Vaultline Backup
Offsite backup of servers and imaging archive. Cloud hosting or backup. Full patient records.
Findings
Plain rules over the facts below. Fix the fact and the finding clears.
Business associate agreement
- Document
- Signed Jul 29, 2024
- Filed at
- BAA-010, compliance share
- Effective
- Jul 29, 2024
- Ends
- With the service agreement
- Next BAA review
- Oct 27, 2026 (in 20 days)
- Breach notice
- 20 days
- YesBreach reported within 60 days of discovery
- YesWe can terminate if the vendor violates a material term
- YesData is returned or destroyed when the relationship ends
- YesSubcontractors are bound by the same terms
Signed BAA history
- Signed Jul 29, 2024, entered Jul 29, 2024: effective Jul 29, 2024, runs with the service agreement. BAA-010, compliance share
Update the BAA
Risk tier
Score 8. Reviewed every 6 months at this tier.
- Can reach full patient records+4
- Cloud hosting or backup carries high inherent risk+2
- Has remote access to our systems+1
- Passes our patient data to its own subcontractors+1
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 8, which is critical. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- Current
Security questionnaire
Dated Jun 29, 2026, valid to Jun 29, 2027
- Current
SOC 2 Type II report
Dated Aug 8, 2026, valid to Aug 8, 2027
- Not needed
HITRUST certification
Valid for 24 months once received
Before any evidence points it rates critical, so it needs a security questionnaire from the last 12 months and a SOC 2 report or HITRUST certification that is still valid.
Record new evidence
Subcontractors
Companies this vendor passes our data to.
- Flow-down confirmed
Stratacore Data Centers
Physical storage for backups, handles patient data
Add or confirm a subcontractor
Data, access and contacts
- Patient data
- Full patient records
- Remote access
- Yes, into our systems
- Internal owner
- Theo Brandt
- In the register since
- Jul 29, 2024
- Contract held by
- Ridgeline Management Services
- Sites served
- Every site
- Patient data first shared
- Jul 29, 2024; the vendor holds our patient data
- Data handled
- Clinical notes and diagnoses; Names, contact details and demographics; Claims, charges and billing codes; Images and radiology reports
- Who to call about an incident
- Incident response, Vendor security office, incident@vaultline.test
Change the contracting entity or sites
Update access and data
Annual reviews
Next review Oct 20, 2026 (in 13 days).
End of the relationship
When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.
Documents (3)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Security questionnaireSecurity questionnaire (sample). Attached Jun 29, 2026 by Marisol Vance.Open the copy
- SOC 2 reportSOC 2 report (sample). Attached Aug 8, 2026 by Marisol Vance.Open the copy
- Signed BAASigned BAA (sample). Attached Jul 29, 2024 by Marisol Vance.Open the copy
Attach a document
Notes
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
No notes yet.
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Recorded SOC 2 Type II reportMarisol Vance, Aug 8, 2026
- Completed the annual review: ApprovedMarisol Vance, Apr 20, 2026