Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

FindingsMenu

Findings

Every gap the rules found, worst first, each with its next step and owner. None of this is guessed: each finding is a plain rule over recorded facts, so recording the missing fact clears it.

As of Oct 7, 2026. Whole organization.

Contract held by
Any entity
Serves
Any site

Regions

Sites in East Region

Sites in West Region

4 critical6 high4 medium
Critical finding

Patient data without a signed BAA

Why this matters

HIPAA requires a written business associate agreement before a vendor creates, receives, keeps or sends patient information for the practice. A draft is not an agreement, and a signed one covers nothing before it takes effect.

1
  • Ironbark IT ServicesA BAA was drafted but never signed. Patient data has been held without one since Aug 8, 2026 (61 days).

    Next step: Get the BAA signed by both parties (or stop sharing patient data until one is in force), then record it under Business associate agreement on the vendor page.

    Owner: Theo Brandt

    Fix it under Business associate agreement
Critical finding

BAA has expired but the vendor is still active

Why this matters

Once the agreement ends, patient data still held or received by the vendor is no longer covered.

1
  • Quillstone TranscriptionThe BAA ended on Aug 23, 2026. Patient data has been held without one since Aug 24, 2026 (45 days).

    Next step: Sign a renewal with the vendor and record it under Business associate agreement, then have the privacy officer assess the days held without one.

    Owner: Dr. Amara Singh

    Fix it under Business associate agreement
Critical finding

Held patient data without a BAA, no breach risk assessment

Why this matters

Giving patient data to a business associate with no signed BAA is an impermissible disclosure, presumed to be a breach unless the practice documents a low probability that the data was compromised (45 CFR 164.402). Signing a BAA later, lowering the vendor's access or ending the relationship does not undo it, because a BAA cannot cover data disclosed before it was signed; recording the assessment outcome for each period does.

1
  • Tallow Creek ScanningHeld patient data from Feb 9, 2026 to Jul 4, 2026 (146 days) while no signed BAA was in force. No breach risk assessment is recorded.

    Next step: Have the privacy officer complete a breach risk assessment for each period, then record the outcome on the vendor page.

    Owner: Dr. Amara Singh

    Fix it under Patient data held without a BAA
Critical finding

Days held without a BAA were covered by a BAA entered later, not yet confirmed

Why this matters

The vendor held our patient data on these days with no BAA on record. A BAA entered afterwards, more than 7 days after the signature date typed in for it, now covers them, and that date is the only thing between those days and a presumed breach (45 CFR 164.402). Check the signed copy and record what it shows, with its filing reference, on the vendor page: the dates entered, or a later signature date, which puts those days back on the record as held without a BAA, each period needing a breach risk assessment. A routine review does not clear this.

1
  • Greyhawk Imaging ReadsThe BAA entered on Sep 17, 2026 with a signature date of Dec 11, 2025 (280 days earlier) covers 280 days the vendor held our patient data before it was entered: Dec 11, 2025 to Sep 16, 2026. Confirm the dates against the signed copy.

    Next step: Pull the signed copy from where it is filed, compare its dates with the record, and record what it shows on the vendor page.

    No owner: assign one

    Fix it under Covered only by a BAA entered later
High finding

BAA needed before any patient data is shared

Why this matters

The vendor is set up to receive patient data, but the register has no record of any being shared yet (it is in procurement, or not live again). A signed BAA must be in force before the first disclosure. Nothing has been disclosed without one, so this is not a breach; sharing data before the BAA is signed would be. Record the date data is first shared once it is.

1
  • Pinecrest Text RemindersThe signed BAA takes effect on Oct 21, 2026. Do not share patient data before then.

    Next step: Keep patient data away from this vendor until a signed BAA is in force, and record the go live date on the vendor page the day data first flows.

    Owner: Owen Castellano

    Fix it under Business associate agreement
High finding

Terminated vendor, data return not confirmed

Why this matters

When a relationship ends, the vendor must return or destroy our patient data, or extend protections if neither is feasible. Without a certificate there is no evidence it happened.

1
High finding

Signed BAA is missing required terms

Why this matters

A BAA must set breach reporting (no later than 60 days), allow termination for a material violation, require return or destruction of data, and bind subcontractors to the same terms.

1
High finding

Not recorded as live for months: confirm no patient data is being shared

Why this matters

The vendor is set up to receive patient data, but no go-live date is recorded. While that is so, the register counts no days held without a BAA and a lapsed BAA is not treated as a gap, so an unrecorded go-live would hide exactly those findings. After 90 days without a fresh answer, someone must confirm it: record the date data was first shared, or confirm again that none has been (on the access form or in the annual review).

1
  • Copperleaf Voice NotesNo patient data was last confirmed as not yet shared on Jun 29, 2026, 100 days ago. A signed BAA is in force, so nothing prompts anyone to record go-live; if it lapses while data is flowing, the lapse would not be recorded.

    Next step: Ask the internal owner whether any patient data has been shared, then record the go live date or confirm again that none has.

    Owner: Dr. Amara Singh

    Fix it under Data, access and contacts
High finding

Subcontractor handles our data without confirmed terms

Why this matters

Subcontractors that handle patient data must agree to the same restrictions as the vendor. The register tracks each one separately because a vendor-level BAA says nothing about whether the vendor actually got those signatures.

1
High finding

High-risk vendor with no independent security evidence

Why this matters

For the vendors with the most exposure, a questionnaire the vendor filled in about itself is not enough. A current SOC 2 report or HITRUST certification, an outside auditor's report on the vendor's security, is the usual independent evidence.

1
  • Northgate Revenue PartnersRated critical before any evidence points, and no current SOC 2 report or HITRUST certification is on file.

    Next step: Ask the vendor for its current SOC 2 report or HITRUST certificate, then record its date under Security evidence.

    Owner: Keisha Okafor

    Fix it under Security evidence
Medium finding

BAA is past its review date

Why this matters

A BAA review confirms the agreement still matches what the vendor does. Services change; agreements drift.

1
Medium finding

Security questionnaire older than 12 months

Why this matters

The annual questionnaire is how the practice learns that a vendor changed hosting, lost a certification or started using a new subcontractor.

1
Medium finding

Annual review overdue or never done

Why this matters

The review is the recurring moment a named person confirms the record is still true.

1
Medium finding

No internal owner

Why this matters

An alert with no addressee is not a control. Someone at the practice has to notice when the service changes.

1