Skip to content
24/7 Support (405) 300-0122

Subprocessors

We use a small number of vendors to deliver our services. This page names all of them, says what each one does for you, and separates the ones that can reach protected health information from the ones that cannot.

Last updated

Vendors that can reach protected health information

Each vendor below is bound to the same restrictions on the use and disclosure of protected health information that we are, and to maintain appropriate safeguards for it. This is the list our Business Associate Agreement refers to.

  • Acronis

    What it does
    Backup and disaster recovery for workstations and servers.
    What it can see
    Backup images of the machines we protect, which contain whatever those machines hold, including clinical and billing records.
  • Amazon Web Services

    What it does
    One of our two HIPAA-covered hosting environments. It runs the Clinic Voice IVR, the Voice Portal and the services we are building next.
    What it can see
    Whatever those services handle, including prescription refill requests, caller details and call records.
  • Atera

    What it does
    Remote monitoring, management and support sessions on the computers we maintain.
    What it can see
    Remote screen access to managed computers, device and software inventory, and the contents of support tickets.
  • HIPAAtizer

    What it does
    Hosting the online forms and agreements you complete and sign.
    What it can see
    Everything submitted through our forms, including intake details, authorizations and signatures.
  • Microsoft 365

    What it does
    Email, file storage and collaboration, where we run one for you.
    What it can see
    Mailbox contents, stored files and anything sent to us by email.
  • Namecheap

    What it does
    Domain registration, a small number of client websites, and email on their PrivateEmail platform where a practice has ordered it through us.
    What it can see
    Domain and DNS records and website content, neither of which carries patient data. Email hosted here receives whatever is sent to it. PrivateEmail is not a HIPAA-compliant email platform, so we point practices that correspond with patients by email to Proton instead.
  • ScreenConnect

    What it does
    Attended remote support sessions on the computers we maintain.
    What it can see
    Screen access to a machine while we are working on it, which means whatever happens to be open on it at the time.
  • SkySwitch

    What it does
    The telephone platform behind Clinic Voice, including CloudMessage for business texting. We build and support your phone system on it, and every one of our accounts sits in their HIPAA environment.
    What it can see
    Call routing and call records, voicemail, recorded calls, and any text message sent to or from a CloudMessage number. We send no health information over text ourselves, but a patient can put anything in a message.
  • Vultr

    What it does
    Our second HIPAA-covered hosting environment, paired with AWS so that a failure at one does not take a service down.
    What it can see
    The same workloads and data as AWS, including the copies held for backup and disaster recovery.

Other vendors, with no access to health information

These handle your business information but never your patients'. They are listed because asking who touches your data should get you a complete answer, not only the regulated part of one.

  • HubSpot

    What it does
    Our customer relationship system, and the platform our marketing email is sent from.
    What it can see
    Business contact details for the people we work with at your practice, and a record of the marketing email we have sent. You do not correspond with us through it, so nothing a patient writes can reach it.
  • QuickBooks

    What it does
    Accounting, invoicing and bookkeeping.
    What it can see
    Business name, billing contacts and invoice amounts. No patient information is recorded here.
  • Quoter

    What it does
    Preparing and sending the quotes you approve.
    What it can see
    Business contact details and the equipment and services being quoted.
  • Skyline Payments

    What it does
    Processing invoice payments and storing a payment method on file. You may see this as PayInvoice or as Skyline Payments; they are the same vendor.
    What it can see
    Billing contact details and payment method. No health information reaches this vendor.
  • SMTP2GO

    What it does
    The relay that delivers our automated email: onboarding instructions, account notices and service alerts.
    What it can see
    The addresses we send to and the contents of those messages. Service notices are written to say that something is waiting and to link you to log in, rather than to carry the thing itself, so a pending refill or a new voicemail is announced without naming anyone.

Changes to this list

We keep this page current. If you have a Business Associate Agreement with us, you can also request the list directly at any time, and we will send it to you in writing.

Questions about a vendor on this page, or about how your data moves between them, go to info@clinicnetworking.com or (405) 300-0122.

See also our Privacy Policy and Terms & Conditions.