Vendor and BAA Management Template
Two documents and three sheets built from two vendor lists, since one of them finds the free tool with data access no invoice shows.
Free download · No account needed
Vendor Register
Two discovery passes, one register
Illustrative preview. Discovery Source shows which pass found each vendor, or both.
| Vendor | Discovery Source | Business Associate | BAA on File |
|---|---|---|---|
The column that finds what an invoice can't
Discovery Source is never assumed. Payment, Access, or Both, pulled from two independent passes and never collapsed into one list.
Remaining columns: Function, Data Access Breadth, Signed Date, Subcontractors Disclosed, Citation.
Every vendor and BAA tracker for a medical practice starts from the same source: the payment history. Pull the recurring charges, list who gets paid, ask each one for a signed agreement. It finds most vendors. It misses a specific, predictable kind: a vendor with live access to patient data and no invoice behind it at all. The feature might be free, bundled into something else already paid for, or switched on by a clinician who never told anyone.
45 CFR 160.103 defines a business associate by what a vendor does with protected health information, not by whether the practice pays it. It names a person who "creates, receives, maintains, or transmits" it, or discloses it while providing certain services, on the practice's behalf. No dollar figure appears anywhere in that test, which is why a second, independent discovery pass, pulled from each system's own connected-apps or OAuth-grants page rather than from a card statement, finds vendors the first pass cannot.
Cedarholm Family Medicine, a fictional single-location practice, found 22 vendors on its payment trail and 16 on its access trail, with only 13 on both. The 3 access-only vendors included a free SMS appointment-reminder feature bundled into its phone carrier plan, pulling full patient PHI to compose each text with no BAA on file. It scores 5 of 5 on the Risk Rating, Critical, and the carrier's own contract happens to renew in 45 days, the real lever to require one.
What's in the pack
Vendor Register
One row per vendor, tagged Payment, Access, or Both by which discovery pass found it. Vendor-held assets also appear in the security risk assessment's asset register, at a coarser grain than this dedicated discovery runs.
BAA Template
The provisions the regulation requires, laid out with their citations, and separately the terms it leaves silent: the breach-reporting window, subcontractor disclosure cadence, and an explicit term. A vendor's own reporting window feeds directly into the breach notification clock once an incident is known.
Vendor Assessment Procedure
A pass/fail sequence run against every vendor already in the register: business-associate status by function, a signed BAA, the required provisions present, subcontractors disclosed, and the data access breadth actually requested rather than advertised.
Expiry Tracking
Tracks whichever date a vendor's own paperwork names, a drafted BAA term or the underlying contract's renewal, since HIPAA sets neither. A vendor with no date recorded on either is flagged as a standing gap rather than left blank.
Risk Rating
Scores data access breadth, BAA status, and subcontractor disclosure additively, so a fully compliant vendor with full PHI access still rates above a limited-access vendor, and a missing BAA alone is usually enough to reach Critical.
BAA Renewal and Access Review Watch
A weekly read that flags a contract or BAA-term renewal inside 60 days, any vendor newly scoring Critical, and any access-trail vendor with no expiry trigger on file at all.
How to use it
- 1
Open in River, or download it
Open the pack in River and let the agent run both discovery passes against your real systems, or download the blank Word and CSV files instantly and work through them yourself.
- 2
Send both trails, not just one
An eighteen-month payment export, plus the connected-apps or integrations page from your EHR, your patient portal, and your identity provider's OAuth grants list.
- 3
Watch which vendors show up in only one list
A vendor found by access alone is usually the one nobody thought to ask for a BAA, precisely because no invoice ever prompted the question.
- 4
Chase the Critical-tier gaps at their real renewal
Every missing BAA gets scored and routed to the nearest upcoming contract or BAA-term renewal, the moment a vendor is most likely to sign rather than resist.
Frequently asked questions
Is this template free?
Yes. Download the two documents and three sheets as Word and CSV files with no signup and no card. "Edit with AI" is a separate, optional path for practices that want the agent to run both discovery passes against their real systems. The rest of the library is at the template library.
How is this different from the BAA register in the HIPAA policy pack?
The HIPAA policies and procedures template builds its BAA register from a payment export, which is a real improvement over listing vendors from memory. This pack adds the access-trail pass that export cannot run, plus the expiry and risk-scoring sheets the policy pack doesn't carry. Use both together rather than choosing one.
Do I really need a BAA for a vendor I don't pay for?
If it creates, receives, maintains, or transmits PHI on your behalf, yes. The regulation's own test runs on the access, not the invoice, so a free plugin, a bundled carrier feature, or a connected app a clinician authorized without asking anyone is a business associate the moment it meets that test.
Why doesn't the Expiry Tracking sheet just use the BAA's expiration date?
Because most BAAs don't have one. The required-provisions list at 45 CFR 164.504(e)(2) contains no term or expiration clause, so a BAA is legally free to run silently forever, and most vendor-drafted ones do. The sheet tracks whichever date a vendor's own paperwork actually names, a drafted BAA term where one exists, otherwise the underlying contract's renewal date.
How is this different from a general vendor-contract renewal tracker?
A commercial vendor renewal tracker watches every contract for cost and service-level reasons. This pack only cares whether a vendor touches PHI, and tracks BAA status and subcontractor disclosure alongside the date, which a general renewal tracker has no reason to carry.
A vendor's security team just sent us their own questionnaire. Does this help?
That's the reverse direction. The security questionnaire response pack answers what a vendor or partner asks about your practice's own safeguards. This pack is what your practice runs on the vendors you use, not what you hand back when one of them asks about you.
What format are the downloaded files?
Word documents for the BAA Template and the Vendor Assessment Procedure, plus CSV for the Vendor Register, Expiry Tracking and Risk Rating sheets, zipped into one download. They open in Word, Pages, Google Docs, Excel, Numbers and Sheets without a conversion step.
Find the vendor nobody remembered to invoice
Send your payment history and your systems' connected-apps pages. Every vendor comes back tagged by which pass found it, and scored by what it can actually see.
Edit with AI