Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

VendorsMenu
Vendors / Chimeline Patient Messaging
Moderate riskBAA: Signed, in forceReview due soon

Chimeline Patient Messaging

Appointment reminders by text and voice. Patient messaging or reminders. Limited patient data.

Findings (1)

Plain rules over the facts below. Fix the fact and the finding clears.

  • High findingSigned BAA is missing required terms

    Breach notice is 90 days; the rule's outer limit is 60. The contract term is weaker than the law.

    Next step: Ask the vendor to sign an amendment that adds the missing terms, then update the BAA record.

    Owner: Owen Castellano

    Fix it under Business associate agreement
    Draft a request to the vendor

    Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.

    Subject: Amendment needed to our business associate agreement: Chimeline Patient Messaging
    
    Hello Trust and safety,
    
    Our business associate agreement with Chimeline Patient Messaging (BAA-007, vendor paper) is missing terms that HIPAA requires. Please send an amendment, signed by your authorized signer, that adds:
    
    1. a breach reporting deadline of no more than 60 days after discovery (the current agreement allows 90 days)
    
    If your standard agreement already covers these, please point us to the clauses instead.
    
    Thank you,
    Marisol Vance
    Compliance Officer, Ridgeline Health Partners
    Why this matters

    A BAA must set breach reporting (no later than 60 days), allow termination for a material violation, require return or destruction of data, and bind subcontractors to the same terms.

Business associate agreement

BAA: Signed, in force
Document
Signed Sep 2, 2025
Filed at
BAA-007, vendor paper
Effective
Sep 2, 2025
Ends
With the service agreement
Next BAA review
Aug 3, 2027 (in 300 days)
Breach notice
90 days
  • NoBreach reported within 60 days of discovery
  • YesWe can terminate if the vendor violates a material term
  • YesData is returned or destroyed when the relationship ends
  • YesSubcontractors are bound by the same terms

Signed BAA history

  • Signed Sep 2, 2025, entered Sep 2, 2025: effective Sep 2, 2025, runs with the service agreement. BAA-007, vendor paper

One required term is missing. See findings above.

Update the BAA
The agreement says
Attach the copy

Required when you record a newly signed BAA, so anyone checking can open the signed copy. Not needed for a draft or when only amending terms.

Risk tier

Moderate risk

Score 4. Reviewed every 12 months at this tier.

  • Handles some patient data+2
  • Patient messaging or reminders carries medium inherent risk+1
  • Passes our patient data to its own subcontractors+1

Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 4, which is moderate. That part alone decides whether a SOC 2 report or HITRUST certification is required.

8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works

Security evidence

The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.

  • Security questionnaire

    Dated Aug 8, 2026, valid to Aug 8, 2027

    Current
  • SOC 2 Type II report

    Dated Jul 19, 2026, valid to Jul 19, 2027

    Current
  • HITRUST certification

    Valid for 24 months once received

    Not needed

Before any evidence points it rates moderate, so it needs a security questionnaire from the last 12 months. A SOC 2 report or HITRUST certification is welcome but not required.

Record new evidence
Attach the copy

Required: the report, certification or completed questionnaire this date comes from.

Subcontractors

Companies this vendor passes our data to.

  • Relaywave SMS Gateway

    Text message delivery, handles patient data

    Flow-down confirmed
Add or confirm a subcontractor

Entering an existing name updates that subcontractor.

Data, access and contacts

Patient data
Limited patient data
Remote access
No
Internal owner
Owen Castellano
In the register since
Sep 2, 2025
Contract held by
Ridgeline Medical Group
Sites served
Every site
Patient data first shared
Sep 2, 2025; the vendor holds our patient data
Data handled
Names, contact details and demographics
Who to call about an incident
Trust and safety, Vendor security office, trust@chimeline.test
Change the contracting entity or sites
Contract and sites

Sites it serves

Leave every box clear if it serves every site.

East Region

West Region

This vendor serves every site today. Ticking any site limits it to the sites you tick, and it will no longer serve every site.

Update access and data

Vendors change after intake: a phone vendor starts recording calls, an IT vendor is given EHR admin rights. Record what the vendor touches today. The BAA requirement and risk tier are recomputed from your answers.

Patient data access
Data handled
Only if you are lowering access to no patient data

This vendor already holds our patient data, and lowering its access does not take that data back. Record the certificate that confirms it was returned or destroyed. If the vendor keeps the data, keep its access at limited or full.

Who to call about an incident (optional)

Open conditions, follow-up due Nov 6, 2026 (in 30 days)

Vendor agreed to amend breach notice to 30 days. Amendment is pending their signature.

Approved with conditions by Marisol Vance on Aug 8, 2026. The next review closes them if it approves outright.

Annual reviews

Start the review

Next review Nov 6, 2026 (in 30 days).

End of the relationship

When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.

Documents (3)

Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.

  • Security questionnaireSecurity questionnaire (sample). Attached Aug 8, 2026 by Marisol Vance.Open the copy
  • SOC 2 reportSOC 2 report (sample). Attached Jul 19, 2026 by Marisol Vance.Open the copy
  • Signed BAASigned BAA (sample). Attached Sep 2, 2025 by Marisol Vance.Open the copy
Attach a document
Attach the copy

An older signed BAA, an amendment, or anything an auditor will ask to see.

Notes (1)

What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.

  1. Signed on the vendor's own BAA form, which allows 90 days to report a breach.

    At intake, Sep 2, 2025

Add a note

Saved with your name and today's date, and recorded in the audit trail.

History of this record

Recorded automatically when anything changes. Nobody can edit it.

Open in the audit trail
  1. Completed the annual review: Approved with conditionsMarisol Vance, Aug 8, 2026