Ridgeline Health Partners
BAA coverage report
As of Oct 6, 2026. Whole organization.
14 of 17 active vendors with patient data have a signed BAA in force today. Last review completed by Marisol Vance on Sep 16, 2026 (Ironbark IT Services).
| Vendor | Patient data | Risk tier | BAA | BAA effective | BAA ends | SOC 2 or HITRUST | Last review | Open findings |
|---|---|---|---|---|---|---|---|---|
| Greyhawk Imaging Reads | Full patient records | High | Signed, in force | Dec 10, 2025 | With the service | SOC 2, Jul 8, 2026 | Jul 18, 2026 | 1 critical |
| Ironbark IT Services | Full patient records | High | Draft, not signed | None | None | SOC 2, Mar 20, 2026 | Sep 16, 2026 | 1 critical |
| Quillstone Transcription | Full patient records | High | Expired | Oct 7, 2023 | Aug 22, 2026 | SOC 2, Mar 20, 2026 | Nov 10, 2025 | 1 critical |
| Northgate Revenue Partners | Full patient records | Critical | Signed, in force | Nov 5, 2024 | Nov 10, 2027 | SOC 2, Aug 12, 2025 (out of date) | Jul 28, 2026 | 2 high |
| Chimeline Patient Messaging | Limited patient data | Moderate | Signed, in force | Sep 1, 2025 | With the service | SOC 2, Jul 18, 2026 | Aug 7, 2026 | 1 high |
| Copperleaf Voice Notes | Limited patient data | Moderate | Signed, in force | May 19, 2026 | With the service | SOC 2, Apr 29, 2026 | Jun 28, 2026 | 1 high |
| Pinecrest Text Reminders | Limited patient data | Moderate | Signed, not yet in force | Oct 20, 2026 | With the service | SOC 2, Aug 27, 2026 | Never | 1 high |
| Bridgewater Claims Exchange | Full patient records | High | Signed, in force | Aug 28, 2022 | With the service | SOC 2, Jun 28, 2026 | Mar 20, 2026 | None |
| Tallgrass Analytics | Limited patient data | Moderate | Signed, in force | Mar 20, 2026 | Mar 20, 2027 | SOC 2, Jun 28, 2026 | Apr 9, 2026 | None |
| Vaultline Backup | Full patient records | Critical | Signed, in force | Jul 28, 2024 | With the service | SOC 2, Aug 7, 2026 | Apr 19, 2026 | None |
| Bluefern Telehealth | Full patient records | High | Signed, in force | Feb 13, 2025 | Dec 14, 2028 | HITRUST, Mar 20, 2026 | Aug 22, 2026 | None |
| Cobalt Lab Link | Full patient records | High | Signed, in force | Sep 1, 2025 | With the service | SOC 2, Mar 20, 2026 | Aug 27, 2026 | None |
| Larkspur Clinical Cloud | Full patient records | High | Signed, in force | Oct 2, 2023 | With the service | SOC 2, May 9, 2026 | May 19, 2026 | None |
| Evenstar Answering Service | Limited patient data | Moderate | Signed, in force | Sep 1, 2025 | With the service | SOC 2, May 29, 2026 | Jun 18, 2026 | None |
| Hollis and Reyes LLP | Limited patient data | Moderate | Signed, in force | May 24, 2025 | With the service | None on file | Dec 10, 2025 | None |
| Kiteway Check-In | Limited patient data | Moderate | Signed, in force | Oct 21, 2025 | With the service | SOC 2, Jun 8, 2026 | Oct 21, 2025 | None |
| Paperwise Secure Shred | Limited patient data | Moderate | Signed, in force | Apr 19, 2024 | With the service | None on file | Jul 8, 2026 | None |
Signed, in force means a signed BAA covers today. Signed, not yet in force means it takes effect later. BAA effective is the day the signed copy covers from. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers. Open findings counts critical and high findings; medium housekeeping is on the findings page. Vendors with no patient data do not need a BAA and are left off this page. This register is a compliance tool, not legal advice.
Open critical findings (4)
- Greyhawk Imaging Reads: Days held without a BAA were covered by a BAA entered later, not yet confirmed. The BAA entered on Sep 16, 2026 with a signature date of Dec 10, 2025 (280 days earlier) covers 280 days the vendor held our patient data before it was entered: Dec 10, 2025 to Sep 15, 2026. Confirm the dates against the signed copy.
- Ironbark IT Services: Patient data without a signed BAA. A BAA was drafted but never signed. Patient data has been held without one since Aug 7, 2026 (61 days).
- Quillstone Transcription: BAA has expired but the vendor is still active. The BAA ended on Aug 22, 2026. Patient data has been held without one since Aug 23, 2026 (45 days).
- Tallow Creek Scanning: Held patient data without a BAA, no breach risk assessment. Held patient data from Feb 8, 2026 to Jul 3, 2026 (146 days) while no signed BAA was in force. No breach risk assessment is recorded.