Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

Guided tourMenu
Step 4 of 12

The findings engine

14 plain rules run over the register. The demo is a mostly healthy register with a few sharp problems, and 4 of them are critical: the IT firm started work before its BAA came back from their lawyers, a transcription BAA quietly expired while dictation kept flowing, a chart scanning contractor held charts with no BAA at all and nobody has assessed it, and a radiology BAA found in a departed manager's files was entered late and not yet checked. Each vendor's notes say how it happened.

The rules also read the BAA itself. A signed BAA can still be deficient: the patient messaging vendor signed on its own paper, which allows 90 days to report a breach when the legal limit is 60. A billing company uses an overflow coding team nobody bound to the same terms.

Every finding is a task: worst first, with a plain next step, the vendor's internal owner (or "No owner: assign one") and a link to the form on the vendor page that fixes it. For gaps only the vendor can close, the compliance officer can open a ready request letter, pre-filled with the vendor and the gap, in their own email or copy it as a letter. Sending it does not clear the finding; recording the fact does.

Findings are not an AI guessing. Each one is a rule over a recorded fact, so it reproduces, it can be explained, and fixing the fact clears it.

A bar stays at the top of every screen so you can come straight back to this step.

Changed things while exploring? Resetting clears this browser's changes and restores the starting data.