Tallgrass Analytics
Payer mix and denial trend dashboards. Analytics or reporting. Limited patient data.
Findings (1)
Plain rules over the facts below. Fix the fact and the finding clears.
- Medium findingSecurity questionnaire older than 12 months
Last questionnaire was received on Sep 21, 2025.
Fix it under Security evidenceNext step: Send the vendor this year's security questionnaire and record the date it comes back under Security evidence.
Owner: Keisha Okafor
Draft a request to the vendor
Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.
Subject: Annual security questionnaire: Tallgrass Analytics Hello Customer success, Please complete our annual security questionnaire for the services Tallgrass Analytics provides to Ridgeline Health Partners. The last one we received is dated Sep 21, 2025. It tells us about changes since last year to where our data is hosted, your certifications and the subcontractors you use. Reply to this message and we will send the form. Thank you, Marisol Vance Compliance Officer, Ridgeline Health Partners
Why this matters
The annual questionnaire is how the practice learns that a vendor changed hosting, lost a certification or started using a new subcontractor.
Business associate agreement
- Document
- Signed Mar 20, 2026
- Filed at
- BAA-012, one-year pilot
- Effective
- Mar 20, 2026
- Ends
- Mar 20, 2027
- Next BAA review
- Nov 20, 2026 (in 45 days)
- Breach notice
- 60 days
- YesBreach reported within 60 days of discovery
- YesWe can terminate if the vendor violates a material term
- YesData is returned or destroyed when the relationship ends
- YesSubcontractors are bound by the same terms
Signed BAA history
- Signed Mar 20, 2026, entered Mar 20, 2026: effective Mar 20, 2026, ends Mar 20, 2027. BAA-012, one-year pilot
Update the BAA
Risk tier
Score 4. Reviewed every 12 months at this tier.
- Handles some patient data+2
- Analytics or reporting carries medium inherent risk+1
- No security questionnaire in the last 12 months+1
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 3, which is moderate. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- Out of date
Security questionnaire
Dated Sep 21, 2025, valid to Sep 21, 2026
- Current
SOC 2 Type II report
Dated Jun 28, 2026, valid to Jun 28, 2027
- Not needed
HITRUST certification
Valid for 24 months once received
Before any evidence points it rates moderate, so it needs a security questionnaire from the last 12 months. A SOC 2 report or HITRUST certification is welcome but not required.
Record new evidence
Subcontractors
Companies this vendor passes our data to.
None recorded.
Add or confirm a subcontractor
Data, access and contacts
- Patient data
- Limited patient data
- Remote access
- No
- Internal owner
- Keisha Okafor
- In the register since
- Mar 20, 2026
- Contract held by
- Ridgeline Management Services
- Sites served
- Every site
- Patient data first shared
- Mar 20, 2026; the vendor holds our patient data
- Data handled
- Claims, charges and billing codes; Names, contact details and demographics
- Who to call about an incident
- Customer success, Account team, success@tallgrass-analytics.test
Change the contracting entity or sites
Update access and data
Annual reviews
Next review Apr 9, 2027 (in 185 days).
End of the relationship
When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.
Documents (3)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Security questionnaireSecurity questionnaire (sample). Attached Sep 21, 2025 by Marisol Vance.Open the copy
- SOC 2 reportSOC 2 report (sample). Attached Jun 28, 2026 by Marisol Vance.Open the copy
- Signed BAASigned BAA (sample). Attached Mar 20, 2026 by Marisol Vance.Open the copy
Attach a document
Notes (1)
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
One-year pilot. Receives a monthly claims extract. This year's security questionnaire went out with the renewal paperwork and has not come back.
At intake, Mar 20, 2026
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Completed the annual review: ApprovedMarisol Vance, Apr 9, 2026
- Added Tallgrass Analytics with limited patient data accessMarisol Vance, Mar 20, 2026
- Recorded a signed BAA (BAA-012, one-year pilot)Marisol Vance, Mar 20, 2026