Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

VendorsMenu
Vendors / Quillstone Transcription
High riskBAA: ExpiredScheduled

Quillstone Transcription

Dictation transcription for clinic notes. Transcription or dictation. Full patient records.

Findings (1)

Plain rules over the facts below. Fix the fact and the finding clears.

  • Critical findingBAA has expired but the vendor is still active

    The BAA ended on Aug 23, 2026. Patient data has been held without one since Aug 24, 2026 (45 days).

    Next step: Sign a renewal with the vendor and record it under Business associate agreement, then have the privacy officer assess the days held without one.

    Owner: Dr. Amara Singh

    Fix it under Business associate agreement
    Draft a request to the vendor

    Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.

    Subject: Renewal of our business associate agreement with Quillstone Transcription
    
    Hello Operations manager,
    
    Our business associate agreement with Quillstone Transcription (BAA-005, three-year term) ended on Aug 23, 2026, and your team still handles patient information for Ridgeline Health Partners.
    
    Please send a renewal signed by your authorized signer, taking effect as soon as possible, so that our patient information is covered again. If the renewal needs changes on our side, tell us who to contact.
    
    Thank you,
    Marisol Vance
    Compliance Officer, Ridgeline Health Partners
    Why this matters

    Once the agreement ends, patient data still held or received by the vendor is no longer covered.

Patient data held without a BAA

Every day the vendor held our patient data with no signed BAA in force, worked out from the holding and BAA histories below. These periods never disappear: a BAA signed later does not cover them. Each needs a breach risk assessment (45 CFR 164.402).

  • Holding our patient data since Aug 24, 2026 (45 days so far) while the signed BAA had ended and no new one was in force. Still running today.

    This period ends when a BAA is signed or the vendor stops holding the data. It can be assessed once it has ended; until then it is a critical finding above.

Business associate agreement

BAA: Expired
Document
Signed Oct 8, 2023
Filed at
BAA-005, three-year term
Effective
Oct 8, 2023
Ends
Aug 23, 2026
Next BAA review
Aug 23, 2026 (45 days ago)
Breach notice
45 days
  • YesBreach reported within 60 days of discovery
  • YesWe can terminate if the vendor violates a material term
  • YesData is returned or destroyed when the relationship ends
  • YesSubcontractors are bound by the same terms

Signed BAA history

  • Signed Oct 8, 2023, entered Oct 8, 2023: effective Oct 8, 2023, ends Aug 23, 2026. BAA-005, three-year term
Update the BAA

The vendor has held patient data with no signed BAA in force since Aug 24, 2026. A BAA covers the data from the day it takes effect, and it cannot take effect before it was signed. Any days before that stay on the record as held without a BAA and need a breach risk assessment.

The agreement says
Attach the copy

Required when you record a newly signed BAA, so anyone checking can open the signed copy. Not needed for a draft or when only amending terms.

Risk tier

High risk

Score 5. Reviewed every 12 months at this tier.

  • Can reach full patient records+4
  • Transcription or dictation carries medium inherent risk+1

Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 5, which is high. That part alone decides whether a SOC 2 report or HITRUST certification is required.

8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works

Security evidence

The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.

  • Security questionnaire

    Dated Dec 11, 2025, valid to Dec 11, 2026

    Current
  • SOC 2 Type II report

    Dated Mar 21, 2026, valid to Mar 21, 2027

    Current
  • HITRUST certification

    Valid for 24 months once received

    Not needed

Before any evidence points it rates high, so it needs a security questionnaire from the last 12 months and a SOC 2 report or HITRUST certification that is still valid.

Record new evidence
Attach the copy

Required: the report, certification or completed questionnaire this date comes from.

Subcontractors

Companies this vendor passes our data to.

None recorded.

Add or confirm a subcontractor

Entering an existing name updates that subcontractor.

Data, access and contacts

Patient data
Full patient records
Remote access
No
Internal owner
Dr. Amara Singh
In the register since
Oct 8, 2023
Contract held by
Ridgeline Medical Group
Sites served
Stonebridge and Riverside Orthopedics
Patient data first shared
Oct 8, 2023; the vendor holds our patient data
Data handled
Voice recordings and dictation; Clinical notes and diagnoses; Names, contact details and demographics
Who to call about an incident
Operations manager, Operations, ops@quillstone.test
Change the contracting entity or sites
Contract and sites

Sites it serves

Leave every box clear if it serves every site.

East Region

West Region

Update access and data

Vendors change after intake: a phone vendor starts recording calls, an IT vendor is given EHR admin rights. Record what the vendor touches today. The BAA requirement and risk tier are recomputed from your answers.

Patient data access
Data handled
Only if you are lowering access to no patient data

This vendor already holds our patient data, and lowering its access does not take that data back. Record the certificate that confirms it was returned or destroyed. If the vendor keeps the data, keep its access at limited or full.

The vendor has held patient data with no signed BAA in force since Aug 24, 2026 (the signed BAA had ended and no new one was in force). Lowering access ends that period on the certificate date; it stays on the record as a critical finding until a breach risk assessment is recorded. Signing a BAA does not change the past.

Who to call about an incident (optional)

Annual reviews

Start the review

Next review Nov 11, 2026 (in 35 days).

End of the relationship

When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.

The vendor has held patient data with no signed BAA in force since Aug 24, 2026 (the signed BAA had ended and no new one was in force). Ending the relationship ends that period on the end date; it stays on the record as a critical finding until a breach risk assessment is recorded.

Documents (3)

Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.

  • Security questionnaireSecurity questionnaire (sample). Attached Dec 11, 2025 by Marisol Vance.Open the copy
  • SOC 2 reportSOC 2 report (sample). Attached Mar 21, 2026 by Marisol Vance.Open the copy
  • Signed BAASigned BAA (sample). Attached Oct 8, 2023 by Marisol Vance.Open the copy
Attach a document
Attach the copy

An older signed BAA, an amendment, or anything an auditor will ask to see.

Notes (1)

What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.

  1. The BAA had a fixed three-year term and nobody renewed it. Dictation is still being sent.

    At intake, Oct 8, 2023

Add a note

Saved with your name and today's date, and recorded in the audit trail.

History of this record

Recorded automatically when anything changes. Nobody can edit it.

Open in the audit trail
  1. Completed the annual review: ApprovedMarisol Vance, Nov 11, 2025