This SLA forms part of the Master Services Agreement between Caresoft Systems Private Limited and the Hospital. Capitalised terms have the meaning given there and in the Intended Use & Clinical Safety Statement.
PLATFORM AVAILABILITY IS NOT PATIENT SAFETY.
Bedside monitors, ventilators and their alarms operate independently of this Platform and are unaffected by any outage described in this document. Patient safety during a Platform outage is maintained by bedside monitoring and the Hospital's downtime procedure — not by this SLA.
Service credits compensate for a commercial shortfall. They are not, and must never be treated as, a measure of clinical risk.
This SLA applies to production deployments at sites that have passed the Go-Live Gate under the Master Services Agreement §4, for a Hospital in good standing. It does not apply to pilot, pre-go-live, test or training environments, or to any period during which the Platform is used under a signed go-live exception.
Buffered data is not lost data. If the Platform is unavailable but edge agents are running, device data continues to be buffered locally and uploads on restoration. Loss of visibility is not loss of record. This distinction matters when assessing the clinical impact of an outage.
| Service | Monthly Uptime | Permitted downtime / month |
|---|---|---|
| Ingest API — acceptance and persistence of device data | [99.9]% | ~43 m |
| Clinical portal — command board and patient views | [99.9]% | ~43 m |
| Notification dispatch — generation and handover to the delivery channel | [99.5]% | ~3 h 39 m |
| Admin and client portals | [99.5]% | ~3 h 39 m |
| Reporting, export and scheduled reports | [99.0]% | ~7 h 18 m |
Ingest is committed higher than viewing, deliberately. If clinicians temporarily cannot view data, the record can still be reconstructed afterwards. If ingest fails and edge buffers overflow, the data is gone permanently. Protecting the record takes priority over protecting the view.
Notification dispatch covers Caresoft handing the message to the delivery channel. Actual delivery by email, SMS or WhatsApp providers is outside our control and outside this SLA — see Intended Use §7.
| S0 — Patient safety | Any issue that has caused, or could reasonably cause, patient harm. Includes: data attributed to the wrong patient; incorrect physiological values displayed; a score computed wrongly; a notification that should have fired and did not; loss of a patient's clinical record; or any defect the Hospital's Clinical Owner designates as a patient safety concern. |
| S1 — Critical | Ingest or clinical portal unavailable across a site; total loss of device data flow; command centre unable to see any patient. No workaround. |
| S2 — High | Major function impaired — one ICU or several beds without data; notifications not generating; export or scheduled reports failing; severe degradation with a workaround available. |
| S3 — Medium | Single bed or single device affected; a non-critical feature failing; limited clinical impact with a workaround. |
| S4 — Low | Questions, configuration requests, cosmetic issues, documentation, enhancement requests. |
The Hospital's Clinical Owner may designate any issue as S0, and that designation is not disputed at the time. Caresoft responds at S0 first and reviews classification afterwards. Arguing severity while a patient may be at risk is never acceptable.
Caresoft assigns the initial severity for all other issues, applying the Hospital's assessment in good faith. Severity may be revised as impact becomes clear, with reasons recorded. Response clocks pause only while Caresoft is awaiting information reasonably requested from the Hospital, and never pause for S0.
Response means first substantive human contact by a person able to act. Restoration means service restored or a clinically acceptable workaround in place, not necessarily root cause resolved.
| Severity | Response | Restoration target | Update frequency | Coverage |
|---|---|---|---|---|
| S0 | [15] minutes | [2] hours or documented mitigation | Every [30] min | 24×7×365 |
| S1 | [30] minutes | [4] hours | Every [60] min | 24×7×365 |
| S2 | [2] hours | [1] business day | Daily | 24×7 |
| S3 | [8] business hours | [5] business days | Every [2] days | Business hours |
| S4 | [2] business days | Next release or as agreed | On change | Business hours |
S0 and S1 must be raised by phone as well as by ticket. Email or ticket alone does not start an S0 or S1 clock. Restoration targets are targets, not guarantees; where a target will be missed, Caresoft notifies the Hospital before it expires with a revised estimate and the reason.
| Level | Trigger | Caresoft contact |
|---|---|---|
| L1 | Ticket raised | Support engineer on duty |
| L2 | Response target missed, or S2 unresolved [4] hours | Support lead — [name, mobile] |
| L3 | S1 unresolved [2] hours, or any S0 on raising | Engineering manager — [name, mobile] |
| L4 | S0 unresolved [2] hours, or S1 unresolved [4] hours | CTO / Head of Delivery — [name, mobile] |
| L5 | S0 unresolved [4] hours, or repeat S0 | Director / CEO — [name, mobile] |
The Hospital provides equivalent named contacts with mobile numbers for its Clinical Owner, Technical Owner and command centre lead. Both parties keep the matrix current and review it at each service review. An out-of-date escalation matrix is itself a service risk.
| Purpose | Channel | Availability |
|---|---|---|
| Patient safety (S0) | Phone [24×7 number] then [email protected] | 24×7×365 |
| Critical technical (S1) | Phone 7400390415 then ticket | 24×7×365 |
| Standard support (S2–S4) | [email protected] / portal | Per severity |
| Device integration | [email protected] | Business hours |
| Security incident | [email protected] + 7400390415 | 24×7 |
| Status | [status page URL] | Continuous |
| Measure | Commitment |
|---|---|
| Backup frequency | [Continuous transaction log + full daily] |
| Backup retention | [35] days rolling, plus long-term copies per the retention schedule |
| Backup location | Encrypted, within India, separate failure domain from production |
| RPO (maximum data loss) | [15] minutes server-side. Edge buffering typically reduces effective loss to zero for device data |
| RTO (time to restore service) | [4] hours for a full platform failure |
| Restore testing | At least [quarterly], with results available to the Hospital |
| DR exercise | At least [annually], report shared with the Hospital |
The Hospital may request evidence of the most recent restore test at any time. RPO and RTO are Platform-level objectives and do not substitute for the Hospital's own clinical continuity arrangements.
The following are not Downtime and do not attract credits:
Where a defect originates on the Hospital side but Caresoft's monitoring detected it and Caresoft did not notify the Hospital in reasonable time, Caresoft does not rely on the exclusion for the period of delayed notification. Integrity monitoring exists to be acted upon.
| Monthly Uptime achieved (per service) | Credit (% of Eligible Fee) |
|---|---|
| Below commitment but ≥ 99.5% | [10]% |
| Below 99.5% but ≥ 99.0% | [20]% |
| Below 99.0% but ≥ 98.0% | [35]% |
| Below 98.0% | [50]% |
Service credits are the sole financial remedy for availability failures only. They are not a remedy for, and do not limit, any claim relating to patient harm, data loss, confidentiality breach, or breach of the Data Processing Addendum. Those are governed by Master Services Agreement §20 and §21 and are expressly outside this credit regime.
Submit to [email protected] within [30] days of the end of the affected month, with site, service, dates and times with time zone, and the ticket reference raised at the time. Caresoft responds within [15] working days. Where Caresoft's own monitoring shows a commitment was missed, Caresoft will apply the credit without requiring a claim and report it in the monthly service review.
If a service misses its commitment in [two (2)] consecutive months, or in [three (3)] months in any rolling twelve, or if [two (2)] S0 incidents attributable to Caresoft occur within any rolling six months, the Hospital may:
This is in addition to credits already earned and does not limit any other remedy available for patient harm or data breach.
Caresoft's ability to meet these targets depends on the Hospital:
Where the Hospital's failure to meet these obligations materially prevents Caresoft from responding, targets are extended by the period of that prevention — except for S0, where Caresoft proceeds regardless and any dispute is resolved afterwards.
This SLA may be amended by written agreement, or by Caresoft on [60] days' notice effective at renewal. Any change reducing a commitment entitles the Hospital to terminate the affected scope without penalty before it takes effect. Commitments will not be reduced during a term for which the Hospital has prepaid.