Evenstar Answering Service
After-hours phone answering and triage messages. Answering service. Limited patient data.
Findings
Plain rules over the facts below. Fix the fact and the finding clears.
Business associate agreement
- Document
- Signed Sep 1, 2025
- Filed at
- BAA-009, compliance share
- Effective
- Sep 1, 2025
- Ends
- With the service agreement
- Next BAA review
- Jun 23, 2027 (in 260 days)
- Breach notice
- 30 days
- YesBreach reported within 60 days of discovery
- YesWe can terminate if the vendor violates a material term
- YesData is returned or destroyed when the relationship ends
- YesSubcontractors are bound by the same terms
Signed BAA history
- Signed Sep 1, 2025, entered Sep 1, 2025: effective Sep 1, 2025, runs with the service agreement. BAA-009, compliance share
Update the BAA
Risk tier
Score 3. Reviewed every 12 months at this tier.
- Handles some patient data+2
- Answering service carries medium inherent risk+1
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 3, which is moderate. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- Current
Security questionnaire
Dated Jun 18, 2026, valid to Jun 18, 2027
- Current
SOC 2 Type II report
Dated May 29, 2026, valid to May 29, 2027
- Not needed
HITRUST certification
Valid for 24 months once received
Before any evidence points it rates moderate, so it needs a security questionnaire from the last 12 months. A SOC 2 report or HITRUST certification is welcome but not required.
Record new evidence
Subcontractors
Companies this vendor passes our data to.
None recorded.
Add or confirm a subcontractor
Data, access and contacts
- Patient data
- Limited patient data
- Remote access
- No
- Internal owner
- Owen Castellano
- In the register since
- Sep 1, 2025
- Contract held by
- Ridgeline Medical Group
- Sites served
- Main Campus, Jefferson Park and Eastgate Family Care
- Patient data first shared
- Sep 1, 2025; the vendor holds our patient data
- Data handled
- Names, contact details and demographics; Clinical notes and diagnoses
- Who to call about an incident
- Client services, Account team, clients@evenstar-answering.test
Change the contracting entity or sites
Update access and data
Annual reviews
Next review Jun 18, 2027 (in 255 days).
End of the relationship
When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.
Documents (3)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Security questionnaireSecurity questionnaire (sample). Attached Jun 18, 2026 by Marisol Vance.Open the copy
- SOC 2 reportSOC 2 report (sample). Attached May 29, 2026 by Marisol Vance.Open the copy
- Signed BAASigned BAA (sample). Attached Sep 1, 2025 by Marisol Vance.Open the copy
Attach a document
Notes (1)
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
Takes patient messages overnight, including symptoms. A clinic manager first signed up on a credit card; compliance caught it at intake and the BAA was signed before any calls were forwarded.
At intake, Sep 1, 2025
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Completed the annual review: ApprovedMarisol Vance, Jun 18, 2026
- Added Evenstar Answering Service with limited patient data accessMarisol Vance, Sep 1, 2025
- Recorded a signed BAA (BAA-009, compliance share)Marisol Vance, Sep 1, 2025