Legal · Subprocessors

Subprocessor list

The third parties we engage to process data on our customers' behalf, what each one does, and where it operates. This is the list referenced by Annex C of our Data Processing Addendum.

Last updated · August 13, 2026

How to read this page

A subprocessor is a vendor that processes personal data on our behalf while we process it on our customer's behalf. Where a subprocessor may encounter Protected Health Information, we execute a Business Associate Agreement with it and flow down our HIPAA obligations, as required by 45 C.F.R. § 164.308(b) and § 164.502(e).

01

Current subprocessors

SubprocessorFunctionData categoriesRegion / BAA
Cloud hosting and managed database providerApplication hosting, primary data storage, encrypted backupsAccount data, application data, PHIUnited States · BAA executed
Content delivery and edge networkStatic asset delivery, TLS termination, DDoS protectionIP address, request metadataUnited States · No PHI at rest
Error monitoring and observabilityApplication error and performance telemetryDiagnostic metadata, user identifiers (scrubbed)United States · BAA executed
Transactional email providerAccount, security, and system notificationsName, email address, message contentUnited States · BAA executed
SMS and voice notification providerAppointment and care notifications where enabled by the clinicPhone number, message contentUnited States · BAA executed
E-prescribing and pharmacy routing networkPrescription transmission to the dispensing pharmacyPrescriber, patient, and medication data (PHI)United States · BAA executed
Payments and billing processorSubscription and invoice processing for partner organizationsBilling contact, payment instrument tokensUnited States · No PHI
Identity and access management providerAuthentication, session management, MFAEmail, authentication metadataUnited States · BAA executed
Product analytics (marketing site only)Aggregate site measurement, loaded only with visitor consentPseudonymous site-usage metadataUnited States · No PHI
Scheduling and sales CRM (iClosed)Discovery-call scheduling and partner-application intakeBusiness contact details, application responsesUnited States · No PHI

Functions are described rather than left to inference so that a customer's security review can be completed against this page. Named vendor identities, current SOC 2 reports, and executed BAAs are provided under NDA on request to privacy@myorbithealth.com.

02

Partner clinics are not subprocessors

Independently owned professional entities and licensed providers that deliver care through the platform are separate Covered Entities or their workforce, not our subprocessors. Their handling of Protected Health Information is governed by their own Notice of Privacy Practices and their agreements with their patients.

03

How we vet subprocessors

Before engagement, each subprocessor is assessed for security posture (independent audit report or equivalent evidence), data-residency commitments, breach-notification timelines, subcontracting controls, and deletion capability. Each is bound by written terms providing protection materially equivalent to our own commitments, and — where PHI is in scope — by a Business Associate Agreement with subcontractor flow-down. Engagements are re-reviewed at least annually.

04

Change notice and objection rights

We will give customers at least thirty (30) days' notice before adding or replacing a subprocessor that processes their personal data, by updating this page and notifying the customer's designated contact. To subscribe to change notifications, email privacy@myorbithealth.com with the subject line “Subprocessor notifications.”

A customer may object on reasonable, documented data-protection grounds within that notice period. We will work in good faith to provide a commercially reasonable alternative; if none is available, the customer may terminate the affected service without penalty for the remainder of the then-current term, as set out in our Data Processing Addendum.