HIPAA - Health Insurance Portability and Accountability Act Business Associate Agreements Questions and Answers — Questions and Answers
Question 1: A covered entity hires a third-party data analytics firm to process patient data for a quality improvement study. The analytics firm then hires a cloud storage provider to host the data. According to HIPAA, what is the minimum requirement for Business Associate Agreements (BAAs) in this scenario?
- The covered entity must have a BAA with the analytics firm, and the analytics firm must have a separate BAA with the cloud provider. (Correct answer)
- The covered entity must have a single, three-party BAA with both the analytics firm and the cloud provider.
- The covered entity only needs a BAA with the analytics firm, as this agreement automatically extends to any of their subcontractors.
- No BAAs are required as long as the data is de-identified before being transferred to the cloud provider.
Correct answer: The covered entity must have a BAA with the analytics firm, and the analytics firm must have a separate BAA with the cloud provider.
HIPAA requires a 'chain of custody' for Protected Health Information (PHI). The covered entity must have a BAA with its direct business associate (the analytics firm). That business associate must then have its own BAA with its subcontractor (the cloud provider) that will handle the PHI. This ensures that HIPAA protections and liability flow down the entire chain of vendors handling the PHI.
Question 2: Which of the following is a direct liability for a Business Associate under the HIPAA Omnibus Rule?
- Failing to provide a Notice of Privacy Practices to patients.
- Failure to comply with the HIPAA Security Rule. (Correct answer)
- Charging an unreasonable, cost-based fee for providing an individual with access to their PHI.
- Designating a new Privacy Official without notifying the covered entity.
Correct answer: Failure to comply with the HIPAA Security Rule.
The HIPAA Omnibus Rule and HITECH Act made Business Associates directly liable for compliance with the HIPAA Security Rule. This includes implementing administrative, physical, and technical safeguards. Other duties, like providing a Notice of Privacy Practices or liability for charging unreasonable fees for records access, generally remain the direct responsibility of the Covered Entity.
Question 3: A Business Associate Agreement (BAA) must include a provision that addresses the termination of the agreement. Which of the following is a required element of this termination provision?
- A clause stating that the BAA is perpetual and can only be terminated by mutual consent.
- A requirement that the business associate pay a financial penalty to the covered entity upon any termination.
- A mandate for the business associate to return or destroy all PHI at the end of the contract. (Correct answer)
- A provision that all PHI becomes the property of the business associate upon termination.
Correct answer: A mandate for the business associate to return or destroy all PHI at the end of the contract.
A standard and required component of a BAA is a clause specifying that upon termination of the contract, the business associate must, if feasible, return or destroy all PHI received from, or created or received by the business associate on behalf of, the covered entity. If this is not feasible, protections must be extended to the information, and limits must be placed on further uses and disclosures.
Question 4: In which of the following situations is a Business Associate Agreement (BAA) NOT required?
- A hospital hires a shredding company to dispose of paper records containing PHI.
- A health plan uses a third-party administrator to process claims.
- A physician's office uses a courier service, like the US Postal Service, to mail patient records to another provider for treatment purposes. (Correct answer)
- A medical practice hires an IT consultant who has persistent access to their electronic health record (EHR) system.
Correct answer: A physician's office uses a courier service, like the US Postal Service, to mail patient records to another provider for treatment purposes.
HIPAA does not require a BAA with entities that act as a mere conduit for PHI, such as the US Postal Service or other couriers, where access to PHI is transient and not persistent. The other scenarios involve services where the vendor creates, receives, maintains, or transmits PHI on behalf of the covered entity, which explicitly defines them as business associates requiring a BAA.
Question 5: A covered entity learns that its business associate has a pattern of non-compliance that constitutes a material breach of the Business Associate Agreement (BAA). If the business associate fails to cure the breach, what is the covered entity's primary obligation under HIPAA?
- Report the business associate to the local law enforcement agency.
- Immediately pay any fines on behalf of the business associate.
- Publish a notice of the business associate's non-compliance in a major newspaper.
- Terminate the BAA with the business associate, if feasible. (Correct answer)
Correct answer: Terminate the BAA with the business associate, if feasible.
If a covered entity knows of a material breach or violation by the business associate, it must take reasonable steps to cure the breach or end the violation. If such steps are unsuccessful, the covered entity is required to terminate the contract or arrangement, if doing so is feasible.
Question 6: A law firm provides legal services to a hospital and, in the course of its work, has access to PHI. Under HIPAA, what is the relationship between the law firm and the hospital?
- The law firm is considered part of the hospital's workforce and does not need a BAA.
- The law firm is a 'Covered Entity' in this context, operating under its own HIPAA policies.
- The law firm is a 'Business Associate' and must have a signed BAA with the hospital. (Correct answer)
- The law firm is exempt from HIPAA because legal services are not a core healthcare function.
Correct answer: The law firm is a 'Business Associate' and must have a signed BAA with the hospital.
A business associate is a person or entity that performs certain functions or activities involving the use or disclosure of PHI on behalf of a covered entity. Providing legal services that involve access to PHI is explicitly listed as a business associate function. Therefore, the hospital (covered entity) must have a signed BAA with the law firm (business associate).
A covered entity hires a third-party data analytics firm to process patient data for a quality improvement study.
The analytics firm then hires a cloud storage provider to host the data.
According to HIPAA, what is the minimum requirement for Business Associate Agreements (BAAs) in this scenario?