Pinecrest Text Reminders
Appointment reminder texts and two-way scheduling messages. Patient messaging or reminders. Limited patient data.
Findings (2)
Plain rules over the facts below. Fix the fact and the finding clears.
- High findingBAA needed before any patient data is shared
The signed BAA takes effect on Oct 21, 2026. Do not share patient data before then.
Fix it under Business associate agreementNext step: Keep patient data away from this vendor until a signed BAA is in force, and record the go live date on the vendor page the day data first flows.
Owner: Owen Castellano
Draft a request to the vendor
Sending this does not clear the finding. Record the signed BAA, report, confirmation or certificate on this page once the vendor sends it.
Subject: Business associate agreement needed before we share patient information: Pinecrest Text Reminders Hello Pinecrest Text Reminders team, Before Ridgeline Health Partners shares any patient information with Pinecrest Text Reminders, we need a business associate agreement signed by both parties and in force. The signed agreement we hold takes effect on Oct 21, 2026, so it does not cover our patient information today. Please return a copy signed by your authorized signer, with the date it takes effect. Until it is in force, please do not start any work that involves our patient information. Thank you, Marisol Vance Compliance Officer, Ridgeline Health Partners
No incident contact email is on file; copy it into a letter or email.Why this matters
The vendor is set up to receive patient data, but the register has no record of any being shared yet (it is in procurement, or not live again). A signed BAA must be in force before the first disclosure. Nothing has been disclosed without one, so this is not a breach; sharing data before the BAA is signed would be. Record the date data is first shared once it is.
- Medium findingAnnual review overdue or never done
This vendor has never been reviewed.
Fix it under Annual reviewsNext step: Complete the annual review from the vendor page.
Owner: Owen Castellano
Why this matters
The review is the recurring moment a named person confirms the record is still true.
Business associate agreement
- Document
- Signed Oct 4, 2026
- Filed at
- BAA-024, compliance share
- Effective
- Oct 21, 2026. Not in force today.
- Ends
- With the service agreement
- Next BAA review
- Oct 7, 2027 (in 365 days)
- Breach notice
- 30 days
- YesBreach reported within 60 days of discovery
- YesWe can terminate if the vendor violates a material term
- YesData is returned or destroyed when the relationship ends
- YesSubcontractors are bound by the same terms
Signed BAA history
- Signed Oct 4, 2026, entered Oct 4, 2026: effective Oct 21, 2026, runs with the service agreement. BAA-024, compliance share
Update the BAA
Risk tier
Score 3. Reviewed every 12 months at this tier.
- Handles some patient data+2
- Patient messaging or reminders carries medium inherent risk+1
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 3, which is moderate. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- Current
Security questionnaire
Dated Sep 29, 2026, valid to Sep 29, 2027
- Current
SOC 2 Type II report
Dated Aug 28, 2026, valid to Aug 28, 2027
- Not needed
HITRUST certification
Valid for 24 months once received
Before any evidence points it rates moderate, so it needs a security questionnaire from the last 12 months. A SOC 2 report or HITRUST certification is welcome but not required.
Record new evidence
Subcontractors
Companies this vendor passes our data to.
None recorded.
Add or confirm a subcontractor
Data, access and contacts
- Patient data
- Limited patient data
- Remote access
- No
- Internal owner
- Owen Castellano
- In the register since
- Sep 25, 2026
- Contract held by
- Ridgeline Medical Group
- Sites served
- Eastgate Family Care
- Patient data first shared
- Not yet, last confirmed Sep 25, 2026. No patient data has been shared, so none is held without a BAA. Record the date when it is; confirm again at least every 90 days.
- Data handled
- Names, contact details and demographics
- Who to call about an incident
- Not recorded
Change the contracting entity or sites
Update access and data
Annual reviews
Never reviewed. A vendor with patient data is due for review as soon as it is added.
End of the relationship
When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.
Documents (3)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Security questionnaireSecurity questionnaire (sample). Attached Sep 29, 2026 by Marisol Vance.Open the copy
- SOC 2 reportSOC 2 report (sample). Attached Aug 28, 2026 by Marisol Vance.Open the copy
- Signed BAASigned BAA (sample). Attached Oct 4, 2026 by Marisol Vance.Open the copy
Attach a document
Notes (1)
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
Chosen to replace the reminder phone calls. The BAA is signed and takes effect on the go-live date; the intake review is booked for go-live week.
At intake, Sep 25, 2026
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Recorded a signed BAA (BAA-024, compliance share), taking effect on the go-live dateMarisol Vance, Oct 4, 2026
- Added Pinecrest Text Reminders with limited patient data access, no patient data shared yetMarisol Vance, Sep 25, 2026