The third parties that support the Corevia platform, what each one does, and whether it can access protected health information.
Effective: September 1, 2026 · Last updated: September 1, 2026
We publish this because every serious security review asks for it, and answering the question once in public is faster than answering it forty times in a questionnaire. It sets out every category of subprocessor that supports the Corevia platform, what each one does, whether it can touch protected health information, and the agreement that governs that access — which is what a reviewer is actually assessing.
Providers are identified by role rather than by name. The specific entities, and the underlying agreements, are provided under NDA as part of the security diligence pack: legal@coreviahealth.com. Customers under a Business Associate Agreement receive the named list, and notice of material changes to it, in accordance with the notice terms of their agreement.
Corevia Health, LLC is a California limited liability company.
| Category | Purpose | Can access PHI? | Agreement |
|---|---|---|---|
| Cloud infrastructure provider | Hosting, storage, networking and key management, United States regions only | Yes | BAA |
| Clinical data platform | FHIR R4 record storage and access control | Yes | BAA |
| AI services, in-account | Clinical documentation drafting and clinical assistance, running inside our own cloud account | Yes | Covered by the cloud BAA |
| Document data extraction | Reading identity documents during verification | Yes | Covered by the cloud BAA |
| Medical speech transcription | Visit audio transcription for the AI scribe | Yes | Covered by the cloud BAA |
| E-prescribing provider | Surescripts-certified electronic prescribing | Yes | BAA |
| National reference laboratories | Diagnostic laboratory services and result delivery | Yes | Direct agreement |
| 503A compounding pharmacy partners | Prescription compounding and fulfillment | Yes | Direct agreement |
| Transactional email delivery | Account and notification email | Limited | Covered by the cloud BAA |
| Payment processor | Payment processing on the customer's own merchant account | No | Customer's own merchant agreement |
| Website delivery and analytics | Cookieless, aggregate measurement for coreviahealth.com only | No | Standard terms; no PHI in scope |
The AI services listed above run inside Corevia's own cloud account under that provider's Business Associate Agreement. No third-party model vendor, and no outside scribe service, receives protected health information — and nothing is used to train anyone's model.
The payment processor row is different in kind from every other row, and the difference is deliberate. Corevia is not the merchant of record and never holds customer funds. The customer connects their own payment processor account, under their own merchant agreement, and money moves between the patient and the customer without passing through Corevia. Corevia is not a payment facilitator, a money transmitter or a merchant of record.
That relationship is therefore the customer's, not ours: the customer selects the processor, signs its terms, and is that processor's counterparty. The processor does not receive protected health information from Corevia. This is explained in more detail on the payments page.
Why this is by category rather than by company. What a security review needs to establish is which functions touch protected health information, on what legal basis, and whether anything sits outside a Business Associate Agreement. Every one of those questions is answered above. The specific corporate identities are commercial information, and several of them vary by customer — the compounding partners and the payment processor are chosen per tenant, not by us.
We provide the named list, and the underlying agreements, under NDA as part of the security diligence pack. Customers operating under a Business Associate Agreement receive it as a matter of course, together with notice of material changes. Ask at legal@coreviahealth.com.
Questions about this list, or a request for the underlying agreements as part of a security review: legal@coreviahealth.com
Corevia Health, LLC