Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

VendorsMenu
Vendors / Old Mill Billing Co.
Critical riskBAA: ExpiredNo review neededTerminated

Old Mill Billing Co.

Former billing service, replaced by Northgate. Billing or coding service. Full patient records.

Findings (1)

Plain rules over the facts below. Fix the fact and the finding clears.

  • High findingTerminated vendor, data return not confirmed

    No return or destruction has been confirmed.

    Next step: Ask the vendor for a certificate of return or destruction, then record it under End of the relationship.

    Owner: Keisha Okafor

    Fix it under End of the relationship
    Draft a request to the vendor

    Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.

    Subject: Return or destruction of patient information: Old Mill Billing Co.
    
    Hello Old Mill Billing Co. team,
    
    Our relationship with Old Mill Billing Co. ended on Aug 17, 2026. Please confirm in writing that all patient information you held for Ridgeline Health Partners has been returned to us or destroyed, and send a certificate of return or destruction that states the date.
    
    If returning or destroying any of it is not feasible, tell us what you still hold and confirm that the protections of our business associate agreement continue to apply to it for as long as you do.
    
    Thank you,
    Marisol Vance
    Compliance Officer, Ridgeline Health Partners
    No incident contact email is on file; copy it into a letter or email.
    Why this matters

    When a relationship ends, the vendor must return or destroy our patient data, or extend protections if neither is feasible. Without a certificate there is no evidence it happened.

Business associate agreement

BAA: Expired
Document
Signed Apr 15, 2021
Filed at
BAA-019, archived
Effective
Apr 15, 2021
Ends
Aug 17, 2026
Next BAA review
Not set
Breach notice
30 days
  • YesBreach reported within 60 days of discovery
  • YesWe can terminate if the vendor violates a material term
  • YesData is returned or destroyed when the relationship ends
  • YesSubcontractors are bound by the same terms

Signed BAA history

  • Signed Apr 15, 2021, entered Apr 15, 2021: effective Apr 15, 2021, ends Aug 17, 2026. BAA-019, archived

Risk tier

Critical risk

Score 9. Reviewed every 6 months at this tier.

  • Can reach full patient records+4
  • Billing or coding service carries high inherent risk+2
  • No current SOC 2 report or HITRUST certification+2
  • No security questionnaire in the last 12 months+1

Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 6, which is high. That part alone decides whether a SOC 2 report or HITRUST certification is required.

8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works

Security evidence

The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.

  • Security questionnaire

    Dated Feb 13, 2025, valid to Feb 13, 2026

    Out of date
  • SOC 2 Type II report

    Valid for 12 months once received

    None on file
  • HITRUST certification

    Valid for 24 months once received

    None on file

Subcontractors

Companies this vendor passes our data to.

None recorded.

Data, access and contacts

Patient data
Full patient records
Remote access
No
Internal owner
Keisha Okafor
In the register since
Apr 15, 2021
Contract held by
Ridgeline Management Services
Sites served
Every site
Patient data first shared
Not held when the relationship ended
Data handled
Claims, charges and billing codes; Insurance and member IDs; Names, contact details and demographics
Who to call about an incident
Not recorded

Annual reviews

Terminated vendors are no longer reviewed.

End of the relationship

Terminated
Aug 17, 2026
Our data
Not yet confirmed
Certificate
None on file
Attach the copy

Required when you enter a certificate date: attach the certificate itself.

Documents (2)

Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.

  • Security questionnaireSecurity questionnaire (sample). Attached Feb 13, 2025 by Marisol Vance.Open the copy
  • Signed BAASigned BAA (sample). Attached Apr 15, 2021 by Marisol Vance.Open the copy
Attach a document
Attach the copy

An older signed BAA, an amendment, or anything an auditor will ask to see.

Notes (1)

What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.

  1. Contract ended. They still hold five years of claim history.

    At intake, Apr 15, 2021

Add a note

Saved with your name and today's date, and recorded in the audit trail.

History of this record

Recorded automatically when anything changes. Nobody can edit it.

Open in the audit trail
  1. Marked Old Mill Billing Co. as terminatedMarisol Vance, Aug 17, 2026