Findings
As of Oct 7, 2026. Whole organization.
Patient data without a signed BAA
Why this matters
HIPAA requires a written business associate agreement before a vendor creates, receives, keeps or sends patient information for the practice. A draft is not an agreement, and a signed one covers nothing before it takes effect.
- Ironbark IT ServicesA BAA was drafted but never signed. Patient data has been held without one since Aug 8, 2026 (61 days).Fix it under Business associate agreement
Next step: Get the BAA signed by both parties (or stop sharing patient data until one is in force), then record it under Business associate agreement on the vendor page.
Owner: Theo Brandt
BAA has expired but the vendor is still active
Why this matters
Once the agreement ends, patient data still held or received by the vendor is no longer covered.
- Quillstone TranscriptionThe BAA ended on Aug 23, 2026. Patient data has been held without one since Aug 24, 2026 (45 days).Fix it under Business associate agreement
Next step: Sign a renewal with the vendor and record it under Business associate agreement, then have the privacy officer assess the days held without one.
Owner: Dr. Amara Singh
Held patient data without a BAA, no breach risk assessment
Why this matters
Giving patient data to a business associate with no signed BAA is an impermissible disclosure, presumed to be a breach unless the practice documents a low probability that the data was compromised (45 CFR 164.402). Signing a BAA later, lowering the vendor's access or ending the relationship does not undo it, because a BAA cannot cover data disclosed before it was signed; recording the assessment outcome for each period does.
- Tallow Creek ScanningHeld patient data from Feb 9, 2026 to Jul 4, 2026 (146 days) while no signed BAA was in force. No breach risk assessment is recorded.Fix it under Patient data held without a BAA
Next step: Have the privacy officer complete a breach risk assessment for each period, then record the outcome on the vendor page.
Owner: Dr. Amara Singh
Days held without a BAA were covered by a BAA entered later, not yet confirmed
Why this matters
The vendor held our patient data on these days with no BAA on record. A BAA entered afterwards, more than 7 days after the signature date typed in for it, now covers them, and that date is the only thing between those days and a presumed breach (45 CFR 164.402). Check the signed copy and record what it shows, with its filing reference, on the vendor page: the dates entered, or a later signature date, which puts those days back on the record as held without a BAA, each period needing a breach risk assessment. A routine review does not clear this.
- Greyhawk Imaging ReadsThe BAA entered on Sep 17, 2026 with a signature date of Dec 11, 2025 (280 days earlier) covers 280 days the vendor held our patient data before it was entered: Dec 11, 2025 to Sep 16, 2026. Confirm the dates against the signed copy.Fix it under Covered only by a BAA entered later
Next step: Pull the signed copy from where it is filed, compare its dates with the record, and record what it shows on the vendor page.
No owner: assign one
BAA needed before any patient data is shared
Why this matters
The vendor is set up to receive patient data, but the register has no record of any being shared yet (it is in procurement, or not live again). A signed BAA must be in force before the first disclosure. Nothing has been disclosed without one, so this is not a breach; sharing data before the BAA is signed would be. Record the date data is first shared once it is.
- Pinecrest Text RemindersThe signed BAA takes effect on Oct 21, 2026. Do not share patient data before then.Fix it under Business associate agreement
Next step: Keep patient data away from this vendor until a signed BAA is in force, and record the go live date on the vendor page the day data first flows.
Owner: Owen Castellano
Terminated vendor, data return not confirmed
Why this matters
When a relationship ends, the vendor must return or destroy our patient data, or extend protections if neither is feasible. Without a certificate there is no evidence it happened.
- Old Mill Billing Co.No return or destruction has been confirmed.Fix it under End of the relationship
Next step: Ask the vendor for a certificate of return or destruction, then record it under End of the relationship.
Owner: Keisha Okafor
Signed BAA is missing required terms
Why this matters
A BAA must set breach reporting (no later than 60 days), allow termination for a material violation, require return or destruction of data, and bind subcontractors to the same terms.
- Chimeline Patient MessagingBreach notice is 90 days; the rule's outer limit is 60. The contract term is weaker than the law.Fix it under Business associate agreement
Next step: Ask the vendor to sign an amendment that adds the missing terms, then update the BAA record.
Owner: Owen Castellano
Not recorded as live for months: confirm no patient data is being shared
Why this matters
The vendor is set up to receive patient data, but no go-live date is recorded. While that is so, the register counts no days held without a BAA and a lapsed BAA is not treated as a gap, so an unrecorded go-live would hide exactly those findings. After 90 days without a fresh answer, someone must confirm it: record the date data was first shared, or confirm again that none has been (on the access form or in the annual review).
- Copperleaf Voice NotesNo patient data was last confirmed as not yet shared on Jun 29, 2026, 100 days ago. A signed BAA is in force, so nothing prompts anyone to record go-live; if it lapses while data is flowing, the lapse would not be recorded.Fix it under Data, access and contacts
Next step: Ask the internal owner whether any patient data has been shared, then record the go live date or confirm again that none has.
Owner: Dr. Amara Singh
Subcontractor handles our data without confirmed terms
Why this matters
Subcontractors that handle patient data must agree to the same restrictions as the vendor. The register tracks each one separately because a vendor-level BAA says nothing about whether the vendor actually got those signatures.
- Northgate Revenue PartnersNot confirmed for Keystone Coding Services.Fix it under Subcontractors
Next step: Ask the vendor to confirm in writing that each subcontractor signed the same terms, then mark it confirmed under Subcontractors.
Owner: Keisha Okafor
High-risk vendor with no independent security evidence
Why this matters
For the vendors with the most exposure, a questionnaire the vendor filled in about itself is not enough. A current SOC 2 report or HITRUST certification, an outside auditor's report on the vendor's security, is the usual independent evidence.
- Northgate Revenue PartnersRated critical before any evidence points, and no current SOC 2 report or HITRUST certification is on file.Fix it under Security evidence
Next step: Ask the vendor for its current SOC 2 report or HITRUST certificate, then record its date under Security evidence.
Owner: Keisha Okafor
BAA is past its review date
Why this matters
A BAA review confirms the agreement still matches what the vendor does. Services change; agreements drift.
- Bridgewater Claims ExchangeReview was due 20 days ago.Fix it under Business associate agreement
Next step: Reread the BAA against what the vendor does today, then set the next BAA review date on the BAA record.
Owner: Keisha Okafor
Security questionnaire older than 12 months
Why this matters
The annual questionnaire is how the practice learns that a vendor changed hosting, lost a certification or started using a new subcontractor.
- Tallgrass AnalyticsLast questionnaire was received on Sep 22, 2025.Fix it under Security evidence
Next step: Send the vendor this year's security questionnaire and record the date it comes back under Security evidence.
Owner: Keisha Okafor
Annual review overdue or never done
Why this matters
The review is the recurring moment a named person confirms the record is still true.
- Pinecrest Text RemindersThis vendor has never been reviewed.Fix it under Annual reviews
Next step: Complete the annual review from the vendor page.
Owner: Owen Castellano
No internal owner
Why this matters
An alert with no addressee is not a control. Someone at the practice has to notice when the service changes.
- Greyhawk Imaging ReadsNobody at the practice is named as owner.Fix it under Data, access and contacts
Next step: Name someone at the practice as the internal owner under Data, access and contacts.
No owner: assign one