River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Vendor and BAA Management Template

Two documents and three sheets built from two vendor lists, since one of them finds the free tool with data access no invoice shows.

Free download  ·  No account needed

Vendor Register

Two discovery passes, one register

Illustrative preview. Discovery Source shows which pass found each vendor, or both.

VendorDiscovery SourceBusiness AssociateBAA on File
    
    

The column that finds what an invoice can't

Discovery Source is never assumed. Payment, Access, or Both, pulled from two independent passes and never collapsed into one list.

Remaining columns: Function, Data Access Breadth, Signed Date, Subcontractors Disclosed, Citation.

Every vendor and BAA tracker for a medical practice starts from the same source: the payment history. Pull the recurring charges, list who gets paid, ask each one for a signed agreement. It finds most vendors. It misses a specific, predictable kind: a vendor with live access to patient data and no invoice behind it at all. The feature might be free, bundled into something else already paid for, or switched on by a clinician who never told anyone.

45 CFR 160.103 defines a business associate by what a vendor does with protected health information, not by whether the practice pays it. It names a person who "creates, receives, maintains, or transmits" it, or discloses it while providing certain services, on the practice's behalf. No dollar figure appears anywhere in that test, which is why a second, independent discovery pass, pulled from each system's own connected-apps or OAuth-grants page rather than from a card statement, finds vendors the first pass cannot.

Cedarholm Family Medicine, a fictional single-location practice, found 22 vendors on its payment trail and 16 on its access trail, with only 13 on both. The 3 access-only vendors included a free SMS appointment-reminder feature bundled into its phone carrier plan, pulling full patient PHI to compose each text with no BAA on file. It scores 5 of 5 on the Risk Rating, Critical, and the carrier's own contract happens to renew in 45 days, the real lever to require one.

The vendor nobody was invoiced for

The full vendor register, the expiry clock behind it, and the additive risk score.

Vendor Register

Illustrative sample for a fictional practice, Cedarholm Family Medicine, 25 distinct vendors found across both passes.

VendorDiscovery SourceBusiness AssociateBAA on FileSubcontractors Disclosed
EHR / practice management platformBothYesYesDisclosed
Check-in kiosk vendorBothYesNoUnknown
Insurance eligibility verification toolPayment onlyYesNoUnknown
Website chat widgetAccess onlyYesYesDisclosed
SMS appointment-reminder add-on (carrier bundle)Access onlyYesNoUndisclosed
Landscaping servicePayment onlyNon/an/a

22 vendors on the payment trail, 16 on the access trail, 13 on both, 25 distinct in all. The highlighted row is access-only and was never on an invoice.

Expiry Tracking

Tracks whichever date a vendor's own paperwork actually names. HIPAA requires neither, so a blank here is a real gap, not a non-event.

VendorTrigger TypeNext Trigger DateDays Until Trigger
Reference lab results interfaceContract renewal2026-03-159
Medical transcription serviceContract renewal2026-04-0126
SMS appointment-reminder add-onUnderlying contract only (no BAA)2026-04-2045
E-prescribing network / pharmacy gatewayNo trigger on fileNonen/a

The highlighted row has no BAA to expire. Its carrier contract renewal in 45 days is the only date on file anywhere, and it is the lever the assessment procedure uses to require a BAA rather than opening a cold ask with no deadline behind it.

Risk Rating

Data access breadth + BAA status + subcontractor disclosure, additive. 0-1 Standard, 2-3 Elevated, 4-5 Critical.

VendorAccessBAASubcontractorTotalTier
SMS appointment-reminder add-on2215Critical
Cloud fax / eFax service2215Critical
EHR / practice management platform2002Elevated
Website chat widget1001Standard

A signed BAA does not zero the score. The practice management platform has every paper in order and still rates Elevated, because Full PHI access alone is a standing risk. Missing paperwork is what pushes a vendor past it into Critical.

What's in the pack

01

Vendor Register

One row per vendor, tagged Payment, Access, or Both by which discovery pass found it. Vendor-held assets also appear in the security risk assessment's asset register, at a coarser grain than this dedicated discovery runs.

02

BAA Template

The provisions the regulation requires, laid out with their citations, and separately the terms it leaves silent: the breach-reporting window, subcontractor disclosure cadence, and an explicit term. A vendor's own reporting window feeds directly into the breach notification clock once an incident is known.

03

Vendor Assessment Procedure

A pass/fail sequence run against every vendor already in the register: business-associate status by function, a signed BAA, the required provisions present, subcontractors disclosed, and the data access breadth actually requested rather than advertised.

04

Expiry Tracking

Tracks whichever date a vendor's own paperwork names, a drafted BAA term or the underlying contract's renewal, since HIPAA sets neither. A vendor with no date recorded on either is flagged as a standing gap rather than left blank.

05

Risk Rating

Scores data access breadth, BAA status, and subcontractor disclosure additively, so a fully compliant vendor with full PHI access still rates above a limited-access vendor, and a missing BAA alone is usually enough to reach Critical.

06

BAA Renewal and Access Review Watch

A weekly read that flags a contract or BAA-term renewal inside 60 days, any vendor newly scoring Critical, and any access-trail vendor with no expiry trigger on file at all.

How to use it

  1. 1

    Open in River, or download it

    Open the pack in River and let the agent run both discovery passes against your real systems, or download the blank Word and CSV files instantly and work through them yourself.

  2. 2

    Send both trails, not just one

    An eighteen-month payment export, plus the connected-apps or integrations page from your EHR, your patient portal, and your identity provider's OAuth grants list.

  3. 3

    Watch which vendors show up in only one list

    A vendor found by access alone is usually the one nobody thought to ask for a BAA, precisely because no invoice ever prompted the question.

  4. 4

    Chase the Critical-tier gaps at their real renewal

    Every missing BAA gets scored and routed to the nearest upcoming contract or BAA-term renewal, the moment a vendor is most likely to sign rather than resist.

Frequently asked questions

Is this template free?

Yes. Download the two documents and three sheets as Word and CSV files with no signup and no card. "Edit with AI" is a separate, optional path for practices that want the agent to run both discovery passes against their real systems. The rest of the library is at the template library.

How is this different from the BAA register in the HIPAA policy pack?

The HIPAA policies and procedures template builds its BAA register from a payment export, which is a real improvement over listing vendors from memory. This pack adds the access-trail pass that export cannot run, plus the expiry and risk-scoring sheets the policy pack doesn't carry. Use both together rather than choosing one.

Do I really need a BAA for a vendor I don't pay for?

If it creates, receives, maintains, or transmits PHI on your behalf, yes. The regulation's own test runs on the access, not the invoice, so a free plugin, a bundled carrier feature, or a connected app a clinician authorized without asking anyone is a business associate the moment it meets that test.

Why doesn't the Expiry Tracking sheet just use the BAA's expiration date?

Because most BAAs don't have one. The required-provisions list at 45 CFR 164.504(e)(2) contains no term or expiration clause, so a BAA is legally free to run silently forever, and most vendor-drafted ones do. The sheet tracks whichever date a vendor's own paperwork actually names, a drafted BAA term where one exists, otherwise the underlying contract's renewal date.

How is this different from a general vendor-contract renewal tracker?

A commercial vendor renewal tracker watches every contract for cost and service-level reasons. This pack only cares whether a vendor touches PHI, and tracks BAA status and subcontractor disclosure alongside the date, which a general renewal tracker has no reason to carry.

A vendor's security team just sent us their own questionnaire. Does this help?

That's the reverse direction. The security questionnaire response pack answers what a vendor or partner asks about your practice's own safeguards. This pack is what your practice runs on the vendors you use, not what you hand back when one of them asks about you.

What format are the downloaded files?

Word documents for the BAA Template and the Vendor Assessment Procedure, plus CSV for the Vendor Register, Expiry Tracking and Risk Rating sheets, zipped into one download. They open in Word, Pages, Google Docs, Excel, Numbers and Sheets without a conversion step.

Find the vendor nobody remembered to invoice

Send your payment history and your systems' connected-apps pages. Every vendor comes back tagged by which pass found it, and scored by what it can actually see.

Edit with AI