Skip to main content
Last updated: October 5, 2026 Z360 uses trusted third-party companies, called subprocessors, to deliver its services. Which subprocessors process your data depends on the features your organization uses.

All subprocessors

Covered means the subprocessor is included in Z360’s BAA and has its own BAA with Z360. Not covered means it is unavailable or configured so patient information does not reach it in HIPAA organizations.

HIPAA-covered subprocessors

For an organization with an active BAA, patient information is processed only by the covered subprocessors above: Amazon Web Services, Telnyx, LiveKit, and Deepgram. In HIPAA organizations:
  • ElevenLabs voices are labeled Not HIPAA-supported and unavailable.
  • Integrations, connected apps, custom actions, and remote MCP servers are disabled.
    • Web search is blocked for HIPAA organizations.
  • Analytics content is masked, session recording is off, and only anonymous identifiers are used.
  • Nightwatch is not used for HIPAA organizations.
    • Push notifications carry generic alerts without names, message content, or other PHI.

Services you connect yourself

Gmail, Microsoft 365, Meta Lead Ads, and apps connected through integrations belong to your organization. Their terms and your agreement with those providers govern them. Email is not covered by your Z360 BAA.

Changes to this list

We announce additions, removals, or replacements in the Z360 release changelog. HIPAA organizations also receive email notice at least 10 days before a change affecting a subprocessor that handles patient information. Questions? Contact help@z360.biz.