Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Reading from the database as the signed-in user.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

DashboardMenu

Vendor oversight

Every vendor that touches patient information needs a signed, current business associate agreement and a known risk tier. This page says how close the practice is to that today.

BAA coverage

15 of 17

active vendors with patient data have a signed BAA in force today. 2 do not.

88% covered

Open findings

Gaps the rules found in the register, by severity.

Active vendors by risk tier

22 active vendors. Tiers are computed from patient data access, the kind of service and current security evidence. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers. Whether one is required is decided before the evidence points, so a missing one cannot demand itself.

Needs attention now

Vendors with critical or high findings, worst first.

All findings
Ironbark IT Services

Managed IT: servers, backups and help desk. IT managed services, full patient records. Owner: Theo Brandt.

Critical findingHigh riskBAA: Draft, not signed

1 finding: Patient data without a signed BAA

Quillstone Transcription

Dictation transcription for clinic notes. Transcription or dictation, full patient records. Owner: Dr. Amara Singh.

Critical findingHigh riskBAA: Signed, in force

1 finding: Days held without a BAA were covered by a BAA entered later, not yet confirmed

Northgate Revenue Partners

Outsourced billing, coding and denial follow-up. Billing or coding service, full patient records. Owner: Keisha Okafor.

High findingCritical riskBAA: Signed, in force

2 findings: Subcontractor handles our data without confirmed terms; High-risk vendor with no independent security evidence

Chimeline Patient Messaging

Appointment reminders by text and voice. Patient messaging or reminders, limited patient data. Owner: Owen Castellano.

High findingModerate riskBAA: Signed, in force

1 finding: Signed BAA is missing required terms

Copperleaf Voice Notes

Ambient dictation pilot for two clinics. Transcription or dictation, limited patient data. Owner: Dr. Amara Singh.

High findingModerate riskBAA: Signed, in force

1 finding: Not recorded as live for months: confirm no patient data is being shared

Pinecrest Text Reminders

Appointment reminder texts and two-way scheduling messages. Patient messaging or reminders, limited patient data. Owner: Owen Castellano.

High findingModerate riskBAA: Signed, not yet in force

2 findings: BAA needed before any patient data is shared; Annual review overdue or never done