Version 1.0 · Effective Date: January 01, 2026
Defines clinical, biomedical, and operational responsibilities
Addresses device handling, training, and support workflows
Applies only if selected in an applicable order document
Optional services in this addendum apply only where expressly referenced or selected by the customer. It does not apply by default.
(Public Standard Form - Exhibit E-2 – Mandatory; Optional Delegations Inside)
Version: 1.0
Effective Date: 01/01/2026
This Clinical Operations & Device Management Addendum (“Addendum”) is incorporated by reference into and forms part of the Master Software as a Service Agreement (Public Standard Form) (“Master Agreement”) between Braincare USA Corp. (“Company”) and the healthcare organization identified in a quotation, order form, or purchase order referencing the Master Agreement (“Client”).
This Addendum automatically applies to all Clients under the Master Agreement.
Optional delegations described herein apply only if expressly requested by Client.
Except as expressly stated herein, all terms of the Master Agreement, the Service Level Agreement (“SLA”), and the Business Associate Agreement (“BAA”), if applicable, remain unchanged and in full force and effect. In the event of conflict, the Master Agreement controls.
This Addendum defines the default and optional operational responsibilities related to:
Platform user administration
Trusted-device configuration within the Braincare system
Limited, support-driven PHI access (if authorized)
This Addendum:
Does not alter clinical responsibility or decision-making
Does not modify HIPAA roles or default PHI access
Does not change liability allocation or regulatory obligations
All patient care, clinical use, and compliance with hospital policies remain solely Client’s responsibility.
E2-A – Client Managed (Default): Client manages creation, modification, role assignment, and deactivation of users through its internal administrative and authorization processes.
E2-B – Company Assisted (Optional): If Client expressly requests, Company may execute user or role changes based solely on written instructions from an authorized Client contact. Company acts as an administrative operator only and does not validate clinical appropriateness or internal authorization.
Company is not responsible for errors, omissions, or unauthorized access resulting from incorrect or incomplete Client instructions.
E2-C – Client Managed (Default): Client manages trusted-device designation, lifecycle, and custody through its internal biomedical or IT procedures.
E2-D – Company Assisted (Optional): If Client expressly requests, Company may assist with trusted-device actions at the cloud-platform level, including registration, trust-level modification, or removal, based solely on Client instructions.
Clarifications:
Client retains full responsibility for physical custody, labeling, storage, and local security of devices
Company does not assume responsibility for device misidentification, incorrect serial numbers, or compromised Client-approved devices
Company actions are limited to system-level configuration only
E2-E – No PHI Access (Default): Company support personnel access only de-identified data, encrypted data, and technical metadata.
E2-F – Authorized PHI Access (Optional): If Client expressly authorizes, Company’s U.S.-based support personnel may access session-level PDF reports containing PHI strictly for troubleshooting, validation, or quality-assurance purposes.
Any PHI access:
Is governed exclusively by the BAA
Is limited to the minimum necessary
May be revoked by Client at any time
This Addendum does not grant standing clinical access or ongoing patient visibility.
All Company activities under this Addendum comply with:
SOC 2 Type II
HIPAA Security Rule (where applicable)
FDA-cleared system use requirements
Company’s liability remains fully subject to the limitation of liability provisions of the Master Agreement.
Company is not responsible for incidents arising from:
Client-managed users, credentials, or devices
Incorrect, incomplete, or unauthorized Client instructions
Client-owned hardware, networks, or local environments
Nothing in this Addendum limits Company’s obligations under applicable law.
This Addendum is co-terminous with the Master Agreement.
Client may change or revoke any optional delegation under this Addendum by written notice to support@brain4.care.
Company will implement the change and confirm completion within five (5) business days.
This Addendum is governed by the laws of the State of Delaware and subject to the governing-law and dispute-resolution provisions of the Master Agreement.
This Exhibit E-2 is published as a public standard form and is automatically incorporated by reference into all applicable quotations, order forms, and purchase orders referencing the Master Agreement.
Execution of an order document or use of the Services constitutes Client’s acceptance of this Addendum and its default provisions.