Subprocessors
Last updated: August 20, 2026
Running Vadia takes a small number of third parties. This page lists them, what each one does, whether it handles protected health information, and where it operates. We keep the list short on purpose, and we publish it so a practice can review it as part of its own vendor diligence.
Our commitment
We engage every subprocessor under a written contract. Where a subprocessor creates, receives, maintains, or transmits protected health information on our behalf, we execute a business associate agreement whose terms are at least as stringent as our own obligations to your practice, as 45 CFR §§ 164.502(e) and 164.308(b) require, and we obtain documented evidence of its safeguards rather than relying on a signature alone. No protected health information flows to a subprocessor before that is in place. Subprocessors that handle PHI process and store it in the United States.
Current subprocessors
Anthropic
PHI: YesAI-assisted documentation and drafting
Clinical text submitted to an AI feature, only when a practice enables it
United States
LiveKit
PHI: YesTelehealth video and audio
Real-time session media, session metadata, and consented recordings
United States
Telnyx
PHI: YesVoice, SMS, and fax
Phone numbers, message and fax content, call metadata
United States
Stedi
PHI: YesClaims clearinghouse and eligibility
Eligibility requests, claims, remittances, and payer responses
United States
Cloudflare
PHI: YesNetwork protection, TLS, custom domains, and email routing
Web traffic in transit and transactional email delivery
Global edge network, United States processing
Contabo
PHI: YesOff-site encrypted backup storage
Encrypted database and object-store backups
United States
Stripe
PHI: NoSubscription and payment processing
Payment card details, billing contact, opaque account identifiers
United States
Apple
PHI: NoPush notification delivery to iPhone and iPad
Device tokens and clinically non-specific notification text
United States
Google
PHI: NoPush notification delivery to Android
Device tokens and clinically non-specific notification text
United States
What stays in-house
The application database, the object store that holds documents and recordings, the queue, and speech-to-text transcription all run on infrastructure we operate ourselves rather than on a third-party managed service. Our source code and continuous integration run on GitHub, and no protected health information is permitted in a repository, a test fixture, or a build log.
Changes to this list
We give reasonable advance notice before adding a subprocessor that will handle protected health information. A practice may object on reasonable data-protection grounds under section 7 of the Business Associate Agreement; we will work in good faith toward a resolution, and the practice may terminate if none is reached. To be notified of changes, write to [email protected].