Medora Terms of Service
Effective August 24, 2026. This addendum supplements the Callora master Terms of Service and governs your use of the Medora physician-recruiting product.
1. Scope
Medora is the Callora product suite offered specifically to locum tenens agencies, physician staffing firms, and hospital MSO/VMS teams. Where this addendum conflicts with the master Terms for a Medora customer, this addendum controls; every other clause of the master Terms continues in force.
2. Customer responsibilities — TCPA + consent
You confirm that every phone number you upload, sync, or otherwise submit to Medora has obtained express written or prior express consent for the type of outreach you intend to run. Consent capture in Medora’s onboarding flow satisfies this only for candidates onboarded through that flow; imported records are your obligation to attest.
Sarah, our AI recruiter, will refuse to dial any number whose consent field is null or whose local-timezone quiet-hours window is closed. Manually bypassing these guards requires the "bypass_tcpa=true" parameter with documented consent on file; the bypass event is written to your audit chain and surfaced to Medora Trust.
3. Business Associate Agreement (BAA)
A mutual BAA is available on the Locum Pro and Agency plans. Executing the BAA is a precondition for uploading any Protected Health Information (PHI) into Medora — including but not limited to DEA numbers, clinical rotation transcripts, malpractice histories, or peer references. Free-tier customers agree not to upload PHI.
4. Credential monitoring accuracy
Medora sweeps OIG LEIE, SAM.gov, and 10 US state medical boards daily. The datasets we consume are public and authoritative, but they are not real-time; a physician’s exclusion may appear in a source up to 24 hours after entry. You agree to treat Medora alerts as an automation layer on top of your existing credentialing responsibilities, not a substitute for them.
5. Public provider directory + opt-outs
Medora ingests CMS NPPES data (a FOIA-disclosable public record) plus state-board public license data. Any physician who submits a valid opt-out through POST /api/providers/opt-out is removed from the directory and their NPI is added to the opt-out ledger. Callora will not resurface an opted-out NPI even if it reappears in a downstream refresh.
6. Letters of Authorization (LOA) + e-signature
Medora generates LOAs from your placement data and routes them through either DocuSign or your self-hosted Docuseal instance. Signed envelopes are your legal record; Medora stores an audit copy and the hash-chained event trail, but the executed PDF should be retained in your record-of-truth (agency ATS / VMS).
7. VMS / ATS export accuracy
Where Medora offers direct connectors (Workable, Greenhouse) we sync your data as documented. Where we offer CSV / JSON export for a VMS platform, the schema and field mapping are your responsibility to validate before submission to the hospital.
8. Termination + data portability
You may cancel any Medora plan at any time from the dashboard. On cancellation Medora exports your candidates, placements, audit chain, and signed LOAs as a downloadable ZIP within 24 hours; primary-source verifications are attested per NCQA principles and travel with the export.