Skip to content

BetaVadia is still being built. You will find rough edges — we would rather you found them than your patients did. Report something broken

Subprocessors

Last updated: August 20, 2026

Running Vadia takes a small number of third parties. This page lists them, what each one does, whether it handles protected health information, and where it operates. We keep the list short on purpose, and we publish it so a practice can review it as part of its own vendor diligence.

Our commitment

We engage every subprocessor under a written contract. Where a subprocessor creates, receives, maintains, or transmits protected health information on our behalf, we execute a business associate agreement whose terms are at least as stringent as our own obligations to your practice, as 45 CFR §§ 164.502(e) and 164.308(b) require, and we obtain documented evidence of its safeguards rather than relying on a signature alone. No protected health information flows to a subprocessor before that is in place. Subprocessors that handle PHI process and store it in the United States.

Current subprocessors

  • Anthropic

    PHI: Yes

    AI-assisted documentation and drafting

    Clinical text submitted to an AI feature, only when a practice enables it

    United States

  • LiveKit

    PHI: Yes

    Telehealth video and audio

    Real-time session media, session metadata, and consented recordings

    United States

  • Telnyx

    PHI: Yes

    Voice, SMS, and fax

    Phone numbers, message and fax content, call metadata

    United States

  • Stedi

    PHI: Yes

    Claims clearinghouse and eligibility

    Eligibility requests, claims, remittances, and payer responses

    United States

  • Cloudflare

    PHI: Yes

    Network protection, TLS, custom domains, and email routing

    Web traffic in transit and transactional email delivery

    Global edge network, United States processing

  • Contabo

    PHI: Yes

    Off-site encrypted backup storage

    Encrypted database and object-store backups

    United States

  • Stripe

    PHI: No

    Subscription and payment processing

    Payment card details, billing contact, opaque account identifiers

    United States

  • Apple

    PHI: No

    Push notification delivery to iPhone and iPad

    Device tokens and clinically non-specific notification text

    United States

  • Google

    PHI: No

    Push notification delivery to Android

    Device tokens and clinically non-specific notification text

    United States

What stays in-house

The application database, the object store that holds documents and recordings, the queue, and speech-to-text transcription all run on infrastructure we operate ourselves rather than on a third-party managed service. Our source code and continuous integration run on GitHub, and no protected health information is permitted in a repository, a test fixture, or a build log.

Changes to this list

We give reasonable advance notice before adding a subprocessor that will handle protected health information. A practice may object on reasonable data-protection grounds under section 7 of the Business Associate Agreement; we will work in good faith toward a resolution, and the practice may terminate if none is reached. To be notified of changes, write to [email protected].