Rōvn · Investor Room
AI agent: checking…
All sections
Legal & Commercial Templates

Sub-Processor Flow-Down

Current truthRōvn master canon generation 8 · effective 2026-07-21. Earlier dated diligence documents are historical snapshots, not current deployment proof.Ask the canon-grounded agent →
AI Diligence Console

Sub-Processor Flow-Down

Reviewed: 2026-07-22 · Canon: generation 8, effective 2026-07-21

This document describes the cascade by which a customer-facing BAA flows down through every Rōvn vendor that would touch PHI. The current gating register lives at 06.4 and 06.11; because the deployed environment is synthetic-only, the cascade below describes the designed flow-down that activates with real data, and execution is stated only with signed documents on file.


1. The flow-down chain

  +------------------------------------------------+
  |  Customer facility                             |
  |  (signs Rovn Customer BAA + MSA)               |
  +-----------------------+------------------------+
                          |
                          |  customer authorizes the disclosed
                          |  sub-processors in the BAA
                          v
  +------------------------------------------------+
  |  Rovn, Inc. (Delaware C-Corp)                  |
  |  (Business Associate to the customer)          |
  +-----------------------+------------------------+
                          |
                          |  Rovn vendor BAAs (sub-BAAs),
                          |  executed before any PHI flows
                          v
  +----------------+  +----------------------+  +---------------------+
  |  Cloud         |  |  AI model providers  |  |  Identity and       |
  |  provider BAA  |  |  BAA + provider      |  |  screening vendors  |
  |  (Google Cloud)|  |  gates (06.5)        |  |  BAA / equivalent   |
  +----------------+  +----------------------+  +---------------------+
  +----------------+  +----------------------+
  |  SSO and       |  |  Non-PHI vendors     |
  |  communications|  |  (billing metadata,  |
  |  BAA if scope  |  |  scrubbed telemetry: |
  |  includes PHI  |  |  no BAA required)    |
  +----------------+  +----------------------+

2. Cascade enforcement mechanics

Customer-side

  1. Customer reviews the published sub-processor register (06.11)
  2. Customer signs the Rōvn Customer BAA
  3. The BAA's flow-down clause names the current register, requires BAA-equivalent terms with each PHI-touching vendor, provides 30 days' advance notice of material changes, and allows objection to specific sub-processors subject to feasibility

Rōvn-side

  1. Rōvn executes a BAA with every PHI-touching vendor before any PHI flows; onboarding is gated on execution
  2. Each vendor BAA carries PHI handling requirements consistent with the customer BAA, breach notification obligations, and subcontractor flow-down
  3. Annual vendor review with outside counsel

Vendor-side

  1. Each vendor maintains its own cascade to its subcontractors under its BAA
  2. Cloud provider sub-cascades are covered under the provider BAA on HIPAA-eligible services
  3. AI providers additionally pass the configuration, minimization, and logging gates in 06.5

3. Material change protocol

Change typeNotification window
New PHI-touching sub-processor added30 days advance
Sub-processor jurisdiction change30 days advance
Vendor BAA terminationImmediate, with immediate cessation of PHI flow to that vendor
Vendor name change or acquisitionWithin 30 days post-event

4. Opt-out mechanics

  • Cloud provider: no opt-out possible; foundational to the service.
  • AI providers: opt-out possible by disabling AI-assisted workflows for that customer; the experience degrades but no regulated data flows to the provider.
  • Identity and screening vendors: workflow-required; alternative arrangements considered case by case.
  • SSO: configurable per organization.
  • Observability: opt-out not feasible; PHI exclusion by scrubbing is the control.

5. Sub-processor list at signing (frozen reference)

The register as it stands at customer BAA signing is captured by an audit-ledger entry and an immutable artifact snapshot, with a copy delivered to the customer's compliance contact. That snapshot is the diligence record of what the customer agreed to.


6. Breach cascade

  1. Vendor notifies Rōvn per the vendor BAA terms
  2. Rōvn assesses affected customer scope
  3. Rōvn notifies affected customers per the customer BAA (within the HIPAA 60-day maximum, faster where the contract requires)
  4. The cascade continues to HHS OCR and individuals as the Breach Notification Rule requires

This cascade is exercised through the incident response runbook (06.10, section 6).

End of sub-processor flow-down.

Ask the AI agent about this section, the raise, compliance posture, or any cross-document question. Grounded in Rōvn canon generation 8, with on-page source citations.

Investor questions run through Google Cloud Vertex AI and are constrained to the hash-pinned Rōvn generation 8 canon. No PHI belongs in this room or its prompts.