Skip to content

Vendor Risk Inventory

Purpose: Central inventory of third-party vendors that create, receive, maintain, or transmit ePHI on behalf of Cirius Group, plus other vendors with privileged access to the environment. Supports HIPAA §164.308(b)(1), §164.314(a) (Business Associate contracts) and SOC2 CC9.2 (vendor management).

Owner: Adriana (BAA / vendor / risk docs) with Rory (Security Officer) Audience: Security Officer, Business Associate counterparties, auditors Review frequency: Annual (September, pre-audit) and when any vendor changes scope, data access, or attestation status Last refreshed: April 2026


How this inventory is used

  1. Onboarding — no new vendor is granted ePHI access until a row is added here with BAA status IN_FORCE
  2. Monthly gap check — any vendor with BAA status != IN_FORCE is flagged HIGH finding in the compliance scorecard
  3. Audit evidence — the most recent SOC2 Type II / SOC2+HITRUST / ISO 27001 report for each vendor lives in SharePoint → Compliance → Vendor Reports → <vendor> → <YYYY-MM>/
  4. Risk rating — combines likelihood of compromise, ePHI blast radius, and vendor's own attestations

Risk rating methodology

Risk tierCriteria
CRITICALDirect access to ePHI at scale + admin-level access to our tenant. BAA MUST be in force.
HIGHAccess to ePHI at smaller scale OR admin-level access without ePHI. BAA required.
MEDIUMNetwork-level access or metadata access. BAA typically required.
LOWNo ePHI access; infrastructure-only (network, monitoring) where exposure is minimal. BAA may be optional.

Inventory

#VendorServiceData access scopeRisk tierSOC2 report on fileBAA statusLast reviewedNotes
1Microsoft CorporationAzure (compute, storage, identity, Key Vault, Azure OpenAI)Full ePHI (hosting)CRITICALSOC2 Type II + HITRUST + FedRAMPIN_FORCE via MBSA2026-04BAA covers Azure AI/OpenAI; verified in latest MBSA amendment
2Microsoft CorporationM365 / SharePoint / TeamsFull ePHI (files, collab)CRITICALSOC2 Type IIIN_FORCE via MBSA2026-04Covered by the same MBSA umbrella; M365 data residency US
3Amazon Web ServicesAWS (backup, DR, identity, networking across 7 accounts)Full ePHI (backup + DR)CRITICALSOC2 Type II + SOC1 + ISO 27001 + FedRAMPIN_FORCE via AWS HIPAA agreement (BAA addendum)2026-04All 7 accounts covered; S3 Object Lock + KMS encryption
4Arctic Wolf NetworksManaged Detection and Response (MDR) agent on all VLCsFull ePHI (log visibility)CRITICALSOC2 Type IITBD — Adriana to confirm by May 20262026-04Agent has broad Azure read access; act-first authorization. HIGH finding until BAA confirmed.
5Keeper SecurityPrivileged Access Management (PAM) + vaultNo ePHI by default; stores ePHI-adjacent credentialsHIGHSOC2 Type II + ISO 27001TBD — Adriana to confirm by May 20262026-04Session recording of DC/firewall/database access. HIGH finding until BAA confirmed.
6TwingateZero Trust Access (ZTA) connectorNetwork-level; no direct ePHIMEDIUMSOC2 Type IITBD — Adriana to confirm by May 20262026-04BAA advisable given privileged admin tunneling through Twingate.
7Palo Alto NetworksVM-Series NGFW + PanoramaNetwork-level only (inspection)MEDIUMSOC2 Type II + ISO 27001NOT APPLICABLE (network device, no ePHI storage)2026-04No ePHI leaves the firewall boundary; BAA not required.
8Palo Alto NetworksCortex XDREndpoint telemetry (may include ePHI in process logs)HIGHSOC2 Type IITBD — Adriana to confirm by May 20262026-04Behavioral telemetry could incidentally capture ePHI filenames. HIGH finding until BAA confirmed.
9Microsoft CorporationAzure OpenAI (gpt-4o)Input prompts from Kobe; policy forbids ePHI in promptsHIGHSOC2 Type II (MBSA coverage)IN_FORCE via MBSA (no-training and no-PHI-in-prompts policy acknowledged)2026-04Data residency US; content filtering active; "no PHI in prompts" policy published.
10KnowBe4Phishing simulation + trainingEmployee email addresses onlyLOWSOC2 Type IIIN_FORCE2026-04No ePHI access; standard vendor DPA sufficient.
11GitHub (Microsoft)Source code hosting + ActionsCode only, no ePHILOWSOC2 Type IINot required (no ePHI)2026-04OIDC authentication; SHA-pinned Actions.
12Veeam SoftwareBackup + ReplicationFull ePHI (backup images)CRITICALSOC2 Type IIIN_FORCE2026-04On-prem software; Cirius controls the keys.
13CloudflareDNS + edge / secops.bedrockcybersecurity.orgMetadata only; TLS-terminated trafficMEDIUMSOC2 Type II + ISO 27001Not required (no ePHI storage)2026-04TLS terminates at Cloudflare; no long-term body retention.

Gap summary

VendorGapImpactAction
Arctic WolfBAA status TBDCRITICAL-tier vendor without confirmed BAAAdriana to confirm by May 2026
Keeper SecurityBAA status TBDHIGH-tier vendor without confirmed BAAAdriana to confirm by May 2026
TwingateBAA status TBDMEDIUM-tier vendor without confirmed BAAAdriana to confirm by May 2026
Cortex XDR (PAN)BAA status TBDHIGH-tier vendor without confirmed BAAAdriana to confirm by May 2026

All four items above MUST be closed before the September 2026 SOC2 audit. Until closed, each is a HIGH finding in the compliance scorecard.


Adding a new vendor

  1. Open a SecOps story with category=vendor-onboarding
  2. Collect: SOC2 Type II (or equivalent) report, BAA (or confirmation of non-applicability), data flow diagram, risk tier assignment
  3. Rory reviews risk tier; Adriana finalizes BAA
  4. Once IN_FORCE, add a row to this inventory, update compliance scorecard
  5. For CRITICAL-tier, add vendor to the incident-response.md breach notification list

Document history

DateChangeAuthor
April 2026Initial inventory covering 13 vendorsKobe

Internal use only — Cirius Group