Home · Legal
Legal

Subprocessors

The third parties that support the Corevia platform, what each one does, and whether it can access protected health information.

Effective: September 1, 2026  ·  Last updated: September 1, 2026

We publish this because every serious security review asks for it, and answering the question once in public is faster than answering it forty times in a questionnaire. It sets out every category of subprocessor that supports the Corevia platform, what each one does, whether it can touch protected health information, and the agreement that governs that access — which is what a reviewer is actually assessing.

Providers are identified by role rather than by name. The specific entities, and the underlying agreements, are provided under NDA as part of the security diligence pack: legal@coreviahealth.com. Customers under a Business Associate Agreement receive the named list, and notice of material changes to it, in accordance with the notice terms of their agreement.

Corevia Health, LLC is a California limited liability company.

Current subprocessors

CategoryPurposeCan access PHI?Agreement
Cloud infrastructure providerHosting, storage, networking and key management, United States regions onlyYesBAA
Clinical data platformFHIR R4 record storage and access controlYesBAA
AI services, in-accountClinical documentation drafting and clinical assistance, running inside our own cloud accountYesCovered by the cloud BAA
Document data extractionReading identity documents during verificationYesCovered by the cloud BAA
Medical speech transcriptionVisit audio transcription for the AI scribeYesCovered by the cloud BAA
E-prescribing providerSurescripts-certified electronic prescribingYesBAA
National reference laboratoriesDiagnostic laboratory services and result deliveryYesDirect agreement
503A compounding pharmacy partnersPrescription compounding and fulfillmentYesDirect agreement
Transactional email deliveryAccount and notification emailLimitedCovered by the cloud BAA
Payment processorPayment processing on the customer's own merchant accountNoCustomer's own merchant agreement
Website delivery and analyticsCookieless, aggregate measurement for coreviahealth.com onlyNoStandard terms; no PHI in scope

The AI services listed above run inside Corevia's own cloud account under that provider's Business Associate Agreement. No third-party model vendor, and no outside scribe service, receives protected health information — and nothing is used to train anyone's model.

Why the payments row reads the way it does

The payment processor row is different in kind from every other row, and the difference is deliberate. Corevia is not the merchant of record and never holds customer funds. The customer connects their own payment processor account, under their own merchant agreement, and money moves between the patient and the customer without passing through Corevia. Corevia is not a payment facilitator, a money transmitter or a merchant of record.

That relationship is therefore the customer's, not ours: the customer selects the processor, signs its terms, and is that processor's counterparty. The processor does not receive protected health information from Corevia. This is explained in more detail on the payments page.

Why this is by category rather than by company. What a security review needs to establish is which functions touch protected health information, on what legal basis, and whether anything sits outside a Business Associate Agreement. Every one of those questions is answered above. The specific corporate identities are commercial information, and several of them vary by customer — the compounding partners and the payment processor are chosen per tenant, not by us.

We provide the named list, and the underlying agreements, under NDA as part of the security diligence pack. Customers operating under a Business Associate Agreement receive it as a matter of course, together with notice of material changes. Ask at legal@coreviahealth.com.

Contact

Questions about this list, or a request for the underlying agreements as part of a security review: legal@coreviahealth.com

Corevia Health, LLC
8605 Santa Monica Blvd, Suite 560166
West Hollywood, California 90069
United States