EMStool LLC — Cadence MIH Scheduling Platform

Third-Party Vendor & Service Documentation

Policy #: HIPAA-SEC-007 Effective Date: June 1, 2026 Version: 1.0 Next Review: June 1, 2027

1. Purpose

This document identifies all third-party vendors and external services used by EMStool LLC in the operation of the Cadence platform. It documents whether each vendor receives Protected Health Information (PHI), the Business Associate Agreement (BAA) status, and the risk classification for each service.

Under HIPAA (45 CFR §164.308(b)), covered entities and business associates must enter into a Business Associate Agreement with any vendor that creates, receives, maintains, or transmits PHI on their behalf. This document serves as the organizational record of all such relationships.

2. Vendor Summary

Vendor Service PHI Contact BAA Status Risk
Cloudflare Zero Trust Tunnel / CDN Encrypted transit only Pending Low
Cloudflare Realtime (TURN) WebRTC media relay for Clinical Video Consult Audio/video call content — relayed calls only Pending Medium
Telnyx SMS delivery — appointment scheduling notifications None — staff phone numbers + non-patient appointment metadata only Not Required — No PHI Low
Nominatim (self-hosted) Address geocoding Patient addresses — local only Not Required — Local None
OSRM (self-hosted) Route optimization Patient coordinates — local only Not Required — Local None
Gotenberg (self-hosted) PDF generation Shift report data — local only Not Required — Local None
Resend Transactional email None — password resets only Not Required — No PHI None
OpenStreetMap (tile server) Map tile display Coordinates only (no patient identifiers) Not Required — No PHI Minimal
Google Maps Patient navigation links User-initiated only — address in URL Acknowledged Risk Low
GitHub Source code repository None — no live data, code only Not Required — No PHI None

3. Vendor Details

Cloudflare — Zero Trust Tunnel

BAA Status: Pending — Available on Business/Enterprise plans. Current plan does not include BAA.

Cloudflare Realtime — TURN Relay (Clinical Video Consult)

BAA Status: Pending — Available on Business/Enterprise plans. Current plan does not include BAA. Separate Cloudflare product from the Zero Trust Tunnel above — distinct account App ID/token, distinct data flow.

Telnyx — SMS Delivery

BAA Status: Not Required — No PHI is transmitted via Telnyx.

Nominatim — Address Geocoding (Self-Hosted)

BAA Status: Not Required — Service runs entirely on EMStool LLC infrastructure. No data leaves the local network.

OSRM — Route Optimization (Self-Hosted)

BAA Status: Not Required — Service runs entirely on EMStool LLC infrastructure.

Gotenberg — PDF Generation (Self-Hosted)

BAA Status: Not Required — Service runs entirely on EMStool LLC infrastructure.

Resend — Transactional Email

BAA Status: Not Required — No PHI is transmitted via Resend.

OpenStreetMap Tile Server

BAA Status: Not Required — No PHI transmitted.

Google Maps — Navigation Links

BAA Status: Acknowledged Risk — No BAA available (consumer product)

GitHub — Source Code Repository

BAA Status: Not Required — No PHI in repository.

4. BAA Action Log

VendorAction RequiredStatusTarget Date
Cloudflare (Tunnel/CDN)Sign BAA upon upgrade to Business/Enterprise planPending plan upgradeTBD
Cloudflare Realtime (TURN)Sign BAA upon upgrade to Business/Enterprise plan — higher priority, carries relayed call media not just metadataPending plan upgradeTBD
All others (incl. Telnyx)No BAA requiredN/A

5. Annual Review Checklist

During the annual policy review, the Security Officer must:

Security Officer Signature
Jacob Russell, Security Officer
Date
June 1, 2026