Appearance
Vendor Risk Inventory
Purpose: Central inventory of third-party vendors that create, receive, maintain, or transmit ePHI on behalf of Cirius Group, plus other vendors with privileged access to the environment. Supports HIPAA §164.308(b)(1), §164.314(a) (Business Associate contracts) and SOC2 CC9.2 (vendor management).
Owner: Adriana (BAA / vendor / risk docs) with Rory (Security Officer) Audience: Security Officer, Business Associate counterparties, auditors Review frequency: Annual (September, pre-audit) and when any vendor changes scope, data access, or attestation status Last refreshed: April 2026
How this inventory is used
- Onboarding — no new vendor is granted ePHI access until a row is added here with BAA status IN_FORCE
- Monthly gap check — any vendor with BAA status != IN_FORCE is flagged HIGH finding in the compliance scorecard
- Audit evidence — the most recent SOC2 Type II / SOC2+HITRUST / ISO 27001 report for each vendor lives in
SharePoint → Compliance → Vendor Reports → <vendor> → <YYYY-MM>/ - Risk rating — combines likelihood of compromise, ePHI blast radius, and vendor's own attestations
Risk rating methodology
| Risk tier | Criteria |
|---|---|
| CRITICAL | Direct access to ePHI at scale + admin-level access to our tenant. BAA MUST be in force. |
| HIGH | Access to ePHI at smaller scale OR admin-level access without ePHI. BAA required. |
| MEDIUM | Network-level access or metadata access. BAA typically required. |
| LOW | No ePHI access; infrastructure-only (network, monitoring) where exposure is minimal. BAA may be optional. |
Inventory
| # | Vendor | Service | Data access scope | Risk tier | SOC2 report on file | BAA status | Last reviewed | Notes |
|---|---|---|---|---|---|---|---|---|
| 1 | Microsoft Corporation | Azure (compute, storage, identity, Key Vault, Azure OpenAI) | Full ePHI (hosting) | CRITICAL | SOC2 Type II + HITRUST + FedRAMP | IN_FORCE via MBSA | 2026-04 | BAA covers Azure AI/OpenAI; verified in latest MBSA amendment |
| 2 | Microsoft Corporation | M365 / SharePoint / Teams | Full ePHI (files, collab) | CRITICAL | SOC2 Type II | IN_FORCE via MBSA | 2026-04 | Covered by the same MBSA umbrella; M365 data residency US |
| 3 | Amazon Web Services | AWS (backup, DR, identity, networking across 7 accounts) | Full ePHI (backup + DR) | CRITICAL | SOC2 Type II + SOC1 + ISO 27001 + FedRAMP | IN_FORCE via AWS HIPAA agreement (BAA addendum) | 2026-04 | All 7 accounts covered; S3 Object Lock + KMS encryption |
| 4 | Arctic Wolf Networks | Managed Detection and Response (MDR) agent on all VLCs | Full ePHI (log visibility) | CRITICAL | SOC2 Type II | TBD — Adriana to confirm by May 2026 | 2026-04 | Agent has broad Azure read access; act-first authorization. HIGH finding until BAA confirmed. |
| 5 | Keeper Security | Privileged Access Management (PAM) + vault | No ePHI by default; stores ePHI-adjacent credentials | HIGH | SOC2 Type II + ISO 27001 | TBD — Adriana to confirm by May 2026 | 2026-04 | Session recording of DC/firewall/database access. HIGH finding until BAA confirmed. |
| 6 | Twingate | Zero Trust Access (ZTA) connector | Network-level; no direct ePHI | MEDIUM | SOC2 Type II | TBD — Adriana to confirm by May 2026 | 2026-04 | BAA advisable given privileged admin tunneling through Twingate. |
| 7 | Palo Alto Networks | VM-Series NGFW + Panorama | Network-level only (inspection) | MEDIUM | SOC2 Type II + ISO 27001 | NOT APPLICABLE (network device, no ePHI storage) | 2026-04 | No ePHI leaves the firewall boundary; BAA not required. |
| 8 | Palo Alto Networks | Cortex XDR | Endpoint telemetry (may include ePHI in process logs) | HIGH | SOC2 Type II | TBD — Adriana to confirm by May 2026 | 2026-04 | Behavioral telemetry could incidentally capture ePHI filenames. HIGH finding until BAA confirmed. |
| 9 | Microsoft Corporation | Azure OpenAI (gpt-4o) | Input prompts from Kobe; policy forbids ePHI in prompts | HIGH | SOC2 Type II (MBSA coverage) | IN_FORCE via MBSA (no-training and no-PHI-in-prompts policy acknowledged) | 2026-04 | Data residency US; content filtering active; "no PHI in prompts" policy published. |
| 10 | KnowBe4 | Phishing simulation + training | Employee email addresses only | LOW | SOC2 Type II | IN_FORCE | 2026-04 | No ePHI access; standard vendor DPA sufficient. |
| 11 | GitHub (Microsoft) | Source code hosting + Actions | Code only, no ePHI | LOW | SOC2 Type II | Not required (no ePHI) | 2026-04 | OIDC authentication; SHA-pinned Actions. |
| 12 | Veeam Software | Backup + Replication | Full ePHI (backup images) | CRITICAL | SOC2 Type II | IN_FORCE | 2026-04 | On-prem software; Cirius controls the keys. |
| 13 | Cloudflare | DNS + edge / secops.bedrockcybersecurity.org | Metadata only; TLS-terminated traffic | MEDIUM | SOC2 Type II + ISO 27001 | Not required (no ePHI storage) | 2026-04 | TLS terminates at Cloudflare; no long-term body retention. |
Gap summary
| Vendor | Gap | Impact | Action |
|---|---|---|---|
| Arctic Wolf | BAA status TBD | CRITICAL-tier vendor without confirmed BAA | Adriana to confirm by May 2026 |
| Keeper Security | BAA status TBD | HIGH-tier vendor without confirmed BAA | Adriana to confirm by May 2026 |
| Twingate | BAA status TBD | MEDIUM-tier vendor without confirmed BAA | Adriana to confirm by May 2026 |
| Cortex XDR (PAN) | BAA status TBD | HIGH-tier vendor without confirmed BAA | Adriana to confirm by May 2026 |
All four items above MUST be closed before the September 2026 SOC2 audit. Until closed, each is a HIGH finding in the compliance scorecard.
Adding a new vendor
- Open a SecOps story with
category=vendor-onboarding - Collect: SOC2 Type II (or equivalent) report, BAA (or confirmation of non-applicability), data flow diagram, risk tier assignment
- Rory reviews risk tier; Adriana finalizes BAA
- Once IN_FORCE, add a row to this inventory, update compliance scorecard
- For CRITICAL-tier, add vendor to the incident-response.md breach notification list
Document history
| Date | Change | Author |
|---|---|---|
| April 2026 | Initial inventory covering 13 vendors | Kobe |