# Hospital paperwork for CareFix

Two documents. The first is signed once per hospital before CareFix is enabled there. The second is the consent CareFix asks for before any High-risk change. Both are drafts prepared for Caresoft's counsel to review and put on Caresoft letterhead; they are not legal advice.

---

## A. Addendum to the software support agreement — AI-assisted data correction

**Between** Caresoft Systems Private Limited ("Caresoft") **and** __________________________ ("the Hospital"), as an addendum to the Software Licence and Support Agreement dated __________, in respect of Caresoft HIS.

**1. Purpose.** Caresoft operates CareFix, a support tool that helps Caresoft's support engineers diagnose and correct data errors in the Hospital's Caresoft HIS database more quickly and with a complete audit trail.

**2. How it works.**
   a. CareFix connects to the Hospital's HIS database using two dedicated SQL logins created by the Hospital: a read-only login used for diagnosis, and a second login that can execute only the CareFix correction procedure and nothing else.
   b. An AI service (Anthropic's Claude API) is used to interpret the support request, read data and draft a proposed correction. The AI cannot write to the Hospital's database. It has no direct connection to it.
   c. Every correction is reviewed and approved by named Caresoft staff before it runs, is applied inside a single transaction, is recorded in the Hospital's own database in table `carefix.CF_CHANGE_LOG`, and can be reversed.
   d. CareFix may change only the columns the Hospital has listed in `carefix.CF_ALLOWLIST` in its own database. The Hospital controls that list and may change it at any time. CareFix does not insert or delete rows.
   e. Where the Hospital's server is on-premise, a CareFix Agent runs on the Hospital's own machine and makes only outbound connections. No inbound access to the Hospital's network is required, and the Hospital can stop the agent at any time.

**3. Personal data.** For the purposes of the Digital Personal Data Protection Act, 2023, the Hospital is the Data Fiduciary and Caresoft is its Data Processor, acting only on the Hospital's instructions as set out in the main agreement and this addendum.
   a. Data accessed is limited to what is needed to diagnose and correct the reported issue.
   b. Patient-identifying fields (name, mobile number, Aadhaar, ABHA, address, e-mail) are masked before any data is sent to the AI service, and are stored masked in CareFix's query log.
   c. Query results sent to the AI service are not used to train any AI model. Caresoft's agreement with the AI provider prohibits such use.
   d. CareFix stores in its own database: the support conversation, the queries run and their masked results, the proposed and executed changes with before and after values, approvals, and a copy of the affected rows taken immediately before a change (kept for rollback).
   e. Retention: query logs and row snapshots are retained for ____ months (suggested: 12), audit records for ____ months (suggested: 36), then deleted. On termination, Caresoft will delete or return the Hospital's CareFix records within 30 days on written request.
   f. Sub-processors: the AI service provider named above, and no other, without prior written notice to the Hospital.
   g. Location of processing: CareFix servers are located in India. The AI service may process the masked request outside India.

**4. Approvals and consent.** Corrections are classified Low, Medium or High risk. High-risk corrections, which include any change to amounts, receipts, refunds or ledger-related data, require the Hospital's written consent in the form at Annexure B before they are executed. The Hospital will nominate at least one authorised person for this purpose:

   Name: ____________________  Designation: ____________________  E-mail / mobile: ____________________

**5. The Hospital's responsibilities.** Creating the two SQL logins, approving and maintaining the allow-list, nominating the authorised person above, and checking corrected data after Caresoft reports it fixed.

**6. Limits.** CareFix corrects data errors. It does not replace the Hospital's own verification, and Caresoft's liability remains as set out in the main agreement. Caresoft will not use CareFix to change clinical records except where the Hospital specifically requests a correction and an authorised person consents in writing.

**7. Security.** Caresoft maintains ISO 27001 certification and applies it to CareFix. Database credentials are stored encrypted. Access is limited to named Caresoft staff, with two-step sign-in for anyone who can approve a change. Caresoft will notify the Hospital without undue delay, and in any case within 72 hours, of any personal data breach affecting the Hospital's data.

**8. Audit.** On request, Caresoft will provide the Hospital with a report of every CareFix change made to its database in a given period. The Hospital may also read `carefix.CF_CHANGE_LOG` in its own database at any time.

**9. Term.** This addendum runs with the main agreement. Either party may suspend CareFix for the Hospital on written notice, without affecting the rest of the agreement.

For Caresoft Systems Private Limited &nbsp;&nbsp;&nbsp;&nbsp; For the Hospital

Name: ____________________ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Name: ____________________

Designation: ______________ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Designation: ______________

Date: ____________________ &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Date: ____________________

---

## B. Consent for a data correction (Annexure B)

Fill this in, have the authorised person sign it, and upload it to the fix in CareFix. One form per correction.

**Hospital:** ____________________  **CareFix ticket:** CF-__________  **Fix number:** #______

**What is wrong**

_(Copy the fix summary from CareFix)_

**What will change**

| Record | Field | From | To |
|---|---|---|---|
|  |  |  |  |
|  |  |  |  |

**Effect on accounts.** Does this change amounts, receipts, refunds or anything already posted to Tally? Yes / No
If yes, what the Hospital's accounts team must do: ____________________________________________

**Reversal.** CareFix keeps a copy of these records as they are now and can reverse this change on request, provided the same values have not been changed again in the meantime.

**Consent.** I confirm that I am authorised by the Hospital, that the change described above is correct and required, and that the Hospital asks Caresoft to apply it.

Name: ____________________  Designation: ____________________

Signature: ________________  Date: ____________  Mobile / e-mail: ____________________

_(A signed scan, photo or an e-mail from the authorised person's official address is acceptable. Attach it to the fix in CareFix before approval.)_
