Who touches the data, and the addendum that binds them.
Published so counsel and IT can answer the question without a bespoke negotiation. Changes to this list are notified before they take effect.
Current subprocessors
| Function | Purpose | Location | PHI in scope |
|---|---|---|---|
| Application hosting | Cloud application and edge delivery | United States | Yes |
| Managed database | Primary datastore, backups, and audit logs | United States | Yes |
| Transactional email | Report delivery, alerts, countersigned agreements | United States | No |
| Error monitoring | Application fault traces, scrubbed of case fields | United States | No |
| Product analytics | Aggregate page and referral counts, marketing site only | United States | No |
Every subprocessor handling protected health information is under a written agreement with the same obligations we owe you, flowed down under the BAA. Subprocessors marked “No” never receive case-level data.
Change notification
We notify practices in writing before a new subprocessor with PHI in scope begins processing, with enough time to object. Objection is handled under the addendum, not by ticket.
What the addendum covers
| Clause | Position |
|---|---|
| Subprocessor list and change notice | This page, plus written notice before the change |
| Security measures | Encryption in transit and at rest, tenant isolation, least privilege |
| Audit rights | Annual, on reasonable notice, subject to confidentiality |
| Breach notification | Written notice within the timeline in the executed BAA |
| Return or destruction | On termination, per the BAA, with certification on request |
