Cobalt Lab Link
Interface between our EHR and the reference lab. Lab or device interface. Full patient records.
Findings
Plain rules over the facts below. Fix the fact and the finding clears.
Patient data held without a BAA
Every day the vendor held our patient data with no signed BAA in force, worked out from the holding and BAA histories below. These periods never disappear: a BAA signed later does not cover them. Each needs a breach risk assessment (45 CFR 164.402).
Held our patient data from Aug 13, 2025 to Aug 31, 2025 (19 days) while the signed BAA had ended and no new one was in force.
- Assessment
- Low probability of compromise, documented
- Completed
- Sep 21, 2025
- Assessed by
- Marisol Vance, privacy officer
Business associate agreement
- Document
- Signed Sep 1, 2025
- Filed at
- BAA-011, renewal, amended to add termination
- Effective
- Sep 1, 2025
- Ends
- With the service agreement
- Next BAA review
- Jan 4, 2027 (in 90 days)
- Breach notice
- 30 days
- YesBreach reported within 60 days of discovery
- YesWe can terminate if the vendor violates a material term
- YesData is returned or destroyed when the relationship ends
- YesSubcontractors are bound by the same terms
Signed BAA history
- Signed Mar 16, 2023, entered Mar 16, 2023: effective Mar 16, 2023, ends Aug 12, 2025. BAA-011, first term, archived
- Signed Sep 1, 2025, entered Sep 1, 2025: effective Sep 1, 2025, runs with the service agreement. BAA-011, renewal, amended to add termination
Update the BAA
Risk tier
Score 5. Reviewed every 12 months at this tier.
- Can reach full patient records+4
- Lab or device interface carries medium inherent risk+1
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 5, which is high. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- Current
Security questionnaire
Dated May 9, 2026, valid to May 9, 2027
- Current
SOC 2 Type II report
Dated Mar 20, 2026, valid to Mar 20, 2027
- Not needed
HITRUST certification
Valid for 24 months once received
Before any evidence points it rates high, so it needs a security questionnaire from the last 12 months and a SOC 2 report or HITRUST certification that is still valid.
Record new evidence
Subcontractors
Companies this vendor passes our data to.
None recorded.
Add or confirm a subcontractor
Data, access and contacts
- Patient data
- Full patient records
- Remote access
- No
- Internal owner
- Dr. Amara Singh
- In the register since
- Mar 16, 2023
- Contract held by
- Ridgeline Medical Group
- Sites served
- Main Campus and Stonebridge
- Patient data first shared
- Mar 16, 2023; the vendor holds our patient data
- Data handled
- Lab results; Names, contact details and demographics; Insurance and member IDs
- Who to call about an incident
- Interface support, Support, support@cobalt-lablink.test
Change the contracting entity or sites
Update access and data
Annual reviews
Next review Aug 27, 2027 (in 325 days).
End of the relationship
When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.
Documents (3)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Security questionnaireSecurity questionnaire (sample). Attached May 9, 2026 by Marisol Vance.Open the copy
- SOC 2 reportSOC 2 report (sample). Attached Mar 20, 2026 by Marisol Vance.Open the copy
- Signed BAASigned BAA (sample). Attached Sep 1, 2025 by Marisol Vance.Open the copy
Attach a document
Notes (1)
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
The renewal was signed late and on an older template with no termination clause. Legal had the vendor sign an amendment, and the follow-up review approved it.
At intake, Mar 16, 2023
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Completed the annual review: ApprovedMarisol Vance, Aug 27, 2026
- Amended the BAA to add termination for a material violation (BAA-011, renewal, amended to add termination)Marisol Vance, Aug 22, 2026
- Completed the annual review: Approved with conditionsMarisol Vance, May 9, 2026