Skip to content

Legal

Limited Agency Authorization for Payer Transactions

Version: 1.1

Effective date: 2026-07-10

Last updated: 2026-07-10

This Limited Agency Authorization ("Authorization") is between the organization that owns or controls the Upstream workspace identified in the acceptance record ("Customer" or "Principal") and ByteWorthy LLC, a Texas limited liability company offering the Upstream service ("Upstream" or "Agent"). It supplements the Terms of Service and Business Associate Agreement (together, the "Services Agreement").

1. Electronic Acceptance and Authority

Customer grants this Authorization when an authorized person affirmatively accepts it through the dedicated electronic control. The acceptance record identifies the Customer account and accepting user and stores the signer's name and title, authority attestation, this Authorization's version and SHA-256 hash, acceptance time, IP address, and user agent.

The accepting person represents that they have authority to bind Customer and grant the limited agency below. The Parties agree that the acceptance record constitutes their electronic signatures and evidence of the complete version accepted. The Effective Date is the recorded acceptance time.

2. Appointment and Scope

Customer appoints Upstream as its limited agent solely to transmit, submit, receive, and status check the following transactions through a channel supported and enabled for Customer:

  1. prior authorization and pre-certification requests and responses to payer information requests;
  2. eligibility, benefits, and authorization-status inquiries;
  3. claims, claim corrections, acknowledgments, and claim-status inquiries;
  4. appeals and reconsideration requests; and
  5. documents or attachments directly supporting an approved transaction.

Upstream may act only on an item that Customer's authorized personnel reviewed and approved in the Service, or on a deterministic status inquiry that Customer enabled for an already approved item. Upstream may identify itself to a payer, plan, EHR, clearinghouse, portal, or service provider as Customer's authorized submitter or agent only to the extent needed for an approved transaction.

This Authorization does not represent that every transaction is available through every channel. Customer-specific payer enrollment, credentials, technical capability, and destination rules still apply. If no supported automated channel is available, Upstream may prepare an auditable task for Customer or its authorized service personnel instead of transmitting it.

3. Customer Retains All Decisions

Customer retains sole authority and responsibility for clinical judgment, medical necessity, coding, billing, appeal strategy, financial decisions, and the truth and completeness of each submission. Customer's approval is Customer's instruction to transmit the exact approved item. Upstream is responsible for following that instruction accurately and securely through the selected channel.

4. Express Limits

Upstream has no authority under this Authorization to:

  1. originate or materially alter a submission after approval without renewed Customer approval;
  2. make, change, or override a clinical, coding, medical-necessity, billing, or appeal decision;
  3. enter, amend, or terminate a payer, network, or provider contract for Customer;
  4. negotiate a settlement or bind Customer beyond the approved transaction;
  5. receive, hold, direct, or disburse Customer funds, payer remittances, or patient payments;
  6. use a credential, provider identity, NPI, enrollment, or destination Customer has not authorized;
  7. delegate broader authority than this Authorization grants; or
  8. use or disclose PHI beyond the Business Associate Agreement.

5. Customer Representations and Cooperation

Customer represents that it has the legal rights, provider relationships, enrollments, credentials, and patient or member authority needed for the approved transactions. Customer will keep routing, provider, payer, and contact information accurate and will promptly revoke access that should no longer be used.

Customer authorizes Upstream to complete a payer, clearinghouse, or technical submitter designation only when the designation is necessary for the transactions in Section 2 and does not grant broader authority. Customer will execute a separate payer or trading-partner form when the recipient requires Customer's direct signature.

6. Approval Record and Transmission Evidence

For an automated or service-assisted transaction, Upstream will maintain an operational record that identifies the approved action, destination, selected channel, payload or manifest integrity hash, approval evidence, attempts, and available terminal evidence. A registration, queue receipt, or transport acknowledgment is not a representation that a payer approved the underlying request. Unknown outcomes remain subject to reconciliation rather than being treated as success.

7. HIPAA, Privacy, and Security

The Business Associate Agreement governs all PHI created, received, maintained, or transmitted under this Authorization. This Authorization does not expand the BAA's permitted uses or disclosures. If this Authorization conflicts with the BAA regarding PHI, the BAA controls.

Upstream will use the minimum information reasonably necessary for the transaction and will use only subprocessors and channels permitted by the applicable agreement and Customer configuration.

8. Term, Suspension, and Revocation

This Authorization begins on the Effective Date and continues until Customer revokes it or the Services Agreement ends. Customer may revoke it through available account controls or by written notice to legal@upstream.cx. Upstream may suspend transmissions to contain a security incident, comply with law or a recipient's rules, address invalid credentials or enrollment, or prevent material harm.

Revocation or suspension stops new transmissions after it becomes effective. It does not withdraw a transaction already delivered to a recipient or eliminate obligations arising from earlier activity. Upstream may continue a minimum-necessary status inquiry or record-reconciliation step for an earlier transmission only when authorized by Customer or reasonably necessary to preserve an accurate audit record.

Sections 3, 4, 6, 7, and 9 survive termination to the extent needed to govern prior activity.

9. Relationship and Liability

This Authorization creates a limited agency only for Section 2. For every other purpose, the Parties remain independent contractors. It does not create a partnership, joint venture, general agency, fiduciary relationship, or employment relationship.

The disclaimers, indemnities, liability limitations, dispute terms, and general provisions in the Services Agreement apply to this Authorization. In a conflict about the scope of transmission authority, this Authorization controls. In a conflict about PHI, the BAA controls.

10. Notices

Notices to Upstream must be sent to legal@upstream.cx and may also be mailed to:

ByteWorthy LLC

220 Town Park Avenue

Princeton, TX 75407-9846

United States

Notices to Customer will be sent to the account owner, signer, or other notice contact in the Customer account or Services Agreement.


End of Limited Agency Authorization version 1.1.

Canonical source: care/legal/agency.md | Version 1.1 | SHA-256 4fa3cf35ae533133af32a2d514ecb1cc9b4ccb071885fea209fcfd9f950293ca