Tallow Creek Scanning
Former chart scanning project, paper charts into the EHR. Document storage or shredding. Limited patient data.
Findings (1)
Plain rules over the facts below. Fix the fact and the finding clears.
- Critical findingHeld patient data without a BAA, no breach risk assessment
Held patient data from Feb 8, 2026 to Jul 3, 2026 (146 days) while no signed BAA was in force. No breach risk assessment is recorded.
Fix it under Patient data held without a BAANext step: Have the privacy officer complete a breach risk assessment for each period, then record the outcome on the vendor page.
Owner: Dr. Amara Singh
Why this matters
Giving patient data to a business associate with no signed BAA is an impermissible disclosure, presumed to be a breach unless the practice documents a low probability that the data was compromised (45 CFR 164.402). Signing a BAA later, lowering the vendor's access or ending the relationship does not undo it, because a BAA cannot cover data disclosed before it was signed; recording the assessment outcome for each period does.
Patient data held without a BAA
Every day the vendor held our patient data with no signed BAA in force, worked out from the holding and BAA histories below. These periods never disappear: a BAA signed later does not cover them. Each needs a breach risk assessment (45 CFR 164.402).
Held our patient data from Feb 8, 2026 to Jul 3, 2026 (146 days) while no signed BAA was in force.
No breach risk assessment is recorded. The disclosure is presumed to be a breach unless a documented assessment of four factors (the nature of the data, who received it, whether it was actually viewed, and how far the risk was mitigated) shows a low probability of compromise.
Business associate agreement
No BAA on file. This vendor holds our patient information, so one is required.
Risk tier
Score 5. Reviewed every 12 months at this tier.
- Handles some patient data+2
- No current SOC 2 report or HITRUST certification+2
- No security questionnaire in the last 12 months+1
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 2, which is moderate. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- None on file
Security questionnaire
Valid for 12 months once received
- Not needed
SOC 2 Type II report
Valid for 12 months once received
- Not needed
HITRUST certification
Valid for 24 months once received
Subcontractors
Companies this vendor passes our data to.
None recorded.
Data, access and contacts
- Patient data
- Limited patient data
- Remote access
- No
- Internal owner
- Dr. Amara Singh
- In the register since
- Feb 8, 2026
- Contract held by
- Ridgeline Medical Group
- Sites served
- Riverbend
- Patient data first shared
- Not held when the relationship ended
- Data handled
- Paper records for storage or destruction; Names, contact details and demographics
- Who to call about an incident
- Not recorded
Annual reviews
Terminated vendors are no longer reviewed.
End of the relationship
- Terminated
- Jul 3, 2026
- Our data
- Destroyed
- Certificate
- Jul 8, 2026
Documents (1)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Return or destruction certificateReturn or destruction certificate (sample). Attached Jul 8, 2026 by Marisol Vance.Open the copy
Attach a document
Notes (1)
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
Scanned the older paper charts. The clinic booked them on a purchase order and nobody asked for a BAA before the boxes were picked up. The privacy officer has not yet assessed the months they held the charts.
At intake, Feb 8, 2026
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Recorded data disposition: Destroyed, certificate receivedMarisol Vance, Jul 8, 2026
- Marked Tallow Creek Scanning as terminated. Held patient data with no BAA on file; breach risk assessment requiredMarisol Vance, Jul 3, 2026
- Added Tallow Creek Scanning with limited patient data accessMarisol Vance, Feb 8, 2026