โ† All CHP Flashcard Decks

CHP Business Associates & Vendor Management Flashcards

6 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CHP Business Associates & Vendor Management flashcards as text
  1. Under HIPAA, a Business Associate Agreement (BAA) is required when a vendor does which of the following?

    Answer: Creates, receives, maintains, or transmits PHI on behalf of a covered entity

    A BAA is required whenever a vendor creates, receives, maintains, or transmits PHI while performing services or functions on behalf of a covered entity.

  2. Which of the following is NOT a required element of a HIPAA Business Associate Agreement?

    Answer: The business associate's annual revenue and profit margins

    Financial figures such as annual revenue are not required elements of a HIPAA Business Associate Agreement.

  3. When a business associate discovers a breach of unsecured PHI, it must notify the covered entity:

    Answer: Without unreasonable delay and no later than 60 days after discovery

    Business associates must notify the covered entity of a breach without unreasonable delay and within no more than 60 days after discovery.

  4. Under HIPAA, subcontractors of business associates who handle PHI are treated as:

    Answer: Business associates with direct HIPAA obligations

    Subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate are themselves considered business associates with direct HIPAA obligations.

  5. Which federal legislation made business associates directly subject to HIPAA compliance obligations?

    Answer: The Health Information Technology for Economic and Clinical Health (HITECH) Act

    The HITECH Act of 2009 made business associates directly liable for HIPAA compliance, extending obligations beyond covered entities.

  6. A covered entity discovers that its business associate has violated the terms of their BAA. What is the covered entity's first required step?

    Answer: Take reasonable steps to cure the breach or end the violation

    Upon discovering a BAA violation, the covered entity must first take reasonable steps to cure the breach or end the violation before escalating.