Dion Health — Product Schedules
Version: 1.0 Effective Date: July 24, 2026 Last Updated: July 24, 2026
These product schedules (each a "Schedule," and collectively these "Schedules") are incorporated into and governed by the Dion Health Master Subscription Agreement between Dion Health Management Company LLC ("Dion") and Customer (the "Agreement"), as contemplated by Section 2.2 of the Agreement. Each Schedule applies only to the Service it identifies, and only where Customer has subscribed to that Service under an Order Form. Capitalized terms used but not defined in a Schedule have the meanings given in the Agreement.
Consistent with Section 2.2 of the Agreement, in the event of a conflict the order of precedence is: (a) the Order Form; (b) the applicable Schedule; (c) the Agreement; and (d) all other policies incorporated by reference. The restrictions in each Schedule are in addition to, and do not replace, the restrictions in Section 4 of the Agreement, and the disclaimers in each Schedule are in addition to those in Sections 11 and 12 of the Agreement.
How to Read These Schedules
Availability Designations
Each Schedule states the Service's availability. "Generally Available" means the Service is offered for production use under the Agreement's warranties and the Service Level Agreement. "Limited Availability" means the Service is offered for production use to designated customers, with functionality that continues to change materially. "Not Generally Available" means the Service has not been released; its Schedule applies upon release, and until release the Service is offered, if at all, only as a Beta Feature under Section 2.6 of the Agreement ("AS IS," unsupported, and excluded from the Service Level Agreement).
Integration Modes
Services connect to the Dion platform in one of two ways, each described in the applicable Schedule:
- Read Integration. Dion's hub reads the Service's database directly using a service-role credential and applies tenant scoping in code on every read. Dion does not write to, modify, or delete records in a Service read this way.
- Event Integration. The Service emits structured events into Dion's event bus, where each event is validated against Dion's published event contract before acceptance. Events carry identifiers, references, codes, and amounts only — never clinical content or narrative Protected Health Information. Events that fail validation are rejected and dead-lettered.
Data Categories
Each Schedule states the data categories the Service is designed to process. Consistent with Section 4(l) of the Agreement, Customer must not submit a data category to a Service that the applicable Schedule states the Service is not designed to receive. Where a Service processes PHI, a Business Associate Agreement must be executed before Customer transmits PHI to it (Agreement Section 10.3).
Schedule A — Dion Console and Suite Platform
Availability: Generally Available.
A.1 Description of the Service
The Dion Console is the operator console and shared platform layer of the Dion Suite. It provides a single sign-on session across subscribed products, an application launcher, unified dashboards and per-product read views, a cross-product activity feed derived from the event bus, cross-product person linking, entitlement enforcement, and an audit surface. The Console reads and links; it does not replicate or replace the operational surfaces of the individual products, and operating a product occurs in that product's own application.
A.2 Data Categories
The Console processes: PHI, to the extent PHI is present in the products Customer has connected and is surfaced in Console read views; operator identity and account data (names, work email addresses, roles, entitlements); event metadata carrying identifiers, references, codes, and amounts; and Service Data (audit records, telemetry, usage measurements). The Console is not designed to receive payment card numbers, government identifiers, or clinical narrative content entered directly into it.
A.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will not: (a) use Console credentials, service-role keys, or launch tokens outside the Console's intended interfaces; (b) connect a product, database, or tenant that Customer does not own, manage, or serve under a written agreement disclosed to Dion; or (c) use the Console's cross-product views to aggregate data across customers, practices, or tenants that Customer is not authorized to access.
A.4 Product-Specific Disclaimers
The Console displays data sourced from the connected products; it is not a system of record for any workflow. Where a connected product's credentials are absent, expired, or misconfigured, the Console reports an unconfigured or error state rather than a value, and Customer remains responsible for maintaining valid credentials. Customer remains responsible for provisioning and de-provisioning Authorized Users and for the accuracy of the data in each connected product.
Schedule B — Dion Insights
Availability: Limited Availability.
B.1 Description of the Service
Dion Insights is a subscription analytics application for dental practices and dental service organizations. It connects to Customer practice management systems ("PMS") through read-only integrations, and to other subscribed Dion products, to compute and display operational and financial key performance indicators — including production by provider and by procedure code, accounts-receivable aging, new-patient counts, recare and reactivation, case acceptance, and comparable measures — together with opportunity reporting derived from that data. This Schedule supersedes the prior standalone Dion Insights Terms of Service with respect to any Order Form governed by the Agreement.
B.2 Data Categories
Dion Insights processes PHI (including patient-level appointment, procedure, and financial records retrieved from the connected PMS and from other Dion products), procedure and diagnosis codes, and practice financial data (production, collections, adjustments, receivable balances). It does not process employee payroll data and is not designed to receive payment card data.
B.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) connect only PMS instances and practices that Customer owns, manages, or is contractually engaged to support, and will maintain the authorizations warranted in Section 5.2 of the Agreement; and (b) keep PMS credentials and API keys confidential, rotate them promptly upon suspected compromise, and notify Dion at security@dionhealth.com.
B.4 Product-Specific Disclaimers
Dion accesses connected PMS data in read-only mode and does not create, modify, or delete records in a connected PMS. Analytics are computed from data retrieved from the Customer's source systems and are only as accurate, complete, and current as those source systems; Dion makes no representation regarding analytics derived from inaccurate, incomplete, duplicated, or misconfigured source data, and Customer is responsible for maintaining accurate records in its PMS. Benchmarks, scorecards, opportunity lists, and comparative measures are informational management tools; they are not audited financial statements, not valuation or diligence opinions, and — consistent with Section 12.5 of the Agreement — not a determination that Customer is in compliance with any law, payer requirement, or professional standard.
Schedule C — MedicalDentalRCM (MDRCM)
Availability: Generally Available. Integration: Read Integration.
C.1 Description of the Service
MedicalDentalRCM is a revenue cycle management application covering eligibility verification, credentialing and payer enrollment, pre-authorization, coordination of benefits, claim preparation and submission, denial and appeal workflow, and accounts-receivable and patient-balance tracking, with connections to clearinghouses and practice management systems. It emits claim lifecycle events into the Dion event bus.
C.2 Data Categories
MDRCM processes PHI, including patient demographics and contact information, insurance and subscriber information, procedure and diagnosis codes, claim and remittance data, denial and adjustment codes, payment records, and patient balances. It also processes payer and clearinghouse configuration data. Full payment card numbers are not processed by MDRCM; patient payment collection is addressed in Schedule K.
C.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) submit claims only for services actually rendered by providers Customer employs or contracts with, and only for practices identified in the Order Form; (b) maintain in effect all payer contracts, provider enrollments, and clearinghouse agreements required for its submissions; and (c) not use the Service to submit, resubmit, or alter a claim in a manner Customer knows or should know is inaccurate, duplicative, or unsupported by the underlying record.
C.4 Product-Specific Disclaimers
Outputs of the Service — including eligibility responses, claim scrubbing results, code suggestions, denial classifications, and estimated patient responsibility — are not a guarantee of claim acceptance, adjudication, reimbursement, or payment. Customer remains solely responsible for the accuracy and completeness of every claim it submits, for the selection and support of procedure and diagnosis codes, for documentation sufficient to support each claim, and for compliance with payer rules and contracts, the False Claims Act, the Anti-Kickback Statute, and all applicable billing, coding, and reimbursement regulations. Dion does not practice billing, does not provide coding, reimbursement, legal, or compliance advice, and does not act as Customer's billing agent unless a separate written services agreement expressly says so. Eligibility, adjudication, and remittance information originates with payers and clearinghouses and is subject to Section 11.5 of the Agreement.
Schedule D — Lead Intelligence
Availability: Generally Available. Integration: Read Integration.
D.1 Description of the Service
Lead Intelligence is a sales and lead-management application: inbound lead capture, AI-assisted qualification and scoring, conversation and campaign tracking across messaging channels, a voice-call layer, and appointment-request handling. It emits lead and conversation events into the Dion event bus.
D.2 Data Categories
Lead Intelligence processes prospect and patient personal information (names, email addresses, telephone numbers, inquiry content), marketing and lead-source data, conversation content (message bodies, call records, transcripts, and sentiment and intent classifications), and estimated treatment value. Because prospects routinely volunteer health information in inquiries and calls, the Service may receive PHI; Customer must execute a BAA before using the Service for any practice whose inquiries may include PHI.
D.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) use the Service only with leads Customer has lawfully collected, and will not upload purchased, scraped, or otherwise unlawfully sourced contact lists; (b) obtain and maintain all consents required to contact each individual by the channel used, including prior express written consent where required; and (c) not commingle marketing or lead data with PHI except within a Service and configuration covered by the applicable BAA.
D.4 Product-Specific Disclaimers
Customer is solely responsible for compliance with the Telephone Consumer Protection Act, the CAN-SPAM Act, state telemarketing, autodialer, and consent statutes, do-not-call obligations, and all laws governing recorded or monitored communications, including the call-recording consent laws of every jurisdiction in which a party to a call is located (which in some states require the consent of all parties). Customer is responsible for the required disclosures and for its own lead sources, offers, and marketing claims. Dion does not warrant lead volume, lead quality, qualification accuracy, appointment rates, conversion, or any revenue outcome. AI scoring, qualification, sentiment, and intent outputs are assistive and probabilistic and are subject to Section 12.4 of the Agreement.
Schedule E — Smile Design Lab
Availability: Generally Available. Integration: Read Integration.
E.1 Description of the Service
Smile Design Lab is a smile-design and dental-laboratory marketplace: practices submit restorative cases, cases are routed to participating laboratories, and the Service tracks case status, case messaging, orders, pricing, and dispute handling, together with laboratory onboarding and verification.
E.2 Data Categories
Smile Design Lab processes PHI in the form of case-level patient records (name, contact details, case photographs and scans where submitted) and case clinical parameters (restoration type, shade, materials, urgency, due dates), together with commercial data (case pricing, orders, disputes) and laboratory business and verification data.
E.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement: the Service is a two-sided marketplace, and a given participant account operates either as a practice or as a laboratory, not both. Customer will not attempt to access, filter, or report on records belonging to the opposite side of the marketplace, and will not use marketplace data to solicit counterparties outside the Service. Customer will submit only cases for patients of practices identified in the Order Form.
E.4 Product-Specific Disclaimers
Designs, case files, and laboratory outputs are planning and fabrication support materials. The treating provider is solely responsible for diagnosis, final treatment planning, case design approval, material and restoration selection, fit, seating, and the clinical suitability of any appliance or restoration for a given patient. Dion does not practice dentistry or dental technology, does not manufacture restorations, and does not warrant the workmanship, materials, delivery timing, or regulatory status of any third-party laboratory. Marketplace verification and status indicators are informational and are not a certification, endorsement, or guarantee of any laboratory.
Schedule F — Oralogix
Availability: Generally Available. Integration: Read Integration.
F.1 Description of the Service
Oralogix supports the prescription and manufacturing workflow for clear aligners, TMJ appliances, and sleep appliances: intake of diagnostic scans, doctor prescriptions and appliance specifications, case simulation and doctor approval, and manufacturing orders through shipment.
F.2 Data Categories
Oralogix processes PHI, including patient identifiers and dates of birth, diagnostic imaging and intraoral scan files, prescriptions and clinical parameters (appliance type, material, vertical opening, clinical notes), and case and manufacturing status records.
F.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) submit prescriptions only through a licensed provider acting within the scope of that provider's license and in the jurisdiction where the patient is treated; (b) review and expressly approve each case at the approval step before manufacturing proceeds; and (c) not use scans, designs, or case files obtained through the Service to source equivalent appliances from another manufacturer in circumvention of the Order Form.
F.4 Product-Specific Disclaimers
Simulations, treatment-setup renderings, and appliance specifications are planning and fabrication support outputs, not diagnoses or treatment plans. The prescribing provider is solely responsible for diagnosis, treatment planning, appliance selection, prescription parameters, patient screening (including airway, sleep, and temporomandibular indications), delivery, monitoring, and the clinical suitability and safety of any appliance for a given patient. Consistent with Section 12.2 of the Agreement, the software components of the Service are practice-management, design, and manufacturing-workflow tools and are not represented as a medical device requiring FDA clearance or approval; Customer is responsible for the regulatory obligations attaching to appliances it prescribes and dispenses.
Schedule G — Dion Growth Studio
Availability: Generally Available. Integration: Read Integration.
G.1 Description of the Service
Dion Growth Studio is a marketing and demand-generation workspace: campaign management, inbound lead capture, daily performance metrics, brand-mention monitoring, and attribution reporting across practice workspaces.
G.2 Data Categories
Growth Studio processes marketing and lead data (inbound lead contact details and source, campaign configuration and performance metrics, brand mentions, subscription records) and advertising platform data. The Service is not designed to receive PHI, clinical records, or payment card data, and Customer must not submit those categories to it except to the extent an executed BAA expressly covers the Service.
G.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) comply with the terms and advertising policies of every third-party advertising, analytics, and social platform it connects; (b) obtain all consents and provide all notices required for tracking, cookies, pixels, and marketing contact; and (c) not commingle marketing data with PHI unless the applicable BAA covers the Service and the configuration in use.
G.4 Product-Specific Disclaimers
Customer is solely responsible for its marketing claims, offers, disclosures, and creative, and for compliance with the Telephone Consumer Protection Act, the CAN-SPAM Act, state consent and telemarketing laws, dental advertising and professional-advertising rules, and FTC advertising and endorsement requirements. Attribution, spend, ROI, and performance figures are computed from third-party advertising and analytics platforms and inherit their reporting methodologies, delays, and restatements; they are estimates and are subject to Section 11.5 of the Agreement. Dion does not warrant lead volume, cost per acquisition, ranking, reach, or any marketing or revenue outcome.
Schedule H — Dion Workforce
Availability: Generally Available. Integration: Event Integration.
H.1 Description of the Service
Dion Workforce is a multi-tenant human resources, payroll, and compliance application: employee records and onboarding, time entry and approval, payroll run preparation and paycheck records, credential and license tracking with expiration monitoring, and compliance item tracking. It is the reference federation integrator and emits its full HR, payroll, and compliance event families into the Dion event bus.
H.2 Data Categories
Dion Workforce processes employee personal information and employment records (names, contact details, work authorization and identification data, job and location assignment), compensation and payroll data (pay rates, hours, earnings, deductions, withholding elections, net pay, and payroll run records), tax-related identifiers submitted by Customer, and credential, license, and compliance records. It is not designed to process patient PHI. Where Customer stores employee health-related records (for example immunization or occupational-health items) in compliance tracking, Customer is responsible for the additional legal requirements attaching to that data.
H.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) restrict access to payroll and employee records to Authorized Users with a legitimate need, and de-provision access promptly on separation; (b) review and approve each pay run before it is finalized; and (c) not use the Service to administer employees of any entity Customer does not employ or is not contractually engaged to support.
H.4 Product-Specific Disclaimers
Dion is not the employer, joint employer, or employer of record of Customer's personnel, is not a professional employer organization, is not a payroll agent, and is not a licensed tax preparer or filing agent. Customer is solely responsible for: wage and hour compliance, including minimum wage, overtime, meal and rest periods, and pay-frequency and pay-statement requirements; worker classification (employee versus independent contractor, and exempt versus non-exempt); tax withholding, deposit, reporting, and filing obligations; benefits administration and eligibility determinations; leave administration; recordkeeping and retention; and all hiring, discipline, compensation, and termination decisions. Outputs of the Service — including calculated pay, deductions, tax figures, credential status, and compliance indicators — are not tax, legal, accounting, or human-resources advice, and Customer must review and approve every pay run before approval or disbursement. Consistent with Section 12.5 of the Agreement, compliance indicators are informational aids and do not establish compliance with any law.
Schedule I — Patient Engagement
Availability: Limited Availability. Integration: Event Integration.
I.1 Description of the Service
Patient Engagement is the patient-facing communication and scheduling application: appointment scheduling and confirmation, recall and reactivation programs, unified patient messaging across SMS, email, and in-application chat, digital intake, treatment-plan presentation and follow-up, and patient commerce and loyalty features. It is the system of record for scheduling and patient-facing communications within the Dion Suite, and emits appointment and message events into the Dion event bus.
I.2 Data Categories
Patient Engagement processes PHI, including patient demographics and contact details, appointment records, message content exchanged with patients, intake responses, and treatment-plan information.
I.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) obtain and maintain all consents required to contact each patient by the channel used, and honor opt-outs promptly; (b) configure message content and templates so that PHI is disclosed only in a manner consistent with Customer's notice of privacy practices and applicable law; and (c) not use the Service to send marketing communications that require an authorization under HIPAA without obtaining that authorization.
I.4 Product-Specific Disclaimers
The Service is not a channel for medical emergencies or urgent clinical communication, and Customer is responsible for instructing patients accordingly and for maintaining its own procedures for urgent contact. Message and appointment delivery depends on third-party carriers, messaging providers, and email systems and is subject to Section 11.5 of the Agreement; Dion does not warrant delivery, timing, or receipt of any message. Customer is responsible for TCPA, CAN-SPAM, and state consent compliance for patient outreach, for appointment and scheduling decisions, and for reviewing AI-drafted patient communications before transmission in accordance with Section 12.4 of the Agreement.
Schedule J — Dion Clinical (including Dion Scribe)
Availability: Limited Availability. Integration: Event Integration.
J.1 Description of the Service
Dion Clinical is an in-house dental electronic medical record and practice management application intended to serve as the clinical system of record: charting (odontogram and periodontal charting), examination and clinical note documentation, treatment planning, and a smile-design studio, together with an ambient artificial-intelligence documentation assistant ("Dion Scribe") that produces draft clinical notes from a recorded or transcribed encounter. It is designed to refer airway, sleep, and temporomandibular cases to a diagnostic partner product and to share designed cases to the laboratory and manufacturing products, and to emit clinical lifecycle events into the Dion event bus.
J.2 Data Categories
Dion Clinical processes PHI and complete clinical records, including charting and periodontal data, examination findings, clinical narrative notes, treatment plans, images and scans, and — where Dion Scribe is enabled — audio recordings of clinical encounters and transcripts derived from them.
J.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) obtain all patient consents and provide all notices required to record clinical encounters, including under the recording-consent laws of the applicable jurisdiction, before enabling or using Dion Scribe; (b) restrict charting and note-authoring access to licensed providers and personnel acting within the scope of their licenses and Customer's supervision policies; and (c) maintain its own record-retention, amendment, and release-of-information procedures.
J.4 Product-Specific Disclaimers
The record created in the Service is Customer's legal medical record. Customer is solely responsible for its accuracy, completeness, integrity, retention, amendment, disclosure, and release, and for responding to patient access, accounting-of-disclosure, and subpoena requests. Dion Scribe output is a draft. It must be reviewed, corrected, and attested by the responsible licensed provider before it is signed into or relied upon as part of the clinical record, and an unreviewed draft is not a clinical note. Consistent with Sections 12.1 and 12.2 of the Agreement, the Service does not provide diagnostic, clinical, or treatment advice, makes no diagnostic claim, and is not represented as a medical device requiring FDA clearance or approval. Coding, charting, and treatment-plan suggestions are assistive and probabilistic and are subject to Section 12.4 of the Agreement.
Schedule K — Dion Pay
Availability: Limited Availability. Integration: Event Integration.
K.1 Description of the Service
Dion Pay is the patient-facing financial layer: a single patient ledger, patient statements, membership and subscription plans, payment plans and third-party patient financing, and collections and dunning workflow with escalation. Card and bank payment processing is performed by third-party payment processors; patient financing is provided by third-party lenders. Dion Pay maintains an append-only ledger of amounts and emits payment and billing events into the Dion event bus.
K.2 Data Categories
Dion Pay processes patient financial data (balances, charges, adjustments, plan terms, payment records, statement history, collection status) and patient identifying information necessary to associate a balance with a person, which constitutes PHI. Dion processes it as a Business Associate under the BAA. Full payment card numbers and bank account credentials are collected and processed by the third-party processor, not stored by Dion Pay, which retains processor references and tokens only.
K.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) maintain its own account and agreement in good standing with each payment processor and financing provider, and comply with their terms; (b) not transmit full payment card numbers, magnetic-stripe data, card verification values, or bank credentials into any Dion field not designated in the Documentation to receive them; (c) not initiate a charge, recurring plan, or collection action without the authorization required by law and by the applicable card network or ACH rules; and (d) comply with all applicable debt-collection law in configuring and running collections and dunning sequences.
K.4 Product-Specific Disclaimers
Dion is not a bank, money transmitter, money services business, payment processor, lender, credit provider, debt collector, or insurer, and does not hold, transmit, or take custody of Customer or patient funds. Payment processing, settlement, and patient financing are performed by third-party providers under their own agreements with Customer and are subject to Section 11.5 of the Agreement; approval, decline, funding, settlement timing, and reserve or hold decisions are made by those providers, not by Dion. Customer is solely responsible for refunds, chargebacks, disputes and representment, card network and NACHA rule compliance, PCI DSS obligations arising from its own environment, surprise-billing and price-transparency obligations, and the accuracy of every amount it bills a patient. Ledger figures, statements, and aging reports are records of activity recorded in the Service and are not audited financial statements, tax records, or a substitute for Customer's own accounting reconciliation. Customer is responsible for reconciling the Service's records against its processor settlement reports and its books of account.
Schedule L — Dion Desk
Availability: Generally Available. Integration: Event Integration.
L.1 Description of the Service
Dion Desk is an omnichannel contact center and ticketing application: inbound and outbound email, SMS, and voice interactions unified into tickets, queues and routing, service-level and escalation handling, contact and interaction history, call and voicemail transcription, and task and follow-up management, with tiered artificial-intelligence assistance on agent workflows. Voice and messaging are delivered through third-party carrier and communications providers.
L.2 Data Categories
Dion Desk processes contact and interaction data (names, telephone numbers, email addresses, ticket content, message bodies), call recordings and transcripts where recording is enabled, and — because patients and prospects routinely disclose health information in support interactions — may process PHI. Customer must execute a BAA before using the Service for interactions that may include PHI.
L.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) configure recording, transcription, and retention settings in accordance with applicable law before enabling them; (b) obtain and maintain all consents required to contact each individual by the channel used and honor opt-outs; and (c) comply with the terms and acceptable-use policies of each connected carrier and communications provider, including messaging registration and sender-identification requirements.
L.4 Product-Specific Disclaimers
Telephony, messaging, and call recording are subject to recording- and monitoring-consent laws that vary by jurisdiction, and several states require the consent of all parties to a call. Customer is solely responsible for determining which consent regime applies to each interaction, for delivering the required call-recording and monitoring disclosures, and for configuring the Service accordingly. Dion does not provide the disclosure and does not determine consent requirements on Customer's behalf. Transcription is machine-generated and may be inaccurate or incomplete; a transcript is not a verbatim record. AI-drafted replies, summaries, and suggested resolutions require human review before transmission to any patient, payer, or third party, in accordance with Section 12.4 of the Agreement. Carrier delivery, number availability, and voice quality are third-party dependent and subject to Section 11.5 of the Agreement. The Service is not an emergency service and must not be presented to patients as a channel for emergencies.
Schedule M — Dion Membership
Availability: Limited Availability. Integration: Event Integration. Dion may supplement this Schedule with additional terms before general release.
M.1 Description of the Service
Dion Membership is a membership and coverage administration application: plan quoting using a risk-scoring model, member enrollment and plan lifecycle management, and administration of payouts to participating providers through a third-party payment provider. It emits membership, underwriting, and payout events into the Dion event bus; consistent with the platform's PHI rule, those events carry coarse risk bands and tiers and never a raw score or any clinical condition.
M.2 Data Categories
Dion Membership processes member enrollment and identifying information, plan, premium, and payment records, risk-tier and score-band classifications derived from member data, and participating-provider business and payout data. Member data used to produce a risk classification may constitute PHI, and where it does, Dion processes it as a Business Associate under the BAA.
M.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) offer, market, and administer plans only in jurisdictions where Customer is authorized to do so and only under plan documents Customer has had reviewed by its own counsel; (b) not represent any plan administered through the Service as insurance unless Customer holds the authorizations required to do so; and (c) not use risk classifications produced by the Service in any manner prohibited by applicable anti-discrimination, insurance, or consumer-protection law.
M.4 Product-Specific Disclaimers
Dion is not an insurer, health plan, reinsurer, third-party administrator, insurance producer, or underwriter, does not bear risk under any plan administered through the Service, and does not provide insurance, actuarial, legal, or regulatory advice. Customer is solely responsible for plan design, plan documents, disclosures, premium setting, the determination of whether a plan constitutes insurance or a discount plan under the law of each applicable jurisdiction, and all required filings, licensure, and regulatory approvals. Risk scores, bands, and tiers are statistical outputs of a model; they are assistive and probabilistic under Section 12.4 of the Agreement, are not actuarial certifications, and must not be used as the sole basis for a coverage, eligibility, pricing, or benefit determination. Provider payouts are executed by a third-party payment provider under its own terms and are subject to Section 11.5 of the Agreement; Customer remains responsible for provider agreements, payout accuracy, and any tax reporting associated with amounts paid to providers.
Schedule N — Dion PMS Bridge
Availability: Not Generally Available. This Service is not yet generally available; the terms of this Schedule apply upon its release, and any pre-release access is provided as a Beta Feature under Section 2.6 of the Agreement.
N.1 Description of the Service
The Dion PMS Bridge is an on-premises software agent installed on a Customer server at a practice location. It connects to a locally installed legacy practice management system — configurably through that system's sanctioned developer interface or through a read-only database connection — reads incremental changes since a watermark, maps them to Dion's PHI-safe PMS event family, and transmits them outbound over HTTPS to the Dion hub's event ingest endpoint. The agent does not write to, modify, or delete records in the connected practice management system.
N.2 Data Categories
The Bridge reads PHI from the connected practice management system and transmits event data limited to identifiers, references, codes, and amounts — never clinical narrative content — to the hub. It also generates Service Data (agent health, watermark, and synchronization telemetry).
N.3 Product-Specific Restrictions
In addition to the restrictions in Section 4 of the Agreement, Customer will: (a) install and run the agent only on servers Customer controls at practice locations identified in the Order Form; (b) maintain in effect its own license and agreement with the practice management system vendor, and obtain any vendor authorization required for programmatic or database read access, and warrants under Section 5.2 of the Agreement that it has the right to grant that access; (c) not modify, decompile, or redistribute the agent binary; and (d) maintain the security of the host server, including operating-system patching, endpoint protection, and network controls.
N.4 Product-Specific Disclaimers
Dion does not warrant that Customer's practice management system vendor permits the access Customer configures, and Customer is solely responsible for its relationship with that vendor and for any consequence of that vendor restricting, revoking, or disabling access. The agent depends on the availability, schema, and version of a third-party on-premises system, on Customer's server, and on Customer's network, all of which are subject to Section 11.5 of the Agreement; vendor upgrades may change or break synchronization without notice. Data synchronized by the Bridge is incremental and may lag the source system; it is not a real-time mirror, not a backup, and not a substitute for Customer's own retention and disaster-recovery obligations for its practice management system.
Contact
Dion Health Management Company LLC 450 Sutter Street, Suite 1519 San Francisco, CA 94108
- Legal: legal@dionhealth.com
- Privacy: privacy@dionhealth.com
- Security: security@dionhealth.com