Subprocessors
The providers below process data on our behalf. This register is generated from the same source that fills Exhibit C of every dailybuilt Business Associate Agreement, so what you read here is what the agreements say.
Subprocessors in the PHI scope
Each subprocessor listed here creates, receives, maintains, or transmits protected health information in connection with the Service, and each is bound by a business associate agreement or equivalent HIPAA addendum at least as restrictive as our own, consistent with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b).
| Subprocessor | Service and PHI processed | HIPAA basis | Location |
|---|---|---|---|
| Google LLC Google Cloud Platform | Application hosting, the primary PHI database, encrypted object storage for executed and signed documents, superbills, issued agreements, and client file attachments (accessed via short-lived signed URLs), secret management, and system logging. Processes and stores all categories of PHI in Exhibit A-2. | Google Cloud HIPAA Business Associate Addendum (account-wide); PHI confined to Google Cloud “Covered Products.” | United States |
| Amazon Web Services, Inc. SES, S3, Lambda | Delivery of appointment- and care-related email, and receipt and threading of client email replies (including any attachments a client sends). Processes client name, email address, message content, and attachments. | AWS Business Associate Addendum (AWS Artifact), over HIPAA-eligible services; TLS enforced. | United States |
Providers outside the PHI scope
These providers support the Service but are not in the PHI scope:
- Stripe, Inc.: payment processing; operates under the payment-processing exception at § 1179 of the Social Security Act and receives only opaque identifiers and generic descriptors, not clinical PHI.
- WorkOS, Inc.: authentication for Covered Entity’s operators and staff only; clients do not authenticate and no client PHI is transmitted.
- Cloudflare, Inc.: DNS, bot-protection challenge, and static marketing-site delivery; on these surfaces PHI hostnames are served DNS-only so TLS terminates at the BAA-covered host and Cloudflare does not decrypt or receive PHI request content.
SMS / text messaging is designated a non-PHI channel and is disabled for the Healthcare Edition; web analytics for Covered Entity’s hosted sites is performed on a de-identified basis and is not PHI.
The full list of service providers we use, including those that never touch health information, is in Section 5.1 of the Privacy Policy.
Changes to this register
We may add or replace a subprocessor that processes PHI provided we first bind it to written obligations at least as restrictive as our own agreement. On written request we will provide the then-current list and reasonable advance notice of a material change, and a covered entity may object on reasonable HIPAA-compliance grounds.
Prior versions of this document are archived by date and are available on request to hello@dailybuilt.co.