Terms of Service

Last Updated: August 30, 2026 · Version 2026-08-31

1. Educational purpose only — no medical advice

MDS Command provides tools referencing CDC, CMS RAI Manual v1.20.1, and Myers and Stauffer guidance for documentation and training. It does not provide medical advice. Clinical decisions, MDS coding, and infection determinations must be validated by a licensed provider.

The software does not code MDS items, create diagnoses, alter claims, or make revenue-driven recommendations. All drafts are review-only until a qualified user accepts them in the source system of record.

2. No affiliation

MDS Command is an independent educational resource. It is not affiliated with, endorsed by, or sponsored by CMS, CDC, or Myers and Stauffer.

3. Accounts and access

You are responsible for maintaining the confidentiality of your facility credentials. Roles (CNA, LPN, RN, Infection Preventionist, DON, Administrator) must be assigned correctly. You must enable MFA where required. Sessions automatically log off after 15 minutes of inactivity. Access is scoped to your facility; facility data is isolated at the database layer.

4. Customer responsibilities

The customer is responsible for the accuracy of clinical records entered, for validating all assistive output, for timely deactivation of departing staff, and for maintaining its own policies for survey and regulatory submission.

5. HIPAA & BAA

If you are a Covered Entity under HIPAA and use PHI in the application, you must execute our Business Associate Agreement (BAA) before uploading PHI. The BAA is incorporated by reference; where these Terms conflict with the BAA, the BAA controls. Contact us to execute.

6. Audit records

Access, exports, approvals, and AI dispositions are written to an append-only audit log that cannot be edited or deleted by any application user, and is retained for six years.

7. SMS compliance (TCPA)

If you opt in to SMS alerts: message and data rates may apply, and message frequency varies. Reply STOP to opt out at any time; reply HELP for help. We maintain delivery receipts and opt-out records for compliance proof.

8. Breach notification

We will notify you within 24 hours of discovery of a confirmed breach of unsecured PHI, per the BAA.

9. Data return and destruction

Upon termination, upon written request, we will return or securely destroy PHI within 30 days, except where retention is required by law (for example, 6-year audit logs).

10. De-identified data

We will not use your facility's identifiable data for case studies or marketing without your prior written authorization. We may use de-identified, aggregate data per 45 CFR §164.514.

11. Disclaimer of warranties

Provided "as is" for educational support.

These terms are a product description drafted for review by the customer's counsel; they are not legal advice.