Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

Guided tourMenu
Step 5 of 12

Try it: sign a BAA that came back late

This step signs you in as Marisol, the compliance officer, and opens Ironbark IT Services, the managed IT firm with administrator access to every server. It has held full patient records for 61 days on a BAA that was never signed.

Under "Business associate agreement", choose "Update the BAA", set it to signed with today as the signature and effective date and a review date next year, and save. BAA coverage on the dashboard goes up by one, but the register does not pretend the 61 days were covered: a BAA cannot take effect before it was signed, so an effective date before today is refused. Those days become a permanent period "held without a BAA", a critical finding until the breach risk assessment for that period is recorded on the vendor page.

The signature date is the date on the signed copy, not the day it is typed in: a BAA countersigned on Friday and entered on Monday covers Friday. But a typed date cannot quietly erase days already held without a BAA. When a BAA entered more than 7 days after its signature covers days the vendor held our data with no BAA on record (Greyhawk Imaging Reads, whose BAA turned up in a departed manager's files, covers 280 days such days), those days stay a critical finding until someone checks the signed copy and records what it shows, with its filing reference. If the dates match, the days stay covered. If the copy covers from a later date (signed later, or taking effect later than the record says, say on the start of the service agreement), record both dates on the copy: the BAA covers nothing before the later of them, so those days go back on the record as held without a BAA and each period takes a breach risk assessment. A routine review cannot clear it, and the check stays on the record for the auditor.

A vendor added during procurement is different. Pinecrest Text Reminders will get patient names and phone numbers, but none has been shared yet, so it has held nothing without a BAA. Its BAA is signed and takes effect on the go-live date, so it shows as "signed, not yet in force" and a high finding, "BAA needed before any patient data is shared", never a presumed breach. Whether any data has been shared is a required yes or no at intake, with no default, and only from the go-live date does every uncovered day count. Because an unrecorded go-live would hide those days, the annual review asks again, and a vendor nobody has confirmed as not live for 90 days is flagged (Copperleaf Voice Notes).

Every one of those days is worked out from two histories that only ever grow: when the vendor held our data, and when a signed BAA was in force. Nothing about the gap is stored where it could be edited away, so a late signature, a lapse followed by a renewal (see Cobalt Lab Link) or a step down after a gap all leave it on the record. The one fact that could change it after the event is a signature date entered late, which is why the days such an entry covers stay a finding until they are checked against the signed copy.

Your changes stay in this browser only. Nobody else sees them, and you can reset the demo at the bottom of this page.

A bar stays at the top of every screen so you can come straight back to this step.

Changed things while exploring? Resetting clears this browser's changes and restores the starting data.