Every third party that processes customer data, what they do, and where they do it.
Why this list exists
Under HIPAA, your compliance exposure does not stop at your vendor — it runs through your vendor’s vendors. If SuperHIPAA is your business associate, our subcontractors that touch ePHI are subcontractor business associates, and you are entitled to know who they are. Plenty of vendors make you file a support ticket to find out. We publish the list, keep it current, and notify you before it changes.
Current subprocessors
The authoritative list, with each provider’s function, data categories handled, and processing location:
| Provider | Purpose | Data categories | Location | Handles ePHI / BAA |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Hosting and infrastructure | Customer workspace content, account data, logs, backups | United States (us-east-1 primary, us-west-2 backup) | Yes — BAA signed |
| Cloudflare | CDN, DNS, and edge security | Traffic metadata; customer data in transit | United States | Transit only — BAA signed |
| Google Workspace | Email and internal documents | Business contact and support correspondence | United States | No — ePHI is not handled by email |
| HubSpot | CRM and marketing | Business contact data from forms and sales | United States | No |
| Slack | Internal communications | Business contact data in operational notifications | United States | No |
| Stripe | Payments and billing | Billing contact and payment data | United States | No |
Two reading notes. First, “processes customer data” is interpreted broadly here: if a provider could plausibly touch your data in the course of its function, it is on the list, even if the touch is incidental. Second, not every provider on the list handles ePHI — the table marks which ones do, because that distinction determines whether a downstream BAA is required or merely prudent.
How a vendor gets on this list
No subprocessor is added casually. Before any third party touches customer data, it goes through a documented review:
- Security assessment — we review the provider’s audit reports, security documentation, and breach history before signing anything.
- Contractual flow-down — providers handling ePHI sign a BAA with us; all providers handling customer data sign terms at least as protective as our commitments to you. HIPAA’s chain-of-trust requirement is not optional and we do not treat it as negotiable.
- Minimum necessary scoping — each provider gets access to the categories of data its function requires, not a general feed.
- Ongoing review — subprocessors are reassessed on a defined cadence (annually) and when something material changes, such as an acquisition or a disclosed incident.
Change notification
We give notice before adding or materially changing a subprocessor:
- Notice period: at least 30 days before a new subprocessor processes customer data.
- Delivery: email to your registered security contact, plus an update to this page. Subscribe once and you will not need to re-check this page on a schedule.
- Objection: if your agreement includes an objection right and a new subprocessor is unacceptable to you, the agreement sets out the process and remedies. We would rather hear the objection during the notice window than at renewal.
Removals and role reductions are reflected on this page as they happen, with a change log maintained at the foot of this page so you can see history rather than only the current state.
What we commit to
- We give at least 30 days’ notice before a new subprocessor processes customer data.
- Every subprocessor that handles ePHI signs a BAA with us before it handles anything.
- Every subprocessor is security-assessed before onboarding and reassessed annually, and after any material change such as an acquisition or a disclosed incident.
If a subprocessor has an incident
An incident at a subprocessor affecting customer data is treated as an incident of ours. Our contracts with subprocessors require prompt notification to us; our BAA with you defines what we must tell you and when. We do not launder responsibility through the supply chain — if your data was affected, you hear it from us, with what we know and what we are doing, not from a third party’s press release.
Documentation available on request
- SOC 2 Type II report (under NDA)
- Penetration test summary
- Business Associate Agreement
- Architecture and data flow diagram
- Completed CAIQ / SIG Lite
Vendor-risk teams often want our subprocessor assessments summarised rather than just the list; that summary is part of the full security package, requestable through the form on this page.
Questions
Security questions go to security@superhipaa.com and get a human answer within one business day. If you spot a provider you believe should be on this list and is not, tell us — that is exactly the kind of external check a public list is for.