Vendor oversight
As of Oct 7, 2026. Whole organization.
BAA coverage
15 of 17
active vendors with patient data have a signed BAA in force today. 2 do not.
- Ironbark IT Services: BAA draft, not signed
- Pinecrest Text Reminders: BAA signed, not yet in force, no patient data shared yet
88% covered
Open findings
Gaps the rules found in the register, by severity.
Active vendors by risk tier
22 active vendors. Tiers are computed from patient data access, the kind of service and current security evidence. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers. Whether one is required is decided before the evidence points, so a missing one cannot demand itself.
Needs attention now
Vendors with critical or high findings, worst first.
Managed IT: servers, backups and help desk. IT managed services, full patient records. Owner: Theo Brandt.
1 finding: Patient data without a signed BAA
Dictation transcription for clinic notes. Transcription or dictation, full patient records. Owner: Dr. Amara Singh.
1 finding: Days held without a BAA were covered by a BAA entered later, not yet confirmed
Outsourced billing, coding and denial follow-up. Billing or coding service, full patient records. Owner: Keisha Okafor.
2 findings: Subcontractor handles our data without confirmed terms; High-risk vendor with no independent security evidence
Appointment reminders by text and voice. Patient messaging or reminders, limited patient data. Owner: Owen Castellano.
1 finding: Signed BAA is missing required terms
Ambient dictation pilot for two clinics. Transcription or dictation, limited patient data. Owner: Dr. Amara Singh.
1 finding: Not recorded as live for months: confirm no patient data is being shared
Appointment reminder texts and two-way scheduling messages. Patient messaging or reminders, limited patient data. Owner: Owen Castellano.
2 findings: BAA needed before any patient data is shared; Annual review overdue or never done
Coming up
What becomes a finding soon if nobody acts, one line per vendor per day.
- Greyhawk Imaging Readsin 5 days
Annual review, Oct 12, 2026
- Ironbark IT Servicesin 5 days
Annual review, Oct 12, 2026
- Vaultline Backupin 8 days
Annual review, Oct 15, 2026
- Pinecrest Text Remindersin 9 days
Signed BAA takes effect, Oct 16, 2026
- Kiteway Check-Inin 10 days
BAA review, annual review, Oct 17, 2026
- Kiteway Check-Inin 14 days
Questionnaire lapses, Oct 21, 2026
- Clearview Facility Servicesin 15 days
Annual review, Oct 22, 2026
- Northgate Revenue Partnersin 15 days
Annual review, Oct 22, 2026
Open review conditions
What a review said must happen, and by when. A later review that approves outright closes them.
- Ironbark IT ServicesFollow-up in 5 days
Escalated: Working with administrator access and no signed BAA. Theo to get their legal team to sign this month, or remove their access.
- Greyhawk Imaging ReadsFollow-up in 5 days
Approved with conditions: No owner since the radiology lead left. Practice manager to assign one. No signed BAA in the compliance share; ask radiology for their copy.
- Northgate Revenue PartnersFollow-up in 15 days
Approved with conditions: SOC 2 report requested. Confirm Keystone Coding signed flow-down terms before the next review.
- Chimeline Patient MessagingFollow-up in 25 days
Approved with conditions: Vendor agreed to amend breach notice to 30 days. Amendment is pending their signature.