What was said
What this says
Current to 10 Oct 26After discovery, Jordan Pike recapped Enterprise and a 30 Jun 2026 forecast date. CISO Megan Alvarez replied that nothing is approved, the review has not started, and she wants four written answers with firm commitments.
Ask: Megan wants written answers on incidents in the last ninety days, storage and staff access, third parties, and HIPAA obligations. She rejects best-efforts wording.
Customer view: She treats 30 Jun 2026 as BB-Demo's planning date and nothing more. The review starts only when documentation is held in writing.
Next: Jordan must send security documentation and written answers. Megan will then name the documents she requires.
The thread
Updated 9 Oct 26Messages
- Jordan Pike 9 Mar 2026 17:12Hi Ben, hi Megan, Thanks for the time on the discovery call. A short recap, then where I think we go next. What I heard: the aim is to give client-services teams one view of each hospital client, with everything running inside your own Snowflake account. We talked about Enterprise as the tier that fits, given the size of the teams and the review you'll need to run. To be transparent, the date we have in our forecast for a decision is 30 Jun 2026. That is our planning date, not a commitment from anyone at Quillmark, and I know it depends entirely on how your security review goes. Next steps on our side: - We'll send our security documentation to Megan so the review can start. - We'll answer written questions in writing, including anything about incident history. - I'll set up a working session between your security team and ours if that would help. Megan, what do you need from us first, and in what format? I'd rather hear it now than find out halfway through. Thanks, Jordan
- Megan Alvarez 9 Mar 2026 19:10Jordan, Thank you for the recap. For the record, nothing discussed on the call constitutes an approval of any kind, and the review has not started until we hold your documentation in writing. Please respond to the following in writing: Question one: please describe any incidents in the last ninety days, including any that did not involve customer data, and what was done about each. Question two: confirm where our data would be stored and processed, and which of your staff could access it. Please state this precisely, not as a general description. Question three: list any third parties that would handle our data, and the contractual terms that bind them. Question four: confirm in writing how you meet the obligations that apply to us under HIPAA. A statement that you will make best efforts is not sufficient for our risk posture. We need commitments we can hold you to. I will confirm the documents I require once I see your responses. The 30 Jun 2026 date is noted as your planning date and nothing more. Megan Alvarez, CISO