Subprocessor Register
This register lists the vendors used or reserved for EchoMed organizational deployments. Any vendor that creates, receives, maintains, or transmits ePHI must have appropriate contractual coverage before production PHI is allowed through that path.
Last updated: 2026-06-08
Current Data-Handling Rule
Clinical note email and secure-note link delivery are disabled by default unless the delivery path is explicitly approved and covered. Account emails, password resets, billing, and support messages must not contain clinical content.
Microsoft Azure
Services: Azure App Service, Azure OpenAI Service, Azure Speech Services
Application hosting, speech-to-text, and AI note generation.
Data Categories
- Account/session metadata
- Audio during transcription
- Visit text during note generation
- Generated note text during response
Agreement Status
Microsoft Products and Services Data Protection Addendum with HIPAA Business Associate Agreement provisions.
Evidence on file. Confirm the production Azure tenant/subscription is covered by the accepted Microsoft Product Terms and DPA.
PHI exposure: May create, receive, maintain, or transmit ePHI during transcription and note generation when users include PHI.
Stores clinical content at rest: False
Evidence on file: compliance/Microsoft_Products_and_Services_DPA_September_2025.pdf
Required Actions
- Keep production AI and STT traffic on Azure services covered by Microsoft DPA/BAA terms.
- Use region/geography settings approved for the customer population.
- Avoid preview, global, or stateful AI features until reviewed for HIPAA impact.
- Revisit abuse-monitoring review options as Azure account status changes.
Neon
Services: PostgreSQL
Managed database for user accounts, usage counters, audit metadata, subscription metadata, preferences, templates, and short-lived encrypted secure notes if secure links are enabled.
Data Categories
- User account data
- Usage counters
- Audit metadata
- Subscription metadata
- Encrypted secure-note content when secure links are enabled
Agreement Status
Neon HIPAA BAA / HIPAA compliance add-on.
BAA evidence on file. Confirm Scale plan plus HIPAA add-on remains active for production.
PHI exposure: May maintain ePHI only if secure links or future persistent clinical storage are enabled.
Stores clinical content at rest: Only for encrypted short-lived secure-note records when ENABLE_SECURE_NOTE_LINKS is enabled.
Evidence on file: compliance/baa-neon.pdf
Required Actions
- Verify the production project is on the Neon plan covered by the signed BAA.
- Keep database SSL required.
- Do not add persistent clinical-note storage until retention, encryption, and org policy controls are implemented.
Cloudflare
Services: DNS, CDN, WAF, DDoS protection
Edge routing, DNS, TLS termination, caching, and traffic protection.
Data Categories
- HTTP request metadata
- IP addresses
- Headers
- Proxied request/response content if orange-cloud proxy is enabled
Agreement Status
Cloudflare DPA on file. Cloudflare BAA requires Enterprise-level arrangement.
DPA evidence on file. BAA not verified for this account. Do not proxy production PHI traffic through Cloudflare unless an Enterprise BAA is executed.
PHI exposure: May transmit ePHI if authenticated PHI routes are proxied through Cloudflare.
Stores clinical content at rest: False
Evidence on file: compliance/Cloudflare DPA.pdf
Required Actions
- Either execute a Cloudflare Enterprise BAA or bypass Cloudflare proxying for PHI routes.
- Disable caching for authenticated and API routes.
- Document TLS mode and origin certificate configuration.
Resend
Services: Transactional email
Email verification, password reset, support/feedback notifications, and secure-link delivery when enabled.
Data Categories
- Email addresses
- Verification/reset tokens or links
- Message metadata
- Secure-note bearer URLs if secure links are enabled
Agreement Status
Resend DPA.
DPA evidence on file. No public BAA verified. Keep clinical note email and secure-link delivery disabled for HIPAA mode unless BAA coverage is obtained or vendor is replaced.
PHI exposure: May transmit ePHI risk if emails contain note content or bearer URLs that grant access to note content.
Stores clinical content at rest: False
Evidence on file: compliance/Resend_Data_Processing_Addendum.pdf
Required Actions
- Do not send note content through Resend.
- Keep ENABLE_SECURE_NOTE_LINKS disabled until a BAA-covered email/link delivery design is approved.
- Use Resend only for non-PHI account and support email unless BAA coverage is confirmed.
Stripe
Services: Payments, Billing portal, Webhooks
Subscription billing and payment processing.
Data Categories
- Billing contact details
- Payment metadata
- Subscription status
Agreement Status
Stripe Data Processing Addendum.
DPA evidence on file. Keep Stripe outside clinical workflows.
PHI exposure: No clinical content should be sent to Stripe.
Stores clinical content at rest: False
Evidence on file: compliance/Stripe DPA.pdf
Required Actions
- Do not put patient identifiers or clinical details in Stripe customer names, metadata, descriptions, or invoices.
- Keep webhook payload logging sanitized.
OpenAI API
Services: Direct OpenAI API
Optional future AI provider fallback; not approved for production PHI unless a BAA is executed directly with OpenAI.
Data Categories
- Visit text during generation if enabled
Agreement Status
OpenAI BAA / healthcare addendum, if separately executed.
Not active for production PHI. BAA can be requested from OpenAI, but this app should stay Azure-only until direct OpenAI BAA evidence is on file.
PHI exposure: Would create, receive, maintain, or transmit ePHI if used for clinical generation.
Stores clinical content at rest: False
Required Actions
- Do not route production PHI to direct OpenAI APIs until a BAA is executed and filed.
- Keep provider configuration fail-closed for HIPAA mode.
- If direct OpenAI is enabled later, update this register and the compliance pack.
GitHub / GitHub Container Registry
Services: Source control, Container registry
Code hosting and deployment artifact storage.
Data Categories
- Source code
- Build metadata
- Container images
Agreement Status
Not treated as a PHI subprocessor if no PHI, secrets, or clinical logs are committed.
Operational vendor only. Keep out of PHI data flow.
PHI exposure: No PHI should be stored or logged in source control or container images.
Stores clinical content at rest: False
Required Actions
- Do not commit PHI, secrets, logs, database dumps, transcripts, notes, or customer files.
- Use secret scanning and branch protection for production branches.