Quillstone Transcription
Dictation transcription for clinic notes. Transcription or dictation. Full patient records.
Findings (1)
Plain rules over the facts below. Fix the fact and the finding clears.
- Critical findingBAA has expired but the vendor is still active
The BAA ended on Aug 23, 2026. Patient data has been held without one since Aug 24, 2026 (45 days).
Fix it under Business associate agreementNext step: Sign a renewal with the vendor and record it under Business associate agreement, then have the privacy officer assess the days held without one.
Owner: Dr. Amara Singh
Draft a request to the vendor
Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.
Subject: Renewal of our business associate agreement with Quillstone Transcription Hello Operations manager, Our business associate agreement with Quillstone Transcription (BAA-005, three-year term) ended on Aug 23, 2026, and your team still handles patient information for Ridgeline Health Partners. Please send a renewal signed by your authorized signer, taking effect as soon as possible, so that our patient information is covered again. If the renewal needs changes on our side, tell us who to contact. Thank you, Marisol Vance Compliance Officer, Ridgeline Health Partners
Why this matters
Once the agreement ends, patient data still held or received by the vendor is no longer covered.
Patient data held without a BAA
Every day the vendor held our patient data with no signed BAA in force, worked out from the holding and BAA histories below. These periods never disappear: a BAA signed later does not cover them. Each needs a breach risk assessment (45 CFR 164.402).
Holding our patient data since Aug 24, 2026 (45 days so far) while the signed BAA had ended and no new one was in force. Still running today.
This period ends when a BAA is signed or the vendor stops holding the data. It can be assessed once it has ended; until then it is a critical finding above.
Business associate agreement
- Document
- Signed Oct 8, 2023
- Filed at
- BAA-005, three-year term
- Effective
- Oct 8, 2023
- Ends
- Aug 23, 2026
- Next BAA review
- Aug 23, 2026 (45 days ago)
- Breach notice
- 45 days
- YesBreach reported within 60 days of discovery
- YesWe can terminate if the vendor violates a material term
- YesData is returned or destroyed when the relationship ends
- YesSubcontractors are bound by the same terms
Signed BAA history
- Signed Oct 8, 2023, entered Oct 8, 2023: effective Oct 8, 2023, ends Aug 23, 2026. BAA-005, three-year term
Update the BAA
Risk tier
Score 5. Reviewed every 12 months at this tier.
- Can reach full patient records+4
- Transcription or dictation carries medium inherent risk+1
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 5, which is high. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- Current
Security questionnaire
Dated Dec 11, 2025, valid to Dec 11, 2026
- Current
SOC 2 Type II report
Dated Mar 21, 2026, valid to Mar 21, 2027
- Not needed
HITRUST certification
Valid for 24 months once received
Before any evidence points it rates high, so it needs a security questionnaire from the last 12 months and a SOC 2 report or HITRUST certification that is still valid.
Record new evidence
Subcontractors
Companies this vendor passes our data to.
None recorded.
Add or confirm a subcontractor
Data, access and contacts
- Patient data
- Full patient records
- Remote access
- No
- Internal owner
- Dr. Amara Singh
- In the register since
- Oct 8, 2023
- Contract held by
- Ridgeline Medical Group
- Sites served
- Stonebridge and Riverside Orthopedics
- Patient data first shared
- Oct 8, 2023; the vendor holds our patient data
- Data handled
- Voice recordings and dictation; Clinical notes and diagnoses; Names, contact details and demographics
- Who to call about an incident
- Operations manager, Operations, ops@quillstone.test
Change the contracting entity or sites
Update access and data
Annual reviews
Next review Nov 11, 2026 (in 35 days).
End of the relationship
When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.
The vendor has held patient data with no signed BAA in force since Aug 24, 2026 (the signed BAA had ended and no new one was in force). Ending the relationship ends that period on the end date; it stays on the record as a critical finding until a breach risk assessment is recorded.
Documents (3)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Security questionnaireSecurity questionnaire (sample). Attached Dec 11, 2025 by Marisol Vance.Open the copy
- SOC 2 reportSOC 2 report (sample). Attached Mar 21, 2026 by Marisol Vance.Open the copy
- Signed BAASigned BAA (sample). Attached Oct 8, 2023 by Marisol Vance.Open the copy
Attach a document
Notes (1)
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
The BAA had a fixed three-year term and nobody renewed it. Dictation is still being sent.
At intake, Oct 8, 2023
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Completed the annual review: ApprovedMarisol Vance, Nov 11, 2025