CHPC Business Associate Agreements and Third-Party Compliance 1 — Questions and Answers
Question 1: Under HIPAA, which entity is required to sign a Business Associate Agreement (BAA) with a covered entity?
- A vendor that creates, receives, maintains, or transmits PHI on behalf of the covered entity (Correct answer)
- Any vendor that provides services to the covered entity regardless of PHI access
- Only vendors that handle electronic PHI
- Only vendors that store PHI in the cloud
Correct answer: A vendor that creates, receives, maintains, or transmits PHI on behalf of the covered entity
A BAA is required with any business associate that creates, receives, maintains, or transmits PHI while performing services on behalf of the covered entity.
Question 2: Which of the following is NOT required to be included in a Business Associate Agreement?
- The business associate's liability insurance coverage amount (Correct answer)
- Permitted uses and disclosures of PHI by the business associate
- Requirements to report breaches to the covered entity
- Obligation to return or destroy PHI upon termination
Correct answer: The business associate's liability insurance coverage amount
HIPAA mandates specific BAA provisions about permitted uses, safeguards, breach reporting, and PHI disposition, but does not require disclosure of the BA's insurance coverage.
Question 3: A business associate hires a subcontractor who will have access to PHI. What must the business associate do?
- Execute a BAA with the subcontractor that provides equivalent PHI protections (Correct answer)
- Obtain written approval from the covered entity before hiring the subcontractor
- Simply notify the covered entity that a subcontractor will be used
- Nothing, as subcontractors are not covered by HIPAA
Correct answer: Execute a BAA with the subcontractor that provides equivalent PHI protections
Business associates must obtain satisfactory assurances (via a BAA) from subcontractors that they will appropriately safeguard the PHI they handle.
Question 4: When a covered entity discovers that a business associate has materially breached the BAA and the violation has not been cured, what must the covered entity do?
- Terminate the contract with the business associate if feasible (Correct answer)
- File an immediate complaint with HHS OCR
- Notify the affected patients directly
- Suspend the BAA for 60 days while investigating
Correct answer: Terminate the contract with the business associate if feasible
HIPAA requires the covered entity to terminate the contract if a business associate materially breaches the BAA and does not cure the breach when feasible.
Question 5: Which of the following entities is considered a business associate under HIPAA?
- A cloud service provider that stores PHI for a covered entity (Correct answer)
- A covered entity's own workforce members
- A healthcare clearinghouse transmitting claims on behalf of itself
- An individual providing incidental services with no PHI access
Correct answer: A cloud service provider that stores PHI for a covered entity
Cloud service providers that store or process PHI on behalf of covered entities are business associates and require a BAA.
Question 6: Under HITECH, business associates are directly liable for which of the following?
- Compliance with the HIPAA Security Rule's required and addressable safeguards (Correct answer)
- Meeting state insurance commission standards
- HIPAA Privacy Rule provisions only when acting outside the BAA scope
- Only civil penalties assigned by the covered entity
Correct answer: Compliance with the HIPAA Security Rule's required and addressable safeguards
HITECH made business associates directly subject to the HIPAA Security Rule and certain Privacy Rule provisions, meaning HHS OCR can penalize them directly.
Under HIPAA, which entity is required to sign a Business Associate Agreement (BAA) with a covered entity?