Chimeline Patient Messaging
Appointment reminders by text and voice. Patient messaging or reminders. Limited patient data.
Findings (1)
Plain rules over the facts below. Fix the fact and the finding clears.
- High findingSigned BAA is missing required terms
Breach notice is 90 days; the rule's outer limit is 60. The contract term is weaker than the law.
Fix it under Business associate agreementNext step: Ask the vendor to sign an amendment that adds the missing terms, then update the BAA record.
Owner: Owen Castellano
Draft a request to the vendor
Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.
Subject: Amendment needed to our business associate agreement: Chimeline Patient Messaging Hello Trust and safety, Our business associate agreement with Chimeline Patient Messaging (BAA-007, vendor paper) is missing terms that HIPAA requires. Please send an amendment, signed by your authorized signer, that adds: 1. a breach reporting deadline of no more than 60 days after discovery (the current agreement allows 90 days) If your standard agreement already covers these, please point us to the clauses instead. Thank you, Marisol Vance Compliance Officer, Ridgeline Health Partners
Why this matters
A BAA must set breach reporting (no later than 60 days), allow termination for a material violation, require return or destruction of data, and bind subcontractors to the same terms.
Business associate agreement
- Document
- Signed Sep 2, 2025
- Filed at
- BAA-007, vendor paper
- Effective
- Sep 2, 2025
- Ends
- With the service agreement
- Next BAA review
- Aug 3, 2027 (in 300 days)
- Breach notice
- 90 days
- NoBreach reported within 60 days of discovery
- YesWe can terminate if the vendor violates a material term
- YesData is returned or destroyed when the relationship ends
- YesSubcontractors are bound by the same terms
Signed BAA history
- Signed Sep 2, 2025, entered Sep 2, 2025: effective Sep 2, 2025, runs with the service agreement. BAA-007, vendor paper
One required term is missing. See findings above.
Update the BAA
Risk tier
Score 4. Reviewed every 12 months at this tier.
- Handles some patient data+2
- Patient messaging or reminders carries medium inherent risk+1
- Passes our patient data to its own subcontractors+1
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 4, which is moderate. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- Current
Security questionnaire
Dated Aug 8, 2026, valid to Aug 8, 2027
- Current
SOC 2 Type II report
Dated Jul 19, 2026, valid to Jul 19, 2027
- Not needed
HITRUST certification
Valid for 24 months once received
Before any evidence points it rates moderate, so it needs a security questionnaire from the last 12 months. A SOC 2 report or HITRUST certification is welcome but not required.
Record new evidence
Subcontractors
Companies this vendor passes our data to.
- Flow-down confirmed
Relaywave SMS Gateway
Text message delivery, handles patient data
Add or confirm a subcontractor
Data, access and contacts
- Patient data
- Limited patient data
- Remote access
- No
- Internal owner
- Owen Castellano
- In the register since
- Sep 2, 2025
- Contract held by
- Ridgeline Medical Group
- Sites served
- Every site
- Patient data first shared
- Sep 2, 2025; the vendor holds our patient data
- Data handled
- Names, contact details and demographics
- Who to call about an incident
- Trust and safety, Vendor security office, trust@chimeline.test
Change the contracting entity or sites
Update access and data
Open conditions, follow-up due Nov 6, 2026 (in 30 days)
Vendor agreed to amend breach notice to 30 days. Amendment is pending their signature.
Approved with conditions by Marisol Vance on Aug 8, 2026. The next review closes them if it approves outright.
Annual reviews
Next review Nov 6, 2026 (in 30 days).
End of the relationship
When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.
Documents (3)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Security questionnaireSecurity questionnaire (sample). Attached Aug 8, 2026 by Marisol Vance.Open the copy
- SOC 2 reportSOC 2 report (sample). Attached Jul 19, 2026 by Marisol Vance.Open the copy
- Signed BAASigned BAA (sample). Attached Sep 2, 2025 by Marisol Vance.Open the copy
Attach a document
Notes (1)
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
Signed on the vendor's own BAA form, which allows 90 days to report a breach.
At intake, Sep 2, 2025
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Completed the annual review: Approved with conditionsMarisol Vance, Aug 8, 2026