A subprocessor is a third-party company that QR Rx engages to help operate the platform. This page lists every subprocessor that may, in the course of its role, come into contact with information governed by our Business Associate Agreement or our Privacy Policy. If you are a healthcare provider doing procurement, this is the canonical list to share with your privacy and compliance team.
HIPAA-covered subprocessors
Each of the following providers may, in the course of operating the platform, come into contact with Protected Health Information (PHI). Each maintains a signed Business Associate Agreement (BAA) with QR Rx.
Render, Inc.
- Purpose
- Compute hosting and Postgres database infrastructure for the QR Rx application and its data plane.
- Region
- United States (HIPAA-eligible workspace)
- Data accessed
- All application data including PHI processed on behalf of customers.
- BAA
- Yes
Amazon Web Services, Inc.
- Purpose
- Object storage for clinic logos, branding assets, and provider-uploaded files (Amazon S3), using server-side encryption at rest.
- Region
- United States (us-east region)
- Data accessed
- Provider branding assets and file uploads. Dedicated customer-managed KMS key management is not represented as active until deployment is complete.
- BAA
- Yes
Paubox, Inc.
- Purpose
- HIPAA-compliant transactional email delivery. Sends care plan emails, recovery reminders, password resets, team invitations, and outcome digests.
- Region
- United States
- Data accessed
- Recipient email address, patient first name, procedure type, secure care plan link, PIN reference.
- BAA
- Yes
Telnyx LLC
- Purpose
- SMS delivery for care plan links, recovery check-ins, and unscanned-plan nudges. Delivery receipt webhooks for per-message status.
- Region
- United States
- Data accessed
- Recipient phone number, patient first name, secure care plan link.
- BAA
- Yes
Google LLC (Cloud Translation API)
- Purpose
- Procedure-level care plan translation into the patient's preferred language. Used only on the de-identified care plan content, not on patient identifiers.
- Region
- United States (Google Cloud)
- Data accessed
- Procedure type, instructions, milestone descriptions, medication names. No patient identifiers transmitted.
- BAA
- Yes
Non-PHI subprocessors
The following subprocessors support specific platform features but are never sent Protected Health Information. We list them here in the interest of full transparency.
Anthropic, PBC
- Purpose
- Large language model API used as the last-resort tier for the Cura AI care plan assistant, after the provider FAQ library and the verified cross-clinic Knowledge Base. See the BAA Section 22 for the full lookup chain.
- Region
- United States
- Data accessed
- Data-minimized care plan context plus the patient's redacted question. Known patient names and common direct-identifier patterns (email, phone, record identifiers, addresses, URLs, and full numeric dates) are removed before the external fallback; the call is suppressed if redaction fails.
- BAA
- Not authorized for direct patient identifiers or PHI. Contract, retention, and training settings are reviewed through the vendor-risk program before any scope change.
Stripe, Inc.
- Purpose
- Subscription billing, payment processing, and customer billing portal for healthcare providers. Patients are never billed by QR Rx; Stripe is on the provider-account side only.
- Region
- United States
- Data accessed
- Provider billing contact, payment method, subscription status. No patient information.
- BAA
- Not applicable. Stripe does not access PHI. Stripe is PCI DSS Level 1 certified.
Cloudflare, Inc.
- Purpose
- Bot-protection challenge (Turnstile) on public forms (contact, intake, patient verification). Reduces automated abuse without impacting legitimate users.
- Region
- Global edge network
- Data accessed
- Anonymous challenge tokens. No form contents and no PHI are transmitted to Cloudflare.
- BAA
- Not applicable.
Google LLC (Sign-In)
- Purpose
- OAuth identity provider for the optional Sign in with Google flow. Used at the provider-portal sign-in surface and the qrrx.net patient account surface.
- Region
- United States
- Data accessed
- Email address, full name, profile picture URL (the standard Google OAuth scope). No PHI.
- BAA
- Not applicable. Used only for identity, not for any PHI flow.
Google LLC (Google Ads)
- Purpose
- Conversion measurement on public marketing and provider-acquisition pages. The tag is disabled before loading on qrrx.care and all patient care-plan routes.
- Region
- Global
- Data accessed
- Marketing-page interaction and conversion events. No patient identifiers, care-plan content, symptoms, photos, or other PHI.
- BAA
- Not applicable. Google Ads is excluded from every patient PHI surface.
Functional Software, Inc. (Sentry)
- Purpose
- Application error monitoring for operational reliability. Session replay, tracing, logs, request bodies, cookies, and default PII collection are disabled. Events pass through a PHI/credential scrubber before transmission.
- Region
- United States
- Data accessed
- Scrubbed technical error metadata and an internal user ID when available. No patient names, contact details, tokens, request bodies, care-plan content, or session recordings.
- BAA
- Not applicable under the configured no-PHI data flow.
Notification of changes
Business Associate will notify Covered Entities of material changes to this subprocessor list at least 30 calendar days before a new subprocessor with PHI access is engaged, and within 30 calendar days of any other change. Material changes are also reflected in the BAA at qrrx.io/baa. The most current list always lives on this page.
Contact us
For procurement, security review, or compliance questions about any subprocessor on this list, email security@qrrx.io with the subject line "Subprocessor Review."