Northgate Revenue Partners
Outsourced billing, coding and denial follow-up. Billing or coding service. Full patient records.
Findings (2)
Plain rules over the facts below. Fix the fact and the finding clears.
- High findingSubcontractor handles our data without confirmed terms
Not confirmed for Keystone Coding Services.
Fix it under SubcontractorsNext step: Ask the vendor to confirm in writing that each subcontractor signed the same terms, then mark it confirmed under Subcontractors.
Owner: Keisha Okafor
Draft a request to the vendor
Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.
Subject: Confirmation of subcontractor terms: Northgate Revenue Partners Hello Account director, Please confirm in writing that each of these subcontractors, which handle patient information for Ridgeline Health Partners on behalf of Northgate Revenue Partners, has signed an agreement with the same restrictions and conditions as our business associate agreement: Keystone Coding Services. A short letter or email from your compliance lead naming each subcontractor and the date its agreement was signed is enough. Thank you, Marisol Vance Compliance Officer, Ridgeline Health Partners
Why this matters
Subcontractors that handle patient data must agree to the same restrictions as the vendor. The register tracks each one separately because a vendor-level BAA says nothing about whether the vendor actually got those signatures.
- High findingHigh-risk vendor with no independent security evidence
Rated critical before any evidence points, and no current SOC 2 report or HITRUST certification is on file.
Fix it under Security evidenceNext step: Ask the vendor for its current SOC 2 report or HITRUST certificate, then record its date under Security evidence.
Owner: Keisha Okafor
Draft a request to the vendor
Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.
Subject: Security report request for our vendor review: Northgate Revenue Partners Hello Account director, As part of our vendor review, please send your most recent SOC 2 Type II report or HITRUST certification for the services Northgate Revenue Partners provides to Ridgeline Health Partners. The latest one we have on file is your SOC 2 report dated Aug 13, 2025, which is now out of date. If you have neither, please tell us what independent security assessment you have instead, and when it was completed. Thank you, Marisol Vance Compliance Officer, Ridgeline Health Partners
Why this matters
For the vendors with the most exposure, a questionnaire the vendor filled in about itself is not enough. A current SOC 2 report or HITRUST certification, an outside auditor's report on the vendor's security, is the usual independent evidence.
Business associate agreement
- Document
- Signed Nov 6, 2024
- Filed at
- BAA-003, compliance share
- Effective
- Nov 6, 2024
- Ends
- Nov 11, 2027
- Next BAA review
- Apr 25, 2027 (in 200 days)
- Breach notice
- 15 days
- YesBreach reported within 60 days of discovery
- YesWe can terminate if the vendor violates a material term
- YesData is returned or destroyed when the relationship ends
- YesSubcontractors are bound by the same terms
Signed BAA history
- Signed Nov 6, 2024, entered Nov 6, 2024: effective Nov 6, 2024, ends Nov 11, 2027. BAA-003, compliance share
Update the BAA
Risk tier
Score 10. Reviewed every 6 months at this tier.
- Can reach full patient records+4
- Billing or coding service carries high inherent risk+2
- Has remote access to our systems+1
- Passes our patient data to its own subcontractors+1
- No current SOC 2 report or HITRUST certification+2
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 8, which is critical. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- Current
Security questionnaire
Dated Jul 9, 2026, valid to Jul 9, 2027
- Out of date
SOC 2 Type II report
Dated Aug 13, 2025, valid to Aug 13, 2026
- None on file
HITRUST certification
Valid for 24 months once received
Before any evidence points it rates critical, so it needs a security questionnaire from the last 12 months and a SOC 2 report or HITRUST certification that is still valid.
Record new evidence
Subcontractors
Companies this vendor passes our data to.
- Flow-down not confirmed
Keystone Coding Services
Overflow coding team, handles patient data
- Flow-down confirmed
Parcelpost Print and Mail
Patient statement printing, handles patient data
Add or confirm a subcontractor
Data, access and contacts
- Patient data
- Full patient records
- Remote access
- Yes, into our systems
- Internal owner
- Keisha Okafor
- In the register since
- Nov 6, 2024
- Contract held by
- Ridgeline Management Services
- Sites served
- Every site
- Patient data first shared
- Nov 6, 2024; the vendor holds our patient data
- Data handled
- Claims, charges and billing codes; Insurance and member IDs; Names, contact details and demographics; Clinical notes and diagnoses
- Who to call about an incident
- Account director, Client services, accounts@northgate-revenue.test
Change the contracting entity or sites
Update access and data
Open conditions, follow-up due Oct 27, 2026 (in 20 days)
SOC 2 report requested. Confirm Keystone Coding signed flow-down terms before the next review.
Approved with conditions by Marisol Vance on Jul 29, 2026. The next review closes them if it approves outright.
Annual reviews
Next review Oct 27, 2026 (in 20 days).
End of the relationship
When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.
Documents (3)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Security questionnaireSecurity questionnaire (sample). Attached Jul 9, 2026 by Marisol Vance.Open the copy
- SOC 2 reportSOC 2 report (sample). Attached Aug 13, 2025 by Marisol Vance.Open the copy
- Signed BAASigned BAA (sample). Attached Nov 6, 2024 by Marisol Vance.Open the copy
Attach a document
Notes (1)
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
Works in our EHR through a remote login. Their SOC 2 report is overdue, and their overflow coding team has not confirmed it signed our terms.
At intake, Nov 6, 2024
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Completed the annual review: Approved with conditionsMarisol Vance, Jul 29, 2026