Legal · Subprocessors
Subprocessor list
The third parties we engage to process data on our customers' behalf, what each one does, and where it operates. This is the list referenced by Annex C of our Data Processing Addendum.
Last updated · August 13, 2026
How to read this page
A subprocessor is a vendor that processes personal data on our behalf while we process it on our customer's behalf. Where a subprocessor may encounter Protected Health Information, we execute a Business Associate Agreement with it and flow down our HIPAA obligations, as required by 45 C.F.R. § 164.308(b) and § 164.502(e).
01
Current subprocessors
| Subprocessor | Function | Data categories | Region / BAA |
|---|---|---|---|
| Cloud hosting and managed database provider | Application hosting, primary data storage, encrypted backups | Account data, application data, PHI | United States · BAA executed |
| Content delivery and edge network | Static asset delivery, TLS termination, DDoS protection | IP address, request metadata | United States · No PHI at rest |
| Error monitoring and observability | Application error and performance telemetry | Diagnostic metadata, user identifiers (scrubbed) | United States · BAA executed |
| Transactional email provider | Account, security, and system notifications | Name, email address, message content | United States · BAA executed |
| SMS and voice notification provider | Appointment and care notifications where enabled by the clinic | Phone number, message content | United States · BAA executed |
| E-prescribing and pharmacy routing network | Prescription transmission to the dispensing pharmacy | Prescriber, patient, and medication data (PHI) | United States · BAA executed |
| Payments and billing processor | Subscription and invoice processing for partner organizations | Billing contact, payment instrument tokens | United States · No PHI |
| Identity and access management provider | Authentication, session management, MFA | Email, authentication metadata | United States · BAA executed |
| Product analytics (marketing site only) | Aggregate site measurement, loaded only with visitor consent | Pseudonymous site-usage metadata | United States · No PHI |
| Scheduling and sales CRM (iClosed) | Discovery-call scheduling and partner-application intake | Business contact details, application responses | United States · No PHI |
Functions are described rather than left to inference so that a customer's security review can be completed against this page. Named vendor identities, current SOC 2 reports, and executed BAAs are provided under NDA on request to privacy@myorbithealth.com.
02
Partner clinics are not subprocessors
Independently owned professional entities and licensed providers that deliver care through the platform are separate Covered Entities or their workforce, not our subprocessors. Their handling of Protected Health Information is governed by their own Notice of Privacy Practices and their agreements with their patients.
03
How we vet subprocessors
Before engagement, each subprocessor is assessed for security posture (independent audit report or equivalent evidence), data-residency commitments, breach-notification timelines, subcontracting controls, and deletion capability. Each is bound by written terms providing protection materially equivalent to our own commitments, and — where PHI is in scope — by a Business Associate Agreement with subcontractor flow-down. Engagements are re-reviewed at least annually.
04
Change notice and objection rights
We will give customers at least thirty (30) days' notice before adding or replacing a subprocessor that processes their personal data, by updating this page and notifying the customer's designated contact. To subscribe to change notifications, email privacy@myorbithealth.com with the subject line “Subprocessor notifications.”
A customer may object on reasonable, documented data-protection grounds within that notice period. We will work in good faith to provide a commercially reasonable alternative; if none is available, the customer may terminate the affected service without penalty for the remainder of the then-current term, as set out in our Data Processing Addendum.