EMStool LLC — Cadence MIH Scheduling Platform

Vendor Security Register

Policy #: HIPAA-SEC-012 Effective Date: July 16, 2026 (rev. July 16, 2026) Version: 1.5 Next Review: July 16, 2027

1. Purpose

This register tracks every third-party vendor whose service Cadence relies on, what data or exposure each one carries, and each vendor's own security attestation status. It satisfies SOC2 CC9.1 and ISO 27001 5.23 (formal cloud/vendor security assessment) and is the source of truth referenced by hipaa/risk-analysis.html Asset 7.

This register documents vendors' publicly-claimed certifications as researched on July 16, 2026. It is not a substitute for obtaining and reviewing each vendor's actual SOC2 report under NDA where a deeper assessment is warranted — that remains a periodic follow-up, not a one-time check.
Cadence is deployed per-client, each on its own hardware (EMStool-provided or the client's own, in their own rack), connected only via outbound tunnel — there is no shared production instance. Backblaze B2 is one backup-destination option; it is a per-deployment configuration choice, not a fixed architectural dependency. A client deployment may instead back up locally (rsync to client-owned storage/NAS, or any destination the client controls) and skip Backblaze B2 entirely. If a client chooses Backblaze B2 for their own deployment, the client sets up and owns that B2 account directly and is responsible for executing their own BAA with Backblaze — EMStool does not provision or hold that account on the client's behalf. EMStool's own non-client infrastructure (a demo/trial instance for prospective clients) runs on seed/dummy data only and holds no real ePHI, so no vendor BAA is needed there either.

2. Vendor Inventory

VendorRole in CadenceData ExposureSOC2 StatusHIPAA / BAA
Cloudflare Tunnel (all external traffic), CDN, Access, TURN All traffic transits Cloudflare's network (TLS-protected in transit; Cloudflare does not have access to app-layer plaintext for the tunnel path). The tunnel account is expected to be the client's own by default — the client owns that Cloudflare account and its BAA directly, same pattern as Backblaze B2 above — though EMStool can optionally set up and manage the tunnel on the client's behalf if requested. SOC 2 Type II (annual, security/confidentiality/availability) Client-owned by default: client's own BAA responsibility. If EMStool manages the tunnel for a client instead, EMStool's own BAA with Cloudflare for that account is not yet executed (tracked in roadmap).
GitHub Source code hosting, CI/CD (GitHub Actions) Application source code only — no PHI in repo SOC 2 Type II (Enterprise Cloud, covers Actions) N/A — no PHI stored
Backblaze B2 Offsite encrypted database backup storage — optional per deployment, a client's own choice of backup destination GPG-encrypted backup blobs (ciphertext only — B2 never sees plaintext PHI). Deployments that back up locally instead (e.g. rsync to client-owned storage) have no Backblaze exposure at all. SOC 2 Type II BAA offered by vendor on request. Any client that opts into Backblaze B2 for their own deployment owns that B2 account and is responsible for their own BAA with Backblaze directly — not an EMStool action item. EMStool's own demo/trial instance holds no real ePHI, so no BAA applies there.
Telnyx SMS delivery (MFA codes, appointment notifications) Phone numbers, SMS body text (may include appointment details, not clinical PHI) SOC 2 Type I / II / III Falls under HIPAA "conduit exception" as a mere transmission conduit — no BAA required for SMS transport
Resend Transactional email (password reset, welcome, video-consult invites) Email addresses, auth-related content — no clinical PHI in bodies SOC 2 Type II (Vanta-audited) No PHI transmitted — BAA not required for current usage pattern
Pushover Uptime Kuma downtime push notification Generic "service is down" alert text only — no patient data, no app content of any kind No SOC2 attestation found (small indie service) N/A — zero PHI or sensitive data ever transits this channel by design
OSRM / Nominatim / Gotenberg Route optimization, geocoding, report-to-PDF rendering None — all three run as internal, self-hosted services only. No public-fallback code path exists (removed 2026-07-15/16). N/A — internal only N/A — no third-party data transfer occurs

3. Review Cadence

This register is reviewed annually, or immediately when a new third-party service is introduced into the codebase. Each review re-confirms vendor SOC2/attestation status against the vendor's current public trust page (or the actual report under NDA, where warranted) rather than carrying forward institutional memory.

4. Open Follow-Ups