Demonstration environment. Fictional organization, fictional vendors, synthetic data throughout. Changes you make stay in this browser only.
ParvinCorpVendor & BAA Register

Ridgeline Health Partners. Multi-specialty physician group, 6 sites, 14 providers.

Signed in as

Marisol Vance, Compliance Officer. Runs the register. Adds vendors, records BAAs and security evidence, and completes the annual reviews. Sees the audit trail.

VendorsMenu
Vendors / Copperleaf Voice Notes
Moderate riskBAA: Signed, in forceScheduled

Copperleaf Voice Notes

Ambient dictation pilot for two clinics. Transcription or dictation. Limited patient data.

Findings (1)

Plain rules over the facts below. Fix the fact and the finding clears.

  • High findingNot recorded as live for months: confirm no patient data is being shared

    No patient data was last confirmed as not yet shared on Jun 29, 2026, 100 days ago. A signed BAA is in force, so nothing prompts anyone to record go-live; if it lapses while data is flowing, the lapse would not be recorded.

    Next step: Ask the internal owner whether any patient data has been shared, then record the go live date or confirm again that none has.

    Owner: Dr. Amara Singh

    Fix it under Data, access and contacts
    Why this matters

    The vendor is set up to receive patient data, but no go-live date is recorded. While that is so, the register counts no days held without a BAA and a lapsed BAA is not treated as a gap, so an unrecorded go-live would hide exactly those findings. After 90 days without a fresh answer, someone must confirm it: record the date data was first shared, or confirm again that none has been (on the access form or in the annual review).

Business associate agreement

BAA: Signed, in force
Document
Signed May 20, 2026
Filed at
BAA-025, compliance share
Effective
May 20, 2026
Ends
With the service agreement
Next BAA review
May 15, 2027 (in 220 days)
Breach notice
30 days
  • YesBreach reported within 60 days of discovery
  • YesWe can terminate if the vendor violates a material term
  • YesData is returned or destroyed when the relationship ends
  • YesSubcontractors are bound by the same terms

Signed BAA history

  • Signed May 20, 2026, entered May 20, 2026: effective May 20, 2026, runs with the service agreement. BAA-025, compliance share
Update the BAA
The agreement says
Attach the copy

Required when you record a newly signed BAA, so anyone checking can open the signed copy. Not needed for a draft or when only amending terms.

Risk tier

Moderate risk

Score 3. Reviewed every 12 months at this tier.

  • Handles some patient data+2
  • Transcription or dictation carries medium inherent risk+1

Before any security evidence points (patient data access, kind of service, remote access and subcontractors) the score is 3, which is moderate. That part alone decides whether a SOC 2 report or HITRUST certification is required.

8 and up is critical, 5 to 7 high, 2 to 4 moderate, below 2 low. A vendor without patient data is never above moderate. How the score works

Security evidence

The security questionnaire is the vendor's own answers about how it protects data. A SOC 2 report or HITRUST certification is an outside auditor's report on how well the vendor protects data, rather than the vendor's own answers.

  • Security questionnaire

    Dated May 10, 2026, valid to May 10, 2027

    Current
  • SOC 2 Type II report

    Dated Apr 30, 2026, valid to Apr 30, 2027

    Current
  • HITRUST certification

    Valid for 24 months once received

    Not needed

Before any evidence points it rates moderate, so it needs a security questionnaire from the last 12 months. A SOC 2 report or HITRUST certification is welcome but not required.

Record new evidence
Attach the copy

Required: the report, certification or completed questionnaire this date comes from.

Subcontractors

Companies this vendor passes our data to.

None recorded.

Add or confirm a subcontractor

Entering an existing name updates that subcontractor.

Data, access and contacts

Patient data
Limited patient data
Remote access
No
Internal owner
Dr. Amara Singh
In the register since
May 10, 2026
Contract held by
Ridgeline Medical Group
Sites served
Riverside Orthopedics
Patient data first shared
Not yet, last confirmed Jun 29, 2026. No patient data has been shared, so none is held without a BAA. Record the date when it is; confirm again at least every 90 days.
Data handled
Voice recordings and dictation; Clinical notes and diagnoses
Who to call about an incident
Not recorded
Change the contracting entity or sites
Contract and sites

Sites it serves

Leave every box clear if it serves every site.

East Region

West Region

Update access and data

Vendors change after intake: a phone vendor starts recording calls, an IT vendor is given EHR admin rights. Record what the vendor touches today. The BAA requirement and risk tier are recomputed from your answers.

Patient data access
Data handled
If access is limited or full: has any patient data been shared with this vendor yet?
No default: access planned is not data held, but a go-live left unrecorded hides every day held without a BAA. A vendor in procurement needs a signed BAA in force before this date.
Who to call about an incident (optional)

Annual reviews

Start the review

Next review Jun 29, 2027 (in 265 days).

End of the relationship

When this relationship ends, record the date here. For a vendor with patient data, the register then asks for proof the data was returned or destroyed.

Documents (3)

Copies anyone checking can open: signed BAAs, security reports, questionnaires and certificates. Newest first. Attached copies are never removed.

  • Security questionnaireSecurity questionnaire (sample). Attached May 10, 2026 by Marisol Vance.Open the copy
  • SOC 2 reportSOC 2 report (sample). Attached Apr 30, 2026 by Marisol Vance.Open the copy
  • Signed BAASigned BAA (sample). Attached May 20, 2026 by Marisol Vance.Open the copy
Attach a document
Attach the copy

An older signed BAA, an amendment, or anything an auditor will ask to see.

Notes (1)

What happened with this vendor, in order, with who wrote each note and when. Notes are never edited; a correction is a new note.

  1. Pilot approved in the spring. At the review 100 days ago it was not live yet; the clinic lead now says recordings may have started, and nobody has told compliance.

    At intake, May 10, 2026

Add a note

Saved with your name and today's date, and recorded in the audit trail.

History of this record

Recorded automatically when anything changes. Nobody can edit it.

Open in the audit trail
  1. Completed the annual review: ApprovedMarisol Vance, Jun 29, 2026
  2. Recorded a signed BAA (BAA-025, compliance share)Marisol Vance, May 20, 2026
  3. Added Copperleaf Voice Notes with limited patient data access, no patient data shared yetMarisol Vance, May 10, 2026