Vendor transparency

Vendor status should be explicit before patient data flows.

A vendor’s appearance here does not mean it is approved to process PHI. Professional-service approval requires deployment-specific review.

Vendor statusPHI approval boundariesReview dates

Register

Current register

The structured table below distinguishes verified consumer-service use from professional-service approval.

Vendor status reviewed July 28, 2026
ProviderPurposeData categoriesProcessing locationContract statusLast reviewed
SupabaseConsumer app backend and authenticationConsumer account and app dataUnited States — AWS Ohio for the current projectContract and Quebec transfer assessment require accountable approval2026-09-05
AppleApp distribution, purchases and push deliveryStore, purchase and device delivery dataProvider dependentNo professional-service PHI approval asserted2026-09-05
RevenueCatConsumer subscription entitlementsPurchase entitlement dataUnited States / provider dependentNot approved for professional-service PHI2026-09-05
ExpoConsumer app build and notification deliveryBuild and device notification dataProvider dependentNot approved for professional-service PHI2026-09-05
AnthropicOptional Snow responses and controlled generic Program Builder draftingSubmitted Snow message and recent Snow history, or clinician-entered generic template instructions without patient informationUnited StatesUse is consent-gated; contract and Quebec transfer assessment require accountable approval2026-09-05
SentryMinimized application diagnosticsSanitized technical diagnostics without intentionally submitted PII or free textUnited States / provider dependentContract and Quebec transfer assessment require accountable approval2026-09-05

Vendor review

Review vendor status before any professional deployment.

A listed vendor is not automatically approved for professional-service PHI processing.

Contact security