Ironbark IT Services
Managed IT: servers, backups and help desk. IT managed services. Full patient records.
Findings (1)
Plain rules over the facts below. Fix the fact and the finding clears.
- Critical findingPatient data without a signed BAA
A BAA was drafted but never signed. Patient data has been held without one since Aug 8, 2026 (61 days).
Fix it under Business associate agreementNext step: Get the BAA signed by both parties (or stop sharing patient data until one is in force), then record it under Business associate agreement on the vendor page.
Owner: Theo Brandt
Draft a request to the vendor
Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.
Subject: Signed business associate agreement needed: Ridgeline Health Partners and Ironbark IT Services Hello Service desk, We do not have a business associate agreement signed by both parties and in force for the services Ironbark IT Services provides to Ridgeline Health Partners. Our records show the agreement is still an unsigned draft (Draft 2, with vendor legal). HIPAA requires a signed agreement to be in place while a vendor receives, keeps or sends patient information for us. Please return a copy signed by your authorized signer, with the date it takes effect, as soon as you can, and let us know who to contact if anything is holding it up. Thank you, Marisol Vance Compliance Officer, Ridgeline Health Partners
Why this matters
HIPAA requires a written business associate agreement before a vendor creates, receives, keeps or sends patient information for the practice. A draft is not an agreement, and a signed one covers nothing before it takes effect.
Patient data held without a BAA
Every day the vendor held our patient data with no signed BAA in force, worked out from the holding and BAA histories below. These periods never disappear: a BAA signed later does not cover them. Each needs a breach risk assessment (45 CFR 164.402).
Holding our patient data since Aug 8, 2026 (61 days so far) while no signed BAA was in force. Still running today.
This period ends when a BAA is signed or the vendor stops holding the data. It can be assessed once it has ended; until then it is a critical finding above.
Business associate agreement
- Document
- Draft
- Filed at
- Draft 2, with vendor legal
- Effective
- Not recorded
- Ends
- With the service agreement
- Next BAA review
- Not set
- Breach notice
- 30 days
- YesBreach reported within 60 days of discovery
- YesWe can terminate if the vendor violates a material term
- YesData is returned or destroyed when the relationship ends
- YesSubcontractors are bound by the same terms
Update the BAA
Risk tier
Score 7. Reviewed every 12 months at this tier.
- Can reach full patient records+4
- IT managed services carries high inherent risk+2
- Has remote access to our systems+1
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 7, which is high. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- Current
Security questionnaire
Dated Sep 7, 2026, valid to Sep 7, 2027
- Current
SOC 2 Type II report
Dated Mar 21, 2026, valid to Mar 21, 2027
- Not needed
HITRUST certification
Valid for 24 months once received
Before any evidence points it rates high, so it needs a security questionnaire from the last 12 months and a SOC 2 report or HITRUST certification that is still valid.
Record new evidence
Subcontractors
Companies this vendor passes our data to.
None recorded.
Add or confirm a subcontractor
Data, access and contacts
- Patient data
- Full patient records
- Remote access
- Yes, into our systems
- Internal owner
- Theo Brandt
- In the register since
- Aug 8, 2026
- Contract held by
- Ridgeline Management Services
- Sites served
- Every site
- Patient data first shared
- Aug 8, 2026; the vendor holds our patient data
- Data handled
- Clinical notes and diagnoses; Names, contact details and demographics; Claims, charges and billing codes
- Who to call about an incident
- Service desk, Help desk, help@ironbark-it.test
Change the contracting entity or sites
Update access and data
Open conditions, follow-up due Oct 17, 2026 (in 10 days)
Working with administrator access and no signed BAA. Theo to get their legal team to sign this month, or remove their access.
Escalated by Marisol Vance on Sep 17, 2026. The next review closes them if it approves outright.
Annual reviews
Next review Oct 17, 2026 (in 10 days).
End of the relationship
When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.
The vendor has held patient data with no signed BAA in force since Aug 8, 2026 (no signed BAA was in force). Ending the relationship ends that period on the end date; it stays on the record as a critical finding until a breach risk assessment is recorded.
Documents (2)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Security questionnaireSecurity questionnaire (sample). Attached Sep 7, 2026 by Marisol Vance.Open the copy
- SOC 2 reportSOC 2 report (sample). Attached Mar 21, 2026 by Marisol Vance.Open the copy
Attach a document
Notes (1)
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
Started work before the BAA came back from their lawyers. Administrator access to every server. Escalated at intake review; Theo is chasing their legal team for the signature.
At intake, Aug 8, 2026
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Completed the annual review: EscalatedMarisol Vance, Sep 17, 2026
- Recorded security questionnaireMarisol Vance, Sep 7, 2026
- Recorded a draft BAA (Draft 2, with vendor legal)Marisol Vance, Aug 10, 2026
- Added Ironbark IT Services with full patient data accessMarisol Vance, Aug 8, 2026