Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

VendorsMenu

Annual review: Pinecrest Text Reminders

Confirm each fact is still true. The register will not let you pass an item its own records contradict, and the next review date is set from the risk tier and your outcome.
Moderate riskBAA: Signed, not yet in force

Open findings to consider

  • BAA needed before any patient data is shared. The signed BAA takes effect on Oct 20, 2026. Do not share patient data before then.
  • Annual review overdue or never done. This vendor has never been reviewed.
Has any patient data been shared with this vendor yet?

Has any patient data been shared with this vendor yet?

The register has this vendor set up for patient data but no go-live date, last confirmed on Sep 24, 2026. While that stands, no day counts as held without a BAA. Ask the internal owner, not the contract.

Patient data access and data types are still accurate

1. Patient data access and data types are still accurate

Ask the internal owner what the vendor actually touches today, not what the contract says.

If the answer is no, correct it first under Data, access and contacts; the BAA requirement and risk tier are recomputed from the new answer.

A signed, current BAA is on file with the required terms

2. A signed, current BAA is on file with the required terms

Breach notice within 60 days, termination for breach, return or destruction of data, subcontractor terms. Check the signature and effective dates on record against the signed copy. A BAA entered long after it was signed that covers days already held is confirmed separately, on the vendor page.

Security evidence is current

3. Security evidence is current

Every vendor with patient data: a questionnaire from the last 12 months. Vendors rated critical or high before any evidence points also need a SOC 2 report or HITRUST certification that is still valid.

For this vendor: Before any evidence points it rates moderate, so it needs a security questionnaire from the last 12 months. A SOC 2 report or HITRUST certification is welcome but not required.

Subcontractors that handle our data are listed and bound by the same terms

4. Subcontractors that handle our data are listed and bound by the same terms

Mark not applicable only if the vendor uses no subcontractors for our data.

No security incidents or breach reports since the last review

5. No security incidents or breach reports since the last review

Mark failed if anything was reported, even if it was resolved, and describe it in the notes.

A named internal owner is still responsible for this vendor

6. A named internal owner is still responsible for this vendor

Someone at the practice who would notice if the service changed.

Outcome

Outcome

Cancel