Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

VendorsMenu
Vendors / Greyhawk Imaging Reads
High riskBAA: Signed, in forceReview due soon

Greyhawk Imaging Reads

Overnight radiology reads. Teleradiology or remote reads. Full patient records.

Findings (2)

Plain rules over the facts below. Fix the fact and the finding clears.

  • Critical findingDays held without a BAA were covered by a BAA entered later, not yet confirmed

    The BAA entered on Sep 17, 2026 with a signature date of Dec 11, 2025 (280 days earlier) covers 280 days the vendor held our patient data before it was entered: Dec 11, 2025 to Sep 16, 2026. Confirm the dates against the signed copy.

    Next step: Pull the signed copy from where it is filed, compare its dates with the record, and record what it shows on the vendor page.

    No owner: assign one

    Fix it under Covered only by a BAA entered later
    Why this matters

    The vendor held our patient data on these days with no BAA on record. A BAA entered afterwards, more than 7 days after the signature date typed in for it, now covers them, and that date is the only thing between those days and a presumed breach (45 CFR 164.402). Check the signed copy and record what it shows, with its filing reference, on the vendor page: the dates entered, or a later signature date, which puts those days back on the record as held without a BAA, each period needing a breach risk assessment. A routine review does not clear this.

  • Medium findingNo internal owner

    Nobody at the practice is named as owner.

    Next step: Name someone at the practice as the internal owner under Data, access and contacts.

    No owner: assign one

    Fix it under Data, access and contacts
    Why this matters

    An alert with no addressee is not a control. Someone at the practice has to notice when the service changes.

Covered only by a BAA entered later

Days the vendor held our patient data with no BAA on record, which a BAA entered more than 7 days after its signature date now covers. Those days rest on the signature date typed in, so each entry is checked once against the signed copy. The check is kept here and in the audit trail for anyone reviewing the record.

  • BAA signed Dec 11, 2025 and entered Sep 17, 2026 (280 days later), filed at BAA-021, compliance share. It covers 280 days held before it was entered: Dec 11, 2025 to Sep 16, 2026.

    Not checked. Until the signed copy is checked, these days are a critical finding: if it is dated later than the record says, they were held without a BAA and are presumed a breach (45 CFR 164.402). A routine review does not clear this.

    What the signed copy shows

Business associate agreement

BAA: Signed, in force
Document
Signed Dec 11, 2025
Filed at
BAA-021, compliance share
Effective
Dec 11, 2025
Ends
With the service agreement
Next BAA review
Jun 14, 2027 (in 250 days)
Breach notice
30 days
  • YesBreach reported within 60 days of discovery
  • YesWe can terminate if the vendor violates a material term
  • YesData is returned or destroyed when the relationship ends
  • YesSubcontractors are bound by the same terms

Signed BAA history

  • Signed Dec 11, 2025, entered Sep 17, 2026: effective Dec 11, 2025, runs with the service agreement. BAA-021, compliance share. Covers 280 held days from before its entry, not yet confirmed
Update the BAA
The agreement says
Attach the copy

Required when you record a newly signed BAA, so anyone checking can open the signed copy. Not needed for a draft or when only amending terms.

Risk tier

High risk

Score 5. Reviewed every 12 months at this tier.

  • Can reach full patient records+4
  • Teleradiology or remote reads carries medium inherent risk+1

Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 5, which is high. That part alone decides whether a SOC 2 report or HITRUST certification is required.

8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works

Security evidence

The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.

  • Security questionnaire

    Dated Jul 19, 2026, valid to Jul 19, 2027

    Current
  • SOC 2 Type II report

    Dated Jul 9, 2026, valid to Jul 9, 2027

    Current
  • HITRUST certification

    Valid for 24 months once received

    Not needed

Before any evidence points it rates high, so it needs a security questionnaire from the last 12 months and a SOC 2 report or HITRUST certification that is still valid.

Record new evidence
Attach the copy

Required: the report, certification or completed questionnaire this date comes from.

Subcontractors

Companies this vendor passes our data to.

None recorded.

Add or confirm a subcontractor

Entering an existing name updates that subcontractor.

Data, access and contacts

Patient data
Full patient records
Remote access
No
Internal owner
Nobody assigned
In the register since
Dec 11, 2025
Contract held by
Ridgeline Medical Group
Sites served
Riverside Orthopedics
Patient data first shared
Dec 11, 2025; the vendor holds our patient data
Data handled
Images and radiology reports; Clinical notes and diagnoses; Names, contact details and demographics
Who to call about an incident
Medical director office, Vendor privacy office, privacy@greyhawk-reads.test
Change the contracting entity or sites
Contract and sites

Sites it serves

Leave every box clear if it serves every site.

East Region

West Region

Update access and data

Vendors change after intake: a phone vendor starts recording calls, an IT vendor is given EHR admin rights. Record what the vendor touches today. The BAA requirement and risk tier are recomputed from your answers.

Patient data access
Data handled
Only if you are lowering access to no patient data

This vendor already holds our patient data, and lowering its access does not take that data back. Record the certificate that confirms it was returned or destroyed. If the vendor keeps the data, keep its access at limited or full.

Who to call about an incident (optional)

Open conditions, follow-up due Oct 17, 2026 (in 10 days)

No owner since the radiology lead left. Practice manager to assign one. No signed BAA in the compliance share; ask radiology for their copy.

Approved with conditions by Marisol Vance on Jul 19, 2026. The next review closes them if it approves outright.

Annual reviews

Start the review

Next review Oct 17, 2026 (in 10 days).

End of the relationship

When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.

Documents (3)

Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.

  • Security questionnaireSecurity questionnaire (sample). Attached Jul 19, 2026 by Marisol Vance.Open the copy
  • SOC 2 reportSOC 2 report (sample). Attached Jul 9, 2026 by Marisol Vance.Open the copy
  • Signed BAASigned BAA (sample). Attached Sep 17, 2026 by Marisol Vance.Open the copy
Attach a document
Attach the copy

An older signed BAA, an amendment, or anything an auditor will ask to see.

Notes (1)

What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.

  1. The radiology lead who brought them on has left the practice. The signed BAA turned up in their files and was entered late.

    At intake, Dec 11, 2025

Add a note

Saved with your name and today's date, and recorded in the audit trail.

History of this record

Recorded automatically when anything changes. Nobody can edit it.

Open in the audit trail
  1. Recorded a signed BAA (BAA-021, compliance share), signed when the service started. Covers 280 days the vendor held patient data before this entry; entered 280 days after signing, so they stay a critical finding until confirmed against the signed copyMarisol Vance, Sep 17, 2026
  2. Completed the annual review: Approved with conditionsMarisol Vance, Jul 19, 2026