Legal
HealthSherpa ONE API Terms of Service
These HealthSherpa ONE API Terms of Service (these “Terms”) constitute a binding agreement between Geozoning Inc., d/b/a HealthSherpa (“HealthSherpa,” “we,” “us,” or “our”) and the individual or entity accessing or using the HealthSherpa ONE API (“Developer,” “you,” or “your”). By registering for API Credentials, accessing the API, or using any Application built on the API, you accept and agree to be bound by these Terms. If you are agreeing on behalf of an entity, you represent that you have authority to bind that entity, in which case “Developer” refers to that entity.
IF YOU DO NOT AGREE TO THESE TERMS, DO NOT REGISTER FOR OR USE THE API.
1. Definitions
- “API”
- means the HealthSherpa ONE suite of application programming interfaces made available at one.healthsherpa.com, and any related documentation, sample code, and software development kits, as may be modified from time to time.
- “Application”
- means any website, software application, product, or service developed by Developer that accesses or uses the API.
- “Credentials”
- means the API keys, tokens, client secrets, or other access credentials issued to Developer to authenticate to the API.
- “Consumer”
- means an individual who uses, or on whose behalf Developer uses, the API to obtain a quote, initiate or manage an Enrollment Session, or check Policy Status.
- “Enrollment Session”
- means an API-facilitated session through which a Consumer’s selection of, application for, or enrollment in a health plan is initiated, submitted, or modified, including plan switches and special enrollment period submissions.
- “Marketplace Data”
- means data made available through the API that originates from or reflects data obtained from the federal Health Insurance Marketplace or a state-based Marketplace, including eligibility, quoting, enrollment, and policy status data.
- “PHI”
- means “protected health information” as defined under HIPAA.
- “HIPAA”
- means the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended.
- “Policy Status”
- means data reflecting the status of a Consumer’s health insurance policy, including enrollment, effective date, payment, and termination status.
- “Quoting Data”
- means plan, pricing, and eligibility estimate data returned in response to a quote request via the API.
- “Confidential Information”
- has the meaning given in Section 13.
2. Eligibility and Registration
2.1 Eligibility.
You must be at least 18 years old and capable of forming a binding contract to register for the API. If registering on behalf of an entity, you must be authorized to bind that entity.
2.2 Registration Information.
You must provide accurate, current, and complete information about yourself or your entity and your intended use case for the API — including which endpoint categories (quoting, Enrollment Sessions, or Policy Status) you intend to use and how — and must promptly update this information if it changes. HealthSherpa may request additional information about your use case at any time and may condition, delay, or deny issuance of Credentials, or suspend or revoke Credentials already issued, based on the information provided or its absence.
2.3 Credentials.
HealthSherpa will issue Credentials to you upon successful registration. You are solely responsible for maintaining the confidentiality and security of your Credentials and for all activity that occurs using them. You must notify HealthSherpa immediately at security@healthsherpa.com of any known or suspected unauthorized use of your Credentials.
2.4 No Guarantee of Access.
Self-service registration does not guarantee approval. HealthSherpa may decline to issue Credentials, or may issue Credentials subject to additional conditions (including execution of a Business Associate Agreement under Section 7), in its reasonable discretion, particularly where a use case involves Enrollment Session or Policy Status endpoints.
3. License Grant
Subject to your compliance with these Terms, HealthSherpa grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license during the Term to: (a) access and use the API solely to develop, test, and operate your Application for the use case disclosed in your registration; and (b) use HealthSherpa’s API documentation solely to support that use. All rights not expressly granted are reserved.
4. Restrictions
You will not, and will not permit any third party to:
- use the API for any use case other than the one disclosed at registration without HealthSherpa’s prior written consent;
- reverse engineer, decompile, or attempt to derive the source code of the API or any underlying HealthSherpa system;
- exceed applicable rate limits, or interfere with or disrupt the integrity or performance of the API or the systems of HealthSherpa or its carrier or Marketplace partners;
- sublicense, resell, or provide standalone access to the API to any third party other than through the intended functionality of your Application;
- use the API to build a product that is competitive with HealthSherpa’s core Agent Platform or web-broker services, or to replicate substantially all of the API’s functionality;
- misrepresent your identity, affiliation with HealthSherpa, or the nature of your Application, including through use of HealthSherpa’s name or trademarks in a manner suggesting endorsement, sponsorship, or affiliation not authorized in writing;
- use the API in any manner that violates, or that causes HealthSherpa, any Consumer, or any third party to violate, any applicable law, including federal Marketplace regulations, HIPAA, state insurance law, or state or federal privacy or telemarketing law; or
- use the API to scrape, harvest, or compile Marketplace Data, Quoting Data, or Consumer information for any purpose other than the disclosed use case, including resale, unrelated marketing, or aggregation or benchmarking products.
5. Marketplace Data Use
5.1 Permitted Purpose Only.
Marketplace Data, Quoting Data, and Policy Status data obtained through the API may be used solely to provide the disclosed use case to the Consumer to whom the data pertains, or at whose direction it was obtained. You will not use such data for any other purpose, including reselling it, using it to build competing data products, or using it for advertising or marketing not directly related to the transaction in which it was obtained, without HealthSherpa’s prior written consent.
For development, integration testing, and non-production evaluation of your Application for the disclosed use case, you may use Quoting Data and other reference data returned by quoting and lookup endpoints when your requests use synthetic or representative test inputs that do not identify a real Consumer (for example, fictional household members, placeholder contact details, or sample values shown in HealthSherpa’s API documentation). You may use such results only to build, test, and evaluate your Application within your organization or a controlled development environment, and not as live consumer-facing quotes, marketing, or a standalone data product. This paragraph does not permit use of Policy Status data, Enrollment Session data, or other Consumer-specific Marketplace Data for testing except to serve the Consumer to whom that data pertains.
5.2 Retention and Deletion.
You will retain Marketplace Data only as long as reasonably necessary for the disclosed use case (or as required by applicable law) and will delete or de-identify it thereafter, and upon HealthSherpa’s request or termination of these Terms, except to the extent you are separately required by law to retain it (for example, consent-documentation retention requirements applicable to licensed agents).
6. Enrollment Integrity and Consumer Consent
6.1 No Enrollment or Switch Without Consent.
If your use case includes Enrollment Sessions, you must obtain and retain documented, verifiable Consumer consent before initiating, submitting, or modifying any Enrollment Session on the Consumer’s behalf, including any plan switch or special enrollment period submission. You must be able to produce this consent documentation to HealthSherpa, CMS, or a state department of insurance upon request.
6.2 Licensing.
If your Application, or any end customer of your Application, facilitates enrollment on behalf of Consumers in a manner that requires a state insurance producer license or CMS Marketplace registration, you represent and warrant that you and any such end customer hold and will maintain all licenses, appointments, and registrations required by applicable law. HealthSherpa does not verify, and disclaims any obligation to verify, such licensure, and Developer and its end customers remain independent third parties responsible for their own regulatory compliance.
6.3 Monitoring and Cooperation.
HealthSherpa may monitor API usage patterns for indicia of unauthorized enrollment, unauthorized plan switching, or other fraudulent or non-compliant activity. You will cooperate fully and promptly with any HealthSherpa, CMS, or state department of insurance inquiry or investigation relating to your use of the API, including by providing consent documentation and usage records upon request.
7. HIPAA and Protected Health Information
7.1 BAA Requirement.
If your use case involves accessing, creating, receiving, maintaining, or transmitting PHI in a manner that makes you a “business associate” (as defined under HIPAA) of HealthSherpa or of a covered entity on whose behalf HealthSherpa acts, production access to the applicable API endpoints (including Enrollment Session and Policy Status endpoints) is conditioned on your execution of HealthSherpa’s then-current Business Associate Agreement prior to activation. HealthSherpa may suspend or decline to activate such endpoints until a Business Associate Agreement is executed.
7.2 No PHI in Non-Production Environments.
You will not submit real Consumer PHI to any sandbox, testing, or non-production instance of the API.
8. Data Security
You will implement and maintain administrative, physical, and technical safeguards appropriate to the sensitivity of the data accessed through the API, including encryption of data in transit and at rest, access controls limiting access to personnel with a legitimate need, and prompt patching of known vulnerabilities. You will notify HealthSherpa without undue delay, and in no event later than 24 hours after discovery, of any actual or reasonably suspected unauthorized access to, or acquisition, disclosure, or loss of, Marketplace Data, PHI, or Credentials, and will cooperate with HealthSherpa’s investigation and any required notifications.
9. Consumer Contact and Marketing Compliance
If your use case involves generating, submitting, or contacting Consumer leads, you represent and warrant that you have obtained all consents required under the Telephone Consumer Protection Act and other applicable telemarketing, e-mail marketing, and consumer-protection laws before contacting any Consumer, and that your marketing practices comply with applicable state insurance marketing rules and CMS web-broker marketing standards. You are solely responsible for such compliance, and HealthSherpa’s provision of API access does not constitute a representation that your marketing practices are compliant.
10. Compliance with Law
You will comply with all applicable federal, state, and local laws and regulations in connection with your use of the API, including CMS regulations governing the Health Insurance Marketplace, HIPAA, applicable state insurance laws, and applicable privacy laws.
11. Intellectual Property
As between the parties, HealthSherpa retains all right, title, and interest in and to the API, its documentation, and all related intellectual property, including all Marketplace Data formatting, schemas, and HealthSherpa trademarks. No rights are granted except as expressly set forth in Section 3. You retain all right, title, and interest in your Application, exclusive of any HealthSherpa intellectual property incorporated therein.
12. Fees
Access to the API may be offered at no cost, or subject to fees, usage limits, or tiered pricing as published by HealthSherpa or agreed in an applicable order form. HealthSherpa may introduce, modify, or eliminate fees for particular endpoints or usage tiers on prospective notice.
13. Confidentiality
“Confidential Information” means non-public information disclosed by one party to the other that is designated as confidential or that would reasonably be understood to be confidential given its nature, including API documentation not generally published, security practices, and the terms of any negotiated order form. Confidential Information excludes information that is or becomes public through no fault of the receiving party, was already known to the receiving party without confidentiality restriction, or is independently developed. Each party will use the other’s Confidential Information solely to perform under these Terms and will protect it using at least reasonable care.
14. Monitoring, Audit, and Suspension
14.1 Monitoring.
HealthSherpa may monitor your use of the API for compliance with these Terms.
14.2 Audit.
On reasonable notice, and no more than once per year absent a good-faith belief of noncompliance, HealthSherpa may request documentation or other evidence of your compliance with Sections 5, 6, 7, 8, and 9, which you will provide within a reasonable time.
14.3 Suspension.
HealthSherpa may immediately suspend your Credentials and API access, without prior notice, if HealthSherpa reasonably believes suspension is necessary to prevent harm to Consumers, HealthSherpa, a carrier partner, or the Marketplace, including where HealthSherpa suspects unauthorized enrollment or plan-switching activity, a security incident, or a violation of Section 4, 5, 6, 7, or 9. HealthSherpa will provide notice of the suspension and, where practicable, the reason for it, as soon as reasonably possible thereafter.
15. Disclaimer of Warranties
THE API AND ALL DATA PROVIDED THROUGH IT (INCLUDING QUOTING DATA, MARKETPLACE DATA, AND POLICY STATUS DATA) ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR ACCURACY. HEALTHSHERPA DOES NOT WARRANT THAT THE API WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, OR THAT QUOTING DATA OR POLICY STATUS DATA WILL BE CURRENT, COMPLETE, OR ACCURATE AT THE TIME RECEIVED BY DEVELOPER OR RELIED UPON BY A CONSUMER.
16. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW: (A) NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, ARISING OUT OF OR RELATING TO THESE TERMS OR THE API, REGARDLESS OF THE THEORY OF LIABILITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES; AND (B) HEALTHSHERPA’S AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS WILL NOT EXCEED THE GREATER OF (I) THE FEES PAID BY DEVELOPER TO HEALTHSHERPA FOR THE API IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO LIABILITY, OR (II) FIVE HUNDRED DOLLARS ($500). THE FOREGOING LIMITATIONS WILL NOT APPLY TO DEVELOPER’S INDEMNIFICATION OBLIGATIONS UNDER SECTION 17, DEVELOPER’S BREACH OF SECTIONS 4, 5, 6, 7, OR 9, OR EITHER PARTY’S BREACH OF SECTION 13.
17. Indemnification
You will defend, indemnify, and hold harmless HealthSherpa and its officers, directors, employees, and agents from and against any third-party claim, and all associated losses, liabilities, damages, costs, and expenses (including reasonable attorneys’ fees), arising out of or relating to: (a) your Application; (b) your or your end customers’ use of the API, including any unauthorized enrollment or plan switch attributable to your Application; (c) your breach of these Terms; or (d) your violation of applicable law, including HIPAA, CMS Marketplace regulations, state insurance law, or telemarketing or privacy law.
18. Term and Termination
18.1 Term.
These Terms commence when you first accept them and continue until terminated as provided herein.
18.2 Termination for Convenience.
Either party may terminate these Terms for convenience on thirty (30) days’ written notice.
18.3 Termination for Cause.
HealthSherpa may terminate or suspend these Terms and your API access immediately upon notice if you breach Section 4, 5, 6, 7, or 9, or if required to do so by CMS, a state department of insurance, or applicable law.
18.4 Effect of Termination.
Upon termination, your license under Section 3 immediately ends, and you must cease all use of the API and, except as required by applicable law, delete all Marketplace Data, PHI, and Credentials in your possession. Sections 5.2, 7, 11, 13, 15, 16, 17, and 20 survive termination.
19. Modifications
HealthSherpa may modify these Terms or the API (including by adding, changing, or deprecating endpoints) at any time. Material changes to these Terms will be provided on reasonable prior notice (for example, by posting an updated version with a new “Last Updated” date and, where practicable, direct notice to registered developers). Continued use of the API after the effective date of a change constitutes acceptance. HealthSherpa will provide reasonable advance notice before deprecating an API version or endpoint that Developer is actively using in production, except where continued availability would create a legal or security risk.
20. General Provisions
20.1 Relationship of the Parties.
The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship. Except where Section 7.1 requires a Business Associate Agreement, nothing in these Terms makes Developer a business associate, subcontractor, affiliate, or agent of HealthSherpa.
20.2 Assignment.
You may not assign or transfer these Terms without HealthSherpa’s prior written consent; HealthSherpa may assign these Terms in connection with a merger, acquisition, or sale of substantially all of its assets.
20.3 Governing Law; Dispute Resolution.
These Terms are governed by the laws of the State of California, without regard to conflicts-of-laws principles. Any dispute arising out of or relating to these Terms will be resolved by binding arbitration administered by JAMS under its Streamlined Arbitration Rules, seated in Sacramento, California, except that either party may bring an individual action in small claims court for disputes within that court’s jurisdiction.
20.4 Notices.
Notices to HealthSherpa must be sent to legal@healthsherpa.com. Notices to Developer will be sent to the contact information provided at registration.
20.5 Entire Agreement; Order of Precedence.
These Terms, together with any applicable Business Associate Agreement, order form, or API documentation incorporated by reference, constitute the entire agreement between the parties regarding the API and supersede all prior agreements on that subject. In the event of a conflict, a Business Associate Agreement executed under Section 7.1 controls with respect to PHI, and these Terms control otherwise.
20.6 Severability; Waiver.
If any provision of these Terms is held unenforceable, the remaining provisions remain in full force and effect. No waiver of any provision is effective unless made in writing.