EMStool LLC — Cadence EMS Scheduler

Vendor Risk Register

Document #: VRR-2026-01 Version: 1.0 Effective: June 29, 2026 Owner: Jacob Russell, Security Officer
This register documents all third-party vendors and service providers used by EMStool LLC in the operation of Cadence. Each vendor is assessed for data access, risk level, and compliance status per HIPAA Business Associate Agreement requirements.

1. Vendor Inventory

Vendor Service Data Access Risk BAA Compliance Last Review
Cloudflare, Inc. DNS, CDN, Zero Trust tunnel, DDoS protection Network traffic (metadata only — encrypted at tunnel level) Medium Not required (no PHI in transit metadata) SOC 2 Type II, ISO 27001, HIPAA-ready Jun 2026
Cloudflare Realtime (TURN) WebRTC media relay for Clinical Video Consult (OLMC) — separate product/App ID from the Tunnel above Relayed call audio/video (SRTP-encrypted) — only on calls that can't connect peer-to-peer directly (~15-20% of calls) Medium Not required (no plaintext PHI — SRTP encrypted); reassess on Business plan upgrade SOC 2 Type II, ISO 27001, HIPAA-ready Jul 2026
Telnyx, Inc. SMS delivery — appointment scheduling notifications to staff Staff phone numbers + non-patient appointment metadata (date/time/coordinator name) — no patient identifiers in message body Low Not required (no PHI in message content) Toll-free registered, compliance review ongoing Jul 2026
Resend, Inc. Transactional email delivery Email addresses; password-reset/admin-reset/welcome/video-consult-invite content — no patient identifiers in message body Low Not required (no PHI in message content) SOC 2 Type II Jun 2026
Backblaze, Inc. B2 cloud storage — off-site encrypted backups Encrypted database backups (.sql.gpg) — no plaintext PHI Medium Review needed — data is encrypted; verify BAA status SOC 2 Type I Jun 2026
GitHub / Microsoft Source code repository (private repo) Application code only — no PHI or credentials stored in repo Low Not required (no PHI) SOC 2 Type II, ISO 27001 Jun 2026
Google Fonts / Google LLC Web font delivery (DM Sans, Lora) Browser IP only (standard CDN request) Low Not required Standard CDN — no user data transmitted Jun 2026
OSRM (self-hosted) Route optimization engine Address/location data (no PHI) Low Not required (self-hosted) Self-hosted — under EMStool control Jun 2026
Gotenberg (self-hosted) PDF generation Report content including PHI (self-hosted) Medium Not required (self-hosted, on-premises) Self-hosted — under EMStool control Jun 2026

2. Critical Vendor Action Items

3. Vendor Review Process

This register is reviewed annually and whenever a new vendor is onboarded. For each vendor review:

4. New Vendor Approval

Before onboarding a new vendor that will have access to PHI or operate in the Cadence infrastructure:

  1. Classify data access level (PHI, PII, network only, code only)
  2. Obtain vendor's SOC 2 or equivalent compliance report
  3. Execute BAA if vendor will access PHI
  4. Add vendor to this register
  5. Document approval in change management log
Security Officer Signature
Jacob Russell — Security Officer, EMStool LLC
Date Reviewed
June 29, 2026