Update this page with actual provider names before production launch or whenever vendors materially change.
1Hosting Provider
A HIPAA-capable hosting provider may store application files, databases, logs, and backups. Confirm the current provider and BAA status before production use.
2SMS Provider
Twilio or another communications provider may deliver notification messages. SMS content should be configured not to include PHI.
3Email Provider
An email provider may deliver account verification, password reset, support, billing, and notification messages. PHI should not be placed in ordinary email unless specifically secured and authorized.
4Support and Security Vendors
Additional vendors may assist with monitoring, backups, support, or security. Access should be limited, documented, and governed by appropriate agreements.
5Changes to Subprocessors
Material changes to subprocessor categories should be reflected on this page and communicated as required by customer agreements.