MediRecords API Terms of Use

19.0 API Access & Integration Terms

19.1 Definitions

For the purposes of this Section, the following definitions apply in addition to those in Section 2.0:

API means the MediRecords application programming interfaces, endpoints, authentication services, integration services, webhooks, and related technical interfaces made available by MediRecords.

API Key means any authentication credential, token, client secret, certificate, password, or other access credential issued by MediRecords.

Application means any software, integration, connector, middleware, workflow, script, automation, or system interfacing with the MediRecords platform.

Developer means a third-party consultant, contractor, software developer, or service provider engaged by You solely for Your internal use of the Services.

Internal APIs means any undocumented, unsupported, private, restricted, reverse-engineered, or non-public APIs or endpoints not expressly approved by MediRecords.

Third-Party Automation Tools includes Zapier, Make, n8n, UiPath, Power Automate, bots, scraping tools, scheduled polling services, robotic process automation tools, or similar technologies.

19.2 API Access Rights

Subject to this Agreement, MediRecords grants You a limited, revocable, non-exclusive, and non-transferable right to access and use the API solely for Your internal business operations, approved integrations and interoperability activities, and purposes expressly approved by MediRecords in writing. You must only use the API in accordance with applicable Documentation and MediRecords security requirements, for lawful purposes, and within any applicable usage, rate, or throttling limits imposed by MediRecords. API access does not transfer ownership of any intellectual property rights in the MediRecords platform, APIs, software, schemas, documentation, workflows, infrastructure, or related services.

19.3 API Keys and Security

API Keys remain the property of MediRecords at all times. API Keys are confidential, non-transferable, issued solely for approved use by You, and subject to revocation or replacement by MediRecords at any time. You must securely store all API Keys, maintain appropriate credential management processes, prevent unauthorised access to API credentials, restrict API access to authorised personnel only, and immediately notify MediRecords upon any suspected compromise, misuse, or unauthorised disclosure.

API Keys must not be shared with unauthorised third parties, sublicensed, embedded in publicly distributed software, exposed in client-side code, mobile applications, browser code, repositories, or public source code, pooled across unrelated customers or systems, or used outside approved integration purposes. You are responsible for all actions undertaken using issued API Keys, whether authorised or unauthorised. MediRecords may rotate, revoke, suspend, replace, or expire API Keys at any time for operational, commercial, security, compliance, or platform integrity reasons.

19.4 Third-Party Developers and Integrators

You may engage Developers solely to support integrations for Your internal use. You remain fully responsible for all acts and omissions of any Developer engaged by You. Developers must not reuse integrations for other customers, commercialise integrations, create reusable middleware services, provide multi-tenant services using the API, create competing products or services, retain API access following completion of their engagement, or use the API outside Your approved environment. You must ensure all Developers are contractually bound to confidentiality, security, and acceptable use obligations equivalent to this Section before API access is granted. MediRecords may require details of any Developer or third-party integrator accessing the API.

19.5 Prohibited Uses

You must not, and must not permit any third party to: (a) access or attempt to access Internal APIs; (b) reverse engineer, scrape, probe, discover, or exploit undocumented functionality; (c) use the API for bulk extraction, replication, warehousing, migration, or analytics purposes unless expressly approved by MediRecords; (d) create products or services competing with MediRecords; (e) commercialise integrations without MediRecords’ prior written approval; (f) use unauthorised Third-Party Automation Tools; (g) bypass authentication, throttling, or security controls; (h) interfere with system performance, availability, or security; (i) excessively poll APIs or generate unreasonable transaction loads; (j) use the API in a manner likely to negatively impact other MediRecords customers; or (k) expose MediRecords to operational, security, privacy, or regulatory risk.

19.6 Integration Approval

You must obtain MediRecords’ prior written approval before deploying reusable integrations, implementing automated workflows, using third-party middleware platforms, commercialising integrations, enabling high-frequency synchronisation, or implementing integrations involving sensitive or regulated data flows. MediRecords may require architecture documentation, security information, data flow documentation, polling frequency details, infrastructure details, transaction estimates, and testing evidence before approving an integration. MediRecords may approve, reject, suspend, conditionally approve, or revoke integration access at its discretion.

19.7 Monitoring and Operational Controls

MediRecords may monitor API usage including transaction volume, endpoint usage, authentication behaviour, integration activity, polling frequency, infrastructure impact, and security events. MediRecords may impose rate limits, throttling, concurrency restrictions, environment restrictions, transaction limits, and security controls to protect platform integrity and service availability. MediRecords may immediately suspend API access where reasonably necessary to protect platform security, investigate suspected misuse, mitigate operational risk, preserve service stability, protect patient or customer data, or prevent unauthorised activity.

19.8 Data Usage and Privacy

You must only access, use, store, process, or transmit data obtained through the API for approved business purposes, in accordance with applicable laws, and to the minimum extent reasonably necessary. You must implement appropriate technical and organisational security controls to protect all data accessed through the API. You must not create independent data repositories, datasets, reporting warehouses, or external analytics platforms using API data unless expressly approved in writing by MediRecords.

19.9 Suspension and Revocation

MediRecords may immediately suspend or revoke API access where You breach this Section, API misuse is suspected, unauthorised integrations are identified, prohibited automation tooling is detected, excessive or abusive usage occurs, security vulnerabilities arise, or continued access may adversely affect the platform, other customers, or patient data. MediRecords is not liable for any loss arising from suspension or revocation reasonably implemented under this clause.

19.10 API Fees

API access fees are as specified in applicable Order Forms and pricing schedules. MediRecords may vary API pricing, usage thresholds, transaction limits, and related commercial models upon renewal or by reasonable notice where permitted under this Agreement.

19.11 Termination of API Access

Upon termination or expiry of this Agreement or API access: all API rights immediately cease; all API usage must stop; integrations must be disconnected; API Keys must be destroyed; and You must cease attempting to access the API. The obligations in Sections 10.0 (Confidentiality), 9.0 (Proprietary Rights and Licenses), 19.3 (API Keys and Security), 19.5 (Prohibited Uses), 19.9 (Suspension and Revocation), and 13.0 (Limitation of Liability) survive termination of API access.