Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

VendorsMenu
Vendors / Northgate Revenue Partners
Critical riskBAA: Signed, in forceReview due soon

Northgate Revenue Partners

Outsourced billing, coding and denial follow-up. Billing or coding service. Full patient records.

Findings (2)

Plain rules over the facts below. Fix the fact and the finding clears.

  • High findingSubcontractor handles our data without confirmed terms

    Not confirmed for Keystone Coding Services.

    Next step: Ask the vendor to confirm in writing that each subcontractor signed the same terms, then mark it confirmed under Subcontractors.

    Owner: Keisha Okafor

    Fix it under Subcontractors
    Draft a request to the vendor

    Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.

    Subject: Confirmation of subcontractor terms: Northgate Revenue Partners
    
    Hello Account director,
    
    Please confirm in writing that each of these subcontractors, which handle patient information for Ridgeline Health Partners on behalf of Northgate Revenue Partners, has signed an agreement with the same restrictions and conditions as our business associate agreement: Keystone Coding Services.
    
    A short letter or email from your compliance lead naming each subcontractor and the date its agreement was signed is enough.
    
    Thank you,
    Marisol Vance
    Compliance Officer, Ridgeline Health Partners
    Why this matters

    Subcontractors that handle patient data must agree to the same restrictions as the vendor. The register tracks each one separately because a vendor-level BAA says nothing about whether the vendor actually got those signatures.

  • High findingHigh-risk vendor with no independent security evidence

    Rated critical before any evidence points, and no current SOC 2 report or HITRUST certification is on file.

    Next step: Ask the vendor for its current SOC 2 report or HITRUST certificate, then record its date under Security evidence.

    Owner: Keisha Okafor

    Fix it under Security evidence
    Draft a request to the vendor

    Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.

    Subject: Security report request for our vendor review: Northgate Revenue Partners
    
    Hello Account director,
    
    As part of our vendor review, please send your most recent SOC 2 Type II report or HITRUST certification for the services Northgate Revenue Partners provides to Ridgeline Health Partners. The latest one we have on file is your SOC 2 report dated Aug 13, 2025, which is now out of date.
    
    If you have neither, please tell us what independent security assessment you have instead, and when it was completed.
    
    Thank you,
    Marisol Vance
    Compliance Officer, Ridgeline Health Partners
    Why this matters

    For the vendors with the most exposure, a questionnaire the vendor filled in about itself is not enough. A current SOC 2 report or HITRUST certification, an outside auditor's report on the vendor's security, is the usual independent evidence.

Business associate agreement

BAA: Signed, in force
Document
Signed Nov 6, 2024
Filed at
BAA-003, compliance share
Effective
Nov 6, 2024
Ends
Nov 11, 2027
Next BAA review
Apr 25, 2027 (in 200 days)
Breach notice
15 days
  • YesBreach reported within 60 days of discovery
  • YesWe can terminate if the vendor violates a material term
  • YesData is returned or destroyed when the relationship ends
  • YesSubcontractors are bound by the same terms

Signed BAA history

  • Signed Nov 6, 2024, entered Nov 6, 2024: effective Nov 6, 2024, ends Nov 11, 2027. BAA-003, compliance share
Update the BAA
The agreement says
Attach the copy

Required when you record a newly signed BAA, so anyone checking can open the signed copy. Not needed for a draft or when only amending terms.

Risk tier

Critical risk

Score 10. Reviewed every 6 months at this tier.

  • Can reach full patient records+4
  • Billing or coding service carries high inherent risk+2
  • Has remote access to our systems+1
  • Passes our patient data to its own subcontractors+1
  • No current SOC 2 report or HITRUST certification+2

Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 8, which is critical. That part alone decides whether a SOC 2 report or HITRUST certification is required.

8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works

Security evidence

The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.

  • Security questionnaire

    Dated Jul 9, 2026, valid to Jul 9, 2027

    Current
  • SOC 2 Type II report

    Dated Aug 13, 2025, valid to Aug 13, 2026

    Out of date
  • HITRUST certification

    Valid for 24 months once received

    None on file

Before any evidence points it rates critical, so it needs a security questionnaire from the last 12 months and a SOC 2 report or HITRUST certification that is still valid.

Record new evidence
Attach the copy

Required: the report, certification or completed questionnaire this date comes from.

Subcontractors

Companies this vendor passes our data to.

  • Keystone Coding Services

    Overflow coding team, handles patient data

    Flow-down not confirmed
  • Parcelpost Print and Mail

    Patient statement printing, handles patient data

    Flow-down confirmed
Add or confirm a subcontractor

Entering an existing name updates that subcontractor.

Data, access and contacts

Patient data
Full patient records
Remote access
Yes, into our systems
Internal owner
Keisha Okafor
In the register since
Nov 6, 2024
Contract held by
Ridgeline Management Services
Sites served
Every site
Patient data first shared
Nov 6, 2024; the vendor holds our patient data
Data handled
Claims, charges and billing codes; Insurance and member IDs; Names, contact details and demographics; Clinical notes and diagnoses
Who to call about an incident
Account director, Client services, accounts@northgate-revenue.test
Change the contracting entity or sites
Contract and sites

Sites it serves

Leave every box clear if it serves every site.

East Region

West Region

This vendor serves every site today. Ticking any site limits it to the sites you tick, and it will no longer serve every site.

Update access and data

Vendors change after intake: a phone vendor starts recording calls, an IT vendor is given EHR admin rights. Record what the vendor touches today. The BAA requirement and risk tier are recomputed from your answers.

Patient data access
Data handled
Only if you are lowering access to no patient data

This vendor already holds our patient data, and lowering its access does not take that data back. Record the certificate that confirms it was returned or destroyed. If the vendor keeps the data, keep its access at limited or full.

Who to call about an incident (optional)

Open conditions, follow-up due Oct 27, 2026 (in 20 days)

SOC 2 report requested. Confirm Keystone Coding signed flow-down terms before the next review.

Approved with conditions by Marisol Vance on Jul 29, 2026. The next review closes them if it approves outright.

Annual reviews

Start the review

Next review Oct 27, 2026 (in 20 days).

End of the relationship

When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.

Documents (3)

Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.

  • Security questionnaireSecurity questionnaire (sample). Attached Jul 9, 2026 by Marisol Vance.Open the copy
  • SOC 2 reportSOC 2 report (sample). Attached Aug 13, 2025 by Marisol Vance.Open the copy
  • Signed BAASigned BAA (sample). Attached Nov 6, 2024 by Marisol Vance.Open the copy
Attach a document
Attach the copy

An older signed BAA, an amendment, or anything an auditor will ask to see.

Notes (1)

What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.

  1. Works in our EHR through a remote login. Their SOC 2 report is overdue, and their overflow coding team has not confirmed it signed our terms.

    At intake, Nov 6, 2024

Add a note

Saved with your name and today's date, and recorded in the audit trail.

History of this record

Recorded automatically when anything changes. Nobody can edit it.

Open in the audit trail
  1. Completed the annual review: Approved with conditionsMarisol Vance, Jul 29, 2026