Security & Compliance Disclosures
1. Data Residency
Recovery Network's production environment (recovery-network-v3) runs on Google Cloud Platform / Firebase, region us-central1 (Council Bluffs, Iowa), for Firestore, Cloud Functions, Cloud Storage, and associated Cloud Run services. This is the sole processing region for PHI at rest and in transit within our infrastructure; we do not multi-region replicate PHI outside us-central1 today.
2. Subprocessors
The following third parties process data on Recovery Network's behalf as of this disclosure. This list will be kept current as vendors are added, removed, or their role changes.
| Vendor | Role | Data touched | BAA status |
|---|---|---|---|
| Google Cloud / Firebase | Firestore, Cloud Functions, Cloud Storage, Speech-to-Text | PHI (facility_id‑scoped) | Executed BAA in place |
| Anthropic | Council LLM inference (Claude models, via Cloud Function proxy — never called from the browser) | De-identified clinical text; may include PHI in transit depending on facility configuration | Executed where applicable — confirm per-facility with Privacy Officer |
| Google (Gemini API) | Council LLM inference, same proxy pattern as Anthropic | Same as above | Coverage under the Google Cloud BAA has not been separately confirmed for the Gemini API product specifically — open item, see §4 |
| AWS (Bedrock) | Council LLM inference for two of six Council models, reached via an internal Cloud Run proxy — no AWS credentials are held in this codebase | Same as above | Not yet documented — open item, see §4 |
| Twilio | SMS delivery: crisis escalation alerts and aftercare reminders | Message content may reference facility/patient context | Not yet documented — open item, see §4 |
| Stripe | Billing and subscription payment processing | Billing/payment data only — no clinical or PHI data | Not applicable (no PHI touched) |
HubSpot and Apollo.io appear in our marketing/sales stack as inbound-only webhook receivers (deal and outreach-event data delivered to us, HMAC-verified) — Recovery Network does not send clinical, facility, or patient data to either service, and neither is in the PHI processing path.
3. Independent Security Assessment
Recovery Network has completed an internal code-and-configuration compliance review (HIPAA Compliance Audit, 2026-07-10), covering encryption, access control, audit logging, and facility_id scoping across the platform.
4. Open Items
In the interest of the same proactive disclosure, the following are not yet available. We are not representing these as complete:
- Third-party penetration test report — see §3.
- SIG/CAIQ or equivalent standardized vendor security questionnaire — not yet prepared. Available on request timeline; contact info@recoverynetwork.ai to discuss your specific format requirement.
- Written claims/billing/insurance data handling statement — the executed BAA (baa.html) covers clinical PHI, wearable data, and voice/video journal content; it does not yet separately address insurance claims or billing data. We do not currently ingest claims data as part of the platform; a written statement to that effect is in progress.
- Confirmed BAA coverage for the Gemini API and AWS Bedrock — the underlying cloud BAAs (Google Cloud, and any applicable AWS agreement) have not yet been confirmed to extend to these specific AI inference products by name. Being verified with each vendor.
- Twilio BAA status — not yet documented. Being verified.
Contact
Recovery Network Inc.
Attn: Privacy Officer
info@recoverynetwork.ai