Subprocessor Register

This register lists the vendors used or reserved for EchoMed organizational deployments. Any vendor that creates, receives, maintains, or transmits ePHI must have appropriate contractual coverage before production PHI is allowed through that path.

Last updated: 2026-06-08

Current Data-Handling Rule

Clinical note email and secure-note link delivery are disabled by default unless the delivery path is explicitly approved and covered. Account emails, password resets, billing, and support messages must not contain clinical content.

Microsoft Azure

Services: Azure App Service, Azure OpenAI Service, Azure Speech Services

Application hosting, speech-to-text, and AI note generation.

Data Categories

  • Account/session metadata
  • Audio during transcription
  • Visit text during note generation
  • Generated note text during response

Agreement Status

Microsoft Products and Services Data Protection Addendum with HIPAA Business Associate Agreement provisions.

Evidence on file. Confirm the production Azure tenant/subscription is covered by the accepted Microsoft Product Terms and DPA.

PHI exposure: May create, receive, maintain, or transmit ePHI during transcription and note generation when users include PHI.

Stores clinical content at rest: False

Evidence on file: compliance/Microsoft_Products_and_Services_DPA_September_2025.pdf

Required Actions

  • Keep production AI and STT traffic on Azure services covered by Microsoft DPA/BAA terms.
  • Use region/geography settings approved for the customer population.
  • Avoid preview, global, or stateful AI features until reviewed for HIPAA impact.
  • Revisit abuse-monitoring review options as Azure account status changes.

Neon

Services: PostgreSQL

Managed database for user accounts, usage counters, audit metadata, subscription metadata, preferences, templates, and short-lived encrypted secure notes if secure links are enabled.

Data Categories

  • User account data
  • Usage counters
  • Audit metadata
  • Subscription metadata
  • Encrypted secure-note content when secure links are enabled

Agreement Status

Neon HIPAA BAA / HIPAA compliance add-on.

BAA evidence on file. Confirm Scale plan plus HIPAA add-on remains active for production.

PHI exposure: May maintain ePHI only if secure links or future persistent clinical storage are enabled.

Stores clinical content at rest: Only for encrypted short-lived secure-note records when ENABLE_SECURE_NOTE_LINKS is enabled.

Evidence on file: compliance/baa-neon.pdf

Required Actions

  • Verify the production project is on the Neon plan covered by the signed BAA.
  • Keep database SSL required.
  • Do not add persistent clinical-note storage until retention, encryption, and org policy controls are implemented.

Cloudflare

Services: DNS, CDN, WAF, DDoS protection

Edge routing, DNS, TLS termination, caching, and traffic protection.

Data Categories

  • HTTP request metadata
  • IP addresses
  • Headers
  • Proxied request/response content if orange-cloud proxy is enabled

Agreement Status

Cloudflare DPA on file. Cloudflare BAA requires Enterprise-level arrangement.

DPA evidence on file. BAA not verified for this account. Do not proxy production PHI traffic through Cloudflare unless an Enterprise BAA is executed.

PHI exposure: May transmit ePHI if authenticated PHI routes are proxied through Cloudflare.

Stores clinical content at rest: False

Evidence on file: compliance/Cloudflare DPA.pdf

Required Actions

  • Either execute a Cloudflare Enterprise BAA or bypass Cloudflare proxying for PHI routes.
  • Disable caching for authenticated and API routes.
  • Document TLS mode and origin certificate configuration.

Resend

Services: Transactional email

Email verification, password reset, support/feedback notifications, and secure-link delivery when enabled.

Data Categories

  • Email addresses
  • Verification/reset tokens or links
  • Message metadata
  • Secure-note bearer URLs if secure links are enabled

Agreement Status

Resend DPA.

DPA evidence on file. No public BAA verified. Keep clinical note email and secure-link delivery disabled for HIPAA mode unless BAA coverage is obtained or vendor is replaced.

PHI exposure: May transmit ePHI risk if emails contain note content or bearer URLs that grant access to note content.

Stores clinical content at rest: False

Evidence on file: compliance/Resend_Data_Processing_Addendum.pdf

Required Actions

  • Do not send note content through Resend.
  • Keep ENABLE_SECURE_NOTE_LINKS disabled until a BAA-covered email/link delivery design is approved.
  • Use Resend only for non-PHI account and support email unless BAA coverage is confirmed.

Stripe

Services: Payments, Billing portal, Webhooks

Subscription billing and payment processing.

Data Categories

  • Billing contact details
  • Payment metadata
  • Subscription status

Agreement Status

Stripe Data Processing Addendum.

DPA evidence on file. Keep Stripe outside clinical workflows.

PHI exposure: No clinical content should be sent to Stripe.

Stores clinical content at rest: False

Evidence on file: compliance/Stripe DPA.pdf

Required Actions

  • Do not put patient identifiers or clinical details in Stripe customer names, metadata, descriptions, or invoices.
  • Keep webhook payload logging sanitized.

OpenAI API

Services: Direct OpenAI API

Optional future AI provider fallback; not approved for production PHI unless a BAA is executed directly with OpenAI.

Data Categories

  • Visit text during generation if enabled

Agreement Status

OpenAI BAA / healthcare addendum, if separately executed.

Not active for production PHI. BAA can be requested from OpenAI, but this app should stay Azure-only until direct OpenAI BAA evidence is on file.

PHI exposure: Would create, receive, maintain, or transmit ePHI if used for clinical generation.

Stores clinical content at rest: False

Required Actions

  • Do not route production PHI to direct OpenAI APIs until a BAA is executed and filed.
  • Keep provider configuration fail-closed for HIPAA mode.
  • If direct OpenAI is enabled later, update this register and the compliance pack.

GitHub / GitHub Container Registry

Services: Source control, Container registry

Code hosting and deployment artifact storage.

Data Categories

  • Source code
  • Build metadata
  • Container images

Agreement Status

Not treated as a PHI subprocessor if no PHI, secrets, or clinical logs are committed.

Operational vendor only. Keep out of PHI data flow.

PHI exposure: No PHI should be stored or logged in source control or container images.

Stores clinical content at rest: False

Required Actions

  • Do not commit PHI, secrets, logs, database dumps, transcripts, notes, or customer files.
  • Use secret scanning and branch protection for production branches.