Greyhawk Imaging Reads
Overnight radiology reads. Teleradiology or remote reads. Full patient records.
Findings (2)
Plain rules over the facts below. Fix the fact and the finding clears.
- Critical findingDays held without a BAA were covered by a BAA entered later, not yet confirmed
The BAA entered on Sep 17, 2026 with a signature date of Dec 11, 2025 (280 days earlier) covers 280 days the vendor held our patient data before it was entered: Dec 11, 2025 to Sep 16, 2026. Confirm the dates against the signed copy.
Fix it under Covered only by a BAA entered laterNext step: Pull the signed copy from where it is filed, compare its dates with the record, and record what it shows on the vendor page.
No owner: assign one
Why this matters
The vendor held our patient data on these days with no BAA on record. A BAA entered afterwards, more than 7 days after the signature date typed in for it, now covers them, and that date is the only thing between those days and a presumed breach (45 CFR 164.402). Check the signed copy and record what it shows, with its filing reference, on the vendor page: the dates entered, or a later signature date, which puts those days back on the record as held without a BAA, each period needing a breach risk assessment. A routine review does not clear this.
- Medium findingNo internal owner
Nobody at the practice is named as owner.
Fix it under Data, access and contactsNext step: Name someone at the practice as the internal owner under Data, access and contacts.
No owner: assign one
Why this matters
An alert with no addressee is not a control. Someone at the practice has to notice when the service changes.
Covered only by a BAA entered later
Days the vendor held our patient data with no BAA on record, which a BAA entered more than 7 days after its signature date now covers. Those days rest on the signature date typed in, so each entry is checked once against the signed copy. The check is kept here and in the audit trail for anyone reviewing the record.
BAA signed Dec 11, 2025 and entered Sep 17, 2026 (280 days later), filed at BAA-021, compliance share. It covers 280 days held before it was entered: Dec 11, 2025 to Sep 16, 2026.
Not checked. Until the signed copy is checked, these days are a critical finding: if it is dated later than the record says, they were held without a BAA and are presumed a breach (45 CFR 164.402). A routine review does not clear this.
Business associate agreement
- Document
- Signed Dec 11, 2025
- Filed at
- BAA-021, compliance share
- Effective
- Dec 11, 2025
- Ends
- With the service agreement
- Next BAA review
- Jun 14, 2027 (in 250 days)
- Breach notice
- 30 days
- YesBreach reported within 60 days of discovery
- YesWe can terminate if the vendor violates a material term
- YesData is returned or destroyed when the relationship ends
- YesSubcontractors are bound by the same terms
Signed BAA history
- Signed Dec 11, 2025, entered Sep 17, 2026: effective Dec 11, 2025, runs with the service agreement. BAA-021, compliance share. Covers 280 held days from before its entry, not yet confirmed
Update the BAA
Risk tier
Score 5. Reviewed every 12 months at this tier.
- Can reach full patient records+4
- Teleradiology or remote reads carries medium inherent risk+1
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 5, which is high. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- Current
Security questionnaire
Dated Jul 19, 2026, valid to Jul 19, 2027
- Current
SOC 2 Type II report
Dated Jul 9, 2026, valid to Jul 9, 2027
- Not needed
HITRUST certification
Valid for 24 months once received
Before any evidence points it rates high, so it needs a security questionnaire from the last 12 months and a SOC 2 report or HITRUST certification that is still valid.
Record new evidence
Subcontractors
Companies this vendor passes our data to.
None recorded.
Add or confirm a subcontractor
Data, access and contacts
- Patient data
- Full patient records
- Remote access
- No
- Internal owner
- Nobody assigned
- In the register since
- Dec 11, 2025
- Contract held by
- Ridgeline Medical Group
- Sites served
- Riverside Orthopedics
- Patient data first shared
- Dec 11, 2025; the vendor holds our patient data
- Data handled
- Images and radiology reports; Clinical notes and diagnoses; Names, contact details and demographics
- Who to call about an incident
- Medical director office, Vendor privacy office, privacy@greyhawk-reads.test
Change the contracting entity or sites
Update access and data
Open conditions, follow-up due Oct 17, 2026 (in 10 days)
No owner since the radiology lead left. Practice manager to assign one. No signed BAA in the compliance share; ask radiology for their copy.
Approved with conditions by Marisol Vance on Jul 19, 2026. The next review closes them if it approves outright.
Annual reviews
Next review Oct 17, 2026 (in 10 days).
End of the relationship
When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.
Documents (3)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Security questionnaireSecurity questionnaire (sample). Attached Jul 19, 2026 by Marisol Vance.Open the copy
- SOC 2 reportSOC 2 report (sample). Attached Jul 9, 2026 by Marisol Vance.Open the copy
- Signed BAASigned BAA (sample). Attached Sep 17, 2026 by Marisol Vance.Open the copy
Attach a document
Notes (1)
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
The radiology lead who brought them on has left the practice. The signed BAA turned up in their files and was entered late.
At intake, Dec 11, 2025
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Recorded a signed BAA (BAA-021, compliance share), signed when the service started. Covers 280 days the vendor held patient data before this entry; entered 280 days after signing, so they stay a critical finding until confirmed against the signed copyMarisol Vance, Sep 17, 2026
- Completed the annual review: Approved with conditionsMarisol Vance, Jul 19, 2026