "Subcontractor" means a third party to whom Provider provides PHI under this BAA.

Schedule B: CPT® Notices and Disclaimers (AMA)

I. Copyright and Trademark Notices
  1. Licensee will ensure that the following text is displayed prior to initial display of CPT content.

CPT copyright 2025 American Medical Association. All rights reserved.

  1. Licensee will ensure that the following copyright notice is included on each page, or as often as reasonably practical, of any display or print-out where CPT content appears (other than that which would constitute fair use, internal reports, and claim forms for specific patients).

CPT copyright 2025 American Medical Association. All rights reserved.

  1. Licensee will include the trademark symbol ® following the first appearance of "CPT" in each section of the Licensed Products.
  2. When Licensee updates the Licensed Products with subsequent annual releases of Licensed Content, Licensee will update the copyright year as specified in the Licensed Content, which is usually the year prior to the title date (e.g., the copyright year for CPT® 2026 is 2025).
II. Other Notices and Disclaimers
  1. Licensee shall include the following notice prior to the initial display of CPT content in each Licensed Product.

U.S. Government End Users. CPT is commercial technical data, which was developed exclusively at private expense by the American Medical Association (AMA), 330 North Wabash Avenue, Chicago, Illinois 60611. Use of CPT in connection with this product shall not be construed to grant the Federal Government a direct license to use CPT based on FAR 52.227-14 (Data Rights - General) and DFARS 252.227-7015 (Technical Data - Commercial Items).

  1. If a Licensed Product includes National Correct Coding Policy content, Licensee shall include the following notice in such Licensed Product.

The responsibility for the content of any "National Correct Coding Policy" included in this product is with the Centers for Medicare and Medicaid Services and no endorsement by the AMA is intended or should be implied. The AMA disclaims responsibility for any consequences or liability attributable to or related to any use, nonuse or interpretation of information contained in this product.