Sub-Processor Flow-Down
Reviewed: 2026-07-22 · Canon: generation 8, effective 2026-07-21
This document describes the cascade by which a customer-facing BAA flows down through every Rōvn vendor that would touch PHI. The current gating register lives at 06.4 and 06.11; because the deployed environment is synthetic-only, the cascade below describes the designed flow-down that activates with real data, and execution is stated only with signed documents on file.
1. The flow-down chain
+------------------------------------------------+
| Customer facility |
| (signs Rovn Customer BAA + MSA) |
+-----------------------+------------------------+
|
| customer authorizes the disclosed
| sub-processors in the BAA
v
+------------------------------------------------+
| Rovn, Inc. (Delaware C-Corp) |
| (Business Associate to the customer) |
+-----------------------+------------------------+
|
| Rovn vendor BAAs (sub-BAAs),
| executed before any PHI flows
v
+----------------+ +----------------------+ +---------------------+
| Cloud | | AI model providers | | Identity and |
| provider BAA | | BAA + provider | | screening vendors |
| (Google Cloud)| | gates (06.5) | | BAA / equivalent |
+----------------+ +----------------------+ +---------------------+
+----------------+ +----------------------+
| SSO and | | Non-PHI vendors |
| communications| | (billing metadata, |
| BAA if scope | | scrubbed telemetry: |
| includes PHI | | no BAA required) |
+----------------+ +----------------------+
2. Cascade enforcement mechanics
Customer-side
- Customer reviews the published sub-processor register (06.11)
- Customer signs the Rōvn Customer BAA
- The BAA's flow-down clause names the current register, requires BAA-equivalent terms with each PHI-touching vendor, provides 30 days' advance notice of material changes, and allows objection to specific sub-processors subject to feasibility
Rōvn-side
- Rōvn executes a BAA with every PHI-touching vendor before any PHI flows; onboarding is gated on execution
- Each vendor BAA carries PHI handling requirements consistent with the customer BAA, breach notification obligations, and subcontractor flow-down
- Annual vendor review with outside counsel
Vendor-side
- Each vendor maintains its own cascade to its subcontractors under its BAA
- Cloud provider sub-cascades are covered under the provider BAA on HIPAA-eligible services
- AI providers additionally pass the configuration, minimization, and logging gates in 06.5
3. Material change protocol
| Change type | Notification window |
|---|---|
| New PHI-touching sub-processor added | 30 days advance |
| Sub-processor jurisdiction change | 30 days advance |
| Vendor BAA termination | Immediate, with immediate cessation of PHI flow to that vendor |
| Vendor name change or acquisition | Within 30 days post-event |
4. Opt-out mechanics
- Cloud provider: no opt-out possible; foundational to the service.
- AI providers: opt-out possible by disabling AI-assisted workflows for that customer; the experience degrades but no regulated data flows to the provider.
- Identity and screening vendors: workflow-required; alternative arrangements considered case by case.
- SSO: configurable per organization.
- Observability: opt-out not feasible; PHI exclusion by scrubbing is the control.
5. Sub-processor list at signing (frozen reference)
The register as it stands at customer BAA signing is captured by an audit-ledger entry and an immutable artifact snapshot, with a copy delivered to the customer's compliance contact. That snapshot is the diligence record of what the customer agreed to.
6. Breach cascade
- Vendor notifies Rōvn per the vendor BAA terms
- Rōvn assesses affected customer scope
- Rōvn notifies affected customers per the customer BAA (within the HIPAA 60-day maximum, faster where the contract requires)
- The cascade continues to HHS OCR and individuals as the Breach Notification Rule requires
This cascade is exercised through the incident response runbook (06.10, section 6).
End of sub-processor flow-down.