Skip to main content
Legal

Service Level Agreement

Hosting & Development — Version 3.0 — Last updated August 26, 2026

1.0 Agreement Overview

This Agreement represents a Service Level Agreement ("SLA" or "Agreement") between Medical Web Experts ("COMPANY") and its client ("CLIENT") for the provisioning of hosting services and custom software development support required to support and sustain a hosted website, hosted software, custom product, or custom software development (collectively, the "Services"). This SLA is only valid as a supplementary agreement to an active Master Services Agreement ("MSA") between COMPANY and CLIENT.

This SLA remains valid until superseded by a revised agreement mutually endorsed by the parties, or upon termination of the MSA.


2.0 Goals & Objectives

The purpose of this SLA is to ensure that the proper elements and commitments are in place to provide consistent IT service support and delivery to the CLIENT by the COMPANY.

The objectives of this SLA are to:

  • Provide clear reference to service ownership, accountability, roles and/or responsibilities
  • Present a clear, concise and measurable description of service provision to the CLIENT
  • Match perceptions of expected service provision with actual service support and delivery

3.0 Definitions

"Downtime", is defined as a period during which a Hosted Environment is not functional or does not work, that is outside of scheduled maintenance services. This does not include a situation where a single feature or function that is not crucial to the operation of the Hosted Environment is not functioning, but a larger issue which renders the Hosted Environment unusable. For purposes of Service Credits, "Downtime" does not include periods during which the Hosted Environment is not functional due to Force Majeure events, acts or omissions of CLIENT, or issues not caused by, or beyond the control of, COMPANY, including the functionality of CLIENT's API, third party integrations, or other acts or omissions of third parties.

"Uptime", is defined as a period during which a Hosted Environment is operating normally, and while this may include bugs, the bugs are not preventing users from using the system for most of its primary functions.

"Hosting Services", means the ongoing hosting, infrastructure, and platform support COMPANY provides for CLIENT's website, software, or product as described in Section 6.2, and to which the Uptime guarantees and Service Credits in this SLA apply.

"Custom Development Support", means software development, custom features, integrations, enhancements, or other bespoke engineering work performed by COMPANY for CLIENT, which is distinct from ongoing Hosting Services and is addressed separately in Section 6.4.

"Security Package", means the proactive security monitoring, patching, and incident response coverage offered by COMPANY as an optional addition to CLIENT's maintenance plan, as further described in the applicable Statement of Work, and to which Section 6.6 applies.


4.0 Service Agreement

The following detailed service parameters are the responsibility of the COMPANY in the ongoing support of this SLA.

4.1 Service Scope

This SLA applies only to the Services described in this SLA or an applicable Statement of Work. This SLA does not apply to any software, services, or other parts of an information technology system that are not purchased from or managed by COMPANY.

For CLIENT-hosted environments, or COMPANY-hosted environments dependent on CLIENT-hosted resources, where the CLIENT-hosted resource is considered to be the cause of the outage, COMPANY will provide a reasonable amount of support to attempt to identify and resolve any related issues or outages. A reasonable amount of support is defined as up to two (2) hours of support per outage, after which a mutually agreed upon plan will be implemented.

For COMPANY-hosted environments, COMPANY will resolve issues with no limit to the effort or time required to resolve the issue, subject to Section 6.4 for Custom Development Support.

COMPANY will rectify service issues with the Services, except where:

  • The issue has been caused by CLIENT's use of the Services in a manner that is contrary to COMPANY training, documentation, or any other instructions issued by COMPANY
  • The issue has been caused by CLIENT's use of the Services in a manner that is contrary to industry standard cybersecurity safety measures and best practices
  • CLIENT has prevented COMPANY from performing maintenance on the Services, or has been unresponsive or unwilling to update to a COMPANY recommended stable version within a nine (9) month period from its release
  • The issue has been caused by Third Party Products

The following Services are included in this SLA:

  • Manned telephone support
  • Monitored email support
  • Support desk / ticket system

5.0 Responsibilities

5.1 CLIENT Responsibilities

CLIENT responsibilities and/or requirements in support of this SLA include:

  • Use the Services as intended under the MSA and this SLA
  • Payment for all support, maintenance, and development costs according to the MSA and any applicable Statement of Work, where no invoice is past due
  • In case of a high priority alert, ensure the availability of a sufficient number of skilled CLIENT employees to cooperate with COMPANY
  • Reasonable availability of CLIENT representative(s) when resolving a service-related incident or request
  • Notify COMPANY of issues or problems in a timely and descriptive manner

5.2 COMPANY Responsibilities

COMPANY responsibilities and/or requirements in support of this SLA include:

  • Meeting response times associated with service related incidents
  • Appropriate notification to CLIENT for all scheduled maintenance
  • Best effort in diagnosis and repair of incidents, including critical decision making in emergency situations
  • Maintain clear and timely communication with CLIENT at all times

5.3 Service Credit Exceptions

CLIENT shall not receive any Service Credit under this SLA in connection with any failure or deficiency caused by or associated with:

  1. Circumstances beyond COMPANY's reasonable control and where COMPANY has implemented industry best practices to prevent such issues, including, without limitation, acts of any governmental body, war, insurrection, sabotage, armed conflict, embargo, fire, flood, strike or other labor disturbance, interruption of or delay in transportation, unavailability of or interruption or delay in telecommunications or third party services, virus attacks or hackers, failure of third party software, or inability to obtain raw materials, supplies, or power used in or equipment needed for provision of this SLA
  2. Scheduled maintenance and emergency maintenance and upgrades. Every effort will be made to keep downtime to a minimum during maintenance periods and, when possible, COMPANY will notify CLIENT in advance of the expected downtime
  3. DNS issues outside the direct control of COMPANY
  4. CLIENT's acts or omissions (including acts or omissions of others engaged or authorized by CLIENT), including, without limitation, custom scripting or coding, negligence, willful misconduct, or use of the Services in breach of this SLA
  5. DNS propagation
  6. Outages elsewhere on the Internet that hinder access to CLIENT's account. COMPANY is not responsible for browser or DNS caching that may make CLIENT's site appear inaccessible when others can still access it
  7. Issues with CLIENT's SMTP and/or business email service

6.0 Service Management

Effective support of in-scope Services is a result of maintaining consistent service levels. The following sections provide relevant details on service availability, monitoring, and related components.

6.1 Support Availability

  • Regular business hours are 9:00 am to 5:00 pm Eastern Time, Monday to Friday, except Federal U.S. Holidays and observances as defined by the U.S. Government
  • Telephone support: conducted during business hours
  • Email support and Support Desk: monitored during business hours. Any email received outside office hours will be collected, and best efforts will be made to respond. However, no action is guaranteed until the next working day
  • Support desk / ticket system: CLIENT may submit tickets at any time

6.2 Hosting Services, Availability

COMPANY's Uptime guarantee for Hosting Services depends on the hosting tier under CLIENT's MSA or applicable Statement of Work.

MWE Enterprise Hosting

COMPANY guarantees 99.5% Uptime each month, 24 hours a day, 7 days a week ("Agreed Hours of Service"). Uptime is measured based on the monthly average of availability, rounded down to the nearest minute, and calculated as follows:

Uptime % = ((Agreed Hours of Service - hours of Downtime) / Agreed Hours of Service) x 100%

MWE Basic and Professional Hosting

COMPANY guarantees 99% Uptime each month, 24 hours a day, 7 days a week ("Agreed Hours of Service"). Uptime is measured using the same formula above.

MWE Custom Hosting

Because custom hosting environments vary in the level of access, control, and architecture COMPANY has over the platform, COMPANY will agree to an Uptime commitment, if any, on a case by case basis under the applicable Statement of Work or MSA.

6.3 Hosting Services, Service Credits

Should Uptime fall below the guarantee in Section 6.2 in any calendar month, COMPANY will pay liquidated damages in the form of Service Credits, calculated as a percentage of CLIENT's monthly Hosting Fee, as follows:

Hosting TypeConditionCalculation
Basic and Professional HostingUptime < 98%100% of the monthly Hosting Fee
Basic and Professional HostingUptime ≥ 98% and less than 99%((99% – Uptime %) / 0.9%) × monthly Hosting Fee × 50%
Enterprise HostingUptime < 98.5%100% of the monthly Hosting Fee
Enterprise HostingUptime ≥ 98.5% and less than 99.5%((99.5% – Uptime %) / 0.9%) × monthly Hosting Fee × 50%

Custom Hosting is not subject to the Service Credit calculations above, given the absence of a fixed Uptime guarantee described in Section 6.2. Any Service Credits applicable to Custom Hosting will be set forth in the applicable Statement of Work.

To apply for a Service Credit, CLIENT must submit a request to its Support contact by email within 30 days of the end of the applicable month with the subject line "SLA Service Credit". The request must include the dates and times of the Downtime claimed. Service Credits are calculated against CLIENT's recurring monthly Hosting Fee only, and do not apply to non-recurring, milestone based, or hourly billed engagements, which are addressed under Section 6.4. Service Credits are the exclusive remedy for COMPANY's failure to meet its Uptime guarantee.

6.4 Custom Development Support

Custom Development Support covers software development, custom features, integrations, enhancements, and other bespoke engineering work performed by COMPANY that falls outside of Hosting Services.

Because custom built software is inherently more complex and variable than standardized hosting infrastructure, and may involve architecture, third party integrations, or dependencies unique to CLIENT's environment, COMPANY does not guarantee a fixed resolution time for issues arising in Custom Development Support. COMPANY will use best efforts to diagnose and resolve such issues as quickly as reasonably possible, consistent with the response times in Section 6.5, and will provide CLIENT with an estimated resolution timeline once an issue has been triaged.

Custom Development Support is not subject to the Uptime guarantees described in Section 6.2 or the Service Credits described in Section 6.3.

Custom built software may carry a greater number of potential vulnerabilities than standardized, widely deployed hosting platforms, given its bespoke nature. COMPANY will address vulnerabilities identified in code it developed as part of its ordinary support and maintenance obligations. Vulnerabilities arising from CLIENT's own custom scripting, CLIENT directed architecture decisions, or third party components outside COMPANY's control remain subject to the exceptions in Section 5.3.

6.5 Service Requests

In support of the Services outlined in this SLA, COMPANY will respond to service related incidents and/or requests submitted by CLIENT within the following time frames. These are response times, not resolution times. Resolution times are subject to the complexity and nature of the request, particularly for Custom Development Support as described in Section 6.4. Once responded to, COMPANY will make a best effort to resolve any outstanding issue as quickly as possible, including performing such resolution outside of business hours.

ClassificationDescriptionResponse Time
CriticalCritical business impact. Problem or issue that renders the Services unusable (e.g. offline)< 4 hours (business hours) / < 8 hours (non-business hours)
HighSignificant business impact. Problem or issue that impacts operation but does not render the Services unusable (e.g. slow server response)< 6 hours (business hours) / < 12 hours (non-business hours)
LowMinimal business impact. Problem or issue that does not impact operation (e.g. maintenance requests)< 96 hours (business hours)

6.5.1 Support Escalation Policy

If the normal support process does not produce the desired results, or if the problem has changed in priority, the problem can be escalated as follows:

  1. Contact the representative working on the problem and request that priority be escalated
  2. Contact the emergency support line available by calling 1-866-932-9944

6.5.2 Emergency Situation

  1. Any work performed or calls handled outside regular business hours for a problem not deemed to be the fault of COMPANY, and escalated as an emergency by CLIENT or deemed an emergency by COMPANY, may be billed at COMPANY's emergency rate, as defined in CLIENT's MSA or applicable Statement of Work
  2. Services in need of immediate resolution, including but not limited to server failure, software failure, or e-PHI risk, that are not related to an existing project or approved work order, may be completed without CLIENT's prior approval
  3. CLIENT will be provided with an emergency contact email address and phone number, forwarded to multiple parties within COMPANY's organization

CLIENT will be promptly notified in the event of an emergency situation, to the extent feasible, and COMPANY will make best efforts to identify such circumstances to ensure the best possible service.

6.5.3 Critical and Emergency Service Requests

CLIENT is instructed to initiate all critical and emergency support requests by contacting its account manager for the emergency contact information, and should then promptly submit a service desk ticket with a detailed explanation of the problem.

6.6 Security Incident Response

Some CLIENTs elect to purchase a Security Package as part of their maintenance plan. For CLIENT with an active Security Package, incident response for a suspected or confirmed security incident is included within the scope of that Security Package, as further described in the applicable Statement of Work.

For CLIENT without an active Security Package, COMPANY will still respond to and remediate a suspected or confirmed security incident involving CLIENT's Services, including any suspected or confirmed compromise of e-PHI, and will notify CLIENT in accordance with COMPANY's obligations under the Health Insurance Portability and Accountability Act (HIPAA) and the parties' Business Associate Agreement. All COMPANY time spent investigating, containing, and remediating the incident will be billed to CLIENT at COMPANY's emergency rate as defined in CLIENT's MSA or applicable Statement of Work. Consistent with Section 6.5.2, COMPANY may begin incident response work immediately and without CLIENT's prior approval, given the urgency inherent to a suspected security incident.

Billing for a security incident under this Section 6.6 does not affect or delay COMPANY's breach notification obligations to CLIENT, which will be met regardless of Security Package status or CLIENT's payment status.


7.0 Backups

COMPANY performs regular (daily, weekly, and monthly) backups for COMPANY hosted environments, as required by HIPAA and applicable U.S. state specific regulations. For more information on COMPANY's backup frequency, location, and scope, please contact COMPANY directly.


8.0 Preventive Maintenance

Preventive maintenance, including scalability, infrastructure, and security upgrades, is not counted as Downtime and therefore receives no Service Credit compensation. A program of preventive maintenance activities may be carried out by a COMPANY representative for the configured Services.


9.0 Software Updates

As software updates, patches, and fixes become available, including those addressing known security vulnerabilities, COMPANY will make such updates available to CLIENT at no additional charge for the duration of this SLA to help ensure the correct and secure functioning of the Services. Updates may be released as a stand alone release or as part of a consolidated maintenance package. Failure to pay for or facilitate the installation of applicable updates within a reasonable timeframe will disqualify CLIENT from seeking Service Credits for issues caused by unpatched software, including both COMPANY provided software and relevant third party software.


10.0 Scalability

For Hosting Services, COMPANY maintains a hosting environment designed to handle up to three (3) times the traffic of average daily traffic peaks recorded over the previous two (2) service months. CLIENT self hosted environments are expected to maintain a similar degree of scalability. If CLIENT has reason to believe its future average daily traffic will exceed three-times its historical average, CLIENT has a duty to advise COMPANY as soon as reasonably possible to enable the parties to prepare for the increased traffic. COMPANY will not be held responsible for outages resulting from traffic spikes of three (3) times or more of average daily traffic peaks, but will make best efforts to handle such spikes. Traffic spikes exceeding this threshold may result in sustained Downtime that does not count toward Service Credits.


11.0 System Health Checks

COMPANY carries out, on CLIENT's behalf, a program of system health checks on a scheduled basis. The primary purpose of these checks is to monitor system performance and capacity and to notify CLIENT of any current or impending issues.


12.0 Conflicting Terms

If any term of this SLA conflicts with terms of the MSA, a Statement of Work, or other applicable service agreement to which this SLA relates, the terms of that agreement shall prevail unless this SLA expressly states otherwise.

Last updated: August 26, 2026