DEMO
You’re viewing AuditPilot with seeded data for Cedar Creek Family Medicine. Add Clerk + Neon environment variables to enable real multi-tenant data.

Third-party risk

Vendors & BAAs

Every vendor that touches your environment, and the legal paperwork that needs to follow.

Missing BAAs

1

Out of 4 vendors handling PHI.

Expiring within 60 days

0

Schedule renewals now to avoid gaps.

Current BAAs

3

No action required.

All vendors
VendorCategoryPHIRiskBAA statusExpires

Athenahealth

ba@athenahealth.example

EHR
Handles PHI
HighCurrentDec 6, 2026

Microsoft 365

compliance@microsoft.example

Productivity
Handles PHI
HighCurrentMay 30, 2027

Datto SIRIS Backup

ba@datto.example

Backup
Handles PHI
HighCurrentAug 8, 2026

TwilioSendGrid

ba@twilio.example

Email
Handles PHI
MediumBAA missingApr 8, 2026

Stripe

compliance@stripe.example

Payments
No PHI
MediumBAA not required

Bitdefender GravityZone

channel@bitdefender.example

Security
No PHI
MediumBAA not requiredMar 1, 2027

SonicWall TZ470

support@sonicwall.example

Network
No PHI
MediumBAA not required

Why this matters during an audit

HIPAA §164.308(b)(1) requires a signed Business Associate Agreement with every third party that creates, receives, maintains, or transmits PHI on the clinic’s behalf. A single missing BAA will fail this control — and it’s the #1 finding in clinic audits.