A subprocessor is a third-party company that QR Rx engages to help operate the platform. This page is the core service-provider registry for information governed by our Business Associate Agreement or our Privacy Policy. Optional systems a clinic connects, such as a calendar or practice-management service, are governed by the clinic's own connection and contract. If you are a healthcare provider doing procurement, share this registry with your privacy and compliance team.
PHI-authorized services
Each of the following providers may, in the course of operating the platform, come into contact with protected health information. Each must have a documented HIPAA-eligible contract posture, and the exact agreement status is shown below.
Render, Inc.
- Purpose
- Application hosting and Postgres database infrastructure for the QR Rx application and its data plane.
- Region
- United States, HIPAA-eligible workspace
- Data accessed
- Application data, including PHI processed on behalf of customers.
- BAA
- Signed BAA.
Amazon Web Services, Inc. S3 protected storage
- Purpose
- Object storage for clinic branding, provider uploads, patient-submitted recovery photos, and provider data snapshots, using server-side encryption at rest.
- Region
- United States, us-east region
- Data accessed
- Clinic branding, provider uploads, patient-submitted recovery photos, and provider data snapshots.
- BAA
- Signed BAA. Dedicated customer-managed KMS key management is not represented as active until deployment is complete.
Paubox, Inc.
- Purpose
- Transactional email delivery for care plans, recovery reminders, password resets, team invitations, and outcome digests.
- Region
- Vendor-managed service under the recorded BAA
- Data accessed
- Recipient email address, patient first name, procedure type, secure care-plan link, and access PIN when included in the message.
- BAA
- Signed BAA.
Telnyx LLC
- Purpose
- SMS delivery for care-plan links, recovery check-ins, and unscanned-plan nudges, with delivery-receipt webhooks.
- Region
- Vendor-managed service under the recorded HIPAA contract posture
- Data accessed
- Recipient phone number, patient first name, clinic name, secure care-plan link, and access PIN when included in the message.
- BAA
- HIPAA-eligible service terms are in place. Separate written confirmation of BAA status remains open, so QR Rx does not represent a signed BAA here.
Google LLC Cloud Translation API
- Purpose
- Care-plan translation through QR Rx's HIPAA-authorized Google Cloud configuration. Requests are limited to care-plan copy and do not include patient identifiers.
- Region
- Google Cloud global service endpoint
- Data accessed
- Procedure type, instructions, milestone descriptions, medication names, and medication directions. Patient identifiers are not included.
- BAA
- Signed BAA.
Non-PHI subprocessors
The following subprocessors support specific platform features but are not authorized for Protected Health Information. These flows are designed to exclude PHI.
Anthropic, PBC
- Purpose
- Restricted language-model assistance for administrative tools and explicitly governed clinical AI flows. Patient-specific calls require the deployment clinical AI policy gate. The default configuration fails closed.
- Region
- Vendor-managed service. PHI is not authorized.
- Data accessed
- Non-PHI administrative content. A patient-specific flow may be enabled only after the deployment owner documents an applicable BAA or a HIPAA-compliant de-identification basis for that exact flow. Direct-identifier removal is defense in depth and is not itself represented as formal de-identification.
- BAA
- No Anthropic BAA is recorded. Anthropic is not authorized for PHI. Patient-specific calls remain disabled unless the separate documented policy requirement is satisfied.
Cloudflare, Inc. Turnstile
- Purpose
- Bot-protection challenges on public forms and patient verification surfaces.
- Region
- Global edge network
- Data accessed
- Challenge tokens and standard connection metadata. QR Rx does not send form contents or PHI to Turnstile.
- BAA
- Not authorized for PHI.
Google LLC Sign-In
- Purpose
- Optional OAuth identity provider for provider-portal sign-in.
- Region
- Google global identity service
- Data accessed
- Email address, full name, and profile-picture URL from the standard Google OAuth scope. No PHI is sent for sign-in.
- BAA
- Not authorized for PHI. Used only for identity.
Firecrawl, Inc.
- Purpose
- Public website discovery for admin-created clinic demos and branding intake.
- Region
- Vendor-managed service. Public website content only.
- Data accessed
- Public clinic website URLs and publicly available website content. Patient data and PHI are not authorized for this flow.
- BAA
- Not authorized for PHI. Intake is limited to public clinic website content.
Stripe, Inc.
- Purpose
- Provider subscription billing, payment processing, and the customer billing portal. Patients are not billed by QR Rx.
- Region
- Vendor-managed service. Provider billing data only.
- Data accessed
- Provider billing contact, payment method, and subscription status. No patient information is sent to Stripe.
- BAA
- Not authorized for PHI. Stripe is limited to provider-account billing data.
Google LLC Google Ads
- Purpose
- Conversion measurement on public marketing and provider-acquisition pages. The tag is disabled before loading on qrrx.care and patient care-plan routes.
- Region
- Global
- Data accessed
- Marketing-page interactions and conversion events. No patient identifiers, care-plan content, symptoms, photos, or other PHI are sent.
- BAA
- Not authorized for PHI. Google Ads is excluded from patient PHI surfaces.
Functional Software, Inc. Sentry
- Purpose
- Application error monitoring. Session replay, tracing, logs, request bodies, cookies, and default PII collection are disabled, and events pass through PHI and credential scrubbing before transmission.
- Region
- Vendor-managed service. Scrubbed technical data only.
- Data accessed
- Scrubbed technical error metadata and an internal user ID when available. Patient names, contact details, tokens, request bodies, care-plan content, and session recordings are not authorized.
- BAA
- Not authorized for PHI under the configured data flow.
Notification of changes
Business Associate will provide at least 30 days of advance notice before enabling a new subcontractor to access PHI, except when an emergency replacement is reasonably necessary to protect security or continuity. Covered Entities may raise a reasonable data-protection objection during that period. The governing terms are in the BAA at qrrx.io/baa. The current core registry lives on this page.
Contact us
For procurement, security review, or compliance questions about any subprocessor on this list, email dnelson@qrrx.io with the subject line "Subprocessor Review."