Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

VendorsMenu
Vendors / Tallow Creek Scanning
High riskBAA: Required, missingNo review neededTerminated

Tallow Creek Scanning

Former chart scanning project, paper charts into the EHR. Document storage or shredding. Limited patient data.

Findings (1)

Plain rules over the facts below. Fix the fact and the finding clears.

  • Critical findingHeld patient data without a BAA, no breach risk assessment

    Held patient data from Feb 8, 2026 to Jul 3, 2026 (146 days) while no signed BAA was in force. No breach risk assessment is recorded.

    Next step: Have the privacy officer complete a breach risk assessment for each period, then record the outcome on the vendor page.

    Owner: Dr. Amara Singh

    Fix it under Patient data held without a BAA
    Why this matters

    Giving patient data to a business associate with no signed BAA is an impermissible disclosure, presumed to be a breach unless the practice documents a low probability that the data was compromised (45 CFR 164.402). Signing a BAA later, lowering the vendor's access or ending the relationship does not undo it, because a BAA cannot cover data disclosed before it was signed; recording the assessment outcome for each period does.

Patient data held without a BAA

Every day the vendor held our patient data with no signed BAA in force, worked out from the holding and BAA histories below. These periods never disappear: a BAA signed later does not cover them. Each needs a breach risk assessment (45 CFR 164.402).

  • Held our patient data from Feb 8, 2026 to Jul 3, 2026 (146 days) while no signed BAA was in force.

    No breach risk assessment is recorded. The disclosure is presumed to be a breach unless a documented assessment of four factors (the nature of the data, who received it, whether it was actually viewed, and how far the risk was mitigated) shows a low probability of compromise.

    Outcome

Business associate agreement

BAA: Required, missing

No BAA on file. This vendor holds our patient information, so one is required.

Risk tier

High risk

Score 5. Reviewed every 12 months at this tier.

  • Handles some patient data+2
  • No current SOC 2 report or HITRUST certification+2
  • No security questionnaire in the last 12 months+1

Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 2, which is moderate. That part alone decides whether a SOC 2 report or HITRUST certification is required.

8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works

Security evidence

The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.

  • Security questionnaire

    Valid for 12 months once received

    None on file
  • SOC 2 Type II report

    Valid for 12 months once received

    Not needed
  • HITRUST certification

    Valid for 24 months once received

    Not needed

Subcontractors

Companies this vendor passes our data to.

None recorded.

Data, access and contacts

Patient data
Limited patient data
Remote access
No
Internal owner
Dr. Amara Singh
In the register since
Feb 8, 2026
Contract held by
Ridgeline Medical Group
Sites served
Riverbend
Patient data first shared
Not held when the relationship ended
Data handled
Paper records for storage or destruction; Names, contact details and demographics
Who to call about an incident
Not recorded

Annual reviews

Terminated vendors are no longer reviewed.

End of the relationship

Terminated
Jul 3, 2026
Our data
Destroyed
Certificate
Jul 8, 2026
Attach the copy

Required when you enter a certificate date: attach the certificate itself.

Documents (1)

Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.

  • Return or destruction certificateReturn or destruction certificate (sample). Attached Jul 8, 2026 by Marisol Vance.Open the copy
Attach a document
Attach the copy

An older signed BAA, an amendment, or anything an auditor will ask to see.

Notes (1)

What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.

  1. Scanned the older paper charts. The clinic booked them on a purchase order and nobody asked for a BAA before the boxes were picked up. The privacy officer has not yet assessed the months they held the charts.

    At intake, Feb 8, 2026

Add a note

Saved with your name and today's date, and recorded in the audit trail.

History of this record

Recorded automatically when anything changes. Nobody can edit it.

Open in the audit trail
  1. Recorded data disposition: Destroyed, certificate receivedMarisol Vance, Jul 8, 2026
  2. Marked Tallow Creek Scanning as terminated. Held patient data with no BAA on file; breach risk assessment requiredMarisol Vance, Jul 3, 2026
  3. Added Tallow Creek Scanning with limited patient data accessMarisol Vance, Feb 8, 2026