Vendor transparency
Vendor status should be explicit before patient data flows.
A vendor’s appearance here does not mean it is approved to process PHI. Professional-service approval requires deployment-specific review.
Vendor statusPHI approval boundariesReview dates
Register
Current register
The structured table below distinguishes verified consumer-service use from professional-service approval.
| Provider | Purpose | Data categories | Processing location | Contract status | Last reviewed |
|---|---|---|---|---|---|
| Supabase | Consumer app backend and authentication | Consumer account and app data | United States — AWS Ohio for the current project | Contract and Quebec transfer assessment require accountable approval | 2026-09-05 |
| Apple | App distribution, purchases and push delivery | Store, purchase and device delivery data | Provider dependent | No professional-service PHI approval asserted | 2026-09-05 |
| RevenueCat | Consumer subscription entitlements | Purchase entitlement data | United States / provider dependent | Not approved for professional-service PHI | 2026-09-05 |
| Expo | Consumer app build and notification delivery | Build and device notification data | Provider dependent | Not approved for professional-service PHI | 2026-09-05 |
| Anthropic | Optional Snow responses and controlled generic Program Builder drafting | Submitted Snow message and recent Snow history, or clinician-entered generic template instructions without patient information | United States | Use is consent-gated; contract and Quebec transfer assessment require accountable approval | 2026-09-05 |
| Sentry | Minimized application diagnostics | Sanitized technical diagnostics without intentionally submitted PII or free text | United States / provider dependent | Contract and Quebec transfer assessment require accountable approval | 2026-09-05 |
Vendor review
Review vendor status before any professional deployment.
A listed vendor is not automatically approved for professional-service PHI processing.
Contact security