> ## Documentation Index
> Fetch the complete documentation index at: https://docs.clinikehr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Acceptable Use Policy

> What you may and may not do with the ClinikEHR API. Part of the API Terms of Use. Version 2026-10-03.

<p>
  {"Version 2026-10-03"}
</p>

<p>
  {"Effective: the date it is published on the API site."}
</p>

<p>
  {"This policy applies to everyone who calls the ClinikEHR API: a clinic using its own keys, and an organization using a workspace. It is part of the agreement under which you use the API: for an organization, it is part of the ClinikEHR API Terms of Use."}
</p>

## YOU MAY

<ul className="list-disc space-y-2 pl-6">
  <li>
    {"Connect software you operate, or that is operated for you, to records you are permitted to reach."}
  </li>

  <li>
    {"Store what you receive for as long as your purpose and the law allow, and no longer."}
  </li>

  <li>
    {"Test against the sandbox as much as you need, within the published rate limits."}
  </li>
</ul>

## YOU MAY NOT

<p>
  {"1. Reach what you were not given. Do not try to reach a clinic that has not connected to you, a record outside your permissions, or a patient outside the group a clinic agreed to."}
</p>

<p>
  {"2. Discover who is there. Do not use searches, errors, timings or identifiers to work out which clinics, patients or records exist."}
</p>

<p>
  {"3. Sell or advertise. Do not sell patient information, use it to advertise, or build a profile of a person for any purpose the clinic did not agree to."}
</p>

<p>
  {"4. Re-identify. Do not combine what you receive with other data to identify a person you were not told about."}
</p>

<p>
  {"5. Decide about a person by machine alone in a way that denies them care, cover or a medicine. A flag from the API is a signal with its evidence, never a verdict."}
</p>

<p>
  {"6. Pass it on to anyone who is not bound by terms at least as protective as yours."}
</p>

<p>
  {"7. Share a key, place one where the public could read it, or use one key for several organizations."}
</p>

<p>
  {"8. Get around a limit, a refusal, a rate limit or a record's restriction, or create workspaces to do so."}
</p>

<p>
  {"9. Test our security without our written agreement. Report a weakness to support@clinikehr.com. If you find one by accident or while acting in good faith, report it promptly, do not read, keep or change more information than you need to show the problem, do not disclose it to anyone else until we have had a reasonable time to fix it, and stop when we ask. We will not act against a report made in good faith on these terms."}
</p>

<p>
  {"10. Send us what we did not ask for: malicious code, or patient information in a field that is not meant for it (a free-text reference, a code list, a notification address)."}
</p>

<p>
  {"11. Overwhelm a clinic. Do not send requests, orders or messages at a rate a clinic's staff could not reasonably handle."}
</p>

<p>
  {"12. Imitate ClinikEHR, Bettar Platforms, Inc., a clinic or a patient."}
</p>

<p>
  {"13. Break the law, including laws on health information, data protection and consumer protection in the places where you and the clinic operate."}
</p>

## WHAT HAPPENS IF YOU DO

<p>
  {"We may suspend the key or the workspace at once, tell the clinics concerned, and end your access. The Terms of Use, or for a clinic its data agreement, say how suspension and ending work."}
</p>

<p>
  {"ClinikEHR is a product of Bettar Platforms, Inc."}
</p>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.