Acceptable Use Policy
Effective Date: March 5, 2026 | Last Updated: March 5, 2026
1. Purpose
This Acceptable Use Policy ("AUP") governs the use of the Krasyn EMR platform operated by Krasyn LLC This policy supplements our Terms of Service and is designed to protect the security, integrity, and availability of the Platform for all users, and to ensure compliance with HIPAA and other healthcare regulations.
2. Permitted Use
The Platform is intended exclusively for:
- Outpatient clinical documentation and electronic health records management
- Clinical order entry, medication management, and prescription processing
- Results review and clinical decision support
- Practice management, scheduling, and billing operations
- Secure clinical messaging between authorized users
- Quality reporting and clinical analytics
- Authorized administrative functions by designated personnel
3. Prohibited Activities
The following activities are strictly prohibited:
3.1 Security Violations
- Sharing, transferring, or disclosing login credentials to any other person
- Attempting to access accounts, data, or systems not assigned to you
- Attempting to bypass, disable, or circumvent security controls or authentication mechanisms
- Introducing malicious code, viruses, worms, trojans, or other harmful software
- Conducting vulnerability scans, penetration testing, or security assessments without prior written authorization
- Intercepting, monitoring, or altering network communications
3.2 Data Violations
- Accessing, copying, or exporting PHI for unauthorized purposes
- Accessing patient records without a legitimate treatment, payment, or operations purpose ("snooping")
- Downloading, printing, or transmitting PHI to unauthorized locations or devices
- Using automated tools to scrape, harvest, or extract data from the Platform
- Entering false, misleading, or fabricated clinical data
- Deliberately altering or destroying clinical records
3.3 Regulatory Violations
- Using the Platform in a manner that violates HIPAA, the HITECH Act, or other applicable healthcare regulations
- Using the Platform in inpatient, emergency department, ICU, or surgical settings
- Using the Platform for fraudulent billing or coding practices
- Failing to report known security incidents or breaches
3.4 System Abuse
- Interfering with or disrupting the Platform's operations or infrastructure
- Consuming excessive system resources in a manner that degrades service for other users
- Reverse-engineering, decompiling, or disassembling the Platform software
- Using the Platform for purposes other than its intended clinical and administrative functions
4. User Responsibilities
- Maintain the confidentiality of your login credentials
- Lock or log out of workstations when unattended
- Report suspected security incidents immediately to security@krasyn.com
- Access only the minimum PHI necessary for your job function
- Comply with your organization's HIPAA policies and workforce training requirements
- Keep your contact information and professional credentials current
- Review and accept updated terms when notified of changes
5. Monitoring and Enforcement
All activity on the Platform is logged in a tamper-proof audit trail. Krasyn and your organization's administrators may review audit logs to monitor compliance with this AUP and applicable regulations. This monitoring includes, but is not limited to:
- PHI access patterns and frequency
- Authentication events (successful and failed)
- Data exports and downloads
- Administrative actions and configuration changes
- Cross-organization access attempts
6. Violations and Consequences
Violations of this AUP may result in one or more of the following actions, at Krasyn's sole discretion:
- Written warning
- Temporary suspension of access
- Permanent termination of access
- Notification to your organization's administrator and privacy officer
- Referral to law enforcement or regulatory authorities
- Civil legal action for damages
Violations involving unauthorized access to PHI may constitute a HIPAA violation and may be reported to the U.S. Department of Health and Human Services Office for Civil Rights.
7. Reporting Violations
If you become aware of any violation of this AUP, please report it immediately to:
- Security incidents: security@krasyn.com
- Policy violations: compliance@krasyn.com
Good-faith reports of violations will not result in retaliation.