CHPC Business Associate Agreements and Third-Party Compliance 2 — Questions and Answers
Question 1: A business associate discovers a breach of unsecured PHI. How soon must it notify the covered entity?
- Without unreasonable delay and no later than 60 days after discovery (Correct answer)
- Within 24 hours of discovery
- Within 30 days of discovery regardless of circumstances
- Immediately upon confirmation that it was a breach
Correct answer: Without unreasonable delay and no later than 60 days after discovery
Business associates must notify the covered entity without unreasonable delay and within 60 days of discovering a breach of unsecured PHI.
Question 2: Which of the following is a permitted use of PHI by a business associate WITHOUT requiring additional patient authorization?
- Using PHI for the specific services described in the BAA with the covered entity (Correct answer)
- Selling PHI to a marketing firm for research purposes
- Using PHI to create a new commercial database product
- Disclosing PHI to another covered entity for their treatment purposes
Correct answer: Using PHI for the specific services described in the BAA with the covered entity
A business associate may only use or disclose PHI as permitted by its BAA with the covered entity or as required by law.
Question 3: What happens to a BAA if the underlying covered entity–business associate relationship ends?
- The BA must return or destroy all PHI and confirm compliance to the covered entity (Correct answer)
- The BAA automatically extends for one additional year
- The BA may retain PHI indefinitely for its own business records
- No action is required as long as the BA keeps PHI secure
Correct answer: The BA must return or destroy all PHI and confirm compliance to the covered entity
Upon termination of the relationship, the business associate must return or destroy all PHI and certify that no copies have been retained, unless retention is legally required.
Question 4: A HIPAA privacy officer is conducting a third-party vendor risk assessment. Which element should be PRIORITIZED in evaluating a new cloud vendor?
- Whether the vendor will sign a HIPAA-compliant BAA and has documented security controls (Correct answer)
- The vendor's pricing tier and market share
- Whether the vendor has a U.S.-based headquarters
- The number of other healthcare clients the vendor serves
Correct answer: Whether the vendor will sign a HIPAA-compliant BAA and has documented security controls
The most critical factors are the vendor's willingness to sign a compliant BAA and evidence of security controls that protect PHI.
Question 5: Which scenario does NOT require a Business Associate Agreement?
- A U.S. Postal Service carrier that incidentally delivers paper PHI on behalf of a covered entity (Correct answer)
- An IT firm that manages EHR servers for a hospital
- A medical billing company processing insurance claims
- A legal firm providing services involving review of patient records
Correct answer: A U.S. Postal Service carrier that incidentally delivers paper PHI on behalf of a covered entity
HIPAA explicitly exempts transmission-only entities like the USPS from the business associate definition when they are not accessing PHI content.
Question 6: A business associate receives a subpoena for PHI. What should it do first?
- Notify the covered entity and review whether disclosure is permitted under the BAA or law (Correct answer)
- Immediately comply with the subpoena to avoid legal penalty
- Refuse the subpoena entirely until HHS approves the disclosure
- Disclose only after the patient provides written consent
Correct answer: Notify the covered entity and review whether disclosure is permitted under the BAA or law
Business associates should consult their BAA and notify the covered entity before disclosing, since the BA's permitted disclosures are governed by the agreement and applicable law.
A business associate discovers a breach of unsecured PHI.
How soon must it notify the covered entity?