Copperleaf Voice Notes
Ambient dictation pilot for two clinics. Transcription or dictation. Limited patient data.
Findings (1)
Plain rules over the facts below. Fix the fact and the finding clears.
- High findingNot recorded as live for months: confirm no patient data is being shared
No patient data was last confirmed as not yet shared on Jun 29, 2026, 100 days ago. A signed BAA is in force, so nothing prompts anyone to record go-live; if it lapses while data is flowing, the lapse would not be recorded.
Fix it under Data, access and contactsNext step: Ask the internal owner whether any patient data has been shared, then record the go live date or confirm again that none has.
Owner: Dr. Amara Singh
Why this matters
The vendor is set up to receive patient data, but no go-live date is recorded. While that is so, the register counts no days held without a BAA and a lapsed BAA is not treated as a gap, so an unrecorded go-live would hide exactly those findings. After 90 days without a fresh answer, someone must confirm it: record the date data was first shared, or confirm again that none has been (on the access form or in the annual review).
Business associate agreement
- Document
- Signed May 20, 2026
- Filed at
- BAA-025, compliance share
- Effective
- May 20, 2026
- Ends
- With the service agreement
- Next BAA review
- May 15, 2027 (in 220 days)
- Breach notice
- 30 days
- YesBreach reported within 60 days of discovery
- YesWe can terminate if the vendor violates a material term
- YesData is returned or destroyed when the relationship ends
- YesSubcontractors are bound by the same terms
Signed BAA history
- Signed May 20, 2026, entered May 20, 2026: effective May 20, 2026, runs with the service agreement. BAA-025, compliance share
Update the BAA
Risk tier
Score 3. Reviewed every 12 months at this tier.
- Handles some patient data+2
- Transcription or dictation carries medium inherent risk+1
Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 3, which is moderate. That part alone decides whether a SOC 2 report or HITRUST certification is required.
8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works
Security evidence
The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.
- Current
Security questionnaire
Dated May 10, 2026, valid to May 10, 2027
- Current
SOC 2 Type II report
Dated Apr 30, 2026, valid to Apr 30, 2027
- Not needed
HITRUST certification
Valid for 24 months once received
Before any evidence points it rates moderate, so it needs a security questionnaire from the last 12 months. A SOC 2 report or HITRUST certification is welcome but not required.
Record new evidence
Subcontractors
Companies this vendor passes our data to.
None recorded.
Add or confirm a subcontractor
Data, access and contacts
- Patient data
- Limited patient data
- Remote access
- No
- Internal owner
- Dr. Amara Singh
- In the register since
- May 10, 2026
- Contract held by
- Ridgeline Medical Group
- Sites served
- Riverside Orthopedics
- Patient data first shared
- Not yet, last confirmed Jun 29, 2026. No patient data has been shared, so none is held without a BAA. Record the date when it is; confirm again at least every 90 days.
- Data handled
- Voice recordings and dictation; Clinical notes and diagnoses
- Who to call about an incident
- Not recorded
Change the contracting entity or sites
Update access and data
Annual reviews
Next review Jun 29, 2027 (in 265 days).
End of the relationship
When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.
Documents (3)
Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.
- Security questionnaireSecurity questionnaire (sample). Attached May 10, 2026 by Marisol Vance.Open the copy
- SOC 2 reportSOC 2 report (sample). Attached Apr 30, 2026 by Marisol Vance.Open the copy
- Signed BAASigned BAA (sample). Attached May 20, 2026 by Marisol Vance.Open the copy
Attach a document
Notes (1)
What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.
Pilot approved in the spring. At the review 100 days ago it was not live yet; the clinic lead now says recordings may have started, and nobody has told compliance.
At intake, May 10, 2026
Add a note
History of this record
Recorded automatically when anything changes. Nobody can edit it.
- Completed the annual review: ApprovedMarisol Vance, Jun 29, 2026
- Recorded a signed BAA (BAA-025, compliance share)Marisol Vance, May 20, 2026
- Added Copperleaf Voice Notes with limited patient data access, no patient data shared yetMarisol Vance, May 10, 2026