| Vendor | Scope | BAA type | Signed | Signed by | Notes |
|---|---|---|---|---|---|
| Google Cloud / Workspace | All HIPAA-eligible GCP services + Workspace | Google Workspace HIPAA BAA | 2025-09-01 | mohammadi@cytognosis.org | Covers Cloud Run, GCS, Cloud SQL, BigQuery, Artifact Registry, Secret Manager. Does NOT cover all AI APIs — check before using. |
| Google Cloud CDPA | EU data processing | Cloud Data Processing Addendum | 2025-09-01 | mohammadi@cytognosis.org | EU GDPR compliance |
| EU Data Protection | EU subjects | EU DPL certification | 2025-09-01 | mohammadi@cytognosis.org | Certified via Admin console |
admin.google.com → Account → Account settings → Legal & Compliance → Security and Privacy Additional Terms
| Vendor | Used for | PHI risk | Mitigation |
|---|---|---|---|
| GitHub | Source code, CI/CD | None — no PHI in repos | Secret scanning enabled; verify no PHI in code/configs |
| Zotero | Reference management | None | Metadata only; PDFs on Drive |
| Anthropic | Internal Claude usage | None currently | Do not send PHI to Claude; use only de-identified examples |
| Monday.com | Project management | None | No PHI data entered; task tracking only |
| Cal.com (self-hosted) | Scheduling | Low | Self-hosted instance; no PHI in scheduling fields |
1. Check: Does this vendor ever process, store, or transmit PHI?
2. If yes: Obtain signed BAA BEFORE any PHI data flows. Do not rely on vendor's "HIPAA-ready" marketing — require a signed legal document.
3. If no: Document why not (what data does flow, what mitigations exist).
4. Update this file before vendor goes live.