Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

VendorsMenu
Vendors / Faxbridge Cloud Fax
Critical riskBAA: ExpiredNo review neededTerminated

Faxbridge Cloud Fax

Former internet fax service. Cloud hosting or backup. Full patient records.

Findings

Plain rules over the facts below. Fix the fact and the finding clears.

No findings. This vendor meets every rule the register checks.

Business associate agreement

BAA: Expired
Document
Signed Dec 6, 2022
Filed at
BAA-020, archived
Effective
Dec 6, 2022
Ends
Mar 20, 2026
Next BAA review
Not set
Breach notice
30 days
  • YesBreach reported within 60 days of discovery
  • YesWe can terminate if the vendor violates a material term
  • YesData is returned or destroyed when the relationship ends
  • YesSubcontractors are bound by the same terms

Signed BAA history

  • Signed Dec 6, 2022, entered Dec 6, 2022: effective Dec 6, 2022, ends Mar 20, 2026. BAA-020, archived

Risk tier

Critical risk

Score 9. Reviewed every 6 months at this tier.

  • Can reach full patient records+4
  • Cloud hosting or backup carries high inherent risk+2
  • No current SOC 2 report or HITRUST certification+2
  • No security questionnaire in the last 12 months+1

Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 6, which is high. That part alone decides whether a SOC 2 report or HITRUST certification is required.

8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works

Security evidence

The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.

  • Security questionnaire

    Valid for 12 months once received

    None on file
  • SOC 2 Type II report

    Valid for 12 months once received

    None on file
  • HITRUST certification

    Valid for 24 months once received

    None on file

Subcontractors

Companies this vendor passes our data to.

None recorded.

Data, access and contacts

Patient data
Full patient records
Remote access
No
Internal owner
Theo Brandt
In the register since
Dec 6, 2022
Contract held by
Ridgeline Medical Group
Sites served
Every site
Patient data first shared
Not held when the relationship ended
Data handled
Clinical notes and diagnoses; Names, contact details and demographics
Who to call about an incident
Not recorded

Annual reviews

Terminated vendors are no longer reviewed.

End of the relationship

Terminated
Mar 20, 2026
Our data
Destroyed
Certificate
Apr 9, 2026
Attach the copy

Required when you enter a certificate date: attach the certificate itself.

Documents (2)

Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.

  • Return or destruction certificateReturn or destruction certificate (sample). Attached Apr 9, 2026 by Marisol Vance.Open the copy
  • Signed BAASigned BAA (sample). Attached Dec 6, 2022 by Marisol Vance.Open the copy
Attach a document
Attach the copy

An older signed BAA, an amendment, or anything an auditor will ask to see.

Notes (1)

What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.

  1. Replaced by the EHR's built-in fax. Certificate of destruction on file.

    At intake, Dec 6, 2022

Add a note

Saved with your name and today's date, and recorded in the audit trail.

History of this record

Recorded automatically when anything changes. Nobody can edit it.

Open in the audit trail
  1. Recorded data destroyed, certificate receivedMarisol Vance, Apr 9, 2026
  2. Marked Faxbridge Cloud Fax as terminatedMarisol Vance, Mar 20, 2026