Skip to content

Vendor PHI Inventory

Inventory of vendors that have, or may have, access to Protected Health Information (PHI) as defined by HIPAA. Each vendor must have a current Business Associate Agreement (BAA) in place before PHI is exchanged or stored on their systems. This document satisfies COMP-026 and is the authoritative source for BAA coverage.

Scope

Cirius Group handles PHI on behalf of its clients. Any vendor that stores, processes, transmits, or could reasonably access PHI in the course of delivering services is in scope for this inventory.

PHI access is categorized as:

  • Direct storage — PHI is persisted on vendor infrastructure.
  • Direct processing — PHI is processed in memory or in transit through vendor infrastructure, but not persisted.
  • Incidental access — vendor personnel could view PHI while performing a support or investigation activity (for example, during an MDR escalation), but PHI is not a core data type on the service.
  • Transmission only — PHI flows through the vendor's network but is encrypted end-to-end and the vendor holds no keys.

Vendor Table

VendorServicePHI Access TypeBAA Status
Microsoft (Azure)Azure cloud infrastructure — VMs, storage, Key Vault, SentinelDirect storage, direct processingActive — covered by Microsoft Products and Services BAA (Volume Licensing)
Amazon Web ServicesAWS cloud infrastructure — EC2, S3, KMS, workload accountsDirect storage, direct processingActive — AWS BAA executed at org level
Arctic WolfManaged Detection and Response (MDR) — Concierge Security Team, ticketingIncidental access (during investigation)Active — BAA on file
Palo Alto NetworksCortex XDR — endpoint telemetry, EDR, managed threat huntingIncidental access (during investigation)Active — BAA on file
TwingateZero Trust remote access — user network tunnels to internal resourcesTransmission only (end-to-end encrypted, no key custody)Active — BAA on file
Microsoft (M365)Microsoft 365 — Exchange Online, SharePoint, OneDrive, Teams, PurviewDirect storage, direct processingActive — covered by Microsoft Products and Services BAA

Vendor Detail

Microsoft — Azure

  • Service summary: production workloads, identity (Entra), secrets (Key Vault), SIEM (Sentinel), data platform storage, and VM-hosted applications handling PHI.
  • PHI access type: direct storage (blob, managed disks, SQL) and direct processing (VM compute, Functions, Logic Apps).
  • BAA: in effect under the Microsoft Products and Services Agreement. Covers both PROD tenant d477c9f8 and DDE tenant ff1c5d68.
  • Safeguards: tenant isolation, Customer Lockbox enabled on PHI-bearing subscriptions, CMK (customer-managed keys) in Key Vault for PHI-tagged data, Purview DLP policies for identification and containment.

Amazon Web Services — AWS

  • Service summary: AWS accounts hosting workload compute, S3 buckets, RDS, and KMS for any PHI-bearing application on AWS.
  • PHI access type: direct storage (S3, RDS, EBS) and direct processing (EC2, Lambda).
  • BAA: executed at organization level with AWS.
  • Safeguards: CMK via KMS with customer-controlled key policy, SCP-enforced encryption, CloudTrail and Config recording enabled across all accounts, centralized log aggregation to the security account.

Arctic Wolf — MDR

  • Service summary: 24x7 Managed Detection and Response; Concierge Security Team triages alerts and escalates incidents. Ingests log and alert telemetry from Azure, AWS, endpoints, and network.
  • PHI access type: incidental. Arctic Wolf's core dataset is security telemetry, not PHI; however, during investigation a CST analyst could view event content that references PHI (for example, an email subject line in a phishing alert).
  • BAA: on file with Arctic Wolf.
  • Safeguards: CST analysts operate under BAA; Cirius tunes detections and data collection rules to minimize PHI exposure; PHI never stored in Arctic Wolf's core data lake by design.

Palo Alto Networks — Cortex XDR

  • Service summary: endpoint detection and response agent on managed endpoints; cloud-delivered analytics; managed threat hunting.
  • PHI access type: incidental. Endpoint telemetry (processes, file hashes, network flows) is the core dataset. PHI could appear in file paths or command-line arguments observed on endpoints.
  • BAA: on file with Palo Alto Networks.
  • Safeguards: file content is not uploaded by default; file collection for analysis is scoped and approved per incident; data residency configured for US regions.

Twingate — Zero Trust Remote Access

  • Service summary: user-to-resource Zero Trust tunnels replacing legacy VPN for administrative access to internal resources.
  • PHI access type: transmission only. User traffic passes through Twingate Connectors inside the Cirius network; Twingate's cloud control plane does not decrypt traffic and has no key custody.
  • BAA: on file with Twingate.
  • Safeguards: end-to-end encrypted relay (when relay is used); private network access controls enforced at Connector; Twingate admin console access requires FIDO2.

Microsoft — Microsoft 365

  • Service summary: email (Exchange Online), file storage (SharePoint, OneDrive), collaboration (Teams), data governance (Purview).
  • PHI access type: direct storage and direct processing. Email and SharePoint are the most likely locations for PHI to appear in the environment.
  • BAA: covered by the Microsoft Products and Services BAA.
  • Safeguards: Purview DLP policies classify and alert on PHI; Conditional Access restricts access paths; retention policies align to HIPAA record-keeping; audit log (Unified Audit Log) retained and ingested to Sentinel.

BAA Governance

  • BAAs are maintained centrally. Every entry in this table must reference a current, countersigned BAA.
  • BAAs are reviewed annually for currency and scope. See compliance/annual-review-checklist.md.
  • Before onboarding any new vendor that may touch PHI, a BAA must be executed first. Procurement will not release purchase orders for PHI-touching services without a countersigned BAA.

Change Procedure

To add, remove, or change a vendor entry in this inventory:

  1. Open a story in the COMP project describing the change.
  2. Attach the countersigned BAA (or notice of termination).
  3. Rory reviews and approves.
  4. Update this file and related HIPAA control evidence (compliance/hipaa-controls.md).
  5. Close the story with a link to the merged PR.
  • compliance/hipaa-controls.md — HIPAA control crosswalk
  • compliance/annual-review-checklist.md — annual review cadence
  • compliance/access-control-review.md — identity and permission tiers

Internal use only — Cirius Group